Information Protection Analyst & Engineer
Job Description
As a key member of the Information Technology Risk Management and Security (ITRM&S) organization, the successful candidate will act as a core member of the Information Protection team. This is a hybrid role featuring a dual focus on both operational DLP and DLP engineering to protect company data. The candidate will be responsible for managing and remediating instances of sensitive data leakage and insider risk, while concurrently configuring, tuning, and maintaining the information protection technologies that prevent them.
Responsibilities:
Investigate, analyze, and manage security incidents generated from Data Loss Prevention (DLP) and other information protection tools, utilizing log analysis, data visualization, and pattern analysis
Design, build, test, and deploy new DLP policies, rules, and logic across network, endpoint, and cloud environments to address emerging risks and align with the company's data protection strategy
Manage the full lifecycle of information protection incidents, from detection and escalation through to remediation, ensuring clear communication of status to stakeholders and management
Support the maintenance, enhancement, and troubleshooting of the information protection technology stack to ensure high availability, accurate detection, and optimal platform performance
Develop, implement, and maintain automation scripts and processes (e.g., using Python or PowerShell) to improve incident response workflows, reduce manual effort, and enhance reporting accuracy
Collaborate closely with the Global Security Group, Legal, Human Resources, and other business units to respond to sensitive incidents in accordance with established corporate policies
Continuously evaluate, improve, and challenge existing processes, procedures, and technical controls to adapt to a fast-moving and evolving security environment
Create, modify, and review security dashboards and metrics reports to provide actionable insights into the organization’s overall data risk posture
Required Experience and Skills:
Proven experience in an information security discipline, with a professional background that includes both active incident response and technical platform implementation
Strong, practical experience with Data Loss Prevention (DLP) concepts, methodologies, and enterprise-grade tools
Demonstrated ability to independently investigate and resolve complex security incidents (Tier 2/3 support levels), including performing in-depth root cause analysis
Hands-on experience with scripting or programming languages (e.g., Python, PowerShell) specifically applied to automation, data extraction, or system integration
Excellent analytical, problem-solving, and written/verbal communication skills, with the ability to convey technical risks to non-technical stakeholders
Strong foundational understanding of networking protocols (TCP/IP), operating system architectures, and cloud security principles
Ability to work effectively in a collaborative team environment, manage shifting priorities, and balance operational emergencies with project-based engineering tasks
Desired Experience and Skills:
Direct experience with specific DLP and security solutions for network, endpoint, and cloud environments (e.g., Microsoft 365 Purview, Zscaler, CrowdStrike)
Experience proactively creating, fine-tuning, and deploying detection policies within security platforms rather than just monitoring existing alerts
Proven ability to build strong, trusted relationships with cross-functional business and technology stakeholders
Up-to-date knowledge of the current global data protection landscape, privacy regulations, and emerging security threat trends
Relevant industry certifications such as CISSP, CISM, or vendor-specific security engineering certifications
What We Offer
Exciting work in a great team, global projects, international environment
Opportunity to learn and grow professionally within the company globally
Pension and health (Canadian Medical) contributions
Internal reward system plus referral program
5 weeks annual leave, 5 sick days, 15 days of certified sick leave paid above statutory requirements annually, 40 paid hours annually for volunteering activities, 12 weeks of parental contribution
Cafeteria for tax free benefits according to your choice (meal vouchers, sport, culture, health, travel, etc.), Multisport card, Vodafone, Raiffeisen Bank and Foodora discount programs
Up-to-date laptop and iPhone, parking in the garage, showers, refreshments
Competitive salary, incentive pay, and many more
Ready to take up the challenge? Apply now!
Know anybody who might be interested? Refer this job!
The date shown below is the earliest possible closing date for this posting. However, we sometimes extend the job posting period as needed, so please feel free to apply anytime you see the "Apply" button available. You may also reach out to the recruiter directly via https://www.linkedin.com/in/badumtss/
Required Skills:
Data Loss Prevention (DLP), Incident Response, Information Security, Microsoft PowerShell, Python (Programming Language), TCP/IP NetworkingPreferred Skills:
Critical Incident Stress Management (CISM), Data Protection, Privacy RegulationsCurrent Employees apply HERE
Current Contingent Workers apply HERE
Search Firm Representatives Please Read Carefully
Merck & Co., Inc., Rahway, NJ, USA, also known as Merck Sharp & Dohme LLC, Rahway, NJ, USA, does not accept unsolicited assistance from search firms for employment opportunities. All CVs / resumes submitted by search firms to any employee at our company without a valid written search agreement in place for this position will be deemed the sole property of our company. No fee will be paid in the event a candidate is hired by our company as a result of an agency referral where no pre-existing agreement is in place. Where agency agreements are in place, introductions are position specific. Please, no phone calls or emails.
Employee Status:
RegularRelocation:
No relocationVISA Sponsorship:
YesTravel Requirements:
10%Flexible Work Arrangements:
HybridShift:
Not IndicatedValid Driving License:
NoHazardous Material(s):
N/AJob Posting End Date:
08/9/2026*A job posting is effective until 11:59:59PM on the day BEFORE the listed job posting end date. Please ensure you apply to a job posting no later than the day BEFORE the job posting end date.