jobs in Viatris

Kerja Sepenuh Masa, Risk Management Analyst di Viatris Selangor - Maukerja

Risk Management Analyst

Viatris

Kongsi
Simpan

Lokasi Kerja

  • Petaling Jaya Selangor Malaysia

Penerangan Kerja

Tanggungjawab

Position Title : Risk Management Analyst

Location : Petaling Jaya, Malaysia

Mylan Healthcare SDN. BHD. (a Viatris Company)


At VIATRIS, we see healthcare not as it is but as it should be. We act courageously and are uniquely positioned to be a source of stability in a world of evolving healthcare needs.


Viatris empowers people worldwide to live healthier at every stage of life.

We do so via

  • Access – Providing high quality trusted medicines regardless of geography or circumstance
  • Leadership – Advancing sustainable operations and innovative solutions to improve patient health; and
  • Partnership – Leveraging our collective expertise to connect people to products and services


Every day, we rise to the challenge to make a difference and here’s how this role will make an impact.


Role Purpose

The Risk Management Analyst supports Viatris by identifying, assessing, documenting, monitoring, and reporting information security risks across technology, data, third-party, and business environments. The role helps maintain an accurate and audit-ready information security risk register, supports risk assessments, tracks risk treatment activities, and prepares governance reporting to enable timely, risk-informed business decisions.

The role operates in a global pharmaceutical and healthcare environment where security risks may affect regulated systems, data integrity, quality processes, privacy obligations, manufacturing operations, patient safety considerations, intellectual property, and business continuity.


Ownership Boundary

The analyst coordinates risk assessment and risk governance activities but does not own operational remediation unless explicitly assigned. Remediation, technical implementation, system configuration, vulnerability remediation, incident response, privacy compliance remediation, and quality remediation remain accountable to the relevant business, technology, security, privacy, quality, or third-party owners. The analyst documents risk, supports treatment planning, tracks progress, validates evidence, and escalates material or overdue items through the appropriate governance channels.


Primary Focus

Information security risk intake, triage, assessment support, risk register governance, treatment monitoring, and governance reporting


Business Context

Global pharmaceutical and healthcare environment supporting regulated applications, systems, vendors, data, and business processes


Key Tools/Processes

ServiceNow GRC/IRM or equivalent, risk register, risk assessment workflow, reporting dashboards, SharePoint, Power BI, and collaboration tools


Key responsibilities include:

1) Risk Intake, Triage and Scoping

  • Receive, review, prioritize, and document information security risk requests and risk signals from business, technology, third-party, audit, privacy, vulnerability, incident, and monitoring sources.
  • Validate intake details, identify duplicates, and determine the required path: monitor, triage, assess, treat, or escalate.
  • Facilitate scoping and Business Impact Assessment (BIA) discussions to define impacted systems, data, processes, vendors, integrations, and business impacts.
  • Determine inherent risk and recommend the appropriate assessment path using ISRM methodology and risk appetite.

2) Risk Assessment and Control Evaluation

  • Conduct or support information security risk assessments using approved methodologies, control standards, templates, and rating criteria.
  • Identify risk scenarios, threats, vulnerabilities, control gaps, business impacts, and treatment options.
  • Review control evidence and assurance artifacts, including SOC reports, audit results, architecture documents, vendor materials, and security ratings.
  • Assess inherent and residual risk and translate technical findings into clear business risk and treatment recommendations.
  • Support reassessments after major changes, material findings, acceptance reviews, or periodic review triggers.

3) Risk Treatment, Register Governance and Monitoring

  • Maintain the Risk Register as the authoritative record for active, accepted, remediated, and closed risks.
  • Create and update risk records with clear descriptions, ownership, ratings, treatment plans, due dates, evidence, status, and governance decisions.
  • Coordinate with Risk Owners and Remediation Owners to track progress, blockers, evidence, and treatment status.
  • Monitor accepted and residual risks against defined review cycles, Viatris risk appetite, and internal standards.
  • Escalate material, aging, or overdue risks when ownership, progress, or evidence is insufficient.

4) Reporting, Escalation and Closure

  • Prepare risk reports for CSMB, Global Security leadership, auditors, and stakeholders covering new risks, aging risks, overdue remediation, exceptions, trends, and treatment status.
  • Validate closure evidence, including procedures, system evidence, control documentation, change records, assessment reports, and other owner-provided artifacts.
  • Prepare closure recommendations for Risk Manager or governance review and update the risk register with final decisions.
  • Support audit, regulatory, and compliance reviews by maintaining complete, current, and traceable risk documentation.

5) Stakeholder Engagement and Continuous Improvement

  • Communicate information security risks in clear business language for technical and non-technical stakeholders.
  • Partner with IT, Security, Quality, Compliance, Privacy, R&D, manufacturing, supply chain, infrastructure, application, cloud, identity, and third-party teams.
  • Promote risk awareness by clarifying register expectations, scoping inputs, BIA requirements, assessment triggers, evidence needs, and remediation obligations.
  • Improve templates, dashboards, metrics, ServiceNow workflows, risk taxonomy, assessment quality, and reporting practices.

6) Key Deliverables

  • Documented risk assessment intake decisions, queue updates, scoping records, and BIA outputs.
  • Risk assessment reports with risk rationale, control observations, gap analysis, business impact, and treatment recommendations.
  • Accurate, current, and audit-ready risk register entries with assigned owners, ratings, dates, evidence, status, and governance decisions.
  • Risk treatment plans and remediation tracking updates with progress, blockers, due dates, evidence, and escalation status.
  • Governance reporting, dashboards, closure evidence packages, and risk closure recommendations for management, audit, and compliance review.

7) Success Measures

  • Risk assessment requests are triaged, scoped, and documented within agreed service levels or governance expectations.
  • Risk register records are complete, accurate, current, consistently rated, and audit-ready.
  • Risk treatment plans have clear accountable owners, due dates, status updates, evidence requirements, and escalation paths.
  • Overdue, material, or high-priority risks are reported and escalated in a timely manner.
  • Governance reporting is clear, decision-ready, and aligned to ISRM methodology, internal standards, and risk appetite.
  • Risk closure recommendations are supported by appropriate evidence and accurately reflected in the risk register.


Academic, Experience & Knowledge Requirements:

  • Bachelor's degree in Information Security, Information Technology, Computer Science, Risk Management, Life Sciences, Engineering, or a related discipline; equivalent experience may be considered.
  • 3-5 years of experience in information security risk management, governance, risk and compliance (GRC), IT risk, IT audit, third-party risk, compliance, security assessment, or a related technology risk function.
  • Working knowledge of risk assessment practices, control evaluation, risk registers, remediation tracking, evidence review, and governance reporting.
  • Familiarity with security and risk frameworks such as NIST Cybersecurity Framework (CSF), NIST SP 800-53, ISO/IEC 27001/27005, CIS Controls, FAIR, or equivalent internal frameworks.
  • Experience using GRC, workflow, reporting, or collaboration platforms such as ServiceNow GRC/Integrated Risk Management (IRM), SharePoint, Power BI, or similar tools.
  • Ability to analyze technical and business information, document risk clearly, and translate security issues into business impact and practical treatment options.
  • Strong written and verbal communication skills, including the ability to facilitate meetings, document decisions, and influence stakeholders without direct authority.
  • Experience in pharmaceutical, healthcare, biotechnology, manufacturing, or another regulated industry.
  • Understanding of Good Practice (GxP), Computer System Validation (CSV), data integrity, quality management system expectations, privacy requirements, and regulatory inspection support.
  • Exposure to enterprise applications and regulated technology environments such as ERP, Manufacturing Execution Systems (MES), Laboratory Information Management Systems (LIMS), R&D platforms, cloud services, identity services, infrastructure, operational technology (OT) / manufacturing systems, and third-party hosted platforms.
  • Experience reviewing vendor assurance artifacts such as SOC reports, security questionnaires, external security ratings, penetration test summaries, audit reports, or cloud security documentation.
  • Professional certifications such as CRISC, CISA, CISM, CISSP, ISO 27001, Security+, or equivalent are desirable.

Peringatan Penting

Jangan pernah kongsikan maklumat bank atau kad kredit anda semasa memohon pekerjaan. Elakkan membuat sebarang pembayaran atau mengisi survey yang tidak berkaitan. Jika ada yang mencurigakan, sila laporkan iklan pekerjaan ini segera.

Lebih Lanjut