Senior Analyst Operational Technology Cyber Security
Há 12 horas
At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at
Job Function
Technology Enterprise Strategy & Security
Job Sub Function
Security & Controls
Job Category
Scientific/Technology
All Job Posting Locations:
São José dos Campos, São Paulo, Brazil
Job Description
Johnson & Johnson is currently recruiting for a Senior Analyst Operational Technology Cyber Security within the Information Security and Risk Management (ISRM) organization.
This position is based out
Warsaw, Poland
or
São José dos Campos, Brazil
.
As a member of the Operational Technology Cybersecurity Engineering team, you will focus on developing and maintaining automation solutions that enhance the functionality and efficiency of Tanium OT services. You will contribute to custom script development, platform optimization, and integration efforts to support cybersecurity operations across IT and OT environments. This role offers opportunities to lead technical initiatives and collaborate with cross-functional teams to improve visibility, compliance, and platform performance.
This position will also partner with internal ISRM teams such as the Supply Chain security, Cyber Security Operations Center (CSOC), and other groups under the J&J Technology umbrella, including but not limited to End User, Server, and Network support.
Key Responsibilities
- Build and deploy custom scripts aligned with security stakeholder requests and Tanium Platform standards.
- Maintain a repository of reusable code for remediation and data retrieval across IT & OT environments.
- Refactor and validate existing code for performance, security, and maintainability.
- Conduct structured testing of code samples during upgrade cycles and recommend improvements.
- Define and implement strategies for platform performance, security hardening, and automation.
- Validate data flows and integration points to maintain accuracy and compliance.
- Collaborate with security and infrastructure teams to ensure platform reliability and adherence to operational standards.
- Develop Tanium sensors and packages to enhance endpoint data visibility and monitor workflows.
- Support Cybersecurity workflows, to assess risk, increase visibility and reduce impact of vulnerabilities across IT & OT environments.
- Test and validate security controls throughout the different phases of the Cyber Kill Chain, and the MITRE ATT&CK framework to prevent, detect, and respond.
- Generate threat behavior analytics for discovering historical and emerging threats to networks and systems.
- Implement detection strategies based on internal and external intelligence reporting and vulnerability research.
- Perform administrative tasks associated with tuning, alerts, correlation rules, signatures, device configurations, patching, and upgrades.
- Establish and maintain relationships with the suppliers, vendors, and partners.
- Assists with security events/incidents, coordinating activities with the CSOC and others – as needed.
Qualifications
Education:
- A bachelor's degree or equivalent experience in the information security or information technology sector
Required
Experience and Skills
- Strong programming skills in scripting languages (e.g., Python, PowerShell, Bash) for automation and integration.
- Strong foundation in information security principles, with proven ability in debugging and root cause analysis in IT & OT environments.
- Experience in engineering, installing, configuring, and operating security solutions and appliances across large-scale, hybrid environments (AWS, Azure, GCP, on-prem).
- Ability to engineer, customize, and extend endpoint management and visibility platforms, including developing integrations, automation, and product-level enhancements.
- Familiarity with agile frameworks and DevSecOps practices, with the ability to deliver iteratively while maintaining reliability in high-risk environments.
- Proven track record leading complex implementations, demonstrating risk-aware problem solving and balancing security with operational continuity.
- Strong communication skills (written and verbal), able to translate technical details into clear guidance for both technical and non-technical stakeholders.
- Knowledge of security frameworks and standards (NIST CSF, CIS Controls, OWASP, SANS) and ability to apply them pragmatically in OT contexts.
- Working knowledge of the MITRE ATT&CK framework, including OT-specific TTPs, and ability to map telemetry to adversary behaviors.
- Experience collaborating with distributed, global teams, working effectively across diverse cultural and technical backgrounds.
Please note that this role is available across multiple countries and may be posted under different requisition numbers to comply with local requirements. While you are welcome to apply to any or all of the postings, we recommend focusing on the specific country(s) that align with your preferred location(s):
Brazil (Sao Jose dos Campos) - Requisition Number:
R-045644
Poland (Warsaw) - Requisition Number:
R-046653
Required Skills
Operational Technology (OT) Security
Preferred Skills
Communication, Corrective and Preventive Action (CAPA), Critical Thinking, Information Security Auditing, Information Security Management System (ISMS), Information Technology (IT) Security Assessments, Information Technology Strategies, Mentorship, Network Optimization, Presentation Design, Process Optimization, Report Writing, Security Policies, Technical Credibility, Technologically Savvy, Training People, Vulnerability Assessments
-
São José dos Campos, São Paulo, Brasil Johnson & Johnson Innovative Medicine Tempo inteiro US$120.000 - US$180.000 por anoAt Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to...
-
Cloud Security Analyst
Há 10 horas
São Paulo, São Paulo, Brasil Tenchi Security Tempo inteiro US$60.000 - US$120.000 por anoOur CompanyTenchi is a Cyber Security company building innovative technology focused on Third-Party Cyber Risk Management for businesses. Founded by serial entrepreneurs and supported by solid institutional investors, we are driven to disrupt this fast-growing industry.Tenchi was created to tackle a real challenge: companies often face security risks because...
-
Senior Technical Analyst
1 semana atrás
São José dos Campos, São Paulo, Brasil Ball Corporation Tempo inteiro R$90.000 - R$120.000 por anoFurther your career at Ball, a world leader in manufacturing sustainable aluminium packaging. Achieve extraordinary things when you join our team, and make a difference in your professional development, the community, and around the globePlease, submit your resume in English.Ball Corporation is looking for a well-rounded team player with broad technical...
-
Cyber Security Spec I
Há 11 horas
São Paulo, São Paulo, Brasil Santander Tempo inteiro R$80.000 - R$120.000 por anoCyber Security Spec ICountry: BrazilSe você tem vontade de crescer e aprender sempre, e tem paixão em impactar pessoas através de suas análises, esse pode ser o seu lugar. Ao integrar o time de Cyber Security & Anti-Fraud do Santander, você atuará no time que é responsável prevenir fraudes internas e externas, mitigar os riscos de cyber segurança e...
-
Cyber Security Architect
1 semana atrás
São Paulo, Estado de São Paulo, Brasil GeorgiaTEK Systems Inc. Tempo inteiroCyber Security Architect Work Model: Hybrid (2–3 days per week onsite in Alphaville – Barueri, São PauloContract Type: Full-Time Employment We are seeking a Cyber Security Architect with solid technical expertise and a strategic mindset. This role combines advanced security architecture design with hands-on implementation of modern security practices....
-
Especialista em Cyber Security
Há 6 dias
São Paulo, São Paulo, Brasil WTime Business Intelligence Tempo inteiro R$90.000 - R$120.000 por anoLocal de Trabalho - Trem Morumbi /SPExperiência em segurança cibernética, com atuação em ambientes de alta criticidade.RequisitosConhecimentos EspecíficosCyber Threat Intelligence, CSIRT (Cyber Security Incident Response Team), SOC, Engenharia de Detecção, SIEM.Experiência em análise de logs, investigação de incidentes e threat hunting.Forte...
-
Cyber Security Spec I
2 semanas atrás
São Paulo, São Paulo, Brasil Santander Tempo inteiro R$80.000 - R$120.000 por anoCyber Security Spec ICountry: BrazilSe você tem vontade de crescer e aprender sempre, e tem paixão em impactar pessoas através de suas análises, esse pode ser o seu lugar.Ao integrar o time de Cyber Security & Anti-Fraud do Santander, você atuará no time que é responsável prevenir fraudes internas e externas, mitigar os riscos de cyber segurança e...
-
Manager, Business Information Security
Há 6 dias
São José dos Campos, São Paulo, Brasil Johnson & Johnson Tempo inteiro R$60.000 - R$120.000 por anoAt Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to...
-
Cyber Security Spec I
2 semanas atrás
São Paulo, São Paulo, Brasil Santander Tempo inteiro R$40.000 - R$60.000 por anoCyber Security Spec ICountry: BrazilSe você tem vontade de crescer e aprender sempre, e tem paixão em impactar pessoas através de suas análises, esse pode ser o seu lugar. Ao integrar o time de Cyber Security & Anti-Fraud do Santander, você atuará no time que é responsável prevenir fraudes internas e externas, mitigar os riscos de cyber segurança e...
-
Senior GRC Analyst
Há 10 horas
São Paulo, São Paulo, Brasil Kaizen Gaming Tempo inteiro R$10.000 - R$50.000 por anoLet's start with the roleWe are seeking a Senior GRC Analyst, to ensure that security requirements set by laws, regulators, licensing bodies, security standards, customers, and other relevant stakeholders are consistently met. This role is responsible for ensuring that technical security controls are effective and address company-wide security and data...