ActiveJobs

Director, Cybersecurity Engineering

Merck Careers · 4 Locations

Full-timeOn-sitePosted 2 July 2026
Apply on Company Site →

Job description

Job Description The Commercial Technologies Operational Security Lead is a Director role responsible for ensuring the security, resilience, and operational integrity of customer‑facing technology solutions, including software, platforms, and integrated hardware offerings. This role provides hands‑on leadership and subject matter expertise across vulnerability research, security engineering, product security, and operational assurance for technologies delivered to external customers. The individual will partner closely with product, engineering, cloud, and commercial technology teams to ensure security controls are designed, implemented, validated, and continuously improved throughout the product lifecycle. This role plays a critical part in enabling secure innovation, protecting customer trust, and ensuring solutions meet regulatory, contractual, and risk expectations in a highly regulated environment. Key Activities Provide security oversight and operational assurance for customer‑facing software and hardware technology solutions across development, deployment, and runtime operations. Define, assess, and validate security controls for commercial technology platforms, ensuring alignment with enterprise security standards, regulatory requirements, and customer expectations. Lead vulnerability research, analysis, and operational response across applications, platforms, infrastructure, and embedded technologies. Partner with engineering and product teams to integrate security into architecture, design, and development processes using secure‑by‑design and shift‑left principles. Support product security activities including threat modeling, secure design reviews, penetration testing coordination, and remediation validation. Provide security architecture guidance for virtualized, cloud‑native, hybrid, and containerized environments supporting customer solutions. Oversee vulnerability management operations for commercial technologies, including scanning, prioritization, remediation tracking, and risk acceptance. Collaborate with DevSecOps teams to drive automation of security testing, control validation, and continuous monitoring. Ensure security requirements are embedded into CI/CD pipelines and product release processes. Act as a key liaison between commercial technology teams, enterprise security, risk management, and compliance functions. Support customer assurance activities, including security questionnaires, audits, attestations, and incident response coordination. Contribute to incident response and root cause analysis for security events impacting customer‑facing technologies. Identify gaps, emerging risks, and improvement opportunities across product and operational security capabilities. Promote security best practices, standards, and operational maturity across commercial technology portfolios. Education Requirements Bachelor’s degree in Computer Science, Engineering, Information Security, or a related field. Advanced degree or relevant security certifications preferred. Required Skills and Experience Technical Expertise Strong experience in vulnerability research, vulnerability management operations, and remediation validation. Hands‑on experience with security engineering and product security for software‑based and integrated hardware solutions. Solid understanding of security architecture principles for cloud, virtualized, containerized, and hybrid environments. Experience securing APIs, web applications, SaaS platforms, and distributed systems. Familiarity with DevSecOps practices, CI/CD pipelines, and security automation tooling. Working knowledge of cryptography, identity and access management, and secure communications. Operational Security & Product Assurance Experience supporting customer‑facing technologies where security, availability, and trust are business‑critical. Ability to assess operational risk and translate findings into actionable remediation plans. Experience supporting audits, customer security reviews, and regulatory expectations. Experience & Leadership 10+ years of experience in cybersecurity, product security, security engineering, or related technical disciplines. Demonstrated ability to operate as a leader, influencing outcomes through expertise rather than formal authority. Proven ability to work effectively across engineering, product, cloud, and business teams. Communication & Collaboration Strong communication skills with the ability to explain complex security concepts to technical and non‑technical stakeholders. Ability to balance security rigor with business enablement and product delivery timelines. Preferred Skills and Experience Certifications CISSP, CSSLP, GWAPT, OSCP, or equivalent security certifications. Frameworks and Standards Familiarity with NIST, ISO 27001, OWASP, and secure development lifecycle (SDLC) frameworks. Cloud & Automation Experience with major cloud platforms (AWS, Azure, GCP) and infrastructure‑as‑code tooling. Experience leveraging automation to scale security controls and operational assurance. Required Skills: Application Security, Application Security, Business Enablement, Certificate Services, Change Catalyst, Communication, Cross-Cultural Awareness, Cybersecurity, Cybersecurity Analytics, Cybersecurity Operations, Delivery of Security Applications, Design Applications, Information Security, ISO 27000, ISO 27001 Implementation, ISO 27002, Network Segmentation, Operational Technology (OT) Security, Organizational Security, Regulatory Requirements, Security Architecture Design, Security Automation, Security Engineering, SLA Management, System Designs {+ 3 more} Preferred Skills: Current Employees apply HERE Current Contingent Workers apply HERE US and Puerto Rico Residents Only: Our company is committed to inclusion, ensuring that candidates can engage in a hiring process that exhibits their true capabilities. Please click here if you need an accommodation during the application or hiring process. As an Equal Employment Opportunity Employer, we provide equal opportunities to all employees and applicants for employment and prohibit discrimination on the basis of race, color, age, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, disability status, or other applicable legally protected characteristics. As a federal contractor, we comply with all affirmative action requirements for protected veterans and individuals with disabilities. For more information about personal rights under the U.S. Equal Opportunity Employment laws, visit: EEOC Know Your Rights EEOC GINA Supplement​ We are proud to be a company that embraces the value of bringing together, talented, and committed people with diverse experiences, perspectives, skills and backgrounds. The fastest way to breakthrough innovation is when people with diverse ideas, broad experiences, backgrounds, and skills come together in an inclusive environment. We encourage our colleagues to respectfully challenge one another’s thinking and approach problems collectively. Learn more about your rights, including under California, Colorado and other US State Acts The salary range for this role is $156,900.00 - $247,000.00 This is the lowest to highest salary we in good faith believe we would pay for this role at the time of this posting. An employee’s position within the salary range will be based on several factors including, but not limited to relevant education, qualifications, certifications, experience, skills, geographic location, government requirements, and business or organizational needs. The successful candidate will be eligible for annual bonus and long-term incentive, if applicable. We offer a comprehensive package of benefits. Available benefits include medical, dental, vision healthcare and other insurance benefits (for employee and family), retirement benefits, including 401(k), pa

Verified and listed by ActiveJobs. Applications are made directly on Merck Careers's own career page — we never sit in the middle.