Enter a job title or keyword

Manager, Cybersecurity & Information Protection (APAC&EMEA) Base SH or BJ

Pfizer


Job Location:

Shanghai - China

Monthly Salary: Not provided by the employer
Posted: 22 August 2026 (8 days ago)
Application Deadline: 19 November 2026
Vacancies: 1 Vacancy

Job Summary

ROLE SUMMARY

Our Global Cybersecurity Governance Risk and Compliance (GRC) team provides comprehensive blueprints for cybersecurity excellence by embedding governance risk management and compliance into every layer. The team is responsible for ensuring risk-based decision-making is used and that security privacy and regulatory compliance is integrated seamlessly with Pfizers organization.

We are seeking a Manager Information Protection & Technology Privacy to lead and oversee the enterprise information protection program and serve as the primary Technology & Cyber Privacy Advisor within the Cyber GRC organization. This role ensures that sensitive data across intellectual property regulated data and confidential business information is appropriately classified protected and handled in alignment with Pfizer policies regulatory expectations and risk tolerance.

This role partners closely with Data Protection Engineering Privacy Legal IT Security Operations and the DPO office to operationalize controls drive adoption of data protection standards ensure ongoing compliance across a complex regulated pharmaceutical environment and support Business Units in navigating privacy obligations across multiple jurisdictions.

ROLE RESPONSIBILITIES

  • Act as a trusted advisor on cybersecurity information protection and data privacy matters across APAC and EMEA.
  • Partner with Business Digital & Technology Privacy Legal and Compliance stakeholders to provide pragmatic cybersecurity and information protection guidance for strategic initiatives business transformations and technology projects.
  • Assess and manage cybersecurity and information protection risks associated with business initiatives applications digital solutions and third-party engagements.
  • Ensure compliance with applicable cybersecurity and data protection regulations across APAC and EMEA including CSL DSL PIPL GDPRNIS2 and related regulatory requirements.
  • Support regulatory inspections audits compliance reviews and regulatory engagements as required.
  • Lead cybersecurity and data protection compliance programs including regulatory assessments filings remediation planning and related compliance activities.
  • Monitor emerging cybersecurity threats regulatory developments and compliance risks and drive security awareness risk management and information protection initiatives across the organization.
  • Support defininginformation protection controls for our organization to ensure regulatory compliance.
  • Support in the development of data protection policies and standards.
  • Support cybersecurity incident response escalation and remediation activities when required.
  • This role requires flexibility to collaborate with stakeholders and support business needs across multiple time zones.

BASIC QUALIFICATIONS

  • Bachelors degree in Information Security Computer Science Information Systems Risk Management or a related field.
  • 7 years of experience in cybersecurity information security data protection privacy regulatory compliance risk management or related disciplines with at least 2 years in a supervisory or project leadership capacity.
  • Strong knowledge of cybersecurity governance risk management compliance frameworksand applicable regulatory requirements.
  • Strong understanding of cybersecurity and data protection regulations including CSL DSL PIPL GDPR DPDPA NIS2 and related requirements.
  • Experience supporting cybersecurity assessments audits regulatory inspections compliance programs or risk management initiatives.
  • Experience and hands on familiarity with DLP and data discovery tools as well as data labeling and tagging solutions including deployment and ongoing support.
  • Working knowledge of data encryption concepts and approaches across different environments.
  • Strong stakeholder management communication and influencing skills with the ability to work effectively across business and technology functions in a global environment.
  • Strong project coordination across business and technical teams.
  • Professional proficiency in English.

PREFERRED QUALIFICATIONS

  • Professional certifications such as CISSP CISA CISM CRISC CIPP/E CIPM or equivalent are preferred.
  • Experience supporting cybersecurity information protection data privacy or regulatory compliance programs within the pharmaceutical healthcare or life sciences industry is strongly preferred.
  • Handson experience with GRC platforms (e.g. Archer).
  • Familiarity with privacy intellectual property protection and regulated data environments.


Pfizer is an equal opportunity employer and complies with all applicable equal employment opportunity legislation in each jurisdiction in which it operates.

To learn more about acceptable and prohibited uses of AI during the recruitment process please review our candidate AI-use guidelines available onPfizer Careers.

Information & Business Tech


Required Experience:

Manager


About Company

Company Logo

Erfahren Sie mehr über uns als forschendes und produzierendes Pharmaunternehmen: Von unserem Beitrag zum medizinischen Fortschritt bis zur nachhaltigen Produktion.

View Profile View Profile