Description
At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at jnj.com.
As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit.
Job Function:
FinanceJob Sub Function:
Risk ManagementJob Category:
ProfessionalAll Job Posting Locations:
Bangalore, Karnataka, India, PENJERLA, Telangana, IndiaJob Description:
Johnson & Johnson is currently seeking a “J&J IMPO UAM Governance Analyst” to join our TEAM/DEPT located in “Bengaluru, India
At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at https://www.jnj.com/.
About Innovative Medicine Principal Operations
JnJ IMPO is a Global Organization with teams based in US, Switzerland, Belgium, the Netherlands, Ireland, and Singapore working in close collaboration with R&D, Supply Chain, Commercial, Tax and Treasury.
Our greatest asset is our people, and we foster an environment where collaboration, success, passion, and diversity are celebrated. We are committed to developing the talents of our team members and providing opportunities for growth and advancement. By joining us, you become part of a community recognized for its reliability, trustworthiness, and expertise.
DE&I Statement
For more than 130 years, diversity, equity & inclusion (DEI) has been a part of our cultural fabric at Johnson & Johnson and woven into how we do business every day. Rooted in Our Credo, the values of DEI fuel our pursuit to create a healthier, more equitable world. Our diverse workforce and culture of belonging accelerate innovation to solve the world’s most pressing healthcare challenges. We know that the success of our business – and our ability to deliver meaningful solutions – depends on how well we understand and meet the diverse needs of the communities we serve. Which is why we foster a culture of inclusion and belonging where all perspectives, abilities and experiences are valued, and our people can reach their potential. At Johnson & Johnson, we all belong.
Role Purpose:
J&J Innovative Medicine (IM) Transcend is a global, multi-year end-to-end business transformation program aimed at modernizing foundational business processes through the implementation of SAP S/4 HANA. This program focuses on core functionalities related to SAP Manufacturing, Order to Cash, Procure to Pay, and Finance processes. The IMUAM team plays a crucial role in ensuring security requirements are designed and implemented compliantly within this program.
The Implementation Audit Analyst will partner with the UAM Governance Lead to establish, execute, and sustain an implementation audit and governance framework for SAP S/4 deployments. This role will focus on ensuring audit-ready documentation, traceable control evidence, clearly defined procedures, and consistent governance practices across project and operational readiness activities. The analyst will help validate that UAM processes, controls, risks, and deliverables are sufficiently documented, reviewed, and aligned with SoX, GxP, IT compliance, privacy, and internal policy requirements to support Day 1 Go Live readiness and post-go-live operational sustainability.
Key Responsibilities:
- Support implementation audit readiness by partnering with deployment, operational, compliance, and UAM teams to ensure governance processes, controls, and evidence requirements are defined, understood, and ready for each SAP S/4 go-live phase.
- Embed audit and compliance requirements into the UAM project methodology, including control checkpoints, documentation standards, evidence retention expectations, and health checks across implementation milestones.
- Perform implementation governance health checks to assess adherence to UAM strategy, project controls, deliverable quality, remediation tracking, and readiness criteria.
- Maintain, validate, and organize audit-ready documentation, including process narratives, control evidence, decision logs, risk assessments, approvals, issue remediation, and go-live readiness artifacts.
- Provide implementation audit support for SoX, GxP, IT compliance, privacy, and internal control requirements, including preparation of evidence packages and responses to audit inquiries.
- Support implementation risk assessments focused on user access, segregation of duties, sensitive access, data migration, role design, provisioning, and operational handover risks.
- Monitor compliance with UAM controls during implementation, with particular focus on SoD, sensitive access, emergency access, role lifecycle controls, approvals, and evidence completeness.
- Support remediation tracking for governance, audit, and control gaps, ensuring issues are documented, assigned, resolved, and validated before go-live where required.
- Contribute to the UAM taxonomy, control model, and service model as they relate to implementation governance, audit readiness, operational transition, and long-term sustainment.
- Deliver audit-focused UAM governance updates, readiness summaries, and framework materials to key stakeholders tailored to SAP S/4 implementation needs.
Experience and Skills:
Required:
- Bachelor’s degree in Governance, Risk Management, Compliance, Audit, Information Technology, Engineering, or a related field.
- Minimum of 5 years of experience in audit/ controls, compliance, or enterprise risk management, preferably within the Life Sciences or Pharmaceutical industry.
- 3–5 years of experience supporting IT audits, implementation audits, IT control assessments, evidence reviews, or compliance readiness activities.
- 3–5 years of experience working with regulatory and compliance frameworks such as SoX, GxP, Privacy/GDPR, ITGC, and internal control standards.
- Experience supporting large-scale system implementations, with an understanding of project lifecycle methodology, go-live readiness, operational handover, and post-go-live sustainment.
- Familiarity with user access provisioning, SAP GRC Access Control, identity management tools, access approvals, and access review processes.
- Understanding of SAP authorization concepts, SAP Security principles, role design, user lifecycle management, and access risk management.
- Understanding of SoD concepts, sensitive access risk, mitigation controls, remediation strategies, and compliance monitoring approaches.
- Understanding of risk matrices, rulesets, control mapping, data analysis, conversion, migration, and evidence traceability.
- Strong attention to detail with proven ability to prepare audit-ready documentation, process narratives, control evidence, policies, procedures, and governance materials.
- Strong project management, stakeholder coordination, communication, and follow-up skills, including the ability to track risks, issues, actions, and remediation across multiple teams.
- Fluency in English with excellent written and verbal communication skills, including the ability to communicate audit, compliance, and control topics clearly to technical and non-technical audiences.
- Ability to work effectively in a virtual or remote environment and collaborate with cross-functional, cross-cultural, and geographically distributed teams.
- Excellent team player with a customer service-oriented mindset and strong ownership of audit readiness and compliance outcomes.
Preferred:
- Experience in the Life Sciences or Pharmaceutical industry, particularly in regulated system implementation or compliance environments.
- Prior experience supporting SAP Security, SAP S/4, SAP GRC, Identity Governance, or UAM implementation audits.
- Demonstrated ability to support implementation audit planning, evidence collection, control validation, issue remediation, and stakeholder reporting.
- Ability to work with team members of varying technical expertise and communicate clearly, concisely, and tactfully with management, peers, auditors, project teams, and operational stakeholders.
- Relevant certifications such as CISA, CISM, CISSP, CRISC, SAP Security, or GRC-related certifications are a plus.
Other Requirements:
- Ability to work on-site a minimum of three days per week, with up to two remote workdays per the flexible work policy.
- May require up to 10% domestic and/or international travel.
J&J Innovative Medicine Principal Operations is committed to providing an inclusive and equitable work environment and promoting the well-being of all employees. Applicants interested in flexible work arrangements are welcome to apply, and we are open to discussing these options during the hiring process.
Required Skills:
Preferred Skills:
Accounting, Agility Jumps, Analytical Reasoning, Budget Management, Business Behavior, Compliance Frameworks, Data Reporting, Detail-Oriented, Financial Analysis, Financial Risk Management (FRM), Internal Controls, Numerically Savvy, Problem Solving, Process Oriented, Regulatory Environment, Risk Assessments, Risk Measurement
