hirly

Merck & Co.

Director, AI & Cybersecurity Legal

USA - Pennsylvania - North Wales (Upper Gwynedd) · USA - New Jersey - Rahway

See how you match this job — and similar ones. Free.

Upload your resume and hirly scores it against this role at Merck & Co. first, then against similar open jobs, and shows where you fit and why.

PDF or DOCX, up to 12MB. No sign-up to see your matches.

Get past the screening software and onto a recruiter's desk

hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.

  • Keywords matched to this posting
  • Fit score before you apply
  • Cover letter included

Matched against 2.6M live jobs from 190,000+ employers in 200+ countries.

Tailor my resume for this job →

Apply from your AI assistant

Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.

Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.

hirly's read of this role

Seniority
Director
Countries
GB, US
Work mode
On-site / unstated
First seen by hirly
27 Sept 2026

Derived automatically from the posting. Upload your resume above to see how the role scores against it.

the posting

Job Description

The Director, AI and Cybersecurity Legal will report to the Chief Privacy and Digital Trust Officer, partner closely with the Chief Information Security Officer, and serve as a trusted and strategic legal adviser on AI and cybersecurity matters across the enterprise. This role will provide legal counsel on the development, deployment, and governance of AI/ML technologies, as well as cybersecurity risk management, incident response, and regulatory compliance. The Director will partner closely with Information Technology, Information Technology Risk Management, and business teams to enable innovation while managing legal and regulatory risk in a highly regulated global pharmaceutical environment.

Key Responsibilities

Artificial Intelligence & Emerging Technology

Provide strategic legal counsel on the design, development, procurement, and deployment of AI and machine learning systems across research, commercial, and corporate functions.

Advise on AI governance frameworks, including responsible AI principles, algorithmic transparency, bias mitigation, and human oversight requirements for high-risk systems.

Provide strategic legal counsel related to the design and implementation of next-generation AI Governance, including AI policies, evolving AI risk assessment frameworks (e.g., triage design, risk tiering, domain-specific assessment frameworks, automation, and streamlined decision workflows), third-party AI due diligence, and implementing AI incident reporting obligations.

Monitor and interpret evolving AI regulations globally, including the EU AI Act, FDA guidance on AI/ML in drug development and medical devices, and other emerging frameworks.

Serve as a member of divisional AI committees.

Lead AI contract negotiations and counsel on technology transactions. Counsel internal stakeholders on data rights and contractual issues arising from generative AI tools and third-party AI platforms.

Represent the company externally as required, including engaging with regulators, trade associations, and other industry organizations.

Cybersecurity

Serve as the primary legal advisor to the Chief Information Security Officer (CISO) and Information Technology Risk Management organization on legal and regulatory matters.

Provide legal support for cybersecurity incident response efforts, including assessing breach notification obligations under HIPAA, state breach notification laws, and other applicable frameworks.

Advise on cybersecurity regulatory requirements, including SEC cybersecurity disclosure rules, NIST frameworks, and industry-specific standards.

Provide legal guidance on vulnerability disclosure, threat intelligence sharing, and engagement with law enforcement and regulatory authorities.

Support the development and review of cybersecurity policies, vendor security assessments, and security provisions in commercial agreements.

Cross-Functional Collaboration

Partner with privacy, compliance and legal colleagues to address intersections between AI, regulatory and commercial legal considerations, cybersecurity, and data protection laws.

Advise on data governance and data-sharing arrangements that implicate cybersecurity and AI considerations.

Support M&A, licensing, and collaboration transactions with cybersecurity and AI due diligence and integration guidance.

Provide training and awareness to business stakeholders on AI legal risks and cybersecurity legal obligations.

Qualifications

J.D. from an accredited law school and active membership in at least one U.S. state bar.

Minimum 10 years of legal experience, with at least 5 years focused on cybersecurity, technology, and/or AI/emerging technology law, preferably in a pharmaceutical, life sciences, healthcare, or other highly regulated environment. Additional experience or background in data privacy/data protection a plus.

Deep understanding of cybersecurity legal frameworks (HIPAA, GDPR, NIS2, SEC disclosure rules, state breach notification laws) and emerging AI and automated decision-making regulatory frameworks.

Extensive experience managing cybersecurity incident response from a legal perspective.

Experience advising on AI governance, responsible AI principles, and technology transactions.

Experience developing and negotiating contractual provisions addressing cybersecurity, data protection, and AI considerations in connection with mergers, acquisitions, collaborations, strategic partnerships, and technology transactions.

Proven experience counseling on AI systems from a legal and compliance perspective, including risk assessment review, auditability, transparency obligations, and lifecycle governance.

CIPP/E/US/CIPM, AIGP, or other AI certification preferred.

Required Skills

Ability to think strategically, understand client objectives, and offer analytical, well-reasoned, creative, and pragmatic legal advice designed to enable innovation while protecting against legal and regulatory risk.

Strong executive presence and ability to build trust and influence senior leadership and cross-functional stakeholders in a matrixed global organization.

Exceptional written and verbal communication skills, including the ability to contribute to compliance policies and guidance documents, counsel business stakeholders across multiple levels of seniority, and prepare and lead executive-level presentations.

Ability to provide strong, clear legal advice and translate complex technical and legal concepts into concrete implementation strategies for audiences.

Strong technical aptitude and fluency, and the ability to engage meaningfully with technical concepts related to AI, data, and cybersecurity.

Meticulous attention to detail and ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment.

Required Skills:

Business Consulting Services, Business Consulting Services, Compliance Activities, Compliance Monitoring, Compliance Reporting, Confidentiality, Customer Service Leadership, Cybersecurity Risk Management, Data Breach Response, Data Privacy, Data Protection, Data Security, Data Security Management, Ethics, Executive Presence, Exercises Judgment, General Data Protection Regulation, Governance Framework, HIPAA Compliance, Information Technology (IT), Legal Compliance, Legal Research, Legal Strategies, Multilingualism, Negotiation {+ 7 more}

Preferred Skills:

Current Employees apply HERE

Current Contingent Workers apply HERE

US and Puerto Rico Residents Only:

Our company is committed to inclusion, ensuring that candidates can engage in a hiring process that exhibits their true capabilities. Please click here if you need an accommodation during the application or hiring process.

As an Equal Employment Opportunity Employer, we provide equal opportunities to all employees and applicants for employment and prohibit discrimination on the basis of race, color, age, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, disability status, or other applicable legally protected characteristics. As a federal contractor, we comply with all affirmative action requirements for protected veterans and individuals with disabilities. For more information about personal rights under the U.S. Equal Opportunity Employment laws, visit:

EEOC Know Your Rights

EEOC GINA Supplement​

We are proud to be a company that embraces the value of bringing together, talented, and committed people with diverse experiences, perspectives, skills and backgrounds. The fastest way to breakthrough innovation is when people with diverse ideas, broad experiences, backgrounds, and skills come together in an inclusive environment. We encourage our colleagues to respectfully challenge one another’s thinking and approach problems collectively.

Learn more about your rights, including under California, Colorado and other US State Acts

The salary range for this role is

$190,800.00 - $

Original posting on Merck & Co.'s site ↗

Listed on hirly, a job board. hirly is not the employer: Merck & Co. is hiring for this role.

Browse similar roles

Want this one?

Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.

Tailor my resume for this job