Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Director Technology Risk Management image - Rise Careers
Job details

Director Technology Risk Management

Job Description

The Director, Business Information Risk Officer (BIRO) is a critical leadership role responsible for aligning cybersecurity, risk management, and compliance strategies with business objectives. This individual will act as a trusted advisor to the business leaders in our Company Research Labs division IT, ensuring that information security and compliance risks are proactively identified, assessed, and managed while enabling business innovation and growth.

This role provides risk governance for all IT and OT systems in our Company's Research Labs division, fostering a secure, compliant, and risk-aware culture. Additionally, the BIRO maintains a continuous feedback loop with the Information Technology Risk Management & Security (ITRMS) team to enhance and align the risk management processes to the business goals.

The ideal candidate will possess deep technical expertise, a strong understanding of business operations, and excellent leadership and stakeholder management skills. S/he must be able to translate complex security concepts into business language and influence stakeholders to drive a risk-aware culture across our Company Research Labs division organization.

Primary Responsibilities:

1. Strategic Leadership & Business Partnership

  • Serve as the primary cybersecurity and risk advisor to our Company Research Labs division, aligning security strategies with the business priorities.

  • Provide executive-level risk insights and recommendations to leadership in our Company Research Labs division.

  • Ensure security and risk management practices are embedded in business processes, digital transformation initiatives, and operational decision-making.

  • Act as a bridge between ITRMS and our Company Research Labs division, translating technical risks into business impact.

2. Risk Management & Governance

  • Drive compliance with applicable global regulations and internal security policies by tailoring the requirements to our Company Research Labs division’s operational and regulatory context.

  • Identify, design and help Implement risk-based security solutions that are practical, effective, and aligned with our Company Research Labs division business priorities.

  • Stay updated on new and emerging technologies (e.g., AI and Quantum) and new laws and regulations, and to understand their impacts on the business.

3. Technical Expertise & Cyber Resilience

  • Work in unison with our Company Research Labs division IT Value Teams to establish secure design, implementation, and monitoring of IT and OT systems, applications, and cloud environments.

  • Proactively identify opportunities to improve cyber resilience capabilities of our Company Research Labs division IT and OT systems.

  • Support the Cyber Fusion Center in handling Cyber incidents related to our Company Research Labs division

  • Understand emerging cyber threats, vulnerabilities, and attack vectors, and establish proactive risk mitigation strategies.

4. Leadership, Influence & Culture Building

  • Influence our Company Research Labs division stakeholders to foster a security-conscious culture without impeding business agility.

  • Drive security awareness programs that resonate with business functions.

  • Lead, mentor, and develop a high-performing risk and security team

  • Demonstrates high emotional intelligence (EQ) and executive presence (EP), effectively engaging with senior executives and key stakeholders.

Education and Experience Requirements:

  • Bachelor’s Degree in one or more of the following fields: information technology, cyber security, computer science, business administration, communications, or related field.

  • Risk or security certification credentials (CISSP, GSEC, CISA, CISM etc.) are desired but not mandatory

  • 10+ years’ experience working in one or more of the following fields: cybersecurity, IT risk management, IT compliance, IT audit, information technology, or a related field.

  • 5+ years’ experience leading global teams in a management or leadership role, particularly in a fast-paced, service-oriented environment. (desired but not mandatory)

  • Prior experience in the healthcare industry, with an understanding of the unique challenges in securing OT and IT systems. (desired but not mandatory)

Key Competencies

  • ✅ Technical Depth & Business Acumen – Ability to blend security knowledge with business understanding.

  • ✅ Problem-Solving Mindset – Proactive, strategic, and solutions-oriented approach.

  • ✅ Change Management – Experience driving security transformation across the supported organization.

  • ✅ Influence & Executive Presence (EP) – Strong stakeholder management and leadership skills.

  • ✅ High Emotional Intelligence (EQ) – Ability to navigate complex organizational dynamics.

Current Employees apply HERE

Current Contingent Workers apply HERE

US and Puerto Rico Residents Only:

Our company is committed to inclusion, ensuring that candidates can engage in a hiring process that exhibits their true capabilities. Please click here if you need an accommodation during the application or hiring process.

We are an Equal Opportunity Employer, committed to fostering an inclusive and diverse workplace.  All qualified applicants will receive consideration for employment without regard to race, color, age, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, or disability status, or other applicable legally protected characteristics.  For more information about personal rights under the U.S. Equal Opportunity Employment laws, visit:

EEOC Know Your Rights

EEOC GINA Supplement​

Pay Transparency Nondiscrimination

We are proud to be a company that embraces the value of bringing diverse, talented, and committed people together. The fastest way to breakthrough innovation is when diverse ideas come together in an inclusive environment. We encourage our colleagues to respectfully challenge one another’s thinking and approach problems collectively.

Learn more about your rights, including under California, Colorado and other US State Acts

U.S. Hybrid Work Model

Effective September 5, 2023, employees in office-based positions in the U.S. will be working a Hybrid work consisting of three total days on-site per week, Monday - Thursday, although the specific days may vary by site or organization, with Friday designated as a remote-working day, unless business critical tasks require an on-site presence.This Hybrid work model does not apply to, and daily in-person attendance is required for, field-based positions; facility-based, manufacturing-based, or research-based positions where the work to be performed is located at a Company site; positions covered by a collective-bargaining agreement (unless the agreement provides for hybrid work); or any other position for which the Company has determined the job requirements cannot be reasonably met working remotely. Please note, this Hybrid work model guidance also does not apply to roles that have been designated as “remote”.

The Company is required to provide a reasonable estimate of the salary range for this job in certain states and cities within the United States. Final determinations with respect to salary will take into account a number of factors, which may include, but not be limited to the primary work location and the chosen candidate’s relevant skills, experience, and education.

Expected US salary range:

$169,700.00 - $267,200.00

Available benefits include bonus eligibility, long term incentive if applicable, health care and other insurance benefits (for employee and family), retirement benefits, paid holidays, vacation, and sick days. A summary of benefits is listed here.

San Francisco Residents Only: We will consider qualified applicants with arrest and conviction records for employment in compliance with the San Francisco Fair Chance Ordinance

Los Angeles Residents Only: We will consider for employment all qualified applicants, including those with criminal histories, in a manner consistent with the requirements of applicable state and local laws, including the City of Los Angeles’ Fair Chance Initiative for Hiring Ordinance

Search Firm Representatives Please Read Carefully 
Merck & Co., Inc., Rahway, NJ, USA, also known as Merck Sharp & Dohme LLC, Rahway, NJ, USA, does not accept unsolicited assistance from search firms for employment opportunities. All CVs / resumes submitted by search firms to any employee at our company without a valid written search agreement in place for this position will be deemed the sole property of our company.  No fee will be paid in the event a candidate is hired by our company as a result of an agency referral where no pre-existing agreement is in place. Where agency agreements are in place, introductions are position specific. Please, no phone calls or emails. 

Employee Status:

Regular

Relocation:

No relocation

VISA Sponsorship:

No

Travel Requirements:

25%

Flexible Work Arrangements:

Hybrid

Shift:

Not Indicated

Valid Driving License:

No

Hazardous Material(s):

N/A

Job Posting End Date:

04/11/2025

*A job posting is effective until 11:59:59PM on the day BEFORE the listed job posting end date. Please ensure you apply to a job posting no later than the day BEFORE the job posting end date.

Average salary estimate

$218450 / YEARLY (est.)
min
max
$169700K
$267200K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Director Technology Risk Management, MSD

The Director Technology Risk Management at Merck & Co. in Rahway, New Jersey, is a pivotal leadership position that merges cybersecurity with business objectives. In this role, you'll be the go-to advisor for the Research Labs division, guiding key business leaders in effectively identifying and managing information security risks. By fostering a culture of compliance and risk-awareness, you will enable innovative business initiatives while ensuring a secure operational framework. You’ll work closely with the IT Risk Management & Security (ITRMS) team to enhance risk management processes, constantly assessing how emerging technologies impact the business landscape. With your deep technical expertise and understanding of business operations, you'll translate complex cybersecurity concepts into relatable terms, helping stakeholders recognize their importance. Your strategic insights will help embed risk management principles in decision-making processes, making sure security measures are integrated into digital transformations. With a focus on team leadership, you'll mentor and develop a high-performing risk and security team, supporting cybersecurity initiatives across our labs. You’ll guide executive-level discussions, helping to translate technical risks into tangible business impacts. Join us at Merck, where your influence can drive a security-conscious culture that doesn't sacrifice agility, and where your comprehensive approach to risk management plays a critical role in our mission to foster a healthier world.

Frequently Asked Questions (FAQs) for Director Technology Risk Management Role at MSD
What are the primary responsibilities of the Director Technology Risk Management at Merck?

As the Director Technology Risk Management at Merck, you will serve as a cybersecurity and risk advisor, providing insights and recommendations to leadership. Your role includes ensuring compliance with regulations, implementing risk-based security solutions, and fostering a security-conscious culture without compromising business agility. It's all about aligning security strategies with business priorities.

Join Rise to see the full answer
What qualifications are needed to become a Director Technology Risk Management at Merck?

To excel as a Director Technology Risk Management at Merck, you should have a Bachelor’s degree in fields such as information technology or cybersecurity, along with 10+ years of relevant experience. While certifications like CISSP or CISA are beneficial, they are not mandatory. Leadership experience is essential, especially in fast-paced environments.

Join Rise to see the full answer
How does the Director Technology Risk Management influence the culture at Merck?

In your role as the Director Technology Risk Management, you'll have a significant impact on the culture at Merck by promoting a security-conscious environment. You'll lead security awareness programs and influence stakeholders, ensuring that security and risk management practices are woven into the fabric of daily operations and decision-making.

Join Rise to see the full answer
What kind of team will the Director Technology Risk Management lead at Merck?

As the Director Technology Risk Management at Merck, you will lead a high-performing risk and security team. Mentorship and development of team members will be crucial, as you work together to establish effective cybersecurity measures. Your leadership will help build a resilient IT and OT system, aligning with Merck’s operational goals.

Join Rise to see the full answer
What is the work environment like for a Director Technology Risk Management at Merck?

The work environment for a Director Technology Risk Management at Merck is dynamic and collaborative, supporting a hybrid work model. You will work closely with various departments and have opportunities for cross-functional collaboration, all while being a leader in advancing security and risk management processes within the organization.

Join Rise to see the full answer
Common Interview Questions for Director Technology Risk Management
How would you approach aligning cybersecurity initiatives with business objectives as the Director Technology Risk Management?

In this scenario, you should emphasize the importance of understanding the business landscape and actively engaging with key stakeholders. Discuss implementing a feedback loop where cybersecurity strategies are continuously assessed against evolving business needs, thereby ensuring alignment and support from leadership.

Join Rise to see the full answer
Can you provide an example of how you’ve driven security culture within a team?

Share a specific instance where you initiated security awareness programs or training sessions, detailing how you tailored them to resonate with business functions. Highlight the methods you used to measure engagement and effectiveness, demonstrating your commitment to fostering a security-conscious environment.

Join Rise to see the full answer
What experience do you have with regulatory compliance in the healthcare industry?

Discuss any relevant roles you’ve held where you dealt with compliance frameworks or regulations specifically in the healthcare domain. Highlight projects you’ve undertaken that required close collaboration with legal or compliance teams, and how you navigated complex regulatory environments.

Join Rise to see the full answer
How do you stay current on emerging threats and risks in cybersecurity?

Express your commitment to continuous learning by mentioning any industry publications, webinars, or conferences you attend. Discuss how you regularly review threat intelligence reports and collaborate with peers in the industry to share insights and strategies for tackling new challenges.

Join Rise to see the full answer
Describe a situation where you successfully influenced a stakeholder's decision regarding cybersecurity.

Share a specific story where you used data-driven insights to advocate for security measures that were initially met with resistance. Discuss how you built rapport with the stakeholder, Provided compelling evidence, and led them to see the value in taking necessary security actions.

Join Rise to see the full answer
What strategies would you use to implement a risk-based security solution at Merck?

Outline a structured approach, including risk assessment methodologies, alignment with business priorities, and creating tailored security solutions. Discuss incorporating feedback from all levels of the organization and agility in adapting to changes in the threat landscape or business strategy.

Join Rise to see the full answer
How do you balance risk management with the need for business agility?

Explain that striking this balance requires a deep understanding of both risk and business imperatives. Highlight your approach of embedding security into business processes early on to ensure that security measures enhance rather than hinder operational efficiency.

Join Rise to see the full answer
What role does emotional intelligence play in your leadership style?

Elaborate on how high emotional intelligence aids in understanding team dynamics, managing conflicts, and influencing others. Share examples of how you adjust your communication style to connect better with stakeholders and lead effectively.

Join Rise to see the full answer
In your opinion, what is the biggest challenge faced by the Director Technology Risk Management today?

Articulate your perspective on the rapidly changing threat landscape and the difficulties in remaining compliant with various regulatory frameworks. Discuss your belief that the challenge also lies in ensuring organizational buy-in for security initiatives to foster a resilient culture.

Join Rise to see the full answer
How would you define success in the role of Director Technology Risk Management at Merck?

Define success as the ability to effectively mitigate risks while allowing business innovation to flourish. Talk about measurable outcomes such as reduced incident response times, improved security metrics, and widespread culture of security awareness, demonstrating your focus on results-oriented leadership.

Join Rise to see the full answer
Similar Jobs
Posted 9 days ago
Avera Hybrid Sioux Falls, SD
Posted 3 days ago

Join Avera Health as an IT Application Analyst and help enhance our health information system.

Photo of the Rise User
Posted 13 days ago
Photo of the Rise User

Join UMMS as a Senior Program Manager to lead IT initiatives and enhance healthcare delivery through effective project management.

Photo of the Rise User
Polly Remote No location specified
Posted 7 days ago
Photo of the Rise User
Broadridge Remote Newark, New Jersey, United States
Posted 3 days ago

Join Broadridge as a Senior Enterprise Engineer to drive compliance initiatives and support diverse teams in Newark.

Photo of the Rise User
Bosch Group Remote Omladinskih Brigada 90E, Beograd, Serbia, Serbia
Posted 14 days ago

Our purpose: We use the power of leading-edge science to save and improve lives around the world

33 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
April 1, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
Photo of the Rise User
37 people applied to Security Analyst Jr at DEUNA
Photo of the Rise User
43 people applied to Cyber Crime Analyst at TEKsystems
Photo of the Rise User
Someone from OH, Cleveland just viewed Senior Governance Risk and Compliance Analyst at Dave
T
Someone from OH, New Albany just viewed Product Manager - Media & Entertainment at Truelogic
Photo of the Rise User
Someone from OH, Cincinnati just viewed Chief Financial Officer (Single Family Office) at Confidential
Photo of the Rise User
Someone from OH, New Albany just viewed Earned Media Specialist at L2TMedia
Photo of the Rise User
Someone from OH, New Albany just viewed Field Marketing Manager at Houzz
Photo of the Rise User
Someone from OH, New Albany just viewed Fields and Events Marketing Manager at FullStory
Photo of the Rise User
Someone from OH, Cincinnati just viewed Full-Time Google Ad Manager - US Only, No Agencies at Upwork
Photo of the Rise User
Someone from OH, New Albany just viewed Field Marketing Manager at Front
S
7 people applied to SOC Intern at SHEIN
Photo of the Rise User
22 people applied to Cybersecurity Intern at Dewberry
Photo of the Rise User
Someone from OH, Cincinnati just viewed Quality Inspector - Mechanical - Level 1 at SQA Services
Photo of the Rise User
Someone from OH, East Palestine just viewed Business Development Representative - (Remote - US) at Jobgether
Photo of the Rise User
Someone from OH, Columbus just viewed Amazon customer service at Amazon
Photo of the Rise User
Someone from OH, Hilliard just viewed UX Researcher (Contract Position) at RR Donnelley
Photo of the Rise User
Someone from OH, Hilliard just viewed Minor Team Member (14-15) at Chick-fil-A
Photo of the Rise User
Someone from OH, Hilliard just viewed Lead UX Product Designer -Stores(Remote Or Hybrid) at Target
F
Someone from OH, Cincinnati just viewed Payroll Tax Consultant at Fourth Enterprises, LLC
Photo of the Rise User
Someone from OH, Columbus just viewed Aquatics Director at British Swim School
Photo of the Rise User
Someone from OH, North Canton just viewed 2025 MiLB Gameday Support (Seasonal) at MLB (Job Board Only)
E
Someone from OH, Columbus just viewed Intern, Cell Line Development at Evotec