Your Role:
You will consult and support cyber security operations across our Business Units and Enabling Functions to protect the confidentiality, integrity, and availability across the companyâs IT and OT assets, software-based products, and applications. Your main task is ensuring that cyber security policies, standards, controls, and regulatory requirements are properly understood and implemented. As a member of the security governance & business enablement team, your main responsibilities are to maintain a high caliber of expertise on technical cyber security topics to act as a âcenter of excellenceâ to the business and become a solution-oriented partner to the business. You partner with business stakeholders across the company and drive the adoption of cyber security practices and controls in line with the defined risk appetite and policy/standards (e.g., problem solve in projects to âget to yesâ when it comes to considering cyber security) in all domains of IT, OT, IoT, and software-based products.
You will support, help, and consult all business units to execute cyber security operations across all domains (IT, OT, IoT, software-based products) through close and ongoing communication with business unit representatives. Furthermore, you collaborate with the internal cyber strategy, governance, assurance risk management team to identify fundamental gaps in cyber security execution in business units. You foster a culture of secure application development by assisting product teams in adopting secure coding best practices and frameworks and practices to ensure compliance.
Who you are:
- Bachelorâs degree or equivalent in intelligence studies, computer science, engineering, or related field.
- Minimum of 5 yearsâ experience with a focus on cyber security risk management, policy setting, assurance, audit, or equivalent.
- Demonstrated experience and knowledge across multiple information security domains (e.g., IT, OT, IoT, and products).
- Good knowledge of industry-leading Cybersecurity standards and groups: ISA, IEC, ISO, NIST, Namur, ENISA, BSI, and other Critical Infrastructure and Essential Services requirements.
- Capability to understand and take into account different business needs when executing cyber security operations.
- One or more industry-recognized security professional certificates (e.g. CISA, CISM, CISSP, CSSP).
- Strong interpersonal communication, positive customer service, and effective collaboration skills.
- Strong analytical skills, problem-solving attitude, and capability to make decisions even in a hard situation.
- Fluent in English, additional language skills (e.g., German) is a plus.
Department: EF-SQ-SCB Cyber Security Governance & Business Enablement
Job Evaluation: AT / Expert 3
#J-18808-Ljbffr
Kontaktperson:
Merck Gruppe HR Team