686,162open jobs
40,351companies
95,115added this week
Browse all
Salary
$23k – $50k per year (Estimated)
Location
Remote/Hybrid (Hyderabad, India)
Seniority
Senior · 5+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Merck & Co. is an American pharmaceutical company founded in 1891 as the United States arm of the German firm Merck and made independent after the First World War, trading as MSD outside the United States and Canada. Its portfolio is dominated by the immuno-oncology drug Keytruda, alongside vaccines such as Gardasil and Vaxneuvance, hospital acute care products, and a large animal health business covering livestock and companion animals. The company is headquartered in Rahway, New Jersey, listed on the New York Stock Exchange, and spends a very large share of revenue on research into oncology, infectious disease and cardiometabolic therapies.

Job Description

The Opportunity

  • Based in Hyderabad, join a global healthcare biopharma company and be part of a 130- year legacy of success backed by ethical integrity, forward momentum, and an inspiring mission to achieve new milestones in global healthcare.

  • Be part of an organisation driven by digital technology and data-backed approaches that support a diversified portfolio of prescription medicines, vaccines, and animal health products.

  • Drive innovation and execution excellence. Be a part of a team with passion for using data, analytics, and insights to drive decision-making, and which creates custom software, allowing us to tackle some of the world's greatest health threats.

Our Technology Centers focus on creating a space where teams can come together to deliver business solutions that save and improve lives. An integral part of our companys’ IT operating model, Tech Centers are globally distributed locations where each IT division has employees to enable our digital transformation journey and drive business outcomes. These locations, in addition to the other sites, are essential to supporting our business and strategy.

A focused group of leaders in each Tech Center helps to ensure we can manage and improve each location, from investing in growth, success, and well-being of our people, to making sure colleagues from each IT division feel a sense of belonging to managing critical emergencies. And together, we must leverage the strength of our team to collaborate globally to optimize connections and share best practices across the Tech Centers.

Role Overview

We are seeking a highly analytical, technically proficient, and business-oriented Business Technology Risk Specialist to join our Business Technology Risk (BTR) organization.

This role sits at the intersection of technology, cybersecurity, risk management, and business enablement. The successful candidate will serve as a trusted advisor to technology leaders, business stakeholders, and cybersecurity teams by identifying, assessing, and communicating technology risks associated with applications, infrastructure, cloud services, AI solutions, third-party vendors, and strategic technology initiatives.

The role requires strong expertise in vendor risk management, application security risk, technology architecture reviews, security controls assessment, IT risk assessments, and risk governance, along with the ability to translate complex technical findings into concise executive insights that support risk-based decision making by senior leadership and the CISO organization.

What You Will Do

Technology Risk Assessments

  • Conduct end-to-end technology risk assessments across applications, infrastructure, cloud platforms, data platforms, AI/ML solutions, and third-party services.

  • Evaluate inherent, residual, and emerging risks associated with new technologies and business initiatives.

  • Assess technology implementations against corporate security standards, risk management requirements, and regulatory expectations.

  • Facilitate risk identification workshops with business and technical stakeholders.

  • Develop risk scenarios, risk statements, impact assessments, and treatment recommendations.

Third-Party & Vendor Risk Management

  • Lead technical due diligence reviews for vendors, suppliers, SaaS providers, managed service providers, and cloud service providers.

  • Assess security architecture, data flows, application designs, integrations, and hosting environments of third-party solutions.

  • Review SIG questionnaires, security assessments, penetration test reports, SOC reports, audit reports, and vendor security documentation.

  • Identify control gaps and determine appropriate risk ratings and treatment strategies.

  • Advise business owners on vendor onboarding risks, compensating controls, and residual risk acceptance considerations.

  • Support ongoing monitoring of high-risk vendors and critical third-party relationships.

Application & Technology Risk Analysis

  • Assess risks associated with enterprise applications, APIs, integrations, identity services, cloud-hosted workloads, and business platforms.

  • Evaluate application architecture against secure design and security engineering principles.

  • Review authentication, authorization, session management, encryption, secrets management, logging, monitoring, and resilience controls.

  • Analyze technical findings from: Penetration tests Red team exercises Vulnerability assessments Architecture reviews Threat modeling engagements Cloud security assessments

  • Identify root causes and recommend practical remediation actions.

Security Control Evaluation

  • Assess design and operating effectiveness of technology and cybersecurity controls.

  • Evaluate preventive, detective, corrective, and compensating controls.

  • Validate effectiveness of: Identity & Access Management (IAM) Privileged Access Management (PAM) Endpoint Security Vulnerability Management Network Security Logging & Monitoring Data Protection Controls Disaster Recovery & Business Resilience Cloud Security Controls

  • Support control maturity assessments and continuous improvement initiatives.

Risk Governance & Advisory

  • Maintain risk registers and document technology risks in accordance with enterprise risk management processes.

  • Facilitate risk discussions with technology teams, security engineers, architects, auditors, and leadership.

  • Challenge assumptions and validate evidence supporting risk decisions.

  • Ensure risks are accurately documented, quantified, escalated, and tracked through resolution.

  • Support risk acceptance and remediation approval processes.

Executive Communication & CISO Advisory

  • Translate complex technical findings into clear business risk language.

  • Develop executive-level risk summaries, dashboards, briefings, and presentations.

  • Provide concise insights on: Risk trends Emerging threats Control effectiveness High-risk vendors Strategic technology initiatives

  • Support CISO, senior leadership, and risk committees with risk-informed recommendations and decision support.

  • Present risk outcomes and mitigation strategies to executive stakeholders with confidence and credibility.

Strategic Risk Enablement

  • Monitor evolving threat landscapes, attacker techniques, and emerging technology risks.

  • Provide risk advisory for strategic transformation initiatives including: Cloud modernization AI/Generative AI adoption Digital transformation programs Large-scale platform migrations Mergers, acquisitions, and integrations

  • Partner with architecture, engineering, compliance, and cybersecurity teams to embed risk considerations early in the solution lifecycle.

Primary Skills:

The ideal candidate should possess working knowledge across the following domains:

Application Security

  • Secure SDLC

  • OWASP Top 10

  • API Security

  • Authentication & Authorization

  • Secrets Management

  • Data Protection

  • Threat Modeling

Cloud Security

  • AWS

  • Azure

  • SaaS Security

  • Cloud Security Posture Management

  • Identity and Federation

  • Container & Kubernetes Security

Infrastructure Security

  • Operating Systems

  • Active Directory

  • Network Architecture

  • Segmentation

  • Endpoint Security

  • Vulnerability Management

Risk & Governance

  • IT Risk Assessments

  • Control Assessments

  • Risk Treatment Planning

  • Risk Acceptance Frameworks

  • Risk Registers

  • Governance Processes

Secondary Skill:

Third-Party Risk

  • SIG Framework

  • SOC Reports

  • Vendor Security Assessments

  • Third-Party Due Diligence

  • Supply Chain Risk

  • Vendor Continuous Monitoring

What Should You Have:

Required Qualifications

  • Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Engineering, or related discipline.

  • 5+ years of experience in Technology Risk Management, Cybersecurity, IT Audit, Third-Party Risk Management, Security Architecture, or related disciplines.

  • Strong experience conducting technology and cybersecurity risk assessments.

  • Experience assessing third-party vendors, cloud providers, and supplier-hosted solutions.

  • Strong understanding of enterprise applications and technology architectures.

  • Demonstrated ability to identify control gaps and articulate business impacts.

  • Experience developing risk treatment plans and remediation recommendations.

  • Excellent written, verbal, and presentation skills.

  • Ability to communicate effectively with both technical teams and executive leadership.

Preferred Qualifications

  • Professional certifications such as: CISSP CISM CRISC CISA AWS Security Specialty Azure Security Engineer

  • Experience in pharmaceutical, healthcare, or regulated industries.

  • Familiarity with AI/GenAI risk assessments.

  • Experience supporting executive risk committees or CISO organizations.

  • Experience with Archer, ServiceNow GRC, ARAVO, OneTrust, or similar risk platforms

Who we are

We are known as Merck & Co., Inc., Rahway, New Jersey, USA in the United States and Canada and MSD everywhere else. For more than a century, we have been bringing forward medicines and vaccines for many of the world's most challenging diseases. Today, our company continues to be at the forefront of research to deliver innovative health solutions and advance the prevention and treatment of diseases that threaten people and animals around the world.

What we look for

Imagine getting up in the morning for a job as important as helping to save and improve lives around the world. Here, you have that opportunity. You can put your empathy, creativity, digital mastery, or scientific genius to work in collaboration with a diverse group of colleagues who pursue and bring hope to countless people who are battling some of the most challenging diseases of our time. Our team is constantly evolving, so if you are among the intellectually curious, join us-and start making your impact today.

Required Skills:

Application Security, Cloud Security, Information Security, Infrastructure Security, IT Risk Assessments, Risk Management

Preferred Skills:

Current Employees apply HERE

Current Contingent Workers apply HERE

Secondary Language(s) Job Description:

#MSDHYDIT

Search Firm Representatives Please Read Carefully

Merck & Co., Inc., Rahway, NJ, USA, also known as Merck Sharp & Dohme LLC, Rahway, NJ, USA, does not accept unsolicited assistance from search firms for employment opportunities. All CVs / resumes submitted by search firms to any employee at our company without a valid written search agreement in place for this position will be deemed the sole property of our company. No fee will be paid in the event a candidate is hired by our company as a result of an agency referral where no pre-existing agreement is in place. Where agency agreements are in place, introductions are position specific. Please, no phone calls or emails.

Employee Status:

Regular

Relocation:

Domestic

VISA Sponsorship:

No

Travel Requirements:

No Travel Required

Flexible Work Arrangements:

Hybrid

Shift:

Not Indicated

Valid Driving License:

No

Hazardous Material(s):

n/a

Job Posting End Date:

09/25/2026

*A job posting is effective until 11:59:59PM on the day BEFORE the listed job posting end date. Please ensure you apply to a job posting no later than the day BEFORE the job posting end date.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
686,162 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Hyderabad
$21k – $48k per year (Estimated) • Remote/Hybrid • Full-Time • 3+ years exp • Bachelor's Degree • Hyderabad
Python
PowerShell
R
SAS
R
Shiny
AI/ML
Copilot
Claude Code
Streamlit
DevOps
Terraform
Ansible
SLURM
CI/CD
Git
AWS
Docker
Kubernetes
Ubuntu
Platform Engineering
Bitbucket
Amazon EKS
HPC
Linux
Management
Agile
Scrum
Apply
$69k per year (net) • In office • 2+ years exp • Master's Degree
Python
SQL
AI/ML
Machine Learning
DevOps
Azure
AWS
Cybersecurity
GDPR
Analytics
Tableau
Power BI
ETL/ELT
Apply
IT Audit Specialist 2 hours ago
$25k – $61k per year (Estimated) • In office • Full-Time • 2+ years exp • Master's Degree • Madrid
DevOps
GCP
Azure
AWS
Management
Agile
Apply
$18k – $49k per year (Estimated) • Remote/Hybrid • Full-Time • 2+ years exp • Bachelor's Degree • Hyderabad
Python
SQL
Python
pySpark
Databases
Databricks
Apache Iceberg
Delta Lake
AI/ML
Spark
Airflow
DevOps
Terraform
CI/CD
AWS
Docker
AWS Fargate
AWS Lambda
GitHub
Amazon S3
IAM
Amazon ECS
Amazon CloudWatch
AWS Step Functions
Cybersecurity
Least Privilege
Analytics
ETL/ELT
Dimensional Modeling
Collibra
Management
Agile
Apply
$33k – $59k per year (Estimated) • Remote • 5+ years exp • Saint Petersburg
Python
Go
JavaScript
Java
Node JS
AI/ML
AI Agents
DevOps
Rest API
gRPC
CI/CD
Docker
Kubernetes
Apply
$87k – $137k per year • In office • Full-Time • 3+ years exp • Bachelor's Degree • Rahway
Apply
$106k – $167k per year • Remote/Hybrid • Full-Time • 5+ years exp • Philadelphia
Apply
$131k – $207k per year • In office • Full-Time • Bachelor's Degree • South San Francisco
Python
SQL
Apply
$210k – $331k per year • Remote • Full-Time • 3+ years exp • PhD • Jackson • Birmingham • Charleston • New Orleans • Miami
DevOps
GCP
Cybersecurity
HIPAA
Management
Microsoft Office
Apply
$173k – $273k per year • Remote/Hybrid • Full-Time • 12+ years exp • Bachelor's Degree • North Wales
Python
SAS
AI/ML
Claude Code
Apply
$36k – $95k per year (Estimated) • Remote • Full-Time • Bachelor's Degree • Bengaluru • Hyderabad • Chennai • Pune • Noida
Python
Java
Java
Spring Boot
DevOps
GCP
Azure
AWS
Docker
Kubernetes
AWS Lambda
API Gateway
Apply
$27k – $69k per year (Estimated) • In office • Full-Time • 5+ years exp • High School Diploma • Hyderabad
Apply
$21k – $53k per year (Estimated) • Remote/Hybrid • Full-Time • 4+ years exp • Hyderabad
Python
Python
FastAPI
Databases
Milvus
Pinecone
Qdrant
AI/ML
Prompt Engineering
Arize Phoenix
Langfuse
LangSmith
LLM
TruLens
LLMOps
DevOps
Rest API
CI/CD
Vector
Apply
Data Engineer 1 day ago
$20k – $49k per year (Estimated) • In office • Full-Time • 3+ years exp • Hyderabad
SQL
AI/ML
Hadoop
Spark
DevOps
AWS
Analytics
ETL/ELT
Management
Agile
Apply
$31k – $70k per year (Estimated) • In office • Full-Time • 12+ years exp • Hyderabad • Kolkata
Analytics
SAP BusinessObjects
Apply
See all jobs
This is one of many
686,162 more open roles from verified company boards, updated every day.