Director, AI & Cybersecurity Legal

Merck & Co.

North Wales (Montgomery County)

Hybrid

USD 191,000 - 300,000

Full time

3 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Annual bonus potential
Long-term incentive program
Hybrid work arrangement
Comprehensive health benefits

Job summary

Merck & Co. in the United States seeks a Director of AI and Cybersecurity Legal to lead legal support for AI governance, cybersecurity risk, and regulatory compliance. You will advise on policy, vendor agreements, and data rights in AI deployments across R&D, commercial, and corporate functions.

The role requires a JD, 10+ years in tech/cyber/AI law, and the ability to navigate global regulations. Hybrid work and strong executive collaboration are expected.

Qualifications

  • J.D. from an accredited law school and active bar membership in the US.
  • Minimum 10 years of legal experience with 5+ years in cybersecurity, technology, or AI law.
  • Experience in regulated environments (pharma, life sciences) preferred.
  • Experience advising on AI governance, risk assessment, and technology transactions.
  • Familiarity with HIPAA, GDPR, NIS2, SEC rules and data privacy.

Responsibilities

  • Provide strategic legal counsel on AI/ML design, deployment, and governance.
  • Advise on AI governance frameworks, bias mitigation, and human oversight.
  • Lead AI governance policy design, third-party due diligence, and incident reporting.
  • Monitor evolving AI regulations globally including EU AI Act and FDA guidance.
  • Lead AI contract negotiations and advise on data rights in generative AI contexts.
  • Support cybersecurity incident response and regulatory compliance efforts.
  • Collaborate with IT, risk management, and business teams across functions.

Skills

Strategic thinking
Executive presence
Written and verbal communication
Legal advisory excellence
Ability to translate complex technical

Education

J.D. from an accredited law school
Active membership in at least one U.S. state bar
CIPP/E/US/CIPM, AIGP, or AI certification preferred

Job description

Job Description

The Director, AI and Cybersecurity Legal will report to the Chief Privacy and Digital Trust Officer, partner closely with the Chief Information Security Officer, and serve as a trusted and strategic legal adviser on AI and cybersecurity matters across the enterprise. This role will provide legal counsel on the development, deployment, and governance of AI/ML technologies, as well as cybersecurity risk management, incident response, and regulatory compliance. The Director will partner closely with Information Technology, Information Technology Risk Management, and business teams to enable innovation while managing legal and regulatory risk in a highly regulated global pharmaceutical environment.

Key Responsibilities
  • Provide strategic legal counsel on the design, development, procurement, and deployment of AI and machine learning systems across research, commercial, and corporate functions.
  • Advise on AI governance frameworks, including responsible AI principles, algorithmic transparency, bias mitigation, and human oversight requirements for high-risk systems.
  • Provide strategic legal counsel related to the design and implementation of next-generation AI Governance, including AI policies, evolving AI risk assessment frameworks (e.g., triage design, risk tiering, domain-specific assessment frameworks, automation, and streamlined decision workflows), third-party AI due diligence, and implementing AI incident reporting obligations.
  • Monitor and interpret evolving AI regulations globally, including the EU AI Act, FDA guidance on AI/ML in drug development and medical devices, and other emerging frameworks.
  • Serve as a member of divisional AI committees.
  • Lead AI contract negotiations and counsel on technology transactions.
    Counsel internal stakeholders on data rights and contractual issues arising from generative AI tools and third-party AI platforms.
  • Represent the company externally as required, including engaging with regulators, trade associations, and other industry organizations.
Cybersecurity
  • Serve as the primary legal advisor to the Chief Information Security Officer (CISO) and Information Technology Risk Management organization on legal and regulatory matters.
  • Provide legal support for cybersecurity incident response efforts, including assessing breach notification obligations under HIPAA, state breach notification laws, and other applicable frameworks.
  • Advise on cybersecurity regulatory requirements, including SEC cybersecurity disclosure rules, NIST frameworks, and industry-specific standards.
  • Provide legal guidance on vulnerability disclosure, threat intelligence sharing, and engagement with law enforcement and regulatory authorities.
  • Support the development and review of cybersecurity policies, vendor security assessments, and security provisions in commercial agreements.
Cross-Functional Collaboration
  • Partner with privacy, compliance and legal colleagues to address intersections between AI, regulatory and commercial legal considerations, cybersecurity, and data protection laws.
  • Advise on data governance and data-sharing arrangements that implicate cybersecurity and AI considerations.
  • Support M&A, licensing, and collaboration transactions with cybersecurity and AI due diligence and integration guidance.
  • Provide training and awareness to business stakeholders on AI legal risks and cybersecurity legal obligations.
Qualifications
  • J.D. from an accredited law school and active membership in at least one U.S. state bar.
  • Minimum 10 years of legal experience, with at least 5 years focused on cybersecurity, technology, and/or AI/emerging technology law, preferably in a pharmaceutical, life sciences, healthcare, or other highly regulated environment. Additional experience or background in data privacy/data protection a plus.
  • Deep understanding of cybersecurity legal frameworks (HIPAA, GDPR, NIS2, SEC disclosure rules, state breach notification laws) and emerging AI and automated decision-making regulatory frameworks.
  • Extensive experience managing cybersecurity incident response from a legal perspective.
  • Experience advising on AI governance, responsible AI principles, and technology transactions.
  • Experience developing and negotiating contractual provisions addressing cybersecurity, data protection, and AI considerations in connection with mergers, acquisitions, collaborations, strategic partnerships, and technology transactions.
  • Proven experience counseling on AI systems from a legal and compliance perspective, including risk assessment review, auditability, transparency obligations, and lifecycle governance.
  • CIPP/E/US/CIPM, AIGP, or other AI certification preferred.
Required Skills
  • Ability to think strategically, understand client objectives, and offer analytical, well-reasoned, creative, and pragmatic legal advice designed to enable innovation while protecting against legal and regulatory risk.
  • Strong executive presence and ability to build trust and influence senior leadership and cross-functional stakeholders in a matrixed global organization.
  • Exceptional written and verbal communication skills, including the ability to contribute to compliance policies and guidance documents, counsel business stakeholders across multiple levels of seniority, and prepare and lead executive-level presentations.
  • Ability to provide strong, clear legal advice and translate complex technical and legal concepts into concrete implementation strategies for audiences.
  • Strong technical aptitude and fluency, and the ability to engage meaningfully with technical concepts related to AI, data, and cybersecurity.
  • Meticulous attention to detail and ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment.
Required Skills
  • Business Consulting Services
  • Compliance Activities
  • Compliance Monitoring
  • Compliance Reporting
  • Confidentiality
  • Customer Service Leadership
  • Cybersecurity Risk Management
  • Data Breach Response
  • Data Privacy
  • Data Protection
  • Data Security
  • Data Security Management
  • Ethics
  • Executive Presence
  • Exercises Judgment
  • General Data Protection Regulation
  • Governance Framework
  • HIPAA Compliance
  • Information Technology (IT)
  • Legal Compliance
  • Legal Research
  • Legal Strategies
  • Multilingualism
  • Negotiation
US and Puerto Rico Residents Only:

Our company is committed to inclusion, ensuring that candidates can engage in a hiring process that exhibits their true capabilities.

San Francisco Residents Only:

We will consider qualified applicants with arrest and conviction records for employment in compliance with the San Francisco Fair Chance Ordinance.

Los Angeles Residents Only:

We will consider for employment all qualified applicants, including those with criminal histories, in a manner consistent with the requirements of applicable state and local laws, including the City of Los Angeles' Fair Chance Initiative for Hiring Ordinance.

Search Firm Representatives Please Read Carefully-

Merck & Co., Inc., Rahway, NJ, USA, also known as Merck Sharp & Dohme LLC, Rahway, NJ, USA, does not accept unsolicited assistance from search firms for employment opportunities. All CVs / resumes submitted by search firms to any employee at our company without a valid written search agreement in place for this position will be deemed the sole property of our company. No fee will be paid in the event a candidate is hired by our company as a result of an agency referral where no pre-existing agreement is in place. Where agency agreements are in place, introductions are position specific. Please, no phone calls or emails.

Employee Status:

Regular

Relocation:

Domestic

VISA Sponsorship:

No

Travel Requirements:

10%

Flexible Work Arrangements:

Hybrid

Shift:

1st - Day

Valid Driving License:

No

Hazardous Material(s):

N/A

Job Posting End Date:

09/26/2026

*A job posting is effective until 11:59:59PM on the day BEFORE -the listed job posting end date. Please ensure you apply to a job posting no later than the day BEFORE the job posting end date.

Requisition ID:

R417977

Compensation

The salary range for this role is $190,800.00 - $300,300.00.

This is the lowest to highest salary we in good faith believe we would pay for this role at the time of this posting. An employee's position within the salary range will be based on several factors including, but not limited to relevant education, qualifications, certifications, experience, skills, geographic location, government requirements, and business or organizational needs.

The successful candidate will be eligible for annual bonus and long-term incentive, if applicable.

Benefits
  • Medical, dental, vision healthcare and other insurance benefits (for employee and family)
  • Retirement benefits, including 401(k)
  • Paid holidays
  • Vacation
  • Compassionate and sick days
  • More information about benefits is available at https://jobs.merck.com/us/en/compensation-and-benefits.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Director, AI & Cybersecurity Legal
Director, AI & Cybersecurity Legal

Merck & Co. • Rahway (NJ)

Hybrid
USD 191,000 - 300,000
Medical, dental, vision insurance
401(k) retirement plan
Paid holidays
+2
Director, AI & Cybersecurity Legal
Director, AI & Cybersecurity Legal

Merck • North Wales

Hybrid
USD 191,000 - 300,000
Medical insurance
Dental insurance
Vision insurance
+5
Director, AI & Cybersecurity Legal
Director, AI & Cybersecurity Legal

Merck • Rahway (NJ)

Hybrid
USD 191,000 - 300,000
Director, AI & Cybersecurity Legal
Director, AI & Cybersecurity Legal

MSD • Pennsylvania

Hybrid
USD 191,000 - 300,000
Medical, dental, vision
401(k) retirement plan
Paid holidays and leave
+1
Director, AI & Cybersecurity Legal
Director, AI & Cybersecurity Legal

Socket.dev • North Wales

Hybrid
USD 191,000 - 300,000
Director, AI & Cybersecurity Legal
Director, AI & Cybersecurity Legal

MSD Malaysia • North Wales

On-site
USD 191,000 - 300,000
Director, AI-Ready Digital Engagement Innovation
Director, AI-Ready Digital Engagement Innovation

Merck • North Wales

Hybrid
USD 191,000 - 300,000
Hybrid work model
Competitive benefits
Sr. Specialist, Cybersecurity Engineering
Sr. Specialist, Cybersecurity Engineering

Merck • West Point (PA)

Hybrid
USD 117,000 - 184,000
Medical insurance
Dental insurance
Vision insurance
+4
Executive Director, Transformation Enablement & AI Adoption
Executive Director, Transformation Enablement & AI Adoption

Merck • Rahway (NJ)

Hybrid
USD 232,000 - 365,000
Hybrid work arrangement
Comprehensive benefits package
Executive Director, Transformation Enablement & AI Adoption
Executive Director, Transformation Enablement & AI Adoption

Merck • Upper Gwynedd Township

Hybrid
USD 232,000 - 365,000
Annual bonus
Long-term incentive
Comprehensive benefits