Senior Specialist, Technology Risk Management

Merck & Co IND - Telangana - Hyderabad (Hitec City Raidurg) Updated 18 September 2026
PharmaRegulatory AffairsQuality Assurancesasemacroraveinformazure

Job description

Job Description The Opportunity Based in Hyderabad, join a global healthcare biopharma company and be part of a 130- year legacy of success backed by ethical integrity, forward momentum, and an inspiring mission to achieve new milestones in global healthcare. Be part of an organisation driven by digital technology and data-backed approaches that support a diversified portfolio of prescription medicines, vaccines, and animal health products. Drive innovation and execution excellence. Be a part of a team with passion for using data, analytics, and insights to drive decision-making, and which creates custom software, allowing us to tackle some of the world's greatest health threats. Our Technology Centers focus on creating a space where teams can come together to deliver business solutions that save and improve lives. An integral part of our companys’ IT operating model, Tech Centers are globally distributed locations where each IT division has employees to enable our digital transformation journey and drive business outcomes. These locations, in addition to the other sites, are essential to supporting our business and strategy. A focused group of leaders in each Tech Center helps to ensure we can manage and improve each location, from investing in growth, success, and well-being of our people, to making sure colleagues from each IT division feel a sense of belonging to managing critical emergencies. And together, we must leverage the strength of our team to collaborate globally to optimize connections and share best practices across the Tech Centers. Role Overview We are seeking a highly analytical, technically proficient, and business-oriented Business Technology Risk Specialist to join our Business Technology Risk (BTR) organization. This role sits at the intersection of technology, cybersecurity, risk management, and business enablement. The successful candidate will serve as a trusted advisor to technology leaders, business stakeholders, and cybersecurity teams by identifying, assessing, and communicating technology risks associated with applications, infrastructure, cloud services, AI solutions, third-party vendors, and strategic technology initiatives. The role requires strong expertise in vendor risk management, application security risk, technology architecture reviews, security controls assessment, IT risk assessments, and risk governance, along with the ability to translate complex technical findings into concise executive insights that support risk-based decision making by senior leadership and the CISO organization. What You Will Do Technology Risk Assessments Conduct end-to-end technology risk assessments across applications, infrastructure, cloud platforms, data platforms, AI/ML solutions, and third-party services. Evaluate inherent, residual, and emerging risks associated with new technologies and business initiatives. Assess technology implementations against corporate security standards, risk management requirements, and regulatory expectations. Facilitate risk identification workshops with business and technical stakeholders. Develop risk scenarios, risk statements, impact assessments, and treatment recommendations. Third-Party & Vendor Risk Management Lead technical due diligence reviews for vendors, suppliers, SaaS providers, managed service providers, and cloud service providers. Assess security architecture, data flows, application designs, integrations, and hosting environments of third-party solutions. Review SIG questionnaires, security assessments, penetration test reports, SOC reports, audit reports, and vendor security documentation. Identify control gaps and determine appropriate risk ratings and treatment strategies. Advise business owners on vendor onboarding risks, compensating controls, and residual risk acceptance considerations. Support ongoing monitoring of high-risk vendors and critical third-party relationships. Application & Technology Risk Analysis Assess risks associated with enterprise applications, APIs, integrations, identity services, cloud-hosted workloads, and business platforms. Evaluate application architecture against secure design and security engineering principles. Review authentication, authorization, session management, encryption, secrets management, logging, monitoring, and resilience controls. Analyze technical findings from: Penetration tests Red team exercises Vulnerability assessments Architecture reviews Threat modeling engagements Cloud security assessments Identify root causes and recommend practical remediation actions. Security Control Evaluation Assess design and operating effectiveness of technology and cybersecurity controls. Evaluate preventive, detective, corrective, and compensating controls. Validate effectiveness of: Identity & Access Management (IAM) Privileged Access Management (PAM) Endpoint Security Vulnerability Management Network Security Logging & Monitoring Data Protection Controls Disaster Recovery & Business Resilience Cloud Security Controls Support control maturity assessments and continuous improvement initiatives. Risk Governance & Advisory Maintain risk registers and document technology risks in accordance with enterprise risk management processes. Facilitate risk discussions with technology teams, security engineers, architects, auditors, and leadership. Challenge assumptions and validate evidence supporting risk decisions. Ensure risks are accurately documented, quantified, escalated, and tracked through resolution. Support risk acceptance and remediation approval processes. Executive Communication & CISO Advisory Translate complex technical findings into clear business risk language. Develop executive-level risk summaries, dashboards, briefings, and presentations. Provide concise insights on: Risk trends Emerging threats Control effectiveness High-risk vendors Strategic technology initiatives Support CISO, senior leadership, and risk committees with risk-informed recommendations and decision support. Present risk outcomes and mitigation strategies to executive stakeholders with confidence and credibility. Strategic Risk Enablement Monitor evolving threat landscapes, attacker techniques, and emerging technology risks. Provide risk advisory for strategic transformation initiatives including: Cloud modernization AI/Generative AI adoption Digital transformation programs Large-scale platform migrations Mergers, acquisitions, and integrations Partner with architecture, engineering, compliance, and cybersecurity teams to embed risk considerations early in the solution lifecycle. Primary Skills: The ideal candidate should possess working knowledge across the following domains: Application Security Secure SDLC OWASP Top 10 API Security Authentication & Authorization Secrets Management Data Protection Threat Modeling Cloud Security AWS Az

Stand out for this role

NoxPharm tailors your CV to this job description by aligning your experience with the role requirements and terminology. Built for pharma & life sciences.

Tailor my CV now — free to try