Head of EL Cyber Governance, Compliance & Enablement
As the Head of Cyber Security Governance, assurance, and risk management, play a pivotal role within the Electronics (EL) cyber security team, reporting directly to the EL CISO.
Your responsibilities include tailoring corporate cyber security structures to EL's needs, supporting on an operational level, and ensuring constant alignment with Merck corporate cyber security.
Your role is crucial in protecting Merck EL information assets and maintaining a robust cyber security posture. Key Responsibilities : Develop and enhance risk management, compliance, and governance frameworks, aligning with industry best practices and regulatory requirements, Lead teams in developing and maintaining cyber security procedures, standards, and risk management frameworks, including third-party security risks, Ensure compliance with legal, regulatory, and industry requirements (e.
g., GDPR, ISO 27001, NIST CSF, IEC62443), Implement a comprehensive cyber security training and awareness program, Develop KPI frameworks, dashboards, and reports, Provide strategic guidance for advanced IT / OT and cyber risk management practices, Collaborate with Merck EL CISO, corporate cyber security, and Regional and Site Cyber Security Managers, Oversee risk mitigation efforts, including third-party alignment with defined risk appetite, Evaluate third-party vendors' security posture, Measure and adjust awareness program effectiveness, Present risk-related reports to senior leadership.
Who you are : A minimum of 8 years of experience in cyber security, with at least 3 years in a leadership role focused on cyber security governance, risk management, and compliance.
Strong analytical and problem-solving skills with the ability to assess complex security issues and develop effective solutions.
Proven experience in developing and implementing cyber security policies, procedures, and standards.Familiarity with frameworks and standards such as ITIL, CoBiT, NIST CSF, ISO / IEC 27001 / 27002, and IEC62443Extensive experience in developing and implementing risk management frameworks, conducting risk assessments, and managing third-party security risks.
Strong background in regulatory compliance, including conducting and managing audits.Information security certifications in CISM, CISA relevant ISO certification, Sarbanes-Oxley, Data Privacy laws, or PCI is a plus.
Knowledge of IT and OT infrastructure, architecture, and security toolsUnderstanding the specific security challenges and regulatory requirements of the chemical and semiconductor industry incl.
production facilities is a plus.Excellent verbal and written communication skills in English (German is a plus) EL-BP-ICG Cyber Governance, Compliance and Enablement RL / 4