Enterprise Data Access Product Owner

Merck Merck · Pharma · Central Bohemian, Czech Republic

Product Owner for an Enterprise Data Access Control (EDAC) platform, focusing on defining product vision, strategy, and roadmap. The role involves identifying and driving opportunities to automate access governance workflows using AI/GenAI, including intelligent policy recommendation, automated request triage, natural language policy authoring, semantic search, and anomaly detection. The role also requires translating regulatory requirements into product capabilities and collaborating with AI/ML teams.

What you'd actually do

  1. Contribute and communicate the product vision, strategy, and multi-quarter roadmap for EDAC as the enterprise's authoritative access control layer.
  2. Own and drive product success metrics and KPI’s.
  3. Research and evaluate industry-leading access control platforms and technologies (e.g., Immuta, Privacera, Collibra Data Access Governance, Okera, Apache Ranger, Open Policy Agent) to inform build-vs-buy-vs-integrate decisions.
  4. Translate regulatory requirements (GDPR, HIPAA, GxP) and enterprise security policies into product capabilities and technical specifications.
  5. Identify and drive opportunities to automate access governance workflows using AI/GenAI, including:Intelligent policy recommendation — leveraging LLMs to suggest access policies based on data classification, usage patterns, and organizational contextAutomated access request triage — using ML models to auto-approve low-risk requests and flag anomalies for human reviewNatural language policy authoring — enabling data stewards to define access rules in plain language, translated into enforceable policy codeSemantic search for access discovery — helping users understand what access they need and how to obtain it (aligned with Discover's Search 2.0 / LLM-assisted retrieval vision)Anomaly detection & risk scoring — applying behavioral analytics to detect unusual access patterns and dynamically adjust permissions.

Skills

Required

  • Product management
  • Product ownership
  • Roadmap definition
  • User story writing
  • Agile methodologies
  • Market research
  • Technology research
  • Access control paradigms
  • Data governance
  • Security policies
  • AI/GenAI automation opportunities
  • LLM capabilities
  • ML models
  • Behavioral analytics
  • Design thinking
  • User-centric principles
  • Access control models (RBAC, ABAC, PBAC, Purpose-Based, Dynamic/Risk-Adaptive)
  • Identity management integration
  • Data platform integration

Nice to have

  • Experience with Immuta, Privacera, Collibra Data Access Governance, Okera, Apache Ranger, Open Policy Agent
  • Experience with XACML, OPA/Rego, Cedar
  • Experience with HashiCorp Vault
  • Experience with Databricks, Redshift, Trino

What the JD emphasized

  • Translate regulatory requirements (GDPR, HIPAA, GxP) and enterprise security policies into product capabilities and technical specifications.

Other signals

  • Identify and drive opportunities to automate access governance workflows using AI/GenAI
  • Leveraging LLMs to suggest access policies
  • Using ML models to auto-approve low-risk requests
  • Enabling data stewards to define access rules in plain language
  • LLM-assisted retrieval vision
  • Applying behavioral analytics to detect unusual access patterns
  • Proactively propose experiments that reduce manual effort, improve user experience, and accelerate time-to-access
  • Leverage shared AI/ML infrastructure for EDAC automation use cases