MSD

Manager, Risk Analyst BIRO EIT

IND - Telangana - Hyderabad (HITEC City) Full time

Job Description

R2

Manager, Risk Analyst BIRO EIT

The Opportunity

  • Based in Hyderabad, join a global healthcare biopharma company and be part of a 130- year legacy of success backed by ethical integrity, forward momentum, and an inspiring mission to achieve new milestones in global healthcare.

  • Be part of an organisation driven by digital technology and data-backed approaches that support a diversified portfolio of prescription medicines, vaccines, and animal health products.

  • Drive innovation and execution excellence. Be a part of a team with passion for using data, analytics, and insights to drive decision-making, and which creates custom software, allowing us to tackle some of the world's greatest health threats.

Our Technology Centers focus on creating a space where teams can come together to deliver business solutions that save and improve lives. An integral part of our company’s IT operating model, Tech Centers are globally distributed locations where each IT division has employees to enable our digital transformation journey and drive business outcomes. These locations, in addition to the other sites, are essential to supporting our business and strategy.

A focused group of leaders in each Tech Center helps to ensure we can manage and improve each location, from investing in growth, success, and well-being of our people, to making sure colleagues from each IT division feel a sense of belonging to managing critical emergencies. And together, we must leverage the strength of our team to collaborate globally to optimize connections and share best practices across the Tech Centers.

Role Overview

Overview The Business Information Risk role supports the alignment of cybersecurity, risk management, and compliance activities with Enterprise business objectives. This role partners with Enterprise teams, business stakeholders, and the Information Technology Risk Management & Security (ITRMS) organization to identify, assess, and mitigate information security and compliance risks across technology. The position acts as a trusted subject-matter expert, translating technical risk into business context and supporting the implementation of practical, risk-based controls that enable safe business operations and innovation.

Primary Responsibilities

Business Partnership & Advisory

  • Serve as a primary risk advisor to Enterprise teams on assigned programs, products, or technology areas, helping translate security risks into business impact and practical recommendations.

  • Translate enterprise security policies into practical, business-aligned implementation guidance and manage exceptions handling for the business unit.

  • Participate in business planning forums, product roadmaps, and program governance to ensure security is included early (shift-left).

  • Support business stakeholders by providing clear, actionable guidance for embedding security and privacy considerations into projects, digital transformations, and operational processes.

  • Prepare and present risk findings, assessments, and mitigation proposals to IT and business stakeholders; escalate material risks to ITRMS or Enterprise leadership as appropriate.

Risk Assessment & Governance Support

  • Maintain a prioritized risk register for the business unit and drive risk acceptance decisions with business owners and delegated risk approvers.

  • Conduct and document risk assessments (e.g., application, cloud, third‑party) and gap analyses aligned to Enterprise policies and relevant regulatory requirements.

  • Recommend and help implement risk-based security controls, compensating measures, and remediation plans tailored to Enterprise operational contexts.

  • Assist in maintaining risk registers and tracking remediation and compliance activities; contribute to periodic risk reporting.

Technical Risk Management & cybersecurity

  • Work closely with Enterprise Value Teams and solution owners to review architecture, design, and operational controls for systems, applications, and cloud environments.

  • Identify opportunities to strengthen cyber resilience (detection, response, recovery) and support implementation of monitoring and control improvements.

  • Support incident investigations and coordination with the Cyber Fusion Center for Enterprise-related security events; help identify root causes and remediation actions.

Program Execution & Standards

  • Support development and operationalization of security standards, policies, and guidelines relevant to Enterprise.

  • Participate in assurance activities such as control testing, audits, and compliance assessments and support remediation efforts.

  • Stay informed of emerging technologies (e.g., AI, cloud services) and regulatory changes; evaluate their potential security and compliance impacts and escalate concerns.

Stakeholder Engagement & Awareness

  • Collaborate with risk, technology, and business stakeholders to promote a risk-aware culture and practical security behaviors.

  • Contribute to targeted security awareness initiatives and training for Enterprise teams, tailored to role and business processes.

  • Act as a subject-matter expert in cross-functional working groups or project teams.

Qualifications

Education & Certifications

  • Bachelor’s degree in information technology, cybersecurity, computer science, business administration, or related field (or equivalent experience).

  • Relevant security or risk certifications preferred (CISSP, CISM, CISA, CRISC, GSEC) but not required.

Experience

  • Experience in cybersecurity, IT risk management, IT compliance, IT audit, or related fields.

  • Experience performing risk assessments and advising technical and business stakeholders on security controls and remediation.

  • Practical experience with cloud, application, or operational technology security is highly desirable.

  • Prior experience supporting regulated industries (healthcare, life sciences, or manufacturing) is preferred but not mandatory.

Skills & Competencies

  • Technical depth in cybersecurity controls, threats, vulnerabilities, and mitigation strategies across technology.

  • Strong business acumen and ability to explain technical risk in business terms.

  • Proven problem-solving and analytical skills; able to produce clear, actionable recommendations.

  • Good stakeholder management and communication skills; able to influence without formal authority.

  • Comfortable working independently and as part of cross-functional teams; adaptable in a fast-paced environment.

  • High emotional intelligence and collaborative mindset.

Who we are:

We are known as Merck & Co., Inc., Rahway, New Jersey, USA in the United States and Canada and MSD everywhere else. For more than a century, we have been inventing for life, bringing forward medicines and vaccines for many of the world's most challenging diseases. Today, our company continues to be at the forefront of research to deliver innovative health solutions and advance the prevention and treatment of diseases that threaten people and animals around the world.

What we look for:

Imagine getting up in the morning for a job as important as helping to save and improve lives around the world. Here, you have that opportunity. You can put your empathy, creativity, digital mastery, or scientific genius to work in collaboration with a diverse group of colleagues who pursue and bring hope to countless people who are battling some of the most challenging diseases of our time. Our team is constantly evolving, so if you are among the intellectually curious, join us—and start making your impact today.

Required Skills:

Data Management, Information Security, IT Risk Assessments, IT Risk Governance, IT Risk Response and Reporting, Knowledge of regulations and frameworks, Stakeholder Management, Technical Advice

Preferred Skills:

Current Employees apply HERE

Current Contingent Workers apply HERE

Search Firm Representatives Please Read Carefully 
Merck & Co., Inc., Rahway, NJ, USA, also known as Merck Sharp & Dohme LLC, Rahway, NJ, USA, does not accept unsolicited assistance from search firms for employment opportunities. All CVs / resumes submitted by search firms to any employee at our company without a valid written search agreement in place for this position will be deemed the sole property of our company.  No fee will be paid in the event a candidate is hired by our company as a result of an agency referral where no pre-existing agreement is in place. Where agency agreements are in place, introductions are position specific. Please, no phone calls or emails. 

Employee Status:

Regular

Relocation:

VISA Sponsorship:

Travel Requirements:

Flexible Work Arrangements:

Hybrid

Shift:

Valid Driving License:

Hazardous Material(s):

Job Posting End Date:

12/1/2025

*A job posting is effective until 11:59:59PM on the day BEFORE the listed job posting end date. Please ensure you apply to a job posting no later than the day BEFORE the job posting end date.