Our Global Cyber Defense team is responsible for safeguarding Pfizer's digital assets and infrastructure through proactive threat detection, incident response, and risk mitigation across on-premises, cloud, and hybrid environments.
As a Lead Threat Response Operations Analyst within Pfizer's Global Cyber Defense organization, you will serve as a senior individual contributor, providing technical leadership for the investigation and response to sophisticated cyber threats. While this is not a people-management role, you will lead complex investigations, coordinate the response to security incidents on a global scale, and provide technical guidance to analysts and partner teams. You will bring deep expertise in cyber threat analysis, incident response, malware investigations and adversary tradecraft, with the ability to operate confidently across complex business and technical environments.
Working alongside Threat Detection, Digital Forensics, Security Engineering and other partner teams, you will identify, contain and eradicate threats while providing strategic recommendations to strengthen Pfizer's cyber resilience.
ROLE RESPONSIBILITIES
- Correlate and analyse security telemetry from endpoint, identity, network, cloud, email and threat intelligence sources to identify, investigate and respond to malicious activity.
- Apply knowledge of adversary tactics, techniques and procedures (TTPs) to reconstruct attack lifecycles, determine attack pathways, identify root cause and develop strategic detection and mitigation recommendations.
- Lead the assessment of cyber security incidents, determining severity, business impact, threat scope, and appropriate response and escalation actions.
- Apply advanced knowledge of networking, operating systems and security architectures to analyse technical evidence, identify attack vectors and guide effective containment, eradication and remediation actions.
- Communicate complex technical findings, incident impacts, response decisions and remediation recommendations clearly to technical teams, business stakeholders and senior leadership.
- Drive continuous improvement of Threat Response processes, investigation methodologies, operational procedures, reporting standards, and playbooks to enhance the effectiveness and maturity of the cyber incident response capability
- Co-ordinate effectively across technical and business teams to coordinate cyber incident response activities, maintaining professionalism and sound judgement during high-pressure situations.
- Lead complex cyber security projects and cross-functional workstreams, ensuring timely delivery of objectives and operational improvements.
Support the triage of cyber security tickets, providing technical guidance on priority, scope, investigation, escalation and appropriate response actions. - Provide technical guidance, coaching and knowledge sharing to analysts and partner teams to strengthen investigation quality and Threat Response capability.
- Participate in a scheduled on-call rotation, including weekends, providing timely response, investigation, escalation, and coordination of cyber security incidents.
- Maintain and continuously develop technical expertise in cyber security, threat response, and emerging attack techniques through ongoing training, research, and professional development.
BASIC QUALIFICATIONS
- Bachelor's degree in cyber security, computer forensics, computer science, Information Security, Information Systems, Engineering, Sciences or related field.
- Some relevant experience in cyber security operations, incident response or threat investigation, with demonstrated experience leading complex investigations.
- Advanced understanding of TCP/IP, network protocols and traffic flows, operating systems, cloud and identity technologies, enterprise security architectures and defence-in-depth principles.
- Advanced knowledge of Windows operating systems, system administration, security controls, native utilities and investigative artefacts.
- Demonstrated ability to analyse and correlate large volumes of security log data using security information and event management (SIEM) platforms, such as CrowdStrike Falcon Next-Gen SIEM, Splunk, Google SecOps and draw accurate, evidence-based conclusions.
- Experience using endpoint detection and response (EDR) platforms, such as CrowdStrike Falcon, Microsoft Defender for Endpoint or VMware Carbon Black, to investigate malicious activity, analyse endpoint telemetry and support incidentcontainment and remediation.
- Experience using security analysis and investigation tools such as Wireshark, Snort, Splunk, Kali Linux, SIFT Workstation, REMnux and Volatility or comparable commercial and open-source technologies, including tools used for memory forensics and malware analysis.
- Advanced understanding of the life cycle of network threats, attacks, attack vectors and methods of exploitation with an understanding of intrusion set tactics, techniques and procedures (TTPs)
- Demonstrated ability to analyse and resolve complex technical problems, working independently and collaboratively within cross-functional teams.
- Maintain and continuously develop technical expertise in cyber security, threat response and emerging attack techniques through ongoing training, research and professional development.
- Strong written, verbal and interpersonal communication skills, together with demonstrated organisational and planning abilities and the capacity to coordinate multiple complex investigations and workstreams simultaneously.
- Excellent communication and presentation skills with the ability to present to a variety of internal audiences including senior executives.
- Demonstrated experience leading and delivering complex cyber security projects and cross-functional workstreams, achieving both short-term objectives and longer-term operational improvements.
- Practical experience using the Linux command line to support security investigations, data analysis and the operation of cyber security tools.
Preferred qualification:
- Participation in practical cyber security exercises, such as red team and blue team simulations, capture-the-flag challenges, cyber ranges or incident response exercises.
- Experience using scripting or programming languages, such as Python or PowerShell, to support security investigations, analyse security data and automate repetitive tasks.
Work Location Assignment: Hybrid
Purpose
Breakthroughs that change patients' lives... At Pfizer we are a patient centric company, guided by our four values: courage, joy, equity and excellence. Our breakthrough culture lends itself to our dedication to transforming millions of lives.
Digital Transformation Strategy
One bold way we are achieving our purpose is through our company wide digital transformation strategy. We are leading the way in adopting new data, modelling and automated solutions to further digitize and accelerate drug discovery and development with the aim of enhancing health outcomes and the patient experience.
Flexibility
We aim to create a trusting, flexible workplace culture which encourages employees to achieve work life harmony, attracts talent and enables everyone to be their best working self. Let's start the conversation!
Equal Employment Opportunity
We believe that a diverse and inclusive workforce is crucial to building a successful business. As an employer, Pfizer is committed to celebrating this, in all its forms - allowing for us to be as diverse as the patients and communities we serve. Together, we continue to build a culture that encourages, supports and empowers our employees.
DisAbility Confident
We are proud to be a Disability Confident Employer and we encourage you to put your best self forward with the knowledge and trust that we will make any reasonable adjustments necessary to support your application and future career. Our mission is unleashing the power of our people, especially those with unique superpowers. Your journey with Pfizer starts here!
To learn more about acceptable and prohibited uses of AI during the recruitment process, please review our candidate AI-use guidelines available on Pfizer Careers .
Information & Business Tech
#BI-Hybrid
Skills Required
- Bachelor's degree in cybersecurity, computer forensics, computer science, information security, information systems, engineering, sciences, or a related field
- Relevant experience in cybersecurity operations, incident response, or threat investigation, including leading complex investigations
- Advanced understanding of TCP/IP, network protocols, traffic flows, operating systems, cloud and identity technologies, enterprise security architectures, and defense-in-depth principles
- Advanced knowledge of Windows operating systems, system administration, security controls, native utilities, and investigative artifacts
- Experience analyzing and correlating large volumes of security log data using SIEM platforms
- Experience using EDR platforms to investigate malicious activity, analyze endpoint telemetry, and support incident containment and remediation
- Experience using security investigation tools including Wireshark, Snort, Splunk, Kali Linux, SIFT Workstation, REMnux, and Volatility or comparable technologies
- Advanced understanding of network threat lifecycles, attacks, attack vectors, exploitation methods, and adversary TTPs
- Ability to analyze and resolve complex technical problems independently and collaboratively
- Strong written, verbal, interpersonal, organizational, and planning skills
- Ability to communicate and present technical findings to internal audiences, including senior executives
- Experience leading and delivering complex cybersecurity projects and cross-functional workstreams
- Practical experience using the Linux command line for security investigations, data analysis, and cybersecurity tools
- Participation in red team or blue team exercises, capture-the-flag challenges, cyber ranges, or incident response exercises
- Experience using Python or PowerShell for security investigations, security data analysis, and task automation
Pfizer Compensation & Benefits Highlights
-
Healthcare Strength — Health coverage is described as comprehensive, spanning medical, dental, vision, and robust mental‑health benefits, with eligible Pfizer medications available at no cost in U.S. plans. Family‑building support and transgender‑inclusive care are explicitly included, alongside wellbeing resources such as a reimbursement wallet and telehealth options.
-
Retirement Support — Retirement programs feature a 401(k) with company matching plus an additional Retirement Savings Contribution, complemented by company‑subsidized life, short‑term disability, and long‑term disability insurance. Materials also reference subsidized retiree medical coverage for eligible groups.
-
Leave & Time Off Breadth — Paid vacation, holidays, personal days, and paid parental and caregiver leave are consistently highlighted in current U.S. summaries and job postings. Options like buying extra vacation days and transition‑back support strengthen the time‑off offering.
Pfizer Insights
What We Do
Our purpose ensures that patients remain at the center of all we do. We live our purpose by sourcing the best science in the world; partnering with others in the healthcare system to improve access to our medicines; using digital technologies to enhance our drug discovery and development, as well as patient outcomes; and leading the conversation to advocate for pro-innovation/pro-patient policies.
Why Work With Us
We are the inventors, the problem solvers, the big thinkers — those who surmount any hurdle to deliver breakthrough medicines to the people who are counting on them the most.
Gallery
Pfizer Offices
Hybrid Workspace
Employees engage in a combination of remote and on-site work.









