Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Director Technology Risk Management image - Rise Careers
Job details

Director Technology Risk Management

Job Description

The Director, Business Information Risk Officer (BIRO) is a critical leadership role responsible for aligning cybersecurity, risk management, and compliance strategies with business objectives. This individual will act as a trusted advisor to the business leaders in our Company Animal Health IT, ensuring that information security and compliance risks are proactively identified, assessed, and managed while enabling business innovation and growth.

This role provides risk governance for all IT and OT systems in our Company's Animal Health division, fostering a secure, compliant, and risk-aware culture. Additionally, the BIRO maintains a continuous feedback loop with the Information Technology Risk Management & Security (ITRMS) team to enhance and align the risk management processes to the business goals.

The ideal candidate will possess deep technical expertise, a strong understanding of business operations, and excellent leadership and stakeholder management skills. S/he must be able to translate complex security concepts into business language and influence stakeholders to drive a risk-aware culture across our Company's Animal Health organization.

Primary Responsibilities:

1. Strategic Leadership & Business Partnership

  • Serve as the primary cybersecurity and risk advisor to our Company Animal Health, aligning security strategies with the business priorities.

  • Provide executive-level risk insights and recommendations to leadership in our Company Animal Health.

  • Ensure security and risk management practices are embedded in business processes, digital transformation initiatives, and operational decision-making.

  • Act as a bridge between ITRMS and our Company Animal Health, translating technical risks into business impact.

2. Risk Management & Governance

  • Drive compliance with applicable global regulations and internal security policies by tailoring the requirements to our Company Animal Health’s operational and regulatory context.

  • Identify, design and help Implement risk-based security solutions that are practical, effective, and aligned with our Company Animal Health business priorities.

  • Stay updated on new and emerging technologies (e.g., AI and Quantum) and new laws and regulations, and to understand their impacts on the business.

3. Technical Expertise & Cyber Resilience

  • Work in unison with our Company Animal Health IT Value Teams to establish secure design, implementation, and monitoring of IT and OT systems, applications, and cloud environments.

  • Proactively identify opportunities to improve cyber resilience capabilities of our Company Animal Health IT and OT systems.

  • Support the Cyber Fusion Center in handling Cyber incidents related to our Company Animal Health division

  • Understand emerging cyber threats, vulnerabilities, and attack vectors, and establish proactive risk mitigation strategies.

4. Leadership, Influence & Culture Building

  • Influence our Company Animal Health stakeholders to foster a security-conscious culture without impeding business agility.

  • Drive security awareness programs that resonate with business functions.

  • Lead, mentor, and develop a high-performing risk and security team

  • Demonstrates high emotional intelligence (EQ) and executive presence (EP), effectively engaging with senior executives and key stakeholders.

Education and Experience Requirements:

  • Bachelor’s Degree in one or more of the following fields: information technology, cyber security, computer science, business administration, communications, or related field.

  • Risk or security certification credentials (CISSP, GSEC, CISA, CISM etc.) are desired but not mandatory

  • 10+ years’ experience working in one or more of the following fields: cybersecurity, IT risk management, IT compliance, IT audit, information technology, or a related field.

  • 5+ years’ experience leading global teams in a management or leadership role, particularly in a fast-paced, service-oriented environment. (desired but not mandatory)

  • Prior experience in the healthcare industry, with an understanding of the unique challenges in securing OT and IT systems. (desired but not mandatory)

Key Competencies

  • ✅ Technical Depth & Business Acumen – Ability to blend security knowledge with business understanding.

  • ✅ Problem-Solving Mindset – Proactive, strategic, and solutions-oriented approach.

  • ✅ Change Management – Experience driving security transformation across the supported organization.

  • ✅ Influence & Executive Presence (EP) – Strong stakeholder management and leadership skills.

  • ✅ High Emotional Intelligence (EQ) – Ability to navigate complex organizational dynamics.

Current Employees apply HERE

Current Contingent Workers apply HERE

US and Puerto Rico Residents Only:

Our company is committed to inclusion, ensuring that candidates can engage in a hiring process that exhibits their true capabilities. Please click here if you need an accommodation during the application or hiring process.

We are an Equal Opportunity Employer, committed to fostering an inclusive and diverse workplace.  All qualified applicants will receive consideration for employment without regard to race, color, age, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, or disability status, or other applicable legally protected characteristics.  For more information about personal rights under the U.S. Equal Opportunity Employment laws, visit:

EEOC Know Your Rights

EEOC GINA Supplement​

Pay Transparency Nondiscrimination

We are proud to be a company that embraces the value of bringing diverse, talented, and committed people together. The fastest way to breakthrough innovation is when diverse ideas come together in an inclusive environment. We encourage our colleagues to respectfully challenge one another’s thinking and approach problems collectively.

Learn more about your rights, including under California, Colorado and other US State Acts

U.S. Hybrid Work Model

Effective September 5, 2023, employees in office-based positions in the U.S. will be working a Hybrid work consisting of three total days on-site per week, Monday - Thursday, although the specific days may vary by site or organization, with Friday designated as a remote-working day, unless business critical tasks require an on-site presence.This Hybrid work model does not apply to, and daily in-person attendance is required for, field-based positions; facility-based, manufacturing-based, or research-based positions where the work to be performed is located at a Company site; positions covered by a collective-bargaining agreement (unless the agreement provides for hybrid work); or any other position for which the Company has determined the job requirements cannot be reasonably met working remotely. Please note, this Hybrid work model guidance also does not apply to roles that have been designated as “remote”.

The Company is required to provide a reasonable estimate of the salary range for this job in certain states and cities within the United States. Final determinations with respect to salary will take into account a number of factors, which may include, but not be limited to the primary work location and the chosen candidate’s relevant skills, experience, and education.

Expected US salary range:

$169,700.00 - $267,200.00

Available benefits include bonus eligibility, long term incentive if applicable, health care and other insurance benefits (for employee and family), retirement benefits, paid holidays, vacation, and sick days. A summary of benefits is listed here.

San Francisco Residents Only: We will consider qualified applicants with arrest and conviction records for employment in compliance with the San Francisco Fair Chance Ordinance

Los Angeles Residents Only: We will consider for employment all qualified applicants, including those with criminal histories, in a manner consistent with the requirements of applicable state and local laws, including the City of Los Angeles’ Fair Chance Initiative for Hiring Ordinance

Search Firm Representatives Please Read Carefully 
Merck & Co., Inc., Rahway, NJ, USA, also known as Merck Sharp & Dohme LLC, Rahway, NJ, USA, does not accept unsolicited assistance from search firms for employment opportunities. All CVs / resumes submitted by search firms to any employee at our company without a valid written search agreement in place for this position will be deemed the sole property of our company.  No fee will be paid in the event a candidate is hired by our company as a result of an agency referral where no pre-existing agreement is in place. Where agency agreements are in place, introductions are position specific. Please, no phone calls or emails. 

Employee Status:

Regular

Relocation:

No relocation

VISA Sponsorship:

No

Travel Requirements:

25%

Flexible Work Arrangements:

Hybrid

Shift:

Not Indicated

Valid Driving License:

No

Hazardous Material(s):

N/A

Job Posting End Date:

04/11/2025

*A job posting is effective until 11:59:59PM on the day BEFORE the listed job posting end date. Please ensure you apply to a job posting no later than the day BEFORE the job posting end date.


Requisition ID:R342067

Merck Glassdoor Company Review
4.1 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
Merck DE&I Review
4.1 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
CEO of Merck
Merck CEO photo
Rob Davis
Approve of CEO

Average salary estimate

$218450 / YEARLY (est.)
min
max
$169700K
$267200K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Director Technology Risk Management, Merck

The Director of Technology Risk Management at Merck is an exciting opportunity for a seasoned leader looking to make a significant impact in the Animal Health division. This role is fundamental in safeguarding our information systems and ensuring that our cybersecurity strategies align perfectly with business objectives. As the Director, you'll act as a trusted advisor, collaborating closely with business leaders to foster a culture that prioritizes security while still allowing for innovation and growth. You'll oversee risk governance for all IT and OT systems, ensuring compliance with industry regulations and enhancing cyber resilience. Your deep technical expertise and understanding of business operations will enable you to translate complex security concepts into actionable insights, making you a key figure in driving risk management processes across our organization. Leading a high-performing risk and security team, you will have the chance to influence stakeholders and cultivate a security-conscious environment without hindering business agility. With a focus on strategic leadership and a commitment to creating a risk-aware culture, your contributions will be instrumental in guiding Merck's Animal Health IT towards a secure future. If you're looking for a role where you can blend your technical skills with business acumen, this position could be exactly what you've been waiting for!

Frequently Asked Questions (FAQs) for Director Technology Risk Management Role at Merck
What are the primary responsibilities of the Director of Technology Risk Management at Merck?

The Director of Technology Risk Management at Merck is responsible for aligning cybersecurity strategies with business objectives. This includes serving as a primary advisor to business leaders, ensuring risk management practices are embedded in processes, driving compliance with global regulations, and identifying effective risk-based security solutions. Additionally, the role involves overseeing the secure design and implementation of IT and OT systems, enhancing cyber resilience, and promoting security awareness throughout the organization.

Join Rise to see the full answer
What qualifications are required for the Director of Technology Risk Management position at Merck?

To qualify for the Director of Technology Risk Management role at Merck, candidates should possess a Bachelor’s Degree in fields such as information technology, cybersecurity, or business administration. Although risk or security certifications like CISSP, CISA, or CISM are desirable, they are not mandatory. Ideally, applicants will have over 10 years of experience in cybersecurity or IT risk management and at least 5 years in a leadership role. Familiarity with the healthcare sector is also beneficial, given the unique challenges faced in that industry.

Join Rise to see the full answer
What skills are essential for success as a Director of Technology Risk Management at Merck?

The key competencies for a successful Director of Technology Risk Management at Merck include a strong combination of technical depth and business acumen, problem-solving skills, and change management abilities. Excellent influence and executive presence are needed to navigate organizational dynamics and engage effectively with senior leaders. High emotional intelligence is also crucial for fostering a security-conscious culture while maintaining business agility.

Join Rise to see the full answer
How does the Director of Technology Risk Management contribute to Merck's Cybersecurity strategy?

The Director of Technology Risk Management significantly contributes to Merck's Cybersecurity strategy by aligning security practices with business priorities, acting as the bridge between technology risk management and business operations. This role involves providing executive-level insights and tailoring compliance requirements to the organization's context. By staying informed on emerging technologies and threats, the Director can proactively implement strategies that enhance cyber resilience and safeguard information assets.

Join Rise to see the full answer
What is the expected salary range for the Director of Technology Risk Management role at Merck?

The expected salary range for the Director of Technology Risk Management role at Merck is between $169,700 and $267,200. The final salary will be determined based on various factors including relevant skills, experience, and location. In addition, Merck offers a comprehensive benefits package that includes bonuses, healthcare options, and retirement benefits.

Join Rise to see the full answer
Common Interview Questions for Director Technology Risk Management
Can you describe your experience with risk management in a technology environment?

When answering this question, it's beneficial to outline specific instances where you identified risks and implemented effective mitigation strategies. Emphasize your technical expertise while illustrating how it aligns with business priorities in the context of your previous roles to showcase your understanding of both sides.

Join Rise to see the full answer
How do you navigate complex organizational dynamics to influence stakeholders?

To respond effectively, highlight your approach to building relationships and trust with stakeholders. Share examples of how effective communication and emotional intelligence enabled you to influence decisions while balancing security needs and business agility.

Join Rise to see the full answer
What strategies do you use to promote a security-conscious culture within an organization?

Discuss your experience running security awareness programs and mentoring teams on best practices. Illustrate how you align these initiatives with overall business objectives to foster a security culture that supports innovation without restricting agility.

Join Rise to see the full answer
How do you stay updated on emerging technologies and threats?

Talk about the methods you utilize for staying current, such as attending industry conferences, participating in webinars, reading relevant journals, and networking with other professionals. Highlight specific areas of focus that relate to advancements impacting cybersecurity.

Join Rise to see the full answer
What do you consider the most significant challenges in securing IT and OT systems?

Reflect on real-world situations you’ve encountered concerning IT and OT security challenges. Discuss the unique aspects of integrating security across both environments, as well as any strategies you've implemented to overcome these challenges.

Join Rise to see the full answer
Can you provide an example of a successful risk management initiative you led?

Use the STAR method to structure your response, focusing on the context, your actions, and the outcomes of your initiative. Showcase your leadership skills and the positive impact of the initiative on the organization’s risk posture.

Join Rise to see the full answer
How do you assess and prioritize cybersecurity risks?

Explain your approach to risk assessment, including any frameworks or tools you utilize. Discuss how you determine risk priority, balancing potential business impacts with resource availability.

Join Rise to see the full answer
What role does compliance play in your approach to cybersecurity?

Discuss the importance of embedding compliance within risk management strategies, providing examples of how aligning compliance with business processes enhances security efforts while also supporting organizational goals.

Join Rise to see the full answer
How do you handle a cybersecurity incident within your team?

Share your protocol for responding to incidents, emphasizing the importance of communication, collaboration with tech teams, and post-incident analysis to prevent future occurrences. Discuss how maintaining calmness and clarity can help manage the situation successfully.

Join Rise to see the full answer
What do you believe are the key components of a successful cybersecurity strategy?

Outline your understanding of the crucial elements of cybersecurity strategy. Mention considerations like risk management, stakeholder engagement, incident response, compliance, and continuous improvement in relation to emerging threats and organizational goals.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Merck Hybrid Worthington, Minnesota, United States
Posted 12 days ago

Join Merck as an Associate Specialist to uphold quality systems and compliance in a dynamic vaccine manufacturing environment.

Photo of the Rise User

Be a pivotal player in advancing RFID reader technology and marketing strategies in the animal health sector at Merck.

Join CommonSpirit Health as an IT End User Services Technician and contribute to impactful health services through top-notch technical support.

Photo of the Rise User
Posted 13 days ago

As a Staff Database Engineer at Visa, you'll play a key role in managing and supporting MySQL databases within a hybrid work environment.

Photo of the Rise User
Posted 4 days ago

Join NCR VOYIX as an Oracle CPQ Technical/Functional Lead to transform businesses through innovative digital solutions.

Weekday AI Remote No location specified
Posted 9 days ago

Shape the future of AI-driven products as a Tech Lead in Generative AI at one of Weekday's esteemed clients.

Photo of the Rise User

GDIT is seeking a Senior Systems Administrator to support vital DoD missions and maintain critical IT systems.

Photo of the Rise User
Makpar Hybrid Washington D.C.
Posted 5 days ago

Join Makpar as a Security Administrator, where you'll implement robust security strategies for Federal clients.

Posted 11 days ago

Apex Fintech Solutions is looking for a Senior IT Systems Engineer to optimize infrastructure performance and ensure system security within a hybrid work environment.

Photo of the Rise User
Inclusive & Diverse
Collaboration over Competition
Growth & Learning
Transparent & Candid

Become a key player at Affirm as a Staff Security Operations Engineer, driving security initiatives in a remote-first environment.

It all comes back to inventing for life We are all inventors here, no matter the role or title. We rise to any challenge in pursuit of better health outcomes. Everything we do, in and out of the laboratory, is based on our deep appreciation for l...

73 jobs
MATCH
Calculating your matching score...
BADGES
Badge ChangemakerBadge Diversity ChampionBadge Family FriendlyBadge InnovatorBadge Work&Life Balance
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
April 1, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!