Jobs

Technology Risk Management Senior Specialist
CZE - Central Bohemian - Prague (Five)
·
On-site
·
Full-time
·
1w ago
Benefits & Perks
•Healthcare
•401(k)
•Flexible Hours
•Parental Leave
•Learning Budget
•Gym
•Commuter Benefits
•Healthcare
•401k
•Flexible Hours
•Parental Leave
•Learning
•Gym
•Commuter
Required Skills
Cybersecurity
IT Risk Management
Risk Assessment
IT Compliance
Stakeholder Management
Problem-solving
Business Acumen
Communication
Analytical Skills
Job Description:
The Position
The Business Information Risk role supports the alignment of cybersecurity, risk management, and compliance activities with Enterprise business objectives. This role partners with Enterprise teams, business stakeholders, and the Information Technology Risk Management & Security (ITRMS) organization to identify, assess, and mitigate information security and compliance risks across technology.
The position acts as a trusted risk advisor, translating technical risk into business context and supporting the implementation of practical, risk‑based controls that enable safe business operations and innovation.
What will you do
- Serve as a primary risk advisor to Enterprise teams on assigned programs, products, or technology areas, helping translate security risks into business impact and practical recommendations.
- Translate enterprise security policies into practical, business‑aligned implementation guidance and manage exception handling for the business unit.
- Participate in business planning forums, product roadmaps, and program governance to ensure security is included early (shift‑left).
- Support business stakeholders by providing clear, actionable guidance for embedding security and privacy considerations into projects, digital transformations, and operational processes.
- Prepare and present risk findings, assessments, and mitigation proposals to IT and business stakeholders; escalate material risks to ITRMS or Enterprise leadership as appropriate.
- Maintain a prioritized risk register for the business unit and drive risk acceptance decisions with business owners and delegated risk approvers.
- Conduct and document risk assessments (e.g., application, cloud, third‑party) and gap analyses aligned to Enterprise policies and relevant regulatory requirements.
- Recommend and help implement risk‑based security controls, compensating measures, and remediation plans tailored to Enterprise operational contexts.
- Assist in maintaining risk registers and tracking remediation and compliance activities; contribute to periodic risk reporting.
- Work closely with Enterprise Value Teams and solution owners to review architecture, design, and operational controls for systems, applications, and cloud environments.
- Identify opportunities to strengthen cyber resilience (detection, response, recovery) and support implementation of monitoring and control improvements.
- Support incident investigations and coordination with the Cyber Fusion Center for Enterprise‑related security events; help identify root causes and remediation actions.
- Support development and operationalization of security standards, policies, and guidelines relevant to Enterprise.
- Participate in assurance activities such as control testing, audits, and compliance assessments and support remediation efforts.
- Stay informed of emerging technologies (e.g., AI, cloud services) and regulatory changes; evaluate their potential security and compliance impacts and escalate concerns.
- Collaborate with risk, technology, and business stakeholders to promote a risk‑aware culture and practical security behaviors.
- Contribute to targeted security awareness initiatives and training for Enterprise teams, tailored to role and business processes.
- Act as a subject‑matter expert in cross‑functional working groups or project teams.
Qualifications, skills & experience required
- Bachelor’s degree in information technology, cybersecurity, computer science, business administration, or related field (or equivalent experience).
- Relevant security or risk certifications preferred (CISSP, CISM, CISA, CRISC, GSEC) but not required.
- Experience in cybersecurity, IT risk management, IT compliance, IT audit, or related fields.
- Experience performing risk assessments and advising technical and business stakeholders on security controls and remediation.
- Practical experience with cloud, application, or operational technology security is highly desirable.
- Prior experience supporting regulated industries (healthcare, life sciences, or manufacturing) is preferred but not mandatory.
- Technical depth in cybersecurity controls, threats, vulnerabilities, and mitigation strategies across technology.
- Strong business acumen and ability to explain technical risk in business terms.
- Proven problem‑solving and analytical skills; able to produce clear, actionable recommendations.
- Good stakeholder management and communication skills; able to influence without formal authority.
- Comfortable working independently and as part of cross‑functional teams; adaptable in a fast‑paced environment.
- High emotional intelligence and collaborative mindset.
What we offer
- Exciting work in a great team, global projects, international environment
- Opportunity to learn and grow professionally within the company globally
- Hybrid working model, flexible role pattern (e.g., even 80% full-time is possible in justified cases)
- Pension and health insurance contributions
- Internal reward system plus referral programme
- 5 weeks annual leave, 5 sick days, 15 days of certified sick leave paid above statutory requirements annually, 40 paid hours annually for volunteering activities, 12 weeks of parental contribution
- Cafeteria for tax free benefits according to your choice (meal vouchers, Lítačka, sport, culture, health, travel, etc.), Multisport Card
- Vodafone, Raiffeisen Bank and Foodora discount programmes
- Up-to-date laptop and i Phone
- Parking in the garage, showers, refreshments, massage chairs, library, music corner
- Competitive salary, incentive pay, and many more
Ready to take up the challenge? Apply now!Know anybody who might be interested? Refer this job!
Required Skills:
Accountability, Business Administration, Business Processes, Cyber Resilience Management, Cybersecurity, Cybersecurity Risk Management, Data Management, Digital Transformation, Emerging Technologies, Information Security, Information Technology (IT) Risk Management, IT Compliance Management, IT Risk Assessments, IT Risk Governance, IT Risk Response and Reporting, Knowledge of regulations and frameworks, Operational Technology (OT) Security Strategy, Risk Assessments, Risk Control Self Assessment, Risk Management, Stakeholder Engagement, Stakeholder Management, Technical Advice
Preferred Skills:
Current Employees apply HERE:
Current Contingent Workers apply HERE:
Search Firm Representatives Please Read Carefully Merck & Co., Inc., Rahway, NJ, USA, also known as Merck Sharp & Dohme LLC, Rahway, NJ, USA, does not accept unsolicited assistance from search firms for employment opportunities. All CVs / resumes submitted by search firms to any employee at our company without a valid written search agreement in place for this position will be deemed the sole property of our company. No fee will be paid in the event a candidate is hired by our company as a result of an agency referral where no pre-existing agreement is in place. Where agency agreements are in place, introductions are position specific. Please, no phone calls or emails.
Employee Status:
Regular
Relocation:
No relocation
VISA Sponsorship:
No
Travel Requirements:
No Travel Required:
Flexible Work Arrangements:
Hybrid
Shift:
Not Indicated
Valid Driving License:
No
Hazardous Material(s):
n/a
Job Posting End Date:
03/9/2026
A job posting is effective until 11: 59:59PM on the day BEFORE the listed job posting end date. Please ensure you apply to a job posting no later than the day BEFORE the job posting end date.
Total Views
0
Apply Clicks
0
Mock Applicants
0
Scraps
0
Similar Jobs

Sr. Mgr, Business Transformation & Project Management
Centene · 2 Locations

Gestionnaire principal, Relations gouvernementales| Senior Manager, Government Relations
Collins Aerospace (RTX) · CA-ON-OTTAWA-PLANT 23 ~ 1200 Montreal Rd ~ PLANT 23
Senior Staff, Technical Program Management (Global Operations Technology)
Coupang · Seoul, South Korea

Sales Excellence - Proposal Management Senior Analyst
Accenture ·

Senior Account Manager - Microsoft Advertising - German Speaker
Microsoft · Ireland, Dublin, Dublin; Spain, Barcelona, Barcelona
About Merck

Merck
PublicMultinational pharmaceutical company.
10,001+
Employees
Rahway
Headquarters
Reviews
3.6
19 reviews
Work Life Balance
3.8
Compensation
3.2
Culture
3.0
Career
2.8
Management
2.5
60%
Recommend to a Friend
Pros
Large company with networking opportunities
Good work-life balance
Decent benefits and salary
Cons
Limited upward and lateral mobility
Slow promotion timeline
Favoritism in advancement
Salary Ranges
2,500 data points
Director
Director · Associate Director, D&A Strategy
1 reports
$176,890
total / year
Base
$153,800
Stock
-
Bonus
-
$176,890
$176,890
Interview Experience
20 interviews
Difficulty
2.9
/ 5
Duration
14-28 weeks
Offer Rate
25%
Experience
Positive 10%
Neutral 50%
Negative 40%
Interview Process
1
Application Review
2
Recruiter Screen
3
Hiring Manager Interview
4
Panel Interview
5
Final Decision
Common Questions
Technical Knowledge
Behavioral/STAR
Past Experience
Culture Fit
Case Study
News & Buzz
Merck stock jumps to $110 as MRK heads into a big earnings week - TechStock²
Source: TechStock²
News
·
5w ago
Merck & Co., Inc. (MRK) Joins BofA's "US 1 List" - Finviz
Source: Finviz
News
·
5w ago
Cantor Fitzgerald Sees Deal Activity and Pipeline Progress as Key for Merck’s (MRK) Next Phase - Insider Monkey
Source: Insider Monkey
News
·
5w ago
Federated Hermes Inc. Sells 307,109 Shares of Merck & Co., Inc. $MRK - MarketBeat
Source: MarketBeat
News
·
5w ago