User Access Management - Implementation Audit Analyst

Posted 4 Days Ago
Be an Early Applicant
2 Locations
In-Office or Remote
Senior level
Healthtech • Biotech • Pharmaceutical • Manufacturing
The Role
Supports audit readiness and governance for SAP S/4HANA implementations, focusing on user access management controls, segregation of duties, sensitive access, evidence traceability, risk assessments, remediation tracking, and go-live readiness. Partners with deployment, compliance, operational, and UAM teams to maintain audit-ready documentation and validate compliance with SOX, GxP, privacy, IT compliance, and internal control requirements. Provides governance updates and supports post-go-live operational sustainability.
Summary Generated by Built In

At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at jnj.com.

As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit.

Job Function:

Finance

Job Sub Function:

Risk Management

Job Category:

Professional

All Job Posting Locations:

Bangalore, Karnataka, India, PENJERLA, Telangana, India

Job Description:

Johnson & Johnson is currently seeking a “J&J IMPO UAM Governance Analyst” to join our TEAM/DEPT located in “Bengaluru, India

At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at https://www.jnj.com/. 

 

About Innovative Medicine Principal Operations

 

JnJ IMPO is a Global Organization with teams based in US, Switzerland, Belgium, the Netherlands, Ireland, and Singapore working in close collaboration with R&D, Supply Chain, Commercial, Tax and Treasury.

 

Our greatest asset is our people, and we foster an environment where collaboration, success, passion, and diversity are celebrated. We are committed to developing the talents of our team members and providing opportunities for growth and advancement. By joining us, you become part of a community recognized for its reliability, trustworthiness, and expertise.

Learn more_ IMPO video

 

DE&I Statement

For more than 130 years, diversity, equity & inclusion (DEI) has been a part of our cultural fabric at Johnson & Johnson and woven into how we do business every day. Rooted in Our Credo, the values of DEI fuel our pursuit to create a healthier, more equitable world. Our diverse workforce and culture of belonging accelerate innovation to solve the world’s most pressing healthcare challenges. We know that the success of our business – and our ability to deliver meaningful solutions – depends on how well we understand and meet the diverse needs of the communities we serve. Which is why we foster a culture of inclusion and belonging where all perspectives, abilities and experiences are valued, and our people can reach their potential. At Johnson & Johnson, we all belong.

 

  

Role Purpose:

J&J Innovative Medicine (IM) Transcend is a global, multi-year end-to-end business transformation program aimed at modernizing foundational business processes through the implementation of SAP S/4 HANA. This program focuses on core functionalities related to SAP Manufacturing, Order to Cash, Procure to Pay, and Finance processes. The IMUAM team plays a crucial role in ensuring security requirements are designed and implemented compliantly within this program.


The Implementation Audit Analyst will partner with the UAM Governance Lead to establish, execute, and sustain an implementation audit and governance framework for SAP S/4 deployments. This role will focus on ensuring audit-ready documentation, traceable control evidence, clearly defined procedures, and consistent governance practices across project and operational readiness activities. The analyst will help validate that UAM processes, controls, risks, and deliverables are sufficiently documented, reviewed, and aligned with SoX, GxP, IT compliance, privacy, and internal policy requirements to support Day 1 Go Live readiness and post-go-live operational sustainability.


Key Responsibilities:
  • Support implementation audit readiness by partnering with deployment, operational, compliance, and UAM teams to ensure governance processes, controls, and evidence requirements are defined, understood, and ready for each SAP S/4 go-live phase.
  • Embed audit and compliance requirements into the UAM project methodology, including control checkpoints, documentation standards, evidence retention expectations, and health checks across implementation milestones.
  • Perform implementation governance health checks to assess adherence to UAM strategy, project controls, deliverable quality, remediation tracking, and readiness criteria.
  • Maintain, validate, and organize audit-ready documentation, including process narratives, control evidence, decision logs, risk assessments, approvals, issue remediation, and go-live readiness artifacts.
  • Provide implementation audit support for SoX, GxP, IT compliance, privacy, and internal control requirements, including preparation of evidence packages and responses to audit inquiries.
  • Support implementation risk assessments focused on user access, segregation of duties, sensitive access, data migration, role design, provisioning, and operational handover risks.
  • Monitor compliance with UAM controls during implementation, with particular focus on SoD, sensitive access, emergency access, role lifecycle controls, approvals, and evidence completeness.
  • Support remediation tracking for governance, audit, and control gaps, ensuring issues are documented, assigned, resolved, and validated before go-live where required.
  • Contribute to the UAM taxonomy, control model, and service model as they relate to implementation governance, audit readiness, operational transition, and long-term sustainment.
  • Deliver audit-focused UAM governance updates, readiness summaries, and framework materials to key stakeholders tailored to SAP S/4 implementation needs.

Experience and Skills:

Required:

  • Bachelor’s degree in Governance, Risk Management, Compliance, Audit, Information Technology, Engineering, or a related field.
  • Minimum of 5 years of experience in audit/ controls, compliance, or enterprise risk management, preferably within the Life Sciences or Pharmaceutical industry.
  • 3–5 years of experience supporting IT audits, implementation audits, IT control assessments, evidence reviews, or compliance readiness activities.
  • 3–5 years of experience working with regulatory and compliance frameworks such as SoX, GxP, Privacy/GDPR, ITGC, and internal control standards.
  • Experience supporting large-scale system implementations, with an understanding of project lifecycle methodology, go-live readiness, operational handover, and post-go-live sustainment.
  • Familiarity with user access provisioning, SAP GRC Access Control, identity management tools, access approvals, and access review processes.
  • Understanding of SAP authorization concepts, SAP Security principles, role design, user lifecycle management, and access risk management.
  • Understanding of SoD concepts, sensitive access risk, mitigation controls, remediation strategies, and compliance monitoring approaches.
  • Understanding of risk matrices, rulesets, control mapping, data analysis, conversion, migration, and evidence traceability.
  • Strong attention to detail with proven ability to prepare audit-ready documentation, process narratives, control evidence, policies, procedures, and governance materials.
  • Strong project management, stakeholder coordination, communication, and follow-up skills, including the ability to track risks, issues, actions, and remediation across multiple teams.
  • Fluency in English with excellent written and verbal communication skills, including the ability to communicate audit, compliance, and control topics clearly to technical and non-technical audiences.
  • Ability to work effectively in a virtual or remote environment and collaborate with cross-functional, cross-cultural, and geographically distributed teams.
  • Excellent team player with a customer service-oriented mindset and strong ownership of audit readiness and compliance outcomes.

Preferred:

  • Experience in the Life Sciences or Pharmaceutical industry, particularly in regulated system implementation or compliance environments.
  • Prior experience supporting SAP Security, SAP S/4, SAP GRC, Identity Governance, or UAM implementation audits.
  • Demonstrated ability to support implementation audit planning, evidence collection, control validation, issue remediation, and stakeholder reporting.
  • Ability to work with team members of varying technical expertise and communicate clearly, concisely, and tactfully with management, peers, auditors, project teams, and operational stakeholders.
  • Relevant certifications such as CISA, CISM, CISSP, CRISC, SAP Security, or GRC-related certifications are a plus.

Other Requirements:
  • Ability to work on-site a minimum of three days per week, with up to two remote workdays per the flexible work policy.
  • May require up to 10% domestic and/or international travel.


Why Join Us:

J&J Innovative Medicine Principal Operations is committed to providing an inclusive and equitable work environment and promoting the well-being of all employees. Applicants interested in flexible work arrangements are welcome to apply, and we are open to discussing these options during the hiring process.

 



Required Skills:



Preferred Skills:

Accounting, Agility Jumps, Analytical Reasoning, Budget Management, Business Behavior, Compliance Frameworks, Data Reporting, Detail-Oriented, Financial Analysis, Financial Risk Management (FRM), Internal Controls, Numerically Savvy, Problem Solving, Process Oriented, Regulatory Environment, Risk Assessments, Risk Measurement

Skills Required

  • Bachelor's degree in Governance, Risk Management, Compliance, Audit, Information Technology, Engineering, or a related field
  • Minimum 5 years of experience in audit, controls, compliance, or enterprise risk management
  • 3-5 years of experience supporting IT audits, implementation audits, IT control assessments, evidence reviews, or compliance readiness activities
  • 3-5 years of experience with SOX, GxP, Privacy/GDPR, ITGC, and internal control standards
  • Experience supporting large-scale system implementations, go-live readiness, operational handover, and post-go-live sustainment
  • Familiarity with user access provisioning, SAP GRC Access Control, identity management tools, access approvals, and access reviews
  • Understanding of SAP authorization concepts, SAP Security, role design, user lifecycle management, and access risk management
  • Understanding of segregation of duties, sensitive access risk, mitigation controls, remediation strategies, and compliance monitoring
  • Understanding of risk matrices, rulesets, control mapping, data analysis, data conversion, migration, and evidence traceability
  • Strong attention to detail and ability to prepare audit-ready documentation, process narratives, control evidence, policies, procedures, and governance materials
  • Strong project management, stakeholder coordination, communication, and follow-up skills
  • Fluency in English with excellent written and verbal communication skills
  • Ability to collaborate in a virtual, cross-functional, cross-cultural, and geographically distributed environment
  • Ability to work on-site at least three days per week
  • Experience in the Life Sciences or Pharmaceutical industry
  • Prior experience with SAP Security, SAP S/4HANA, SAP GRC, Identity Governance, or UAM implementation audits
  • Relevant CISA, CISM, CISSP, CRISC, SAP Security, or GRC certification

Johnson & Johnson Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Johnson & Johnson and has not been reviewed or approved by Johnson & Johnson.

  • Healthcare Strength Healthcare coverage is characterized as comprehensive across medical, dental, and vision, with added supports like onsite clinics, fitness centers, and Employee Assistance resources. Mental-health services and wellbeing reimbursements are also described as meaningful components of the overall package.
  • Retirement Support Retirement offerings are portrayed as a major differentiator, combining a 401(k) with employer matching and an employer-funded pension plan. Stock options and other long-term financial supports are also positioned as part of the broader rewards mix.
  • Parental & Family Support Family-related benefits are presented as notably strong, including paid parental leave for all new parents and additional leave types for caregiving and bereavement. Financial assistance for adoption, fertility treatment, and surrogacy is highlighted as a significant support.

Johnson & Johnson Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: New Brunswick, NJ
143,612 Employees
Year Founded: 1886

What We Do

Profound Change Requires Boldness. Johnson & Johnson is the largest and most broadly based healthcare company in the world. We’re producing life-changing breakthroughs every day, and have been for the last 130 years. The combination of new technologies and your expertise enables amazing things to happen. Teams from J&J’s consumer business are creating digital tools to help people track the health of their skin. Those working in medical devices are 3-D printing artificial joints personalized for each patient, while researchers in pharmaceuticals use AI to discover lifesaving drugs. Imagine what the rest of our team of 134,000 people at 260 companies in more than 60 countries across the world is accomplishing. We redefine what it means to be a big company in today’s world. Social Media Community Guidelines: http://www.jnj.com/social-media-community-guidelines

Similar Jobs

Cloudflare Logo Cloudflare

Country Director, India

Cloud • Information Technology • Security • Software • Cybersecurity
Remote or Hybrid
India
4400 Employees

Cloudflare Logo Cloudflare

Solutions Engineer

Cloud • Information Technology • Security • Software • Cybersecurity
Remote or Hybrid
2 Locations
4400 Employees

Capco Logo Capco

Business Analyst

Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Remote or Hybrid
India
6000 Employees

CSC Logo CSC

Technology Service Management Analyst

Fintech • Legal Tech • Software • Financial Services • Cybersecurity • Data Privacy
Remote or Hybrid
2 Locations
8500 Employees

Similar Companies Hiring

OneImaging Thumbnail
Healthtech
Miami, FL
62 Employees
Rosendin Thumbnail
Other • Manufacturing
San Jose, CA
6219 Employees
Amalgamated Sugar Thumbnail
Food • Greentech • Agriculture • Industrial • Manufacturing
Boise, Idaho
768 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account