Senior Analyst Operational Technology Cyber Security

2 semanas atrás


São José dos Campos, São Paulo, Brasil Johnson & Johnson Innovative Medicine Tempo inteiro

At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at

Job Function:

Technology Enterprise Strategy & Security

Job Sub Function:

Security & Controls

Job Category:

Scientific/Technology

All Job Posting Locations:

São José dos Campos, São Paulo, Brazil

Job Description:

Johnson & Johnson is currently recruiting for a Senior Analyst Operational Technology Cyber Security within the Information Security and Risk Management (ISRM) organization.

This position is based out Warsaw, Poland or São José dos Campos, Brazil.

As a member of the Operational Technology Cybersecurity Engineering team, you will focus on developing and maintaining automation solutions that enhance the functionality and efficiency of Tanium OT services. You will contribute to custom script development, platform optimization, and integration efforts to support cybersecurity operations across IT and OT environments. This role offers opportunities to lead technical initiatives and collaborate with cross-functional teams to improve visibility, compliance, and platform performance.

This position will also partner with internal ISRM teams such as the Supply Chain security, Cyber Security Operations Center (CSOC), and other groups under the J&J Technology umbrella, including but not limited to End User, Server, and Network support.

Key Responsibilities:
  • Build and deploy custom scripts aligned with security stakeholder requests and Tanium Platform standards.
  • Maintain a repository of reusable code for remediation and data retrieval across IT & OT environments.
  • Refactor and validate existing code for performance, security, and maintainability.
  • Conduct structured testing of code samples during upgrade cycles and recommend improvements.
  • Define and implement strategies for platform performance, security hardening, and automation.
  • Validate data flows and integration points to maintain accuracy and compliance.
  • Collaborate with security and infrastructure teams to ensure platform reliability and adherence to operational standards.
  • Develop Tanium sensors and packages to enhance endpoint data visibility and monitor workflows.
  • Support Cybersecurity workflows, to assess risk, increase visibility and reduce impact of vulnerabilities across IT & OT environments.
  • Test and validate security controls throughout the different phases of the Cyber Kill Chain, and the MITRE ATT&CK framework to prevent, detect, and respond.
  • Generate threat behavior analytics for discovering historical and emerging threats to networks and systems.
  • Implement detection strategies based on internal and external intelligence reporting and vulnerability research.
  • Perform administrative tasks associated with tuning, alerts, correlation rules, signatures, device configurations, patching, and upgrades.
  • Establish and maintain relationships with the suppliers, vendors, and partners.
  • Assists with security events/incidents, coordinating activities with the CSOC and others – as needed.
Qualifications

Education:

  • A bachelor's degree or equivalent experience in the information security or information technology sector
Experience and Skills

Required:

  • Strong programming skills in scripting languages (e.g., Python, PowerShell, Bash) for automation and integration.
  • Strong foundation in information security principles, with proven ability in debugging and root cause analysis in IT & OT environments.
  • Experience in engineering, installing, configuring, and operating security solutions and appliances across large-scale, hybrid environments (AWS, Azure, GCP, on-prem).
  • Ability to engineer, customize, and extend endpoint management and visibility platforms, including developing integrations, automation, and product-level enhancements.
  • Familiarity with agile frameworks and DevSecOps practices, with the ability to deliver iteratively while maintaining reliability in high-risk environments.
  • Proven track record leading complex implementations, demonstrating risk-aware problem solving and balancing security with operational continuity.
  • Strong communication skills (written and verbal), able to translate technical details into clear guidance for both technical and non-technical stakeholders.
  • Knowledge of security frameworks and standards (NIST CSF, CIS Controls, OWASP, SANS) and ability to apply them pragmatically in OT contexts.
  • Working knowledge of the MITRE ATT&CK framework, including OT-specific TTPs, and ability to map telemetry to adversary behaviors.
  • Experience collaborating with distributed, global teams, working effectively across diverse cultural and technical backgrounds.

    Please note that this role is available across multiple countries and may be posted under different requisition numbers to comply with local requirements. While you are welcome to apply to any or all of the postings, we recommend focusing on the specific country(s) that align with your preferred location(s):
    Brazil (Sao Jose dos Campos) - Requisition Number:  R-045644
    Poland (Warsaw) - Requisition Number:  R-046653

Required Skills:

Operational Technology (OT) Security

Preferred Skills:

Communication, Corrective and Preventive Action (CAPA), Critical Thinking, Information Security Auditing, Information Security Management System (ISMS), Information Technology (IT) Security Assessments, Information Technology Strategies, Mentorship, Network Optimization, Presentation Design, Process Optimization, Report Writing, Security Policies, Technical Credibility, Technologically Savvy, Training People, Vulnerability Assessments

  • São José dos Campos, São Paulo, Brasil Johnson & Johnson Innovative Medicine Tempo inteiro

    At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to...


  • São José dos Campos, São Paulo, Brasil Johnson & Johnson Tempo inteiro

    At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to...

  • Cyber Security Analyst

    2 semanas atrás


    São Paulo, São Paulo, Brasil Orange Business Tempo inteiro

    About UsOrange Business is a network and digital integrator that understands the entire value chain of the digital world, freeing our customers to focus on the strategic initiatives that shape their business. Every day, you will collaborate with a team dedicated to providing consistent, sustainable global solutions, no matter where our customers operate....

  • Cyber Security Analyst

    2 semanas atrás


    São Paulo, São Paulo, Brasil Orange Business Tempo inteiro

    About UsOrange Business is a network and digital integrator that understands the entire value chain of the digital world, freeing our customers to focus on the strategic initiatives that shape their business. Every day, you will collaborate with a team dedicated to providing consistent, sustainable global solutions, no matter where our customers operate....


  • São José dos Campos, São Paulo, Brasil Johnson & Johnson Tempo inteiro

    At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across...

  • Cloud Security Analyst

    2 semanas atrás


    São Paulo, São Paulo, Brasil Tenchi Security Tempo inteiro

    Our CompanyTenchi is a Cyber Security company building innovative technology focused on Third-Party Cyber Risk Management for businesses. Founded by serial entrepreneurs and supported by solid institutional investors, we are driven to disrupt this fast-growing industry.Tenchi was created to tackle a real challenge: companies often face security risks because...

  • Security Analyst

    1 semana atrás


    São Paulo, São Paulo, Brasil Bunge Tempo inteiro

    Cidade :São Paulo, BrasilEstado :São Paulo (BR-SP)País :Brasil (BR)Número do Pedido :40317OverviewThe Security Analyst II serves as Tier 1-2 Analyst member of the Bunge Global SOC and all operational activities that serve to protect the confidentiality, integrity and security management of business and employee information and systems in compliance with...


  • São Paulo, São Paulo, Brasil WPP Tempo inteiro

    WPP is the creative transformation company. We use the power of creativity to build better futures for our people, planet, clients, and communities.Working at WPP means being part of a global network of more than 100,000 talented people dedicated to doing extraordinary work for our clients. We operate in over 100 countries, with corporate headquarters in New...


  • São Paulo, São Paulo, Brasil WPP Tempo inteiro

    WPP is the creative transformation company. We use the power of creativity to build better futures for our people, planet, clients, and communities.Working at WPP means being part of a global network of more than 100,000 talented people dedicated to doing extraordinary work for our clients. We operate in over 100 countries, with corporate headquarters in New...


  • São Paulo, São Paulo, Brasil Santander Tempo inteiro

    Cyber Security Spec IIICountry: BrazilSe você tem vontade de crescer e aprender sempre, e tem paixão em impactar pessoas através de suas análises, esse pode ser o seu lugar. Ao integrar o time de Cyber Security & Anti-Fraud do Santander, você atuará no time que é responsável prevenir fraudes internas e externas, mitigar os riscos de cyber segurança...