Cyber Risk & Remediation Service Lead
Job in
Scranton, Lackawanna County, Pennsylvania, 18512, USA
Listed on 2026-07-21
Listing for:
Zoetis Spain SL
Full Time
position Listed on 2026-07-21
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below
Malverntime type:
Full time posted on:
Posted Todayjob requisition :
JRStates considered: PA
** Role Description
**** POSITION SUMMARY
** Zoetis is seeking a Cyber Risk & Remediation service lead who will be accountable for the enterprise cyber risk operating cadence, building and maintaining the cyber risk register, driving risk treatment decisions, and ensuring risks are remediated within defined timelines. This leader owns and matures programs spanning Cyber Risk & Remediation, M&A Security risk, and Security Awareness & Training. The role partners closely with technology and business teams to identify risk, assign accountable owners, track remediation progress, and provide clear reporting to Cyber leadership.
** POSITION RESPONSIBILITIES
**** Cyber Risk Governance & Risk Register Ownership
*** Establish the cyber risk governance model (risk taxonomy, scoring/ratings, risk acceptance thresholds, escalation paths).
* Create, own, and maintain the Cyber Risk Register, ensuring each risk has: + defined risk statement and business impact + inherent/residual rating + accountable risk owner + treatment plan (mitigate/accept/transfer/avoid) + target remediation date / SLA and evidence of closure
* Lead recurring risk review forums with technology and business stakeholders; drive risk decisions and document outcomes.
** Remediation Program Leadership:
*** Partner with infrastructure, application, and engineering teams to create and prioritize remediation plans.
* Define remediation SLAs by severity and risk tier and ensure adherence; proactively remove blockers impacting remediation progress.
* Oversee enterprise cyber exposure management for infrastructure and platforms, including governance of
** Minimum Security Baselines (MSBs)
** and continuous security assessment capabilities (e.g., vulnerability and configuration scanning, posture monitoring, and exposure discovery).
* Translate technical findings into actionable cyber risks, ensuring they are tracked through remediation programs, reported through governance forums, and escalated to technology and business stakeholders when remediation SLAs or risk tolerance thresholds are exceeded.
** M&A Security Risk
*** Lead cyber risk activities for M&A: due diligence security findings intake, risk register entry, ownership assignment, and remediation/integration tracking through closure.
* Standardize M&A security assessment and reporting templates.
* Oversee the implementation and tracking of security controls.
** Security Awareness, Training, and Phishing (Human Risk)
*** Own and lead the enterprise
** Security Awareness & Training program**, including development of role-based, targeted, and risk-informed training initiatives.
* Oversee the
** phishing simulation program**, driving measurable reductions in risky user behaviors and strengthening the organization’s human security posture.
* Develop and maintain
** human risk metrics and KRIs**, integrating insights into enterprise cyber risk reporting and informing continuous improvement of awareness strategies.
** Metrics & Continuous Improvement:
*** Produce executive-ready reporting on risk posture, top risks, remediation SLA performance, and program effectiveness.
* Enable on-demand metrics using industry standard frameworks (MITRE, NIST, etc.)
* Establish strong partnership and trust across business units and stakeholders.
** Mentorship & Leadership:
*** Lead and develop a team and/or matrixed resources supporting cyber risk governance, remediation oversight, and human-risk programs.
* Operate as a player-coach, capable of both leading the program and personally contributing to key initiatives such as risk analysis, governance facilitation, remediation coordination, and executive reporting.
* Create and maintain policies, protocols, and standard operating procedures that enable consistent and scalable cyber risk management practices.
* Manage vendors and partners supporting awareness platforms, phishing simulations, and cyber risk workflow tooling.
* Foster a culture of accountability, operational excellence, and continuous learning, encouraging collaboration and knowledge sharing across the team.
** EDUCATION AND EXPERIENCE
** Indicate the formal education, certification or license required and/or preferred. Include the minimum number of years of relevant experience required for the position (where legally permissible).
*
* Education:
*** Bachelor’s degree in Computer Sciences, Information Security, Information Systems, Engineering, Sciences or relevant professional experience.
*
* Experience:
*** 5+ years of experience in information security, technology risk, or enterprise risk, with demonstrated ownership of addressing risk across a global organization and driving cross-functional remediation to closure within defined timelines.
* 3+ years of people leadership and/or senior program leadership in a global environment, with demonstrated ability to influence and deliver outcomes through…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×