Senior IT Compliance Risk Analyst

Merck & Co.·
CZE - Central Bohemian - Prague (IT Riverview)
1w ago
Full-timeSeniorOphthalmologyBachelors

Description

<p style="text-align:left">Job Description</p><p style="text-align:inherit"></p><p><span><span>Our company’s IT division partners with colleagues across the business to help serve patients and customers around the world. We are a dynamic team of technology and risk professionals dedicated to leveraging data, security insights, and governance practices to strengthen our digital environment.</span></span></p><p><span><span>Join us in <b>Prague</b> as a <b>Compliance Risk Analyst</b> and become part of the <b>IT Risk Management &amp; Security (ITRMS) Governance Risk and Compliance (GRC) </b>team, where you will play a key role in <b>providing data driven insights into IT risk and compliance to our leadership, in support of informed decisions.</b></span></span></p><p><span> </span></p><p><span><span><b>Responsibilities</b></span></span></p><ul><li><span><span>Analyze and prioritize IT risks</span></span></li><li><span><span>Discover internal business <b>reporting needs and data products</b> that meet the reporting needs.</span></span></li><li><span><span>Develop reporting requirements and oversee analytics and reporting solutions from <b>Proof of Concept through Production release.</b></span></span></li><li><span><span>Analyze compliance and risk indicators for <b>IT controls, with a strong focus on Access Management.</b></span></span></li><li><span><span>Translate strategic risk and compliance objectives into <b>actionable delivery plans and initiatives</b>.</span></span></li><li><span><span><b>Partner with platform, security, and engineering teams to design, influence, and drive implementation </b>of agreed solutions.</span></span></li><li><span><span><b>Provide advisory input and practical guidance</b> to platform teams, ensuring alignment with leadership decisions and enterprise standards.</span></span></li><li><span><span>Track remediation progress and control effectiveness, and <b>proactively escalate risks and dependencies as needed</b>.</span></span></li><li><span><span>Keep leadership regularly informed of <b>risk trends, control effectiveness, and remediation status</b>.</span></span></li></ul><p><span> </span></p><p><span><span><b>Qualifications</b></span></span></p><p></p><p><span><span><b>Required</b></span></span></p><ul><li><span><span>Bachelor’s Degree (preferably in <b>Information Technology, Cybersecurity, or Information Systems</b>)</span></span></li><li><span><span><b>6-8 years of IT risk and compliance / IT audit experience</b></span></span></li><li><span><span>Strong hands-on knowledge of <b>Identity &amp; Access Management (IAM)</b> concepts, including:</span></span><ul><li><span><span>Provisioning and deprovisioning</span></span></li><li><span><span>Identity lifecycle management</span></span></li><li><span><span>RBAC / ABAC</span></span></li><li><span><span>Single Sign-On (SSO)</span></span></li><li><span><span>Multi-Factor Authentication (MFA)</span></span></li><li><span><span>Privileged Access Management (PAM)</span></span></li></ul></li><li><span><span>Experience evaluating or auditing <b>access governance processes and identity providers</b></span></span></li><li><span><span>Understanding of <b>IT security and compliance frameworks</b> (e.g., SOX ITGC, NIST)</span></span></li><li><span><span>Experience translating <b>technical control findings into actionable risk insights and remediation plans</b></span></span></li><li><span><span><b>Strong analytical mindset</b> with attention to detail and ability to interpret complex technical data</span></span></li><li><span><span><b>Excellent communication skills</b>, with the ability to tailor messaging for technical teams, business partners, and executive leadership.</span></span></li></ul><p><span> </span></p><p><span><span><b>Preferred</b></span></span></p><ul><li><span><span>Certifications such as <b>CISA, CISSP, CISM, CIA</b>, or similar</span></span></li><li><span><span>Experience in <b>cloud-native IAM governance controls</b></span></span></li><li><span><span>Exposure to <b>Privileged Access Management (PAM) solutions</b></span></span></li><li><span><span>Basic knowledge of <b>SQL or Python</b> for data analysis and reporting automation</span></span></li><li><span><span>Experience with <b>data analytics and reporting tools</b> such as Power BI, Tableau, Spotfire, or similar</span></span></li></ul><p></p><p><b>What we offer</b></p><ul><li><span>Exciting work in a great team, global projects, international environment</span></li><li><span>Opportunity to learn and grow professionally within the company globally</span></li><li><span>Hybrid working model, flexible role pattern</span></li><li><span>Competitive salary &amp; incentive pay</span></li><li><span>Pension and health insurance contributions</span></li><li><span>Internal reward system and referral scheme</span></li><li><b>5  </b><span>weeks annual leave, </span><b>5 </b><span>sick days, </span><b>15 </b><span>days of certified sick leave paid above statutory requirements annually, </span><b>40  </b><span>paid hours annually for volunteering activities, </span><b>12 </b><span>weeks of parental contribution</span></li><li><span>Cafeteria for tax free benefits according to your choice (meal vouchers, Lítačka, sport, culture, health, travel, etc.), Multisport Card</span></li><li><span>Vodafone, Raiffeisen Bank, Foodora, and discount programmes</span></li><li><span>Up-to-date laptop and iPhone</span></li><li><span>Parking in the garage, showers, refreshments, massage chairs, library, music corner </span></li></ul><p></p><p><i>Ready to take up the challenge? Apply now!</i></p><p><i>Know anybody who might be interested? Refer this job!</i> </p><p></p><p><b>Required Skills: </b></p>Analytics, Collaboration, Executive Communications, Identity Access Management (IAM), Information Technology (IT) Risk Management, Information Technology Auditing, IT Governance Risk and Compliance (GRC), Multi-Factor Authentication (MFA), Privileged Access Management (PAM), Role Based Access Control (RBAC), Technology Risk<p></p><p><b>Preferred Skills: </b></p><p style="text-align:inherit"></p><p style="text-align:left">Current Employees apply <a target="_blank" href="https://wd5.myworkday.com/msd/d/task/1422$6687.htmld">HERE</a></p><p style="text-align:inherit"></p><p style="text-align:left">Current Contingent Workers apply <a target="_blank" href="https://wd5.myworkday.com/msd/d/task/1422$4020.htmld">HERE</a></p><p style="text-align:inherit"></p><p style="text-align:left"><b>Search Firm Representatives Please Read Carefully </b><br />Merck &amp; Co., Inc., Rahway, NJ, USA, also known as Merck Sharp &amp; Dohme LLC, Rahway, NJ, USA, does not accept unsolicited assistance from search firms for employment opportunities. All CVs / resumes submitted by search firms to any employee at our company without a valid written search agreement in place for this position will be deemed the sole property of our company.  No fee will be paid in the event a candidate is hired by our company as a result of an agency referral where no pre-existing agreement is in place. Where agency agreements are in place, introductions are position specific. Please, no phone calls or emails. </p><p style="text-align:inherit"></p><p style="text-align:left"><b>Employee Status: </b></p>Regular<p style="text-align:inherit"></p><p style="text-align:left"><b>Relocation:</b></p>No relocation<p style="text-align:inherit"></p><p style="text-align:left"><b>VISA Sponsorship:</b></p>No<p style="text-align:inherit"></p><p style="text-align:left"><b><span>Travel Requirements:</span></b></p>10%<p style="text-align:inherit"></p><p style="text-align:left"><b>Flexible Work Arrangements:</b></p>Hybrid<p style="text-align:inherit"></p><p style="text-align:left"><b>Shift:</b></p>1st - Day<p style="text-align:inherit"></p><p style="text-align:left"><b>Valid Driving License:</b></p>No<p style="text-align:inherit"></p><p style="text-align:left"><b>Hazardous Material(s):</b></p>N/A<p style="text-align:inherit"></p><p style="text-align:left"><b>Job Posting End Date:</b></p>03/21/2026<p style="text-align:left"><b><span>*A job posting is effective until 11:59:59PM on the day <u>BEFORE</u> the listed job posting end date. Please ensure you apply to a job posting no later than the day <u>BEFORE</u> the job posting end date. </span></b></p>
M&

Merck & Co.

PHARMACEUTICAL

LocationRAHWAY, NJ
Employees69,000
Open Jobs672
OncologyVaccinesInfectious DiseaseCardiovascularImmunology
View Company Profile

Pipeline

SitagliptinN/A
A Mixed Methods Approach to the Development and Testing of the Measure of Drug Self-Management (MeDSN/A
Long- and intermediate- acting insulinsN/A
Real time PCRN/A
Functional Living Index - EmesisN/A