
Manager, Cybersecurity Eng Cloud and App Security
- Hyderabad, Telangana
- Permanent
- Full-time
- Based in Hyderabad, join a global healthcare biopharma company and be part of a 130- year legacy of success backed by ethical integrity, forward momentum, and an inspiring mission to achieve new milestones in global healthcare.
- Be part of an organisation driven by digital technology and data-backed approaches that support a diversified portfolio of prescription medicines, vaccines, and animal health products.
- Drive innovation and execution excellence. Be a part of a team with passion for using data, analytics, and insights to drive decision-making, and which creates custom software, allowing us to tackle some of the world's greatest health threats.
- Contribute to the development of enhanced cloud and application security control integrations and architectural best practices.
- Contribute to the development and implementation of product security policies and standards to ensure that application, cloud services and infrastructure meet organizational security requirements.
- Help maintain and monitor security tools and dashboards, ensuring that applications deployed in our environments adhere to organizational security standards and compliance requirements.
- Identify and prioritize adoption of our security tools within other teams ensuring the inputs and outputs are fully integrated enabling a complete security function.
- Follow standard approaches and established design patterns to create new designs for systems or system components. Identify and resolve minor design issues.
- Assist in implementing and maintaining specific security controls as required by organisational policy and local risk assessments and contribute to identifying risks that arise from potential technical solution architectures.
- Monitor and log the actual service provided, compared to that required by service level agreements.
- Undertake low-complexity routine vulnerability assessments using automated and semi-automated tools and contribute to evaluating and documenting the scope of results.
- Design, implement, test, document, and support integration of security tools and technologies in pipelines, Also, assist the product teams in related activities.
- Assist in maintaining security infrastructure and performing system updates.
- Investigate minor security breaches in accordance with established procedures. Assist users in defining their access rights and privileges and perform non-standard operational security tasks. Resolve security events and operational security issues.
- Work closely with cross-functional Infrastructure teams on Automation and Orchestration.
- Create and document detailed designs for simple software applications or components. Apply agreed modelling techniques, standards, patterns, and tools.
- Work within a matrix organizational structure, reporting to both the functional manager and the project manager.
- Bachelors’ degree in Information Technology, Computer Science or any Technology stream.
- Working experience in cloud environments AWS must have and good to have Azure, or GCP.
- Understanding of OWASP security risks and mitigation strategies, relevant NIST standards, and Zero Trust principles.
- Familiarity with programming/scripting languages like Python, Bash, Terraform, Ansible, JSON, PowerShell, or JavaScript for automating tasks.
- Familiarity with software development/delivery lifecycle and related technologies
- 3+ years of hands-on experience working with network protocols, firewalls, intrusion detection systems, encryption technologies, and endpoint security solutions.
- Proficiency in security tools in the areas of cloud, application, endpoint, network or identity, vulnerability scanners, and malware analysis platforms..
- Knowledge of authentication methods, identity management, and security access protocols (e.g., SSO, MFA, LDAP).
- Ideally AWS certified.
- Good interpersonal and communication skills (verbal and written).
- Relevant certifications (e.g., CISSP, CISM, CEH, CompTIA Security+) are often required or highly desirable.
- Proven record of delivering high-quality results.
- Product and customer-centric approach.
- Innovative thinking, experimental mindset.
Merck & Co., Inc., Rahway, NJ, USA, also known as Merck Sharp & Dohme LLC, Rahway, NJ, USA, does not accept unsolicited assistance from search firms for employment opportunities. All CVs / resumes submitted by search firms to any employee at our company without a valid written search agreement in place for this position will be deemed the sole property of our company. No fee will be paid in the event a candidate is hired by our company as a result of an agency referral where no pre-existing agreement is in place. Where agency agreements are in place, introductions are position specific. Please, no phone calls or emails.Employee Status: RegularRelocation:VISA Sponsorship:Travel Requirements:Flexible Work Arrangements: HybridShift:Valid Driving License:Hazardous Material(s):Required Skills: Design Applications, Information Security, Security Operations, SLA Management, Software Development, Software Development Life Cycle (SDLC), System Designs, Technical Advice, Vulnerability ScanningPreferred Skills:Job Posting End Date: 09/30/2025*A job posting is effective until 11:59:59PM on the day BEFORE the listed job posting end date. Please ensure you apply to a job posting no later than the day BEFORE the job posting end date.