MSD

Manager, Attack Automation Engineer

IND - Telangana - Hyderabad (HITEC City) Full time

Job Description

Required Skills:

Adaptability, Analytical Thinking, Cyber Threat Hunting, Cyber Threat Intelligence, Data Loss Prevention (DLP), Detail-Oriented, Digital Forensics, Incident Response Management, Insider Threat Mitigation, Log Analysis, Malware Analysis, Security Information and Event Management (SIEM), Security Monitoring, Security Operations, SLA Management, Team Collaboration, Vulnerability Assessments, Vulnerability Management, Written Communication

Preferred Skills:

Current Employees apply HERE

Current Contingent Workers apply HERE

Secondary Language(s) Job Description:

The Opportunity 

  • Based in Hyderabad, join a global healthcare biopharma company and be part of a 130- year legacy of success backed by ethical integrity, forward momentum, and an inspiring mission to achieve new milestones in global healthcare.  
  • Be part of an organisation driven by digital technology and data-backed approaches that support a diversified portfolio of prescription medicines, vaccines, and animal health products.  
  • Drive innovation and execution excellence. Be a part of a team with passion for using data, analytics, and insights to drive decision-making, and which creates custom software, allowing us to tackle some of the world's greatest health threats.  

Our Technology Centers focus on creating a space where teams can come together to deliver business solutions that save and improve lives. An integral part of our company’s IT operating model, Tech Centers are globally distributed locations where each IT division has employees to enable our digital transformation journey and drive business outcomes. These locations, in addition to the other sites, are essential to supporting our business and strategy.  

A focused group of leaders in each Tech Center helps to ensure we can manage and improve each location, from investing in growth, success, and well-being of our people, to making sure colleagues from each IT division feel a sense of belonging to managing critical emergencies. And together, we must leverage the strength of our team to collaborate globally to optimize connections and share best practices across the Tech Centers.  

Role Overview

As an Attack Automation Engineer (Specialist) with a focus on automated reconnaissance, you will design, develop, and maintain systems that automate the collection, analysis, and enrichment of recon data. You will leverage OSINT, cloud APIs, and enterprise tools to map attack surfaces, discover assets, and identify vulnerabilities—enabling rapid, scalable, and stealthy adversary emulation.

What will you do in this role

  • Automate reconnaissance workflows including asset discovery, subdomain enumeration, credential exposure checks, and technology profiling.
  • Develop integrations with OSINT frameworks (Recon-ng, Spiderfoot), cloud asset management tools, and internal data sources to aggregate and enrich recon findings.
  • Automate identification and mapping of external and internal attack surfaces across cloud, hybrid, and on-prem environments.
  • Collaborate with red and purple teams to design recon-centric attack scenarios and contribute to adversary emulation playbooks.
  • Document recon methodologies, automation processes, and findings for knowledge sharing and continuous improvement.
  • Stay current with emerging recon techniques, OSINT tools, and automation frameworks.

What should you have

  • Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, or related field.
  • 3+ years of hands-on experience in security engineering, red team operations, or automation development.
  • Proficiency in Python and at least one other programming language (Java, TypeScript, .NET).
  • Experience with OSINT and recon automation tools (Recon-ng, Spiderfoot, theHarvester, Maltego).
  • Familiarity with cloud asset management and vulnerability scanning platforms (Wiz.io, Qualys).
  • Strong understanding of MITRE ATT&CK Reconnaissance techniques (T1590–T1599).
  • Experience with DevSecOps practices and infrastructure automation (Docker, Terraform, CI/CD).
  • Solid understanding of IT infrastructure components and operations, including networking, DNS, firewalls, load balancers, virtualization, and enterprise systems architecture.
  • Analytical and problem-solving skills; ability to work independently and collaboratively.
  • Good interpersonal and communication skills.

Our technology teams operate as business partners, proposing ideas and innovative solutions that enable new organizational capabilities. We collaborate internationally to deliver services and solutions that help everyone be more productive and enable innovation.  

Who we are 

We are known as Merck & Co., Inc., Rahway, New Jersey, USA in the United States and Canada and MSD everywhere else. For more than a century, we have been inventing for life, bringing forward medicines and vaccines for many of the world's most challenging diseases. Today, our company continues to be at the forefront of research to deliver innovative health solutions and advance the prevention and treatment of diseases that threaten people and animals around the world.  

What we look for 

Imagine getting up in the morning for a job as important as helping to save and improve lives around the world. Here, you have that opportunity. You can put your empathy, creativity, digital mastery, or scientific genius to work in collaboration with a diverse group of colleagues who pursue and bring hope to countless people who are battling some of the most challenging diseases of our time. Our team is constantly evolving, so if you are among the intellectually curious, join us—and start making your impact today. 

#HYDIT2025

Search Firm Representatives Please Read Carefully 
Merck & Co., Inc., Rahway, NJ, USA, also known as Merck Sharp & Dohme LLC, Rahway, NJ, USA, does not accept unsolicited assistance from search firms for employment opportunities. All CVs / resumes submitted by search firms to any employee at our company without a valid written search agreement in place for this position will be deemed the sole property of our company.  No fee will be paid in the event a candidate is hired by our company as a result of an agency referral where no pre-existing agreement is in place. Where agency agreements are in place, introductions are position specific. Please, no phone calls or emails. 

Employee Status:

Regular

Relocation:

VISA Sponsorship:

Travel Requirements:

Flexible Work Arrangements:

Hybrid

Shift:

Valid Driving License:

Hazardous Material(s):

Job Posting End Date:

12/31/2025

*A job posting is effective until 11:59:59PM on the day BEFORE the listed job posting end date. Please ensure you apply to a job posting no later than the day BEFORE the job posting end date.