- Location
- Cluj-Napoca - Decembrie, Romania
- Workplace
- Hybrid
- Type
- Full-time
- Department
- Security
- Seniority
- Senior
- Experience
- 5+ years
- Source
- Workday
Description
Company:
Marsh CorporateDescription:
The Senior Specialist – Risk & Security role supports Mercer’s technology risk and information security agenda by strengthening risk governance, embedding effective frameworks, and enabling leaders to make informed, pragmatic decisions.
This role will be based in Cluj Napoca. This is a hybrid role that has a requirement of working at least three days a week in the office.
You will help design and implement localized IT, Data Management, and Cyber Risk frameworks aligned to the broader Risk Management Framework, and provide clear guidance on regulatory expectations, risk exposures, and control effectiveness.
This is a highly collaborative role, working with local and global Business and IT stakeholders to drive a strong risk culture, deliver meaningful reporting to leaders and governance bodies, and lead technology risk engagements across Mercer’s technology platforms.
We will count on you to:
Develop and integrate risk-related Information and Data Management frameworks, policies, and guideline documents as part of the existing Risk Management Framework
Design and develop localized Information Technology, Data Management, and Cyber Risk Management frameworks/methodologies aligned to enterprise standards.
Review and provide guidance to Business Leaders and IT stakeholders (local and global) on regulatory standards, obligations, and expectations
Lead and deliver technology risk engagements locally and globally, ensuring outcomes are actionable and aligned to business priorities
Develop appropriate risk reporting for Business leaders, Committees, and Boards, including visibility into IT risk exposure, key controls, and risk trends for Mercer
Provide advice and insights to key stakeholders on how to effectively manage risk across Mercer’s technology platforms through fit-for-purpose, pragmatic solutions
Contribute to embedding the risk management framework into the business and actively help strengthen and sustain Mercer’s risk culture
What you need to have:
Relevant undergraduate qualification combined with 5–8 years of experience in Financial Services
Experience in Information Security, Risk Management, or Audit, supported by relevant formal education/certification or equivalent practical experience
Strong knowledge of IT risk assessment programs and how to apply them in real-world environments
Broad knowledge of information security principles and practices.
Confidence engaging senior business and technology stakeholders to improve technology risk outcomes through practical recommendations
Advanced communication skills with the ability to build rapport, influence, and present recommendations effectively at senior executive and board level
Strong personal drive and accountability to achieve outcomes within defined timeframes
What makes you stand out?
Relevant post-graduate and/or professional qualification
Relevant technical certifications such as CISSP, CISM (or similar)
Why join our team:
We help you be your best through professional development opportunities, interesting work, and supportive leaders;
We foster a vibrant and inclusive culture where you can work with talented colleagues to create new solutions and have an impact for colleagues, clients, and communities;
Our scale enables us to provide a range of career opportunities, as well as benefits and rewards to enhance your well-being;
A yearly budget and the opportunity to build your flexible benefits package (up to 20% of your annual salary);
30+ days off (including legal days, birthday, public holiday replacements, and benefits options);
Performance bonus scheme;
Matching charity contributions, charity days off, and the Pay it Forward charity challenge;
Core benefits: Pension, Life and Medical Insurance, Meal Vouchers, Travel Insurance.