Senior Manager, Information Protection Engineering
Thessaloniki - Greece
Job Summary
Our Global Cybersecurity Governance Risk and Compliance team provides comprehensive blueprints for cybersecurity excellence by embedding governance risk management and compliance into every layer. The team is responsible for ensuring risk-based decision-making is used and that security privacy and regulatory compliance is integrated seamlessly with Pfizers organization.
We are seeking a Senior Manager Information Protection Engineering to lead and evolve our information protection capabilities within the Cyber GRC organization. This role is critical to safeguarding sensitive scientific clinical patient and business information across Pfizers global enterprise.
The role will lead a team of highly skilled engineers and work closely with CISO organization Privacy Legal Compliance R&D Infrastructure and Cloud Services partners to design implement and operate scalable information protection solutions aligned to regulatory requirements and business priorities.
Lead the definition of enterprise information protection technical strategy reference architectures and control frameworks including DLP data discovery and classification and encryption requirements.
Establish and maintain information protection technical standards guardrails and design patterns that guide implementation across endpoints cloud platforms applications and collaboration tools.
Define policy and control requirements for encryption key management and secrets management in partnership with Cloud Infrastructure and Identity teams ensuring alignment with information protection objectives.
Lead and provide hands-on oversight of the implementation configuration and lifecycle governance of information protection technologies such as DLP data classification data discovery solutions and AI information protection.
Provide architectural guidance and design review for information protection integrations within platforms applications and business solutions.
Influence tooling decisions through riskbased requirements rather than operational ownership of underlying cloud or infrastructure services.
Embed securitybydesign principles for information protection into the application and platform lifecycle including requirements for data handling classification retention and policy enforcement.
Partner with Digital Cloud Services Infrastructure and IT teams to ensure information protection controls are designed into platforms not bolted on postdeployment.
Partner with Security Operations and Incident Response teams to support detection investigation and response to information protection incidents and policy violations.
Ensure information protection capabilities align with enterprise risk management frameworks internal security standards and audit expectations.
Collaborate with Privacy Legal Compliance and Cyber GRC teams to ensure information protection controls support global regulatory and industry requirements (e.g. GDPR HIPAA SOX GxP).
Translate NIST regulatory privacy requirements and risk requirements into clear implementable information protection technical controls and guidance.
Define and report metrics that demonstrate information protection effectiveness risk trends and maturity improvement to Cyber GRC and senior leadership.
Lead mentor and develop a team of engineers and analysts focused on information protection engineering and architectural enablement establishing clear role boundaries between control ownership and platform operational ownership to enable scale and clarity.
Bachelors degree in Information Security Computer Science Engineering or a related field or equivalent experience.
6 years of experience in cybersecurity or information protectionrelated roles with responsibility for enterprisescale information protection controls.
Demonstrated experience designing implementing and operating data loss prevention (DLP) controls across endpoints email cloud platforms and collaboration tools.
Strong technical experience with data classification labelling and policybased enforcement across structured and unstructured data.
Handson experience implementing and managing encryption technologies (data at rest and in transit) key management and secure data handling controls.
Experience integrating information protection controls into cloud platforms SaaS applications and enterprise collaboration environments.
Experience operating security controls in large complex and regulated enterprise environments.
Proven ability to collaborate across engineering digital and operations teams to deliver practical and effective information protection outcomes.
Demonstrated experience in an agile work environment possessing qualities such as a collaborative mindset adaptability to change and a proactive problem-solving approach.
Familiarity with cybersecurity frameworks regulatory requirements and risk management practices relevant to pharmaceutical or life sciences organizations.
Professional certifications such as CDPSE CIPT CIPP/E CISSP CISM.
Prior leadership experience managing or mentoring information protection engineers or security engineering teams.
Strong understanding of data lifecycle management including data creation access sharing retention and secure disposal.
Strong analytical and communication skills with the ability to clearly articulate information protection risks and design decisions to senior stakeholders.
Travel as required by the business (less than 20% domestic and/or international)
Work Location Assignment: Must be able to work in assigned Pfizer office 2-3 days per week or as needed by the business
Please apply by sending your CV in English.
Work Location Assignment:Hybrid
Purpose
Breakthroughs that change patients lives... At Pfizer we are apatient centric company guided by our four values: courage joy equity and excellence. Our breakthrough culture lends itself to our dedication to transforming millions of lives.
Digital Transformation Strategy
One bold way we are achieving our purpose is through our company wide digital transformation strategy. We are leading the way in adopting new data modelling and automated solutions to further digitize and accelerate drug discovery and development with the aim of enhancing health outcomes and the patient experience.
Flexibility
We aim to create a trusting flexible workplace culture which encourages employees to achieve work life harmony attracts talent and enables everyone to be their best working start the conversation!
Equal Employment Opportunity
We believe that a diverse and inclusive workforce is crucial to building a successful business. As an employer Pfizer iscommitted to celebratingthisin all itsforms allowing for us to be as diverse as the patients and communities we serve. Together we continue to build a culture that encourages supports and empowers our employees.
Disability Inclusion
Our mission is unleashing the power of all our people and we are proud to be a disability inclusive employer ensuring equal employment opportunities for all candidates. We encourage you to put your best self forward with the knowledge and trust that we will make any reasonable adjustments to support your application and future career. Your journey with Pfizer starts here!
To learn more about acceptable and prohibited uses of AI during the recruitment process please review our candidate AI-use guidelines available onPfizer Careers.
Information & Business TechRequired Experience:
Senior Manager
About Company
Erfahren Sie mehr über uns als forschendes und produzierendes Pharmaunternehmen: Von unserem Beitrag zum medizinischen Fortschritt bis zur nachhaltigen Produktion.