Manage vendors and partners supporting awareness platforms, phishing simulations, and cyber risk workflow tooling. * Foster a culture of accountability, operational excellence, and continuous ...
Manage vendors and partners supporting awareness platforms, phishing simulations, and cyber risk workflow tooling. * Foster a culture of accountability, operational excellence, and continuous ...
Manage vendors and partners supporting awareness platforms, phishing simulations, and cyber risk workflow tooling. * Foster a culture of accountability, operational excellence, and continuous ...
Manage vendors and partners supporting awareness platforms, phishing simulations, and cyber risk workflow tooling. * Foster a culture of accountability, operational excellence, and continuous ...
Those in enterprise risk management at PwC will focus on identifying and mitigating potential risks that could impact an organisation's operations and objectives. You will be responsible for ...
Those in enterprise risk management at PwC will focus on identifying and mitigating potential risks that could impact an organisation's operations and objectives. You will be responsible for ...
Client Pod Senior Lead, Managing Director
$170K - $252K/yr
Operational &Risk Excellence * Own workforce planning, productivity and simplification to support a ... Actively manage operational and regulatory risk, ensuring compliance with internal policies and ...
Client Pod Senior Lead, Managing Director
$170K - $252K/yr
Operational &Risk Excellence * Own workforce planning, productivity and simplification to support a ... Actively manage operational and regulatory risk, ensuring compliance with internal policies and ...
The Senior Manager, Third Party Risk Management (TPRM) Policy is a key leadership role embedded ... Establish standards for vendor offboarding that protect Hagerty's data, systems, and operational ...
The Senior Manager, Third Party Risk Management (TPRM) Policy is a key leadership role embedded ... Establish standards for vendor offboarding that protect Hagerty's data, systems, and operational ...
Risk Analyst - 2LoD Controls Testing and Oversight
Mount Laurel, NJ · On-site
$61K - $99K/yr
The ideal candidate has hands-on experience and knowledge of controls testing, root cause analysis, operational risk management, regulatory reporting requirements, and liquidity and capital risk ...
Risk Analyst - 2LoD Controls Testing and Oversight
Mount Laurel, NJ · On-site
$61K - $99K/yr
The ideal candidate has hands-on experience and knowledge of controls testing, root cause analysis, operational risk management, regulatory reporting requirements, and liquidity and capital risk ...
Those in enterprise risk management at PwC will focus on identifying and mitigating potential risks that could impact an organisation's operations and objectives. You will be responsible for ...
Those in enterprise risk management at PwC will focus on identifying and mitigating potential risks that could impact an organisation's operations and objectives. You will be responsible for ...
Governance & Control Sr Mgr (US) - Risk
Mount Laurel, NJ · On-site
$115K - $173K/yr
Develops an Operational Risk Oversight model for the ATM channel which consolidates known risks, documents existing controls and fits within the overall Direct Channels/TDBFG risk framework
Governance & Control Sr Mgr (US) - Risk
Mount Laurel, NJ · On-site
$115K - $173K/yr
Develops an Operational Risk Oversight model for the ATM channel which consolidates known risks, documents existing controls and fits within the overall Direct Channels/TDBFG risk framework
The Operational Due Diligence team is responsible for performing operational due diligence of ... Perform ongoing monitoring of manager ADV filings and other publicly available information * Setup ...
The Operational Due Diligence team is responsible for performing operational due diligence of ... Perform ongoing monitoring of manager ADV filings and other publicly available information * Setup ...
Technology Risk Advisor
Malvern, PA · On-site
... operational risk, or a related field. * Experience assessing technology risks and evaluating the ... Experience with third-party risk management, AI risk, or emerging technology risk. * Relevant ...
Technology Risk Advisor
Malvern, PA · On-site
... operational risk, or a related field. * Experience assessing technology risks and evaluating the ... Experience with third-party risk management, AI risk, or emerging technology risk. * Relevant ...
Technology Risk Advisor
Malvern, PA · On-site
... operational risk, or a related field. * Experience assessing technology risks and evaluating the ... Experience with third-party risk management, AI risk, or emerging technology risk. * Relevant ...
Technology Risk Advisor
Malvern, PA · On-site
... operational risk, or a related field. * Experience assessing technology risks and evaluating the ... Experience with third-party risk management, AI risk, or emerging technology risk. * Relevant ...
The Operational Due Diligence team is responsible for performing operational due diligence of ... Perform ongoing monitoring of manager ADV filings and other publicly available information * Setup ...
The Operational Due Diligence team is responsible for performing operational due diligence of ... Perform ongoing monitoring of manager ADV filings and other publicly available information * Setup ...
... operational improvement initiatives including workflow streamlining and process refinement. A ... Experience in conflicts, independence, or a closely related risk-management function within a ...
... operational improvement initiatives including workflow streamlining and process refinement. A ... Experience in conflicts, independence, or a closely related risk-management function within a ...
The Safety and Risk Management Consultant (Consultant) of TRISTAR's Risk Control Division, Aspen ... Skills to effectively evaluate the client's operations (onsite or virtually) to determine workplace ...
The Safety and Risk Management Consultant (Consultant) of TRISTAR's Risk Control Division, Aspen ... Skills to effectively evaluate the client's operations (onsite or virtually) to determine workplace ...
Safety and Risk Management Consultant _ Remote: Eastern PA
Philadelphia, PA · On-site +1
$95K - $110K/yr
The Safety and Risk Management Consultant (Consultant) of TRISTAR's Risk Control Division, Aspen ... Skills to effectively evaluate the client's operations (onsite or virtually) to determine workplace ...
Safety and Risk Management Consultant _ Remote: Eastern PA
Philadelphia, PA · On-site +1
$95K - $110K/yr
The Safety and Risk Management Consultant (Consultant) of TRISTAR's Risk Control Division, Aspen ... Skills to effectively evaluate the client's operations (onsite or virtually) to determine workplace ...
... operational, technological, and risk management matters. Required Qualifications: * Bachelor's degree or higher in a relevant field (e.g., Finance, Business, Computer Science, or related discipline)
... operational, technological, and risk management matters. Required Qualifications: * Bachelor's degree or higher in a relevant field (e.g., Finance, Business, Computer Science, or related discipline)
Senior Client Manager, Commercial Risk - Insurance Advisory Solutions, Mid-Atlantic Region
Philadelphia, PA · Hybrid
$90K/yr
The Sr. Client Manager, Commercial Risk assists in the coordination of carrier relationships on ... All such discrimination is unlawful, and all persons involved in the operations of the firm are ...
Senior Client Manager, Commercial Risk - Insurance Advisory Solutions, Mid-Atlantic Region
Philadelphia, PA · Hybrid
$90K/yr
The Sr. Client Manager, Commercial Risk assists in the coordination of carrier relationships on ... All such discrimination is unlawful, and all persons involved in the operations of the firm are ...
Manage pre-closing due diligence, including appraisals, environmental reports, title work ... operational risk controls. PHYSICAL REQUIREMENTS Work is of a generally sedentary nature with ...
New
Quick apply
Manage pre-closing due diligence, including appraisals, environmental reports, title work ... operational risk controls. PHYSICAL REQUIREMENTS Work is of a generally sedentary nature with ...
New
... operational risks within their business processes and systems * Develop in-depth knowledge of ... Assess, manage and optimize information technology risk across a wide range of areas, including ...
... operational risks within their business processes and systems * Develop in-depth knowledge of ... Assess, manage and optimize information technology risk across a wide range of areas, including ...
... operational risks within their business processes and systems * Develop in-depth knowledge of ... Assess, manage and optimize information technology risk across a wide range of areas, including ...
... operational risks within their business processes and systems * Develop in-depth knowledge of ... Assess, manage and optimize information technology risk across a wide range of areas, including ...
Operational Risk Manager information
See Haddonfield, NJ salary details
$45.3K - $61.9K
5% of jobs
$72K is the 25th percentile. Wages below this are outliers.
$61.9K - $78.6K
33% of jobs
The median wage is $93.3K / yr.
$78.6K - $95.2K
14% of jobs
$95.2K - $111.8K
14% of jobs
$111.8K - $128.5K
5% of jobs
$140.3K is the 75th percentile. Wages above this are outliers.
$128.5K - $145.1K
6% of jobs
$145.1K - $161.8K
7% of jobs
$161.8K - $178.4K
5% of jobs
$178.4K - $195K
2% of jobs
$195K - $211.7K
8% of jobs
$211.7K - $228.3K
0% of jobs
$45.3K
$116.3K
$228.3K
How much do operational risk manager jobs pay per year?
What Does an Operational Risk Manager Do?
An operational risk manager works to identify and limit the risk associated with a company’s operations. As an operational risk manager, your responsibilities involve assessing business operations, identifying issues, and creating reports on your findings. You then help develop policies and implement changes to lessen operational risks. Other duties include continually monitoring the business to find potential new threats and ensuring company compliance with laws and regulations.
What are the 4 pillars of operational risk management?
What does an operational risk manager do?
Do risk managers make good money?
What are some common challenges faced by Operational Risk Managers in maintaining effective risk controls across different departments?
What are the three C's of operational risk management?
What are the key skills and qualifications needed to thrive as an Operational Risk Manager, and why are they important?
What is the difference between Operational Risk Manager vs Risk Analyst?
| Aspect | Operational Risk Manager | Risk Analyst |
|---|---|---|
| Certifications | CFA, FRM, or similar | CFA, FRM, or similar |
| Work Environment | Financial institutions, banks, insurance companies | Financial firms, consulting, corporate risk teams |
| Responsibilities | Identify, assess, and mitigate operational risks; develop risk frameworks | Analyze risk data, support risk assessments, prepare reports |
The Operational Risk Manager focuses on managing and mitigating operational risks within organizations, often holding certifications like CFA or FRM. In contrast, Risk Analysts primarily analyze risk data and support risk management processes. Both roles are vital in financial sectors and share similar credentials, but the Operational Risk Manager has a broader responsibility for risk mitigation strategies.
Zoetis rating
7.8
Based on 75 frontline employees who took The Breakroom Quiz
43rd of 74 rated pharmaceutical
Job description
Role Description
POSITION SUMMARY
Zoetis is seeking a Cyber Risk & Remediation service lead who will be accountable for the enterprise cyber risk operating cadence, building and maintaining the cyber risk register, driving risk treatment decisions, and ensuring risks are remediated within defined timelines. This leader owns and matures programs spanning Cyber Risk & Remediation, M&A Security risk, and Security Awareness & Training. The role partners closely with technology and business teams to identify risk, assign accountable owners, track remediation progress, and provide clear reporting to Cyber leadership.
POSITION RESPONSIBILITIES
Cyber Risk Governance & Risk Register Ownership
- Establish the cyber risk governance model (risk taxonomy, scoring/ratings, risk acceptance thresholds, escalation paths).
- Create, own, and maintain the Cyber Risk Register, ensuring each risk has:
- defined risk statement and business impact
- inherent/residual rating
- accountable risk owner
- treatment plan (mitigate/accept/transfer/avoid)
- target remediation date / SLA and evidence of closure
- Lead recurring risk review forums with technology and business stakeholders; drive risk decisions and document outcomes.
Remediation Program Leadership:
- Partner with infrastructure, application, and engineering teams to create and prioritize remediation plans.
- Define remediation SLAs by severity and risk tier and ensure adherence; proactively remove blockers impacting remediation progress.
- Oversee enterprise cyber exposure management for infrastructure and platforms, including governance of Minimum Security Baselines (MSBs) and continuous security assessment capabilities (e.g., vulnerability and configuration scanning, posture monitoring, and exposure discovery).
- Translate technical findings into actionable cyber risks, ensuring they are tracked through remediation programs, reported through governance forums, and escalated to technology and business stakeholders when remediation SLAs or risk tolerance thresholds are exceeded.
M&A Security Risk
- Lead cyber risk activities for M&A: due diligence security findings intake, risk register entry, ownership assignment, and remediation/integration tracking through closure.
- Standardize M&A security assessment and reporting templates.
- Oversee the implementation and tracking of security controls.
Security Awareness, Training, and Phishing (Human Risk)
- Own and lead the enterprise Security Awareness & Training program, including development of role-based, targeted, and risk-informed training initiatives.
- Oversee the phishing simulation program, driving measurable reductions in risky user behaviors and strengthening the organization's human security posture.
- Develop and maintain human risk metrics and KRIs, integrating insights into enterprise cyber risk reporting and informing continuous improvement of awareness strategies.
Metrics & Continuous Improvement:
- Produce executive-ready reporting on risk posture, top risks, remediation SLA performance, and program effectiveness.
- Enable on-demand metrics using industry standard frameworks (MITRE, NIST, etc.)
- Establish strong partnership and trust across business units and stakeholders.
Mentorship & Leadership:
- Lead and develop a team and/or matrixed resources supporting cyber risk governance, remediation oversight, and human-risk programs.
- Operate as a player-coach, capable of both leading the program and personally contributing to key initiatives such as risk analysis, governance facilitation, remediation coordination, and executive reporting.
- Create and maintain policies, protocols, and standard operating procedures that enable consistent and scalable cyber risk management practices.
- Manage vendors and partners supporting awareness platforms, phishing simulations, and cyber risk workflow tooling.
- Foster a culture of accountability, operational excellence, and continuous learning, encouraging collaboration and knowledge sharing across the team.
EDUCATION AND EXPERIENCE
Indicate the formal education, certification or license required and/or preferred. Include the minimum number of years of relevant experience required for the position (where legally permissible).
Education:
- Bachelor's degree in Computer Sciences, Information Security, Information Systems, Engineering, Sciences or relevant professional experience.
Experience:
- 5+ years of experience in information security, technology risk, or enterprise risk, with demonstrated ownership of addressing risk across a global organization and driving cross-functional remediation to closure within defined timelines.
- 3+ years of people leadership and/or senior program leadership in a global environment, with demonstrated ability to influence and deliver outcomes through matrixed teams.
- 8+ years of experience (or equivalent depth of expertise) in cyber/technology risk management, with emphasis on human risk programs (awareness, training, phishing) and broader cyber risk governance (risk identification, assessment, tracking, and treatment).
TECHNICAL SKILLS REQUIREMENTS
- Demonstrated ability to build and operate a cyber risk register and drive closure within defined remediation timelines (SLAs), including governance, escalation, and evidence-based closure.
- Experience running Security Awareness & Training and phishing programs with measurable outcomes (completion, behavior change, reporting rates, reduced susceptibility).
- Experience supporting security due diligence and M&A integration risk tracking, including intake of findings, ownership assignment, and remediation through closure.
- Ability to interpret and communicate technical risk using vulnerability and control data-comfortable with trends, prioritization, and executive-level reporting; able to leverage analytics/data visualization tools (e.g., Power BI, Tableau) personally or through team support.
- Working knowledge of common security frameworks and compliance requirements (e.g., NIST, ISO 27001, PCI-DSS, HIPAA) and ability to map findings to controls and risk statements.
- Proven experience coordinating remediation across technical and business teams, managing SLAs, improving remediation workflows, and driving accountability, without needing to be the deepest VM analyst.
- Solid understanding of vulnerability management concepts and lifecycle (discovery, validation, prioritization, exception handling, remediation, verification) with the ability to review team output and challenge/coach appropriately.
- Understanding of security policy, enterprise security strategy, architecture concepts, and governance practices, including risk acceptance and exception processes.
- Broad knowledge of security technologies and principles and risk considerations across on-prem and cloud; familiarity with control frameworks and basic threat modeling concepts.
- Ability to translate emerging issues (vulnerabilities/exploit trends) into practical guidance, playbooks, and operational improvements-partnering with SMEs as needed.
- Comfort operating in complex enterprise environments: able to troubleshoot at a high level, ask the right technical questions, and mobilize the right experts (hands-on depth not required).
- Strong program/project management skills with the ability to manage multiple priorities, run governance cadences, and deliver measurable outcomes.
- Strong written/verbal communication and influence skills; able to present clearly, negotiate effectively, and drive decisions across levels and functions.
- High standards of ethics, professionalism, and integrity.
- Experience in regulated industries (e.g., pharmaceuticals) is desirable.
- Ability to articulate business-focused security outcomes that guide program direction and improve risk posture.
PHYSICAL POSITION REQUIREMENTS
- Primarily office-based work involving sitting, computer use, and meetings.
- Ability to work flexible hours as needed to coordinate with global teams and support audit readiness activities.
- Occasional travel may be required for audits, regulatory meetings, or integration activities.
- No unusual physical demands or attendance requirements expected.
Travel Requirements: 5%-10%
Full time
Regular
Colleague
Any unsolicited resumes sent to Zoetis from a third party, such as an Agency recruiter, including unsolicited resumes sent to a Zoetis mailing address, fax machine or email address, directly to Zoetis employees, or to Zoetis resume database will be considered Zoetis property. Zoetis will NOT pay a fee for any placement resulting from the receipt of an unsolicited resume.
Zoetis will consider any candidate for whom an Agency has submitted an unsolicited resume to have been referred by the Agency free of any charges or fees. This includes any Agency that is an approved/engaged vendor but does not have the appropriate approvals to be engaged on a search.
Notice: Zoetis Recruiters will contact candidates via email from an address ending in @zoetis.com and may also initially connect with candidates through LinkedIn, including LinkedIn InMail. Zoetis does not use Gmail, Outlook, Yahoo, or other web-based/generic email domains to communicate about job opportunities, interviews, or offers of employment. If you receive a recruitment-related email message claiming to be from Zoetis that does not come from @zoetis.com, please treat it as suspicious. For your security, do not reply, click links, open attachments, share personal or financial information, or send money in response to unexpected or questionable recruitment communications.
Zoetis is committed to equal opportunity in the terms and conditions of employment for all employees and job applicants without regard to race, color, religion, sex, sexual orientation, age, gender identity or gender expression, national origin, disability or veteran status or any other protected classification. Disabled individuals are given an equal opportunity to use our online application system. We offer reasonable accommodations as an alternative if requested by an individual with a disability. Please contact Zoetis Colleague Services at zoetiscolleagueservices@zoetis.com to request an accommodation. Zoetis also complies with all applicable national, state and local laws governing nondiscrimination in employment as well as employment eligibility verification requirements of the Immigration and Nationality Act. All applicants must possess or obtain authorization to work in the US for Zoetis. Zoetis retains sole and exclusive discretion to pursue sponsorship for the acquisition or maintenance of nonimmigrant status and employment eligibility, considering factors such as availability of qualified US workers. Individuals requiring sponsorship must disclose this fact. Please note that Zoetis seeks information related to job applications from candidates for jobs in the U.S. solely via the following: (1) our company website at www.Zoetis.com/careers site, or (2) via email to/from addresses using only the Zoetis domain of "@zoetis.com". In addition, Zoetis does not use Google Hangout for any recruitment related activities. Any solicitation or request for information related to job applications with Zoetis via any other means and/or utilizing email addresses with any other domain should be disregarded. In addition, Zoetis will never ask candidates to make any type of personal financial investment related to gaining employment with Zoetis.
About Zoetis
Sourced by ZipRecruiter
Industry
Pharmaceutical and medicine manufacturing
Company size
5,001 - 10,000 Employees
Headquarters location
Morristown, NJ, US
Year founded
1950