Role at a glance
- Job function
-
Software Engineering & IT Cybersecurity
- Salary
- $99.2K – $165.4K/yr
- Location
- New York City, New York, United States
- Work arrangement
- Hybrid
- Employment
- Full-time
- Education
- Bachelor's, Master's, PhD
Spotted an issue?
We’ll check it against the original posting.
About the role
Original posting provided by Pfizer
ROLE SUMMARY
Our Global Governance, Risk, and Compliance (GRC) team provides comprehensive blueprints for cybersecurity excellence by embedding governance, risk management, and compliance into every layer. The team is responsible for ensuring risk-based decision-making is used and that security, privacy, and regulatory compliance is integrated seamlessly with Pfizer’s organization.
We are seeking a Manager, Technology, Metrics, and Automation who will guide how the organization leverages data, automation, and technical platforms to advance security and risk management outcomes. The role oversees the design and governance of data pipelines, reporting systems, and automated workflows that ensure accurate, reliable, and timely information flows throughout the environment. By integrating technology solutions with operational processes, this role enables teams to monitor performance, identify systemic risks, and make informed decisions that strengthen organizational resilience.
ROLE RESPONSIBILITIES
Define and execute the technology roadmap for Cyber GRC tooling, aligned to enterprise risk priorities, regulatory requirements, and operating model maturity.
Partner with IT and platform teams on system upgrades, integrations, data feeds, and configuration enhancements.
Define and govern a comprehensive set of Cyber GRC metrics, KPIs, and KRIs that provide actionable insights into Pfizer’s GRC environment.
Ensure metrics are risk‑aligned, standardized, and decision‑useful, not just activity‑based.
Develop executive‑level dashboards for senior leadership, risk committees, and governance forums.
Identify and drive automation opportunities across Cyber GRC processes to reduce manual effort, improve data quality, and increase consistency.
Lead implementation of workflow automation, approvals, notifications, evidence collection, and reporting capabilities.
Ensure alignment between GRC data and enterprise data standards.
Partner with data/analytics teams to enable scalable reporting solutions (e.g., BI tools, dashboards, automation pipelines).
Serve as a key partner to Cybersecurity leadership, IT, Infrastructure, Cloud Services, Privacy, Quality, and Internal Audit.
Translate stakeholder needs into practical technology and reporting solutions.
Influence adoption and consistent use of GRC platforms across global teams.
Act as a key contributor during internal audits, external audits, and regulatory inspections, ensuring metrics and system outputs are defensible and traceable.
BASIC QUALIFICATIONS
Applicant must have a bachelor's degree with at least 4 years of experience; OR a master's degree with at least 2 years of experience; OR a PhD with 0+ years of experience; OR as associate's degree with 8 years of experience; OR a high school diploma (or equivalent) and 10 years of relevant experience.
4+ years of experience in information technology or cybersecurity.
Ability to manage multiple priorities, work with cross-functional teams, and deliver high-quality outputs.
Strong experience with GRC platforms, reporting, and workflow automation.
Demonstrated ability to design metrics and dashboards that support executive decision‑making.
Strong stakeholder management and communication skills, including executive‑level presentations.
Experience operating in a highly regulated, matrixed enterprise environment.
Demonstrated experience in an agile work environment possessing qualities such as a collaborative mindset, adaptability to change, and a proactive problem-solving approach.
PREFERRED QUALIFICATIONS
Bachelor’s degree in information technology, cybersecurity, computer science, or a related field.
Demonstrated experience working in pharmaceuticals industry.
Professional certifications such as CISSP, CISM, CRISC, CISA, PMP, or similar.
Hands‑on experience with tools such as ServiceNow GRC, Archer, Power BI, Tableau, or similar.
Experience in large, complex, or regulated environments.
NON-STANDARD WORK SCHEDULE, TRAVEL OR ENVIRONMENT REQUIREMENTS
Travel as required by the business (less than 20% domestic and/or international)
Work Location Assignment: Must be able to work in assigned Pfizer office 2-3 days per week, or as needed by the business
This role is NOT remote
Work Location Assignment: Hybrid
Relocation assistance may be available based on business needs and/or eligibility.
Candidates must be authorized to be employed in the U.S. by any employer.
U.S. work visa sponsorship (such as TN, O-1, H-1B, etc.) is not available for this role now or in the future.
Sunshine Act
Pfizer reports payments and other transfers of value to health care providers as required by federal and state transparency laws and implementing regulations. These laws and regulations require Pfizer to provide government agencies with information such as a health care provider’s name, address and the type of payments or other value received, generally for public disclosure. Subject to further legal review and statutory or regulatory clarification, which Pfizer intends to pursue, reimbursement of recruiting expenses for licensed physicians may constitute a reportable transfer of value under the federal transparency law commonly known as the Sunshine Act. Therefore, if you are a licensed physician who incurs recruiting expenses as a result of interviewing with Pfizer that we pay or reimburse, your name, address and the amount of payments made currently will be reported to the government. If you have questions regarding this matter, please do not hesitate to contact your Talent Acquisition representative.
EEO & Employment Eligibility
Pfizer is committed to equal opportunity in the terms and conditions of employment for all employees and job applicants without regard to race, color, religion, sex, sexual orientation, age, gender identity or gender expression, national origin, disability or veteran status. Pfizer also complies with all applicable national, state and local laws governing nondiscrimination in employment as well as work authorization and employment eligibility verification requirements of the Immigration and Nationality Act and IRCA. Pfizer is an E-Verify employer. This position requires permanent work authorization in the United States.
Pfizer endeavors to make www.pfizer.com/careers accessible to all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process and/or interviewing, please email [email protected]. This is to be used solely for accommodation requests with respect to the accessibility of our website, online application process and/or interviewing. Requests for any other reason will not be returned.
To learn more about acceptable and prohibited uses of AI during the recruitment process, please review our candidate AI-use guidelines available on Pfizer Careers.
Information & Business TechAbout the company
Pfizer
Large Enterprise
Pfizer is a global biopharmaceutical company dedicated to the discovery, development, and manufacturing of innovative healthcare solutions. With a strong focus on improving lives through medications and vaccines, Pfizer has played a significant role in addressing various health challenges, including infectious diseases, chronic illnesses, and rare conditions. The company emphasizes research-driven approaches and collaborative efforts in its mission to enhance global health and empower patients through cutting-edge science and technology. Through its commitment to high standards of safety and efficacy, Pfizer continues to shape the future of medicine.