yoinka

Director, Technology Risk Management

Merck

Rahway, New Jersey, United States of AmericaFull TimeStaff$173.2k – $272.6k/yr
Sign in to applyVerified 55m ago
Location
Rahway, New Jersey, United States of America
Employment
Full Time
Work model
On-Site
Level
Staff
Salary
$173.2k – $272.6k/yr
Posted
23h ago

Skills

CybersecuritySAPSpark

About this role

Job Description

The Director, Business Information Risk Officer (BIRO) is a critical leadership role responsible for aligning cybersecurity, risk management, and compliance strategies with business objectives. This individual will act as a trusted advisor to the business leaders in the Enterprise IT (EIT) that supports our company’s Global Support Functions (GSF), such as Finance, HR, Legal, and Procurement, among others, ensuring that information security and compliance risks are proactively identified, assessed, and managed while enabling business innovation and growth. This role provides risk governance for all IT systems managed by the EIT organization, whether they are hosted internally or in the cloud, fostering a secure, compliant, and risk-aware culture. Additionally, the BIRO maintains a continuous feedback loop with the Information Technology Risk Management & Security (ITRMS) team to enhance and align the risk management processes to the business goals. The ideal candidate will possess deep technical expertise and working knowledge of industry standard platforms such as SAP S/4, Workday, etc., a strong understanding of business operations (particularly Finance, HR, Legal, and Procurement), and excellent leadership and stakeholder management skills. S/he must be able to translate complex Cybersecurity concepts into business language and influence stakeholders to drive a risk-aware culture across the EIT organization and any newly acquired businesses.

Primary Responsibilities

Strategic Leadership & Business Partnership Serve as the primary cybersecurity and risk advisor to EIT, aligning security strategies with the business priorities. Provide executive-level risk insights and recommendations to EIT leadership. Ensure security and risk management practices are embedded in business processes, digital transformation initiatives, and operational decision-making. Act as a bridge between ITRMS and EIT, translating technical risks into business impact. Risk Management & Governance Drive compliance with applicable global regulations and internal security policies by tailoring the requirements to EIT’s operational and regulatory context. Identify, design, and help implement risk-based security solutions that are practical, effective, and aligned with EIT business priorities. Provide security and risk leadership for strategic IT programs, such as SAP S/4HANA implementation, ensuring integration of security and compliance throughout the program lifecycle. Stay updated on new and emerging technologies (e.g., AI and Quantum) and new laws and regulations, and understand their impacts on the business. Technical Expertise & Cyber Resilience Work in unison with EIT IT Value Teams to establish secure design, implementation, and monitoring of IT systems, applications, and cloud environments. Proactively identify opportunities to improve the cyber resilience capabilities of EIT systems. Support the Cyber Fusion Center in handling Cyber incidents related to EIT Understand emerging cyber threats, vulnerabilities, and attack vectors, and establish proactive risk mitigation strategies. Leadership, Influence & Culture Building Influence EIT stakeholders to foster a security-conscious culture without impeding business agility. Drive security awareness programs that resonate with business functions. Lead, mentor, and develop a high-performing risk and security team Demonstrates high emotional intelligence (EQ) and executive presence (EP), effectively engaging with senior executives and key stakeholders.

Education and Experience

Requirements: Bachelor’s Degree in one or more of the following fields: information technology, cyber security, computer science, business administration, communications, or related field. Knowledge of industry standard platforms such as SAP S/4, Workday, etc. 10+ years’ experience working in one or more of the following fields: cybersecurity, IT risk management, IT compliance, Information Technology, or a

Director, Technology Risk Management at Merck, Rahway, New Jersey, United States of America | Yoinka