Skip to main content

Lead Cybersecurity Analyst

Apply now
Share
Technology and cybersecurity team

Description

At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at jnj.com.

As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit.

Job Function:

Technology Enterprise Strategy & Security

Job Sub Function:

Security & Controls

Job Category:

Scientific/Technology

All Job Posting Locations:

Alajuela, Costa Rica

Job Description:

Johnson & Johnson is hiring for a Lead Cybersecurity Analyst to join our team located in Coyol, Alajuela, Costa Rica.

Position Overview

This role will focus on Supply Chain cybersecurity for Circulatory Restoration and other business functions as needed, partnering closely with Information Technology, Supply Chain & Operations, and ISRM partners to strengthen the cybersecurity posture of critical manufacturing, distribution, logistics, and operational technology environments.

This role will bring a strong foundation in cybersecurity operations, risk management, and security governance, combined with the ability to lead across global, matrixed teams. This individual will drive the identification, assessment, prioritization, and remediation of cybersecurity risks that impact Supply Chain operations while delivering strategic security initiatives, regulatory alignment, and operational resilience.

As a trusted cybersecurity partner, you will lead security-by-design practices, drive cyber resilience efforts, and execute risk-based protection strategies across enterprise, cloud, application, and operational technology (OT) environments supporting Supply Chain.

Essential Job Functions

  • Lead cybersecurity risk assessments across Supply Chain applications, infrastructure, cloud environments, and operational technology (OT) assets.
  • Drive the identification, prioritization, and remediation of cybersecurity vulnerabilities and control gaps impacting Supply Chain operations.
  • Partner with business and technology teams to embed security-by-design principles throughout Supply Chain project lifecycles.
  • Deliver cybersecurity metrics, reports, and dashboards that measure security posture, risk trends, and remediation progress.
  • Coordinate with Security Operations Center (SOC) teams on incident investigation, containment, and remediation activities impacting Supply Chain environments.
  • Execute vulnerability management activities, including remediation tracking, risk-based prioritization, and stakeholder follow-through.
  • Lead third-party cybersecurity risk reviews and supplier security assessments relevant to Supply Chain operations.
  • Interpret and apply cybersecurity policies, standards, and regulatory requirements across Supply Chain business initiatives.
  • Drive audit readiness activities, including evidence collection, remediation planning, and stakeholder communications.
  • Advance cybersecurity awareness and shared responsibility through targeted training, communications, and engagement initiatives.
  • Drive deployment and adoption of enterprise security capabilities and controls across Supply Chain environments.
  • Partner with cross-functional teams to improve cybersecurity resilience through process optimization and automation.
  • Deliver cloud security and application security initiatives across AWS, Azure, and SaaS platforms supporting Supply Chain.

Requirements

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or related fields.
  • 5 – 7 years of experience in similar IT roles.
  • At least 5 years of experience in cybersecurity, information security, risk management, or security operations.
  • Experience performing cybersecurity risk assessments and remediation planning.
  • Strong understanding of cybersecurity frameworks and standards, including NIST Cybersecurity Framework, NIST 800-53, ISO 27001, or CIS Controls.
  • Experience supporting audit readiness, compliance activities, evidence collection, and remediation tracking.
  • Effective communication skills with the ability to influence and collaborate across technical, business, and leadership stakeholders.
  • Strong analytical, problem-solving, and critical-thinking capabilities.
  • Ability to lead multiple priorities in a fast-paced, global environment.

Preferred Qualifications

  • Professional certifications such as CISSP, CISM, CRISC, Security+, or GSEC.
  • Experience supporting regulated environments, including healthcare, medical devices, or life sciences.
  • Experience working with Supply Chain, manufacturing, logistics, distribution, or operational technology environments.
  • Familiarity with OT/ICS cybersecurity standards such as ISA/IEC 62443.
  • Knowledge of cloud security principles and platforms such as Microsoft Azure and AWS.
  • Understanding application security, SOX concepts, and secure software development practices.
  • Hands-on experience with enterprise security technologies such as SIEM platforms, endpoint security solutions, vulnerability management tools, Identity and Access Management (IAM), and network security technologies.
  • Experience with security analytics, automation, and reporting platforms.
  • Knowledge of third-party risk management and supplier security assessments.
  • Experience working within global, matrixed organizations.

Required Skills:

Preferred Skills:

Communication, Corrective and Preventive Action (CAPA), Critical Thinking, Information Security Auditing, Information Security Management System (ISMS), Information Technology (IT) Security Assessments, Information Technology Strategies, Mentorship, Network Optimization, Presentation Design, Process Optimization, Report Writing, Security Policies, Technical Credibility, Technologically Savvy, Training People, Vulnerability Assessments

Lead Cybersecurity Analyst

Apply now
Share

Not ready for a new role right now?

No worries. Join our talent community. We’ll reach out when we post new jobs that match your interests and skills so you can apply when the time is right.

Man reading on phone