At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at jnj.com
As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit.
Job Function:
FinanceJob Sub Function:
Internal AuditJob Category:
ProfessionalAll Job Posting Locations:
New Brunswick, New Jersey, United States of AmericaJob Description:
Johnson & Johnson Global Audit & Assurance (GAA) organization is seeking a Senior Technology Auditor in New Brunswick, NJ.
Global Audit & Assurance’s primary mission is to provide independent, objective assurance and advisory services to assist management in maintaining compliance with government and industry regulations, mitigating risk, and achieving operational excellence. The Senior Auditor will work across Johnson & Johnson's global technology environments, collaborate with teams throughout the organization to evaluate risks and internal controls related to cybersecurity, cloud, artificial intelligence, digital platforms, enterprise applications, privacy, and business transformation initiatives. This role provides broad exposure to senior leadership and opportunities to evaluate critical technology initiatives supporting one of the world's largest healthcare organizations.
Responsibilities:
- Perform risk-based technology audits with limited supervision, including Technology Risk-Based Reviews, pre-implementation reviews, and SOX 404 ITGC testing.
- Lead audit workstreams by providing direction, delegating responsibilities, reviewing work, and delivering constructive feedback.
- Plan and execute audit procedures, document assigned review areas and evaluate the design and operating effectiveness of controls across financial reporting, healthcare operations, privacy, data protection, and cybersecurity.
- Develop timely, high-quality audit deliverables, analyses, and communications that clearly support conclusions, demonstrate professional judgment, and meet departmental quality standards.
- Identify key risks, root causes, and business impacts to develop practical recommendations to strengthen controls and reduce technology risk.
- Coordinate ongoing control testing in accordance with industry audit standards and J&J guidelines.
- Build trusted relationships with global cross-functional teams and external stakeholders throughout audit engagements.
- Leverage data analytics, automation, continuous monitoring, and AI-enabled audit techniques to deliver risk insights and enhance audit effectiveness.
- Translate complex technical matters into clear business risks, executive-level insights, and actionable recommendations for technical and non-technical audiences.
- Track remediation of audit findings and validate the adequacy and sustainability of management corrective actions.
- Maintain awareness of relevant laws, regulations, industry standards, and emerging technology risks, including cloud, artificial intelligence, data governance, major system implementations, cybersecurity, privacy, and third-party dependencies.
Qualifications - Required
- Bachelor’s degree (IT, Computer Science, Data Science, Accounting, or related field preferred).
- Minimum of 3 years of professional experience in information technology, audit, assurance or advisory services, preferably within a multinational company, Big 4 firm, leading risk advisory firms or public accounting organization.
- Demonstrated ability to independently execute audit procedures, assess risk, evaluate controls and communicate recommendations to management.
- Strong working knowledge of technology risk, cybersecurity, and information security frameworks and control concepts (e.g., NIST, COBIT, ISO)
- Strong analytical skills with a risk‑and‑control mindset.
- Ability to apply critical thinking and professional judgement to identify emerging risks and assess complex technology environments. Demonstrated ability to build trusted relationships, influence stakeholders, collaborate across teams and levels of management, and effectively lead audit workstreams and projects. Excellent presentation and written communication skills.
- Ability to work in a highly collaborative, team-oriented environment.
- Demonstrated curiosity and commitment to continuous learning in emerging technology, cybersecurity, artificial intelligence and digital risk domains
- Ability to travel domestically and internationally (up to 40%).
Qualifications – Preferred:
- Experience in cybersecurity, cloud technologies, privacy, AI & data governance, supply chain/third-party risk, and technology controls;
- Proficiency/experience in Tech Risk Frameworks (e.g., COBIT, NIST, ISO)
- Familiarity with data analytic tools and knowledge of agile development, and emerging technologies (e.g., AI/ML, RPA).
- Experience with SAP HANA.
- Exposure and understanding of internal control concepts and processes with practical experience in regulatory compliance, internal audits, risk management, and process improvement.
- Professional security, audit, or control-related certification, such as CISSP, CISA, CRISC, or CIA.
Johnson & Johnson is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status or other characteristics protected by federal, state or local law. We actively seek qualified candidates who are protected veterans and individuals with disabilities as defined under VEVRAA and Section 503 of the Rehabilitation Act.
Johnson & Johnson is committed to providing an interview process that is inclusive of our applicants’ needs. If you are an individual with a disability and would like to request an accommodation, external applicants please contact us via https://www.jnj.com/contact-us/careers . internal employees contact AskGS to be directed to your accommodation resource.
If you are under 18 years of age, you (the candidate) may need to obtain the necessary working papers or other documentation required by state law to start the assignment, as well as get a parent’s consent for the background check.
Required Skills:
Preferred Skills:
Analytical Reasoning, Audit and Compliance Trends, Audit Reporting, Business Behavior, Compliance Policies, Data Analysis, Execution Focus, Financial Analysis, Financial Risk Management (FRM), Internal Auditing, Internal Controls, Issue Escalation, Leverages Information, Problem Solving, Process Oriented, Professional Ethics, Risk AssessmentsThe anticipated base pay range for this position is :
$79,000.00 - $127,650.00Additional Description for Pay Transparency:
Subject to the terms of their respective plans, employees are eligible to participate in the Company’s consolidated retirement plan (pension) and savings plan (401(k)).Subject to the terms of their respective policies and date of hire, employees are eligible for the following time off benefits:
Vacation –120 hours per calendar year
Sick time - 40 hours per calendar year; for employees who reside in the State of Colorado –48 hours per calendar year; for employees who reside in the State of Washington –56 hours per calendar year
Holiday pay, including Floating Holidays –13 days per calendar year
Work, Personal and Family Time - up to 40 hours per calendar year
Parental Leave – 480 hours within one year of the birth/adoption/foster care of a child
Bereavement Leave – 240 hours for an immediate family member: 40 hours for an extended family member per calendar year
Caregiver Leave – 80 hours in a 52-week rolling period10 days
Volunteer Leave – 32 hours per calendar year
Military Spouse Time-Off – 80 hours per calendar year
For additional general information on Company benefits, please go to: - https://www.careers.jnj.com/employee-benefits
Skills Required
- Bachelor's degree in IT, Computer Science, Data Science, Accounting, or a related field
- At least 3 years of professional experience in information technology, audit, assurance, or advisory services
- Ability to independently execute audit procedures, assess risk, evaluate controls, and communicate recommendations
- Knowledge of technology risk, cybersecurity, information security frameworks, and control concepts, including NIST, COBIT, or ISO
- Strong analytical skills and a risk-and-control mindset
- Critical thinking and professional judgment in complex technology environments
- Ability to build relationships, influence stakeholders, collaborate across teams, and lead audit workstreams
- Excellent presentation and written communication skills
- Ability to work in a highly collaborative, team-oriented environment
- Curiosity and commitment to continuous learning in emerging technology, cybersecurity, artificial intelligence, and digital risk
- Ability to travel domestically and internationally up to 40%
- Experience in cybersecurity, cloud technologies, privacy, AI and data governance, supply chain or third-party risk, and technology controls
- Proficiency or experience with technology risk frameworks such as COBIT, NIST, or ISO
- Familiarity with data analytics tools, agile development, and emerging technologies such as AI/ML and RPA
- Experience with SAP HANA
- Experience with regulatory compliance, internal audits, risk management, internal controls, and process improvement
- Professional security, audit, or control certification such as CISSP, CISA, CRISC, or CIA
Johnson & Johnson Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Johnson & Johnson and has not been reviewed or approved by Johnson & Johnson.
-
Healthcare Strength — Healthcare coverage is characterized as comprehensive across medical, dental, and vision, with added supports like onsite clinics, fitness centers, and Employee Assistance resources. Mental-health services and wellbeing reimbursements are also described as meaningful components of the overall package.
-
Retirement Support — Retirement offerings are portrayed as a major differentiator, combining a 401(k) with employer matching and an employer-funded pension plan. Stock options and other long-term financial supports are also positioned as part of the broader rewards mix.
-
Parental & Family Support — Family-related benefits are presented as notably strong, including paid parental leave for all new parents and additional leave types for caregiving and bereavement. Financial assistance for adoption, fertility treatment, and surrogacy is highlighted as a significant support.
Johnson & Johnson Insights
What We Do
Profound Change Requires Boldness. Johnson & Johnson is the largest and most broadly based healthcare company in the world. We’re producing life-changing breakthroughs every day, and have been for the last 130 years. The combination of new technologies and your expertise enables amazing things to happen. Teams from J&J’s consumer business are creating digital tools to help people track the health of their skin. Those working in medical devices are 3-D printing artificial joints personalized for each patient, while researchers in pharmaceuticals use AI to discover lifesaving drugs. Imagine what the rest of our team of 134,000 people at 260 companies in more than 60 countries across the world is accomplishing. We redefine what it means to be a big company in today’s world. Social Media Community Guidelines: http://www.jnj.com/social-media-community-guidelines








