yoinka

Director, AI & Cybersecurity Legal

Merck

North Wales, Pennsylvania, United States of AmericaFull TimeStaff$190.8k – $300.3k/yr
Sign in to applyVerified 3h ago
Location
North Wales, Pennsylvania, United States of America
Employment
Full Time
Work model
On-Site
Level
Staff
Salary
$190.8k – $300.3k/yr
Posted
Sep 18, 2026

Skills

CybersecurityGenAIMachine LearningSpark

About this role

Job Description

The Director, AI and Cybersecurity Legal will report to the Chief Privacy and Digital Trust Officer, partner closely with the Chief Information Security Officer, and serve as a trusted and strategic legal adviser on AI and cybersecurity matters across the enterprise. This role will provide legal counsel on the development, deployment, and governance of AI/ML technologies, as well as cybersecurity risk management, incident response, and regulatory compliance. The Director will partner closely with Information Technology, Information Technology Risk Management, and business teams to enable innovation while managing legal and regulatory risk in a highly regulated global pharmaceutical environment.

Key Responsibilities

Artificial Intelligence & Emerging Technology Provide strategic legal counsel on the design, development, procurement, and deployment of AI and machine learning systems across research, commercial, and corporate functions. Advise on AI governance frameworks, including responsible AI principles, algorithmic transparency, bias mitigation, and human oversight requirements for high-risk systems. Provide strategic legal counsel related to the design and implementation of next-generation AI Governance, including AI policies, evolving AI risk assessment frameworks (e.g., triage design, risk tiering, domain-specific assessment frameworks, automation, and streamlined decision workflows), third-party AI due diligence, and implementing AI incident reporting obligations. Monitor and interpret evolving AI regulations globally, including the EU AI Act, FDA guidance on AI/ML in drug development and medical devices, and other emerging frameworks. Serve as a member of divisional AI committees. Lead AI contract negotiations and counsel on technology transactions. Counsel internal stakeholders on data rights and contractual issues arising from generative AI tools and third-party AI platforms. Represent the company externally as required, including engaging with regulators, trade associations, and other industry organizations. Cybersecurity Serve as the primary legal advisor to the Chief Information Security Officer (CISO) and Information Technology Risk Management organization on legal and regulatory matters. Provide legal support for cybersecurity incident response efforts, including assessing breach notification obligations under HIPAA, state breach notification laws, and other applicable frameworks. Advise on cybersecurity regulatory requirements, including SEC cybersecurity disclosure rules, NIST frameworks, and industry-specific standards. Provide legal guidance on vulnerability disclosure, threat intelligence sharing, and engagement with law enforcement and regulatory authorities. Support the development and review of cybersecurity policies, vendor security assessments, and security provisions in commercial agreements. Cross-Functional Collaboration Partner with privacy, compliance and legal colleagues to address intersections between AI, regulatory and commercial legal considerations, cybersecurity, and data protection laws. Advise on data governance and data-sharing arrangements that implicate cybersecurity and AI considerations. Support M&A, licensing, and collaboration transactions with cybersecurity and AI due diligence and integration guidance. Provide training and awareness to business stakeholders on AI legal risks and cybersecurity legal obligations.

Qualifications

J.D. from an accredited law school and active membership in at least one U.S. state bar. Minimum 10 years of legal experience, with at least 5 years focused on cybersecurity, technology, and/or AI/emerging technology law, preferably in a pharmaceutical, life sciences, healthcare, or other highly regulated environment. Additional experience or background in data privacy/data protection a plus. Deep understanding of cybersecurity legal frameworks (HIPAA, GDPR, NIS2, SEC disclosure rules, state breach notification laws) and emerging AI and

Listing verified 3h ago. Applications go through the company's official careers site.

← Back to Yoinka

Director, AI & Cybersecurity Legal at Merck, North Wales, Pennsylvania, United States of America | Yoinka