We are seeking a motivated and collaborative leader to develop and implement our Global Cyber & IT Risk Management strategies. This role will lead the Global 3rd Party Risk Management Team, supporting vendor risk assessments and working closely with teams to identify, assess, and address risks to critical services, information, and systems. This is a hybrid role (3 days a week in office, 2 days a week remote).
Director, IT Risk Management
We will count on you to:
Develop and support global cyber and IT risk management strategies aligned with business goals.
Lead the Global 3rd Party Risk Management Team in conducting vendor risk assessments and facilitating remediation efforts.
Collaborate to develop risk models that assess and quantify risks to critical services, information, and systems.
Maintain current and comprehensive vendor inventories and assessments.
Prepare reports, presentations, and dashboards for executive leadership to communicate risk posture and emerging threats.
Continuously enhance Vendor Risk Assessment methodologies to align with evolving industry standards and best practices.
Foster a skilled team environment to effectively perform risk assessments and maintain strong client communication.
Partner with vendors to establish cybersecurity and resilience standards within contracts.
Coordinate global internal audits, client assessments, and security reviews related to third-party risk.
Participate in incident response activities involving third parties, collaborating across teams to reduce exposure.
Engage with operational leaders to identify emerging risks and co-develop risk-reducing solutions.
Adapt and scale risk management processes to address new and evolving threats, including those related to AI and advanced technologies.
What you need to have:
Experience in cyber and IT risk management, preferably in a global or cross-functional environment.
Strong interpersonal and leadership skills with experience supporting diverse, collaborative teams.
Knowledge of vendor risk assessment and third-party risk management practices.
Effective communication skills, able to engage with internal and external stakeholders at all levels.
Familiarity with current cybersecurity frameworks, standards, and best practices.
Ability to develop and apply risk models and metrics-based reporting.
Experience partnering in contract negotiations related to cybersecurity and resilience.
Understanding of incident response processes and cross-functional collaboration.
Demonstrated ability to innovate and adapt processes to meet evolving threats, including AI-related risks.
What makes you stand out:
Proven track record of leading global teams in cyber and IT risk management.
Experience driving continuous improvement in vendor risk assessment methodologies.
Strong ability to build partnerships with vendors and internal stakeholders to enhance cybersecurity resilience.
Expertise in emerging technologies and their associated risks, including AI.
Ability to communicate complex risk concepts clearly to executive leadership and diverse audiences.
Why join our team:
We help you be your best through professional development opportunities, interesting work and supportive leaders.
We foster a vibrant and inclusive culture where you can work with talented colleagues to create new solutions and have impact for colleagues, clients and communities.
Our scale enables us to provide a range of career opportunities, as well as benefits and rewards to enhance your well-being.
Top Skills
What We Do
Marsh McLennan (NYSE: MMC) brings together nearly 78,000 experts in risk, strategy, and people across Marsh, Guy Carpenter, Mercer, and Oliver Wyman, serving clients in over 130 countries.
Marsh enables enterprise worldwide by helping clients manage risks, transforming uncertainty into opportunity.
Guy Carpenter helps clients grow profitably with reinsurance broking expertise, advisory services, and advanced analytics.
Mercer helps organizations advance the health, wealth, and careers of their most vital asset — their people.
Oliver Wyman’s expertise in strategy, operations, risk, and organization transformation changes what is possible for our clients, their industries, and society.
Together, we combine a unique range of capabilities to help our clients solve problems, seize opportunities, and build lasting success in increasingly complex operating environments.
.png)







