Sr. Associate, Offensive Security
New York City, NY - USA
Job Summary
ROLE SUMMARY
Our Global Cyber Defense team is responsible for safeguarding Pfizers digital assets and infrastructure through proactive threat detection response and risk mitigation across on-premises cloud and hybrid environments.
The Senior Associate Offensive Security supports offensive security activities that proactively identify validate and help prioritize security weaknesses across the digital environment. This role contributes to penetration testing adversary simulation and purple team exercises that continuously assess the organizations exposure to realworld threats. Operating within a highly regulated pharmaceutical environment the Senior Associate partners closely with detection remediation engineering and risk teams to ensure findings are clearly documented actionable and translated into measurable security improvements. This role will report to the Sr. Manager Offensive Security.
ROLE RESPONSIBILITIES
Conduct offensive security testing activities including penetration tests and adversary simulation exercises across onpremises cloud and hybrid environments.
Support red team and purple team engagements by executing test plans collecting evidence and helping evaluate defensive control effectiveness.
Identify validate and document security weaknesses including technical details proof of concept evidence and clear remediation recommendations.
Assist with translating offensive findings into actionable improvement items for detection engineering and remediation teams.
Contribute to threatinformed testing by mapping observed techniques to common attacker behaviors and helping highlight realistic attack paths.
Maintain high quality reporting standards and ensure deliverables are accurate complete and aligned to ethical testing expectations and internal requirements.
Support continuous improvement efforts for offensive security tooling automation repeatable test methods and playbooks.
Collaborate with crossfunctional partners (e.g. detection incident response vulnerability management infrastructure cloud) to coordinate testing logistics and minimize business disruption.
Escalate complex technical issues highrisk findings or unexpected conditions.
BASIC QUALIFICATIONS
Applicant must have a Bachelors degree in Information Security Computer Science Engineering or a related field with at least 2 years of experience in cybersecurity with handson focus in offensive security penetration testing vulnerability research or security engineering; OR a masters degree with more than 0 years of experience; OR an associates degree with 6 years of experience; OR a high school diploma (or equivalent) with 8 years of relevant experience.
Practical experience executing penetration tests or security assessments including reconnaissance exploitation validation and reporting.
Strong understanding of common attack techniques and enterprise security concepts across identity endpoints networks and cloud services.
Ability to clearly document technical findings and communicate risk and remediation guidance to technical stakeholders.
Working knowledge of at least one scripting/programming language commonly used for security work (e.g. Python PowerShell Bash).
Strong collaboration skills and ability to operate in a processdriven highly regulated environment.
PREFERRED QUALIFICATIONS
Strong handson knowledge of:
Red team and adversary emulation methodologies (MITRE ATT&CKaligned)
Application cloud network and identity penetration testing
Social engineering and phishing simulations (where appropriate)
Tooling and frameworks commonly used in offensive security
Experience in pharmaceutical biotech life sciences or similarly regulated industries.
Demonstrated capability supporting offensive security testing in cloud or hybrid environments.
Exposure to partnering with detection engineering / SOC teams to improve detections based on offensive findings.
Experience working in regulated industries (e.g. healthcare life sciences pharmaceuticals) or environments with high compliance expectations.
Relevant certifications (e.g. CISSP OSCP CRTO GPEN/GXPN) or similar offensive security credentials.
Demonstrated interest in improving repeatability through tooling automation and standardized playbooks.
PHYSICAL/MENTAL REQUIREMENTS
No special physical requirements.
Applicants should be capable of working through a personal laptop computer or mobile device for extended periods.
NON-STANDARD WORK SCHEDULE TRAVEL OR ENVIRONMENT REQUIREMENTS
Travel as required by the business (less than 5% domestic and/or international)
Work Location Assignment: Must be able to work in assigned Pfizer office 2-3 days per week or as needed by the business
This role is NOT remote
Other Job Details:
Last Date to Apply for Job: August 24th 2026
Work Location Assignment:Hybrid. Must be able to work from assigned Pfizer office 2-3 days per week or as needed by the business
Relocation assistance may be available based on business needs and/or eligibility.
Candidates must be authorized to be employed in the U.S. by any employer.
U.S. work visa sponsorship (such as TN O-1 H-1B etc.) is not available for this role now or in the future.
Sunshine Act
Pfizer reports payments and other transfers of value to health care providers as required by federal and state transparency laws and implementing regulations. These laws and regulations require Pfizer to provide government agencies with information such as a health care providers name address and the type of payments or other value received generally for public disclosure. Subject to further legal review and statutory or regulatory clarification which Pfizer intends to pursue reimbursement of recruiting expenses for licensed physicians may constitute a reportable transfer of value under the federal transparency law commonly known as the Sunshine Act. Therefore if you are a licensed physician who incurs recruiting expenses as a result of interviewing with Pfizer that we pay or reimburse your name address and the amount of payments made currently will be reported to the government. If you have questions regarding this matter please do not hesitate to contact your Talent Acquisition representative.
EEO & Employment Eligibility
Pfizer is committed to equal opportunity in the terms and conditions of employment for all employees and job applicants without regard to race color religion sex sexual orientation age gender identity or gender expression national origin disability or veteran status. Pfizer also complies with all applicable national state and local laws governing nondiscrimination in employment as well as work authorization and employment eligibility verification requirements of the Immigration and Nationality Act and IRCA. Pfizer is an E-Verify employer. This position requires permanent work authorization in the United States.
Pfizer endeavors to make to all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process and/or interviewing please email. This is to be used solely for accommodation requests with respect to the accessibility of our website online application process and/or interviewing. Requests for any other reason will not be returned.
To learn more about acceptable and prohibited uses of AI during the recruitment process please review our candidate AI-use guidelines available onPfizer Careers.
Information & Business TechRequired Experience:
Senior IC
About Company
Erfahren Sie mehr über uns als forschendes und produzierendes Pharmaunternehmen: Von unserem Beitrag zum medizinischen Fortschritt bis zur nachhaltigen Produktion.