Third-Party Risk Analyst
Johnson & Johnson
- Location
- Bogotá, Distrito Capital, Colombia
- Work model
- On-Site
- Level
- Mid
- H-1B history
- 2 approvals (FY2023)
- Posted
- Sep 9, 2026
About this role
At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at jnj.com . As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit. Job Function: Legal & Compliance Job Sub Function: Enterprise Compliance Job Category: Professional All Job Posting Locations: Bogotá, Distrito Capital, Colombia Job Description:
Position
Title : Third-Party Risk Analyst Supervisor Title : Enterprise Compliance Sr. Specialist Department Name / Number : GS Procurement- Third Party Risk Physical Location of Position: Bogota Geographic Scope of Responsibility: Global / Americas Position Summary The Third-Party Risk Analyst will perform Third party due diligence process as part of the Third-party risk management program. This role establishes and maintains procedures and controls to drive improvement initiatives supporting the daily operational activities of the team focusing on Third party risk. The analyst will also participate on ad hoc compliance projects and maintain procedures and controls to mitigate risk management, communications, audits, training, process capability/process improvement, and compliance general support. Major Duties & Responsibilities Approximate Percentage of Time: 80% Third Parties Due Diligence Perform third-party sanctions screening, risk assessments, and enhanced due diligence activities to identify, evaluate, and mitigate third-party risk exposures. Conduct daily monitoring and review of screening alerts, assessing potential compliance and enterprise risk impacts and escalating high-risk findings in accordance with established governance frameworks. Support supplier master data governance initiatives, ensuring data integrity, risk transparency, and adherence to enterprise control requirements. Execute risk-based third-party due diligence processes prior to onboarding and throughout the lifecycle of existing third parties, ensuring risk levels are appropriately assessed, documented, and managed. Perform data quality reviews, risk control validations, and database reconciliations to strengthen the reliability, completeness, and accuracy of information used for risk-based decision-making. Design, enhance, and maintain risk awareness, communication, and training programs that promote a culture of compliance, risk ownership, and alignment with legal and regulatory requirements. Collaborate with cross-functional stakeholders to develop, update, and strengthen policies, procedures, desktop procedures (DTPs), and work instructions, ensuring alignment with evolving risk landscapes, regulatory expectations, and internal control frameworks. Identify opportunities to strengthen risk controls, improve monitoring capabilities, and drive process optimization, automation, and innovation to enhance operational resilience and risk mitigation. Partner closely with regional and global stakeholders to assess emerging risks, promote consistent risk management practices, and support enterprise-wide compliance objectives. Maintain comprehensive records and evidence supporting risk assessments, due diligence activities, investigations, and compliance controls in accordance with regulatory requirements, audit expectations, and enterprise retention standards. Support the implementation of risk-focused processes, governance