Our Global Cybersecurity Governance, Risk, and Compliance (GRC) team provides comprehensive blueprints for cybersecurity excellence by embedding governance, risk management, and compliance into every layer. The team is responsible for ensuring risk-based decision-making is used and that security, privacy, and regulatory compliance is integrated seamlessly with Pfizer's organization.
We are seeking a Manager, Information Protection & Technology Privacy, to lead and oversee the enterprise information protection program and serve as the primary Technology & Cyber Privacy Advisor within the Cyber GRC organization. This role ensures that sensitive data - across intellectual property, regulated data, and confidential business information - is appropriately classified, protected, and handled in alignment with Pfizer policies, regulatory expectations, and risk tolerance.
This role partners closely with Data Protection Engineering, Privacy, Legal, IT, Security Operations, and the DPO office to operationalize controls, drive adoption of data protection standards, ensure ongoing compliance across a complex, regulated pharmaceutical environment, and support Business Units in navigating privacy obligations across multiple jurisdictions.
ROLE RESPONSIBILITIES
- Act as a trusted advisor on cybersecurity, information protection, and data privacy matters across APAC and EMEA.
- Partner with Business, Digital & Technology, Privacy, Legal, and Compliance stakeholders to provide pragmatic cybersecurity and information protection guidance for strategic initiatives, business transformations, and technology projects.
- Assess and manage cybersecurity and information protection risks associated with business initiatives, applications, digital solutions, and third-party engagements.
- Ensure compliance with applicable cybersecurity and data protection regulations across APAC and EMEA, including CSL, DSL, PIPL, GDPR, NIS2, and related regulatory requirements.
- Support regulatory inspections, audits, compliance reviews, and regulatory engagements as required.
- Lead cybersecurity and data protection compliance programs, including regulatory assessments, filings, remediation planning, and related compliance activities.
- Monitor emerging cybersecurity threats, regulatory developments, and compliance risks, and drive security awareness, risk management, and information protection initiatives across the organization.
- Support defining information protection controls for our organization to ensure regulatory compliance.
- Support in the development of data protection policies and standards.
- Support cybersecurity incident response, escalation, and remediation activities when required.
- This role requires flexibility to collaborate with stakeholders and support business needs across multiple time zones.
BASIC QUALIFICATIONS
- Bachelor's degree in Information Security, Computer Science, Information Systems, Risk Management, or a related field.
- 7+ years of experience in cybersecurity, information security, data protection, privacy, regulatory compliance, risk management, or related disciplines, with at least 2 years in a supervisory or project leadership capacity.
- Strong knowledge of cybersecurity governance, risk management, compliance frameworks,and applicable regulatory requirements.
- Strong understanding of cybersecurity and data protection regulations, including CSL, DSL, PIPL, GDPR, DPDPA, NIS2, and related requirements.
- Experience supporting cybersecurity assessments, audits, regulatory inspections, compliance programs, or risk management initiatives.
- Experience and hands on familiarity with DLP and data discovery tools, as well as data labeling and tagging solutions, including deployment and ongoing support.
- Working knowledge of data encryption concepts and approaches across different environments.
- Strong stakeholder management, communication, and influencing skills, with the ability to work effectively across business and technology functions in a global environment.
- Strong project coordination across business and technical teams.
- Professional proficiency in English.
PREFERRED QUALIFICATIONS
- Professional certifications such as CISSP, CISA, CISM, CRISC, CIPP/E, CIPM, or equivalent are preferred.
- Experience supporting cybersecurity, information protection, data privacy, or regulatory compliance programs within the pharmaceutical, healthcare, or life sciences industry is strongly preferred.
- Hands ‑ on experience with GRC platforms (e.g., Archer).
- Familiarity with privacy, intellectual property protection, and regulated data environments.
Pfizer is an equal opportunity employer and complies with all applicable equal employment opportunity legislation in each jurisdiction in which it operates.
To learn more about acceptable and prohibited uses of AI during the recruitment process, please review our candidate AI-use guidelines available on Pfizer Careers .
Information & Business Tech
Skills Required
- Bachelor's degree in Information Security, Computer Science, Information Systems, Risk Management, or related field
- 7+ years experience in cybersecurity, information security, data protection, privacy, regulatory compliance, or risk management
- At least 2 years in a supervisory or project leadership capacity
- Strong knowledge of cybersecurity governance, risk management, and compliance frameworks
- Strong understanding of cybersecurity and data protection regulations (CSL, DSL, PIPL, GDPR, DPDPA, NIS2)
- Experience supporting cybersecurity assessments, audits, regulatory inspections, compliance programs, or risk management initiatives
- Experience and hands-on familiarity with DLP and data discovery tools, and data labeling and tagging solutions (deployment and ongoing support)
- Working knowledge of data encryption concepts and approaches across environments
- Strong stakeholder management, communication, and influencing skills
- Strong project coordination across business and technical teams
- Professional proficiency in English
- Professional certifications such as CISSP, CISA, CISM, CRISC, CIPP/E, CIPM
- Experience in pharmaceutical, healthcare, or life sciences cybersecurity, information protection, or privacy programs
- Hands-on experience with GRC platforms (e.g., Archer)
- Familiarity with privacy, intellectual property protection, and regulated data environments
Pfizer Compensation & Benefits Highlights
-
Healthcare Strength — Official materials describe comprehensive medical, dental, vision, and mental-health support, plus fertility/family‑building and transgender‑inclusive coverage; eligible Pfizer medications are noted as available at no cost in U.S. plans. Wellness resources such as telehealth and preventative programs are also emphasized.
-
Retirement Support — Company documents highlight a 401(k) with matching contributions plus an additional Retirement Savings Contribution beyond the match. Financial planning support and company‑paid life and disability insurance further bolster long‑term security.
-
Leave & Time Off Breadth — Corporate pages and job postings describe paid vacation and holidays, caregiver leave, and paid parental leave for both parents. Materials also note that details can vary by role and location.
Pfizer Insights
What We Do
Our purpose ensures that patients remain at the center of all we do. We live our purpose by sourcing the best science in the world; partnering with others in the healthcare system to improve access to our medicines; using digital technologies to enhance our drug discovery and development, as well as patient outcomes; and leading the conversation to advocate for pro-innovation/pro-patient policies.
Why Work With Us
We are the inventors, the problem solvers, the big thinkers — those who surmount any hurdle to deliver breakthrough medicines to the people who are counting on them the most.
Gallery
Pfizer Offices
Hybrid Workspace
Employees engage in a combination of remote and on-site work.









