MSD
Job Description
Role Summary The Associate Director for Product Security Platform Engineering will lead, build, and mature the security tooling ecosystem supporting application security, cloud security guardrails, SDLC security automation, vulnerability intelligence, and enterprise‑wide developer enablement. This role serves as a technical and strategic leader working closely with Product Security leadership and platform engineering teams to ensure security capabilities are scalable, measurable, developer‑friendly, and aligned to enterprise security strategy. Key Responsibilities
Platform Engineering & Security Tooling
Lead design, development, and scaling of product security platforms, including integrating application scanners and cloud-native security guardrails. Integrate security controls into CI/CD pipelines, provisioning workflows, and developer platforms Drive automation/AI and orchestration to reduce manual security review overhead. Security Governance & Architecture
Translate enterprise security policies and standards into enforceable platform capabilities. Partner with architecture, Cloud, DevOps, and product teams to integrate secure‑by‑design principles into engineering workflows. Operational Management & Metrics
Establish platform KPIs, KRIs, and adoption metrics; enable reporting for risk reviews, leadership updates, and regulatory needs. Oversee platform operations, including performance, availability, team processes, backlog management, vendor management, and escalations. Team Leadership & Talent Development
Lead a team of platform engineers and security specialists. Provide mentorship, career development, and continuous learning opportunities Cultivate a culture of engineering excellence, automation, and measurable security outcomes. Cross‑Functional Engagement
Work closely with product lines, cloud engineering, DevOps, and enterprise security teams to drive adoption of platform capabilities. Act as a trusted technical advisor to internal teams. Required Qualifications
8+ years of experience in cybersecurity engineering, DevSecOps, platform engineering, cloud security, or application security. Deep experience with at least two of: SAST, SCA, DAST, cloud security platforms, Containers, vulnerability management tooling, logging/telemetry, or CI/CD integration. Strong engineering background (Python, Java, automation frameworks, cloud-native architectures). Experience deploying enterprise‑scale security platforms and integrating them into engineering ecosystems. Proven leadership experience managing teams or large cross‑functional initiatives. Preferred Qualifications
Experience embedded security controls in the developer workflow. Experience with AWS/Azure/GCP/Alibaba cloud guardrails. Background in distributed systems, API platforms, and event-driven architectures. Experience collaborating with globally distributed engineering teams. Bachelor's or Advanced degree in Computer Science, Cybersecurity, or related field. Relevant certifications (CISSP, CCSK, GIAC, etc.). Required Skills
Accountability API Platforms Application Security Backlog Management Cloud Security Computer Science Cybersecurity Cybersecurity Operations Data Protection Delivery of Security Applications Design Applications DevOps Coaching Distributed Systems Event Driven Architecture Influence Information Security Information Systems Management Mentorship Security Governance Security Reviews SLA Management Supply Chain Management System Designs Technical Advice Preferred Skills
Current Employees apply HERE Current Contingent Workers apply HERE US and Puerto Rico Residents Only
Our company is committed to inclusion, ensuring that candidates can engage in a hiring process that exhibits their true capabilities. Please click here if you need an accommodation during the application or hiring process. Equal Employment Opportunity
As an Equal Employment Opportunity Employer, we provide equal opportunities to all employees and applicants for employment and prohibit discrimination on the basis of race, color, age, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, disability status, or other applicable legally protected characteristics. As a federal contractor, we comply with all affirmative action requirements for protected veterans and individuals with disabilities. For more information about personal rights under the U.S. Equal Opportunity Employment laws, visit: EEOC Know Your Rights EEOC GINA Supplement We are proud to be a company that embraces the value of bringing together, talented, and committed people with diverse experiences, perspectives, skills and backgrounds. The fastest way to breakthrough innovation is when people with diverse ideas, broad experiences, backgrounds, and skills come together in an inclusive environment. We encourage our colleagues to respectfully challenge one another’s thinking and approach problems collectively. Learn more about your rights, including under California, Colorado and other US State Acts U.S. Hybrid Work Model
Effective September 5, 2023, employees in office-based positions in the U.S. will be working a Hybrid work consisting of three total days on-site per week, Monday - Thursday, although the specific days may vary by site or organization, with Friday designated as a remote-working day, unless business critical tasks require an on-site presence. This Hybrid work model does not apply to, and daily in-person attendance is required for, field-based positions; facility-based, manufacturing-based, or research-based positions where the work to be performed is located at a Company site; positions covered by a collective-bargaining agreement (unless the agreement provides for hybrid work); or any other position for which the Company has determined the job requirements cannot be reasonably met working remotely. Please note, this Hybrid work model guidance also does not apply to roles that have been designated as “remote”. The salary range for this role is $142,400.00 - $224,100.00 This is the lowest to highest salary we in good faith believe we would pay for this role at the time of this posting. An employee’s position within the salary range will be based on several factors including, but not limited to relevant education, qualifications, certifications, experience, skills, geographic location, government requirements, and business or organizational needs. The successful candidate will be eligible for annual bonus and long-term incentive, if applicable. We offer a comprehensive package of benefits. Available benefits include medical, dental, vision healthcare and other insurance benefits (for employee and family), retirement benefits, including 401(k), paid holidays, vacation, and compassionate and sick days. More information about benefits is available at https://jobs.merck.com/us/en/compensation-and-benefits. You can apply for this role through https://jobs.merck.com/us/en (or via the Workday Jobs Hub if you are a current employee). The application deadline for this position is stated on this posting. San Francisco Residents Only:
We will consider qualified applicants with arrest and conviction records for employment in compliance with the San Francisco Fair Chance Ordinance Los Angeles Residents Only:
We will consider for employment all qualified applicants, including those with criminal histories, in a manner consistent with the requirements of applicable state and local laws, including the City of Los Angeles’ Fair Chance Initiative for Hiring Ordinance Search Firm Representatives Please Read Carefully Merck & Co., Inc., Rahway, NJ, USA, also known as Merck Sharp & Dohme LLC, Rahway, NJ, USA, does not accept unsolicited assistance from search firms for employment opportunities. All CVs / resumes submitted by search firms to any employee at our company without a valid written search agreement in place for this position will be deemed the sole property of our company. No fee will be paid in the event a candidate is hired by our company as a result of an agency referral where no pre-existing agreement is in place. Where agency agreements are in place, introductions are position specific. Please, no phone calls or emails.
#J-18808-Ljbffr
Role Summary The Associate Director for Product Security Platform Engineering will lead, build, and mature the security tooling ecosystem supporting application security, cloud security guardrails, SDLC security automation, vulnerability intelligence, and enterprise‑wide developer enablement. This role serves as a technical and strategic leader working closely with Product Security leadership and platform engineering teams to ensure security capabilities are scalable, measurable, developer‑friendly, and aligned to enterprise security strategy. Key Responsibilities
Platform Engineering & Security Tooling
Lead design, development, and scaling of product security platforms, including integrating application scanners and cloud-native security guardrails. Integrate security controls into CI/CD pipelines, provisioning workflows, and developer platforms Drive automation/AI and orchestration to reduce manual security review overhead. Security Governance & Architecture
Translate enterprise security policies and standards into enforceable platform capabilities. Partner with architecture, Cloud, DevOps, and product teams to integrate secure‑by‑design principles into engineering workflows. Operational Management & Metrics
Establish platform KPIs, KRIs, and adoption metrics; enable reporting for risk reviews, leadership updates, and regulatory needs. Oversee platform operations, including performance, availability, team processes, backlog management, vendor management, and escalations. Team Leadership & Talent Development
Lead a team of platform engineers and security specialists. Provide mentorship, career development, and continuous learning opportunities Cultivate a culture of engineering excellence, automation, and measurable security outcomes. Cross‑Functional Engagement
Work closely with product lines, cloud engineering, DevOps, and enterprise security teams to drive adoption of platform capabilities. Act as a trusted technical advisor to internal teams. Required Qualifications
8+ years of experience in cybersecurity engineering, DevSecOps, platform engineering, cloud security, or application security. Deep experience with at least two of: SAST, SCA, DAST, cloud security platforms, Containers, vulnerability management tooling, logging/telemetry, or CI/CD integration. Strong engineering background (Python, Java, automation frameworks, cloud-native architectures). Experience deploying enterprise‑scale security platforms and integrating them into engineering ecosystems. Proven leadership experience managing teams or large cross‑functional initiatives. Preferred Qualifications
Experience embedded security controls in the developer workflow. Experience with AWS/Azure/GCP/Alibaba cloud guardrails. Background in distributed systems, API platforms, and event-driven architectures. Experience collaborating with globally distributed engineering teams. Bachelor's or Advanced degree in Computer Science, Cybersecurity, or related field. Relevant certifications (CISSP, CCSK, GIAC, etc.). Required Skills
Accountability API Platforms Application Security Backlog Management Cloud Security Computer Science Cybersecurity Cybersecurity Operations Data Protection Delivery of Security Applications Design Applications DevOps Coaching Distributed Systems Event Driven Architecture Influence Information Security Information Systems Management Mentorship Security Governance Security Reviews SLA Management Supply Chain Management System Designs Technical Advice Preferred Skills
Current Employees apply HERE Current Contingent Workers apply HERE US and Puerto Rico Residents Only
Our company is committed to inclusion, ensuring that candidates can engage in a hiring process that exhibits their true capabilities. Please click here if you need an accommodation during the application or hiring process. Equal Employment Opportunity
As an Equal Employment Opportunity Employer, we provide equal opportunities to all employees and applicants for employment and prohibit discrimination on the basis of race, color, age, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, disability status, or other applicable legally protected characteristics. As a federal contractor, we comply with all affirmative action requirements for protected veterans and individuals with disabilities. For more information about personal rights under the U.S. Equal Opportunity Employment laws, visit: EEOC Know Your Rights EEOC GINA Supplement We are proud to be a company that embraces the value of bringing together, talented, and committed people with diverse experiences, perspectives, skills and backgrounds. The fastest way to breakthrough innovation is when people with diverse ideas, broad experiences, backgrounds, and skills come together in an inclusive environment. We encourage our colleagues to respectfully challenge one another’s thinking and approach problems collectively. Learn more about your rights, including under California, Colorado and other US State Acts U.S. Hybrid Work Model
Effective September 5, 2023, employees in office-based positions in the U.S. will be working a Hybrid work consisting of three total days on-site per week, Monday - Thursday, although the specific days may vary by site or organization, with Friday designated as a remote-working day, unless business critical tasks require an on-site presence. This Hybrid work model does not apply to, and daily in-person attendance is required for, field-based positions; facility-based, manufacturing-based, or research-based positions where the work to be performed is located at a Company site; positions covered by a collective-bargaining agreement (unless the agreement provides for hybrid work); or any other position for which the Company has determined the job requirements cannot be reasonably met working remotely. Please note, this Hybrid work model guidance also does not apply to roles that have been designated as “remote”. The salary range for this role is $142,400.00 - $224,100.00 This is the lowest to highest salary we in good faith believe we would pay for this role at the time of this posting. An employee’s position within the salary range will be based on several factors including, but not limited to relevant education, qualifications, certifications, experience, skills, geographic location, government requirements, and business or organizational needs. The successful candidate will be eligible for annual bonus and long-term incentive, if applicable. We offer a comprehensive package of benefits. Available benefits include medical, dental, vision healthcare and other insurance benefits (for employee and family), retirement benefits, including 401(k), paid holidays, vacation, and compassionate and sick days. More information about benefits is available at https://jobs.merck.com/us/en/compensation-and-benefits. You can apply for this role through https://jobs.merck.com/us/en (or via the Workday Jobs Hub if you are a current employee). The application deadline for this position is stated on this posting. San Francisco Residents Only:
We will consider qualified applicants with arrest and conviction records for employment in compliance with the San Francisco Fair Chance Ordinance Los Angeles Residents Only:
We will consider for employment all qualified applicants, including those with criminal histories, in a manner consistent with the requirements of applicable state and local laws, including the City of Los Angeles’ Fair Chance Initiative for Hiring Ordinance Search Firm Representatives Please Read Carefully Merck & Co., Inc., Rahway, NJ, USA, also known as Merck Sharp & Dohme LLC, Rahway, NJ, USA, does not accept unsolicited assistance from search firms for employment opportunities. All CVs / resumes submitted by search firms to any employee at our company without a valid written search agreement in place for this position will be deemed the sole property of our company. No fee will be paid in the event a candidate is hired by our company as a result of an agency referral where no pre-existing agreement is in place. Where agency agreements are in place, introductions are position specific. Please, no phone calls or emails.
#J-18808-Ljbffr