Director, Technology Risk Management
Merck
August 06, 2026
Remote friendly (Rahway, NJ)
United States
IT
Primary Responsibilities
Strategic Leadership & Business Partnership
- Serve as the primary cybersecurity and risk advisor to Enterprise IT (EIT), aligning security strategies with business priorities.
- Provide executive-level risk insights and recommendations to EIT leadership.
- Embed security and risk management into business processes, digital transformation initiatives, and operational decision-making.
- Bridge ITRMS and EIT by translating technical risks into business impact.
Risk Management & Governance
- Drive compliance with applicable global regulations and internal security policies tailored to EITβs context.
- Identify, design, and help implement risk-based security solutions aligned to EIT priorities.
- Provide security and risk leadership for strategic IT programs (e.g., SAP S/4HANA), integrating security/compliance across the lifecycle.
- Stay current on emerging technologies (e.g., AI, Quantum) and new laws/regulations and their business impacts.
Technical Expertise & Cyber Resilience
- Work with EIT IT Value Teams to establish secure design, implementation, and monitoring of IT systems, applications, and cloud environments.
- Identify opportunities to improve cyber resilience.
- Support the Cyber Fusion Center with EIT-related cyber incidents.
- Understand emerging threats/vulnerabilities/attack vectors and establish proactive mitigation strategies.
Leadership, Influence & Culture Building
- Influence EIT stakeholders to foster a security-conscious culture without impeding agility.
- Drive security awareness programs.
- Lead, mentor, and develop a high-performing risk and security team.
- Demonstrate high EQ and executive presence with senior leaders.
Education & Experience Requirements
- Bachelorβs degree in IT, cybersecurity, CS, business administration, communications, or related field.
- Knowledge of platforms such as SAP S/4, Workday.
- 10+ years in cybersecurity, IT risk management, IT compliance, IT, or related field.
- 5+ years leading global teams (preferred in fast-paced, service-oriented environments).
- Preferred: healthcare industry experience.
- Preferred: CISSP, GSEC, CISA, CISM, etc.
Key Competencies
- Technical depth & business acumen; problem-solving; change management; influence & executive presence; high emotional intelligence.
Required Skills
- Business acumen, cybersecurity, data management, digital transformation, emotional intelligence, executive presence, information security, IT risk management/compliance governance, IT risk assessments/governance/response & reporting, regulations/frameworks knowledge, risk management & mitigation, security solutions, stakeholder management, technical advice.
Preferred Skills
- Current employees apply HERE; current contingent workers apply HERE.
Application Instructions
- Apply at https://jobs.merck.com/us/en (or via Workday Jobs Hub). Application deadline stated on posting.
Strategic Leadership & Business Partnership
- Serve as the primary cybersecurity and risk advisor to Enterprise IT (EIT), aligning security strategies with business priorities.
- Provide executive-level risk insights and recommendations to EIT leadership.
- Embed security and risk management into business processes, digital transformation initiatives, and operational decision-making.
- Bridge ITRMS and EIT by translating technical risks into business impact.
Risk Management & Governance
- Drive compliance with applicable global regulations and internal security policies tailored to EITβs context.
- Identify, design, and help implement risk-based security solutions aligned to EIT priorities.
- Provide security and risk leadership for strategic IT programs (e.g., SAP S/4HANA), integrating security/compliance across the lifecycle.
- Stay current on emerging technologies (e.g., AI, Quantum) and new laws/regulations and their business impacts.
Technical Expertise & Cyber Resilience
- Work with EIT IT Value Teams to establish secure design, implementation, and monitoring of IT systems, applications, and cloud environments.
- Identify opportunities to improve cyber resilience.
- Support the Cyber Fusion Center with EIT-related cyber incidents.
- Understand emerging threats/vulnerabilities/attack vectors and establish proactive mitigation strategies.
Leadership, Influence & Culture Building
- Influence EIT stakeholders to foster a security-conscious culture without impeding agility.
- Drive security awareness programs.
- Lead, mentor, and develop a high-performing risk and security team.
- Demonstrate high EQ and executive presence with senior leaders.
Education & Experience Requirements
- Bachelorβs degree in IT, cybersecurity, CS, business administration, communications, or related field.
- Knowledge of platforms such as SAP S/4, Workday.
- 10+ years in cybersecurity, IT risk management, IT compliance, IT, or related field.
- 5+ years leading global teams (preferred in fast-paced, service-oriented environments).
- Preferred: healthcare industry experience.
- Preferred: CISSP, GSEC, CISA, CISM, etc.
Key Competencies
- Technical depth & business acumen; problem-solving; change management; influence & executive presence; high emotional intelligence.
Required Skills
- Business acumen, cybersecurity, data management, digital transformation, emotional intelligence, executive presence, information security, IT risk management/compliance governance, IT risk assessments/governance/response & reporting, regulations/frameworks knowledge, risk management & mitigation, security solutions, stakeholder management, technical advice.
Preferred Skills
- Current employees apply HERE; current contingent workers apply HERE.
Application Instructions
- Apply at https://jobs.merck.com/us/en (or via Workday Jobs Hub). Application deadline stated on posting.