Description
At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at jnj.com.
As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit.
Job Function:
FinanceJob Sub Function:
Risk ManagementJob Category:
ProfessionalAll Job Posting Locations:
Bangalore, Karnataka, India, PENJERLA, Telangana, IndiaJob Description:
Johnson & Johnson is currently seeking a “J&J IMPO UAM GRC Analyst” to join our TEAM/DEPT located in “Bengaluru, India
At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at https://www.jnj.com/.
About Innovative Medicine Principal Operations
JnJ IMPO is a Global Organization with teams based in US, Switzerland, Belgium, the Netherlands, Ireland, and Singapore working in close collaboration with R&D, Supply Chain, Commercial, Tax and Treasury.
Our greatest asset is our people, and we foster an environment where collaboration, success, passion, and diversity are celebrated. We are committed to developing the talents of our team members and providing opportunities for growth and advancement. By joining us, you become part of a community recognized for its reliability, trustworthiness, and expertise.
DE&I Statement
For more than 130 years, diversity, equity & inclusion (DEI) has been a part of our cultural fabric at Johnson & Johnson and woven into how we do business every day. Rooted in Our Credo, the values of DEI fuel our pursuit to create a healthier, more equitable world. Our diverse workforce and culture of belonging accelerate innovation to solve the world’s most pressing healthcare challenges. We know that the success of our business – and our ability to deliver meaningful solutions – depends on how well we understand and meet the diverse needs of the communities we serve. Which is why we foster a culture of inclusion and belonging where all perspectives, abilities and experiences are valued, and our people can reach their potential. At Johnson & Johnson, we all belong.
Role Purpose:The purpose of the role is to support user access security and compliance across global SAP S4 systems, while driving strategic User Access Management initiatives to support organizational growth and technological for business adaptation purposes.
J&J Innovative Medicine (IM) Transcend is a global, multi-year end-to-end business transformation program aimed at modernizing foundational business processes through the implementation of SAP S/4 HANA. This program focuses on core functionalities related to SAP Manufacturing, Order to Cash, Procure to Pay, and Finance processes. The IMUAM team plays a crucial role in ensuring security requirements are designed and implemented compliantly within this program.
The GRC governance analyst will work with the UAM Governance Lead to establish and ensure a robust SAP GRC Access Control, SoD risk management, and ruleset governance framework, emphasizing accurate execution of risk analysis across role and cross-system levels, effective mitigation and ruleset updates, and comprehensive documentation and reporting practices that ensure clarity, consistency, compliance, and audit readiness.Key Responsibilities:
- Implement and support SAP GRC Access Control solutions, ensuring effective user access governance
- Perform Segregation of Duties (SoD) risk analysis across:
- Single role level
- Composite/persona role level
- Cross-system environments (where applicable)
- Propose and implement ruleset updates to eliminate inherent risks
- Update and maintain the mitigating control library
- Produce and validate risk analysis reports using SAP GRC and supporting tools (e.g., Alteryx), ensuring data accuracy and audit readiness.
- Manage the end-to-end GRC ruleset lifecycle:
- Intake, assessment, and prioritization of changes
- Consolidation of change requests (e.g., audit recommendations, new tcodes, false positives/negatives)
- Coordinate with key stakeholders including GRC CoE, SAP Security, Solution Delivery, and Compliance to align on ruleset updates and risk decisions.
- Ensure proper version control, documentation, and audit traceability for all ruleset changes and governance activities.
- Maintain and validate governance documentation (SOPs, taxonomy, playbooks) to support compliance with SoX, GxP, and IT control frameworks.
- Provide audit support by preparing evidence for SoX, GxP, and IT compliance reviews, including SoD analysis and control documentation.
- Support process improvement and automation initiatives aligned to the UAM taxonomy, including KPI definition, reporting, and continuous improvement activities.
Experience and Skills:
Required:
- Bachelor’s degree in a relevant field, with a preference for studies in Governance Risk Management, Compliance, and Audit. Engineering, Information Technology or related fields
- 3-5 years of experience in UAM / SAP GRC governance roles within an enterprise risk and control environment
- Hands-on experience with SAP GRC Access Controls
- 3-5 years of experience in conducting IT Audit and assessment of IT Controls
- 3-5 years of experience with regulatory/ compliance frameworks related to SoX, GxP, Privacy/GDPR.
- Strong experience in Segregation of Duties (SoD) concepts, including:
- Risk analysis at role and user level
- Ruleset design and maintenance
- Mitigation and remediation strategies
- Proven experience in GRC ruleset lifecycle management:
- Intake, assessment, prioritization, and consolidation of changes
- Exposure to audit-driven updates
- Experience supporting end-to-end ruleset updates including UAT testing and go-live activities
- Strong understanding of SAP authorization concepts, SAP Security principles, and role design
- Experience in risk reporting and data analysis using SAP GRC and other tools
- Fluency in English, with outstanding oral and written communication abilities.
- Proficiency in process management with strong coordination skills.
- Ability to work effectively in a virtual/remote environment and manage cross-cultural teams.
- Excellent team player and customer service-oriented mindset
Preferred:
- Experience in Life Sciences/ Pharmaceutical industry
- Prior experience in audit and SAP Security implementation roles with a focus on supporting implementation audits
- Understanding of business functions and how systems and applications are used by business partners in the context of Life Sciences, Pharmaceutical, or related industries.
- Demonstrated leadership ability to embrace innovation and change and promote a culture of ownership and continuous improvement.
- Demonstrated ability to work with team members of varying technical expertise, competence in clear, concise, and tactful communication with management, peers, and team members.
- Relevant certifications (e.g., CISSP, CISM, CISA, etc.) are a plus.
- Ability to work on-site a minimum of three days per week, with up to two remote workdays per the flexible work policy.
- May require up to 10% domestic and/or international travel.
J&J Innovative Medicine Principal Operations is committed to providing an inclusive and equitable work environment and promoting the well-being of all employees. Applicants interested in flexible work arrangements are welcome to apply, and we are open to discussing these options during the hiring process.
Required Skills:
Preferred Skills:
Accounting, Agility Jumps, Analytical Reasoning, Budget Management, Business Behavior, Compliance Frameworks, Data Reporting, Detail-Oriented, Financial Analysis, Financial Risk Management (FRM), Internal Controls, Numerically Savvy, Problem Solving, Process Oriented, Regulatory Environment, Risk Assessments, Risk Measurement
