Manager, Offensive Security

Posted Yesterday
Be an Early Applicant
Chortiatis, GRC
Hybrid
Mid level
Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
We’re in relentless pursuit of breakthroughs that change patients’ lives.
The Role
Leads day-to-day offensive security operations, including penetration testing, red and purple team exercises, and adversary simulations. Manages assessment planning, scoping, execution, and reporting while mentoring offensive security engineers. Partners with detection, incident response, vulnerability management, engineering, and risk teams to translate findings into measurable risk reduction. Oversees risk-based methodologies, documentation, playbooks, tools, and compliance with regulatory and ethical testing standards.
Summary Generated by Built In
ROLE SUMMARY
Our Global Cyber Defense team is responsible for safeguarding Pfizer's digital assets and infrastructure through proactive threat detection, response, and risk mitigation across on-premises, cloud, and hybrid environments.
The Manager, Offensive Security is responsible for leading the execution of offensive security activities that proactively identify, validate, and help prioritize security weaknesses across the digital environment. This role leads day‑to‑day offensive security operations, including penetration testing, red and purple team exercises, and adversary simulation activities. Operating within a highly regulated pharmaceutical environment, the role partners closely with detection, remediation, engineering, and risk teams to ensure offensive findings are clearly communicated, actionable, and effectively translated into measurable risk reduction and improved defensive outcomes. This role will report to the Sr. Manager, Offensive Security.
ROLE RESPONSIBILITIES
  • Lead the day‑to‑day execution of offensive security activities, including penetration testing, red team engagements, purple team exercises, and adversary simulation efforts.
  • Guide or mentor a team of offensive security engineers, providing technical direction, prioritization, and coaching.
  • Oversee planning, scoping, and delivery of offensive security assessments to ensure activities are risk‑based, repeatable, and aligned with business priorities.
  • Ensure offensive security findings are clearly documented, validated, and communicated to detection, remediation, engineering, and risk teams.
  • Partner closely with Threat Detection, Incident Response, Vulnerability Management, and Engineering teams to translate offensive findings into actionable improvements and measurable risk reduction.
  • Support the continuous improvement of offensive security tools, methodologies, and processes to increase coverage, realism, and operational efficiency.
  • Track engagement outcomes, recurring control gaps, and risk trends, escalating material issues and insights.
  • Ensure offensive security activities are conducted in alignment with internal policies, regulatory expectations, and ethical testing standards.
  • Contribute to the development and maintenance of offensive security documentation, playbooks, and reporting standards.

BASIC QUALIFICATIONS
  • Bachelor's degree in Information Security, Computer Science, Engineering, or a related field, or equivalent practical experience.
  • 4+ years of experience in cybersecurity, with significant focus on offensive security, penetration testing, red teaming, or adversary simulation.
  • Strong hands‑on knowledge of:
    • Red team and adversary emulation methodologies (MITRE ATT&CK-aligned)
    • Application, cloud, network, and identity penetration testing
    • Social engineering and phishing simulations (where appropriate)
    • Tooling and frameworks commonly used in offensive security

  • Solid understanding of modern enterprise environments (cloud, SaaS, hybrid).
  • Experience documenting, validating, and communicating offensive security findings to technical and non‑technical stakeholders.
  • Ability to manage priorities, make risk‑based decisions, and operate effectively in a fast‑paced, highly regulated environment.

PREFERRED QUALIFICATIONS
  • Experience in pharmaceutical, biotech, life sciences, or similarly regulated industries.
  • Experience with cloud-native red teaming (AWS, Azure, GCP) and identity-centric attack paths.
  • Familiarity with detection engineering, SIEM/SOAR, and threat intelligence workflows.
  • Professional certifications such as OSCP, OSEP, CRTO, CISSP, GIAC, or similar offensive security‑focused credentials.
  • Strong communication skills, with the ability to clearly articulate technical risk, attack feasibility, and business impact to senior technical and non‑technical stakeholders.

Please apply by sending your CV in English.
Work Location Assignment: Hybrid
Purpose
Breakthroughs that change patients' lives... At Pfizer we are a patient centric company, guided by our four values: courage, joy, equity and excellence. Our breakthrough culture lends itself to our dedication to transforming millions of lives.
Digital Transformation Strategy
One bold way we are achieving our purpose is through our company wide digital transformation strategy. We are leading the way in adopting new data, modelling and automated solutions to further digitize and accelerate drug discovery and development with the aim of enhancing health outcomes and the patient experience.
Flexibility
We aim to create a trusting, flexible workplace culture which encourages employees to achieve work life harmony, attracts talent and enables everyone to be their best working self. Let's start the conversation!
Equal Employment Opportunity
We believe that a diverse and inclusive workforce is crucial to building a successful business. As an employer, Pfizer is committed to celebrating this, in all its forms - allowing for us to be as diverse as the patients and communities we serve. Together, we continue to build a culture that encourages, supports and empowers our employees.
Disability Inclusion
Our mission is unleashing the power of all our people and we are proud to be a disability inclusive employer, ensuring equal employment opportunities for all candidates. We encourage you to put your best self forward with the knowledge and trust that we will make any reasonable adjustments to support your application and future career. Your journey with Pfizer starts here!
Pfizer endeavors to make www.pfizer.com/careers accessible to all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process and/or interviewing, please email [email protected]. This is to be used solely for accommodation requests with respect to the accessibility of our website, online application process and/or interviewing. Requests for any other reason will not be returned.
To learn more about acceptable and prohibited uses of AI during the recruitment process, please review our candidate AI-use guidelines available on Pfizer Careers .
Information & Business Tech
#BI-Hybrid

Skills Required

  • Bachelor's degree in Information Security, Computer Science, Engineering, or a related field, or equivalent practical experience
  • 4+ years of cybersecurity experience with significant focus on offensive security, penetration testing, red teaming, or adversary simulation
  • Strong knowledge of red team and adversary emulation methodologies aligned with MITRE ATT&CK
  • Strong knowledge of application, cloud, network, and identity penetration testing
  • Strong knowledge of social engineering and phishing simulations
  • Strong knowledge of offensive security tools and frameworks
  • Understanding of modern enterprise cloud, SaaS, and hybrid environments
  • Experience documenting, validating, and communicating offensive security findings to technical and non-technical stakeholders
  • Ability to manage priorities, make risk-based decisions, and work in a fast-paced, highly regulated environment
  • Experience in pharmaceutical, biotech, life sciences, or similarly regulated industries
  • Experience with cloud-native red teaming across AWS, Azure, or GCP
  • Experience with identity-centric attack paths
  • Familiarity with detection engineering, SIEM/SOAR, and threat intelligence workflows
  • Professional certification such as OSCP, OSEP, CRTO, CISSP, GIAC, or similar
  • Strong communication skills for articulating technical risk, attack feasibility, and business impact

What the Team is Saying

Daniel
Anna
Esteban
Pfizer

Pfizer Compensation & Benefits Highlights

  • Healthcare Strength — Health coverage is described as comprehensive, spanning medical, dental, vision, and robust mental‑health benefits, with eligible Pfizer medications available at no cost in U.S. plans. Family‑building support and transgender‑inclusive care are explicitly included, alongside wellbeing resources such as a reimbursement wallet and telehealth options.
  • Retirement Support — Retirement programs feature a 401(k) with company matching plus an additional Retirement Savings Contribution, complemented by company‑subsidized life, short‑term disability, and long‑term disability insurance. Materials also reference subsidized retiree medical coverage for eligible groups.
  • Leave & Time Off Breadth — Paid vacation, holidays, personal days, and paid parental and caregiver leave are consistently highlighted in current U.S. summaries and job postings. Options like buying extra vacation days and transition‑back support strengthen the time‑off offering.

Pfizer Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: New York, NY
121,990 Employees
Year Founded: 1848

What We Do

Our purpose ensures that patients remain at the center of all we do. We live our purpose by sourcing the best science in the world; partnering with others in the healthcare system to improve access to our medicines; using digital technologies to enhance our drug discovery and development, as well as patient outcomes; and leading the conversation to advocate for pro-innovation/pro-patient policies.

Why Work With Us

We are the inventors, the problem solvers, the big thinkers — those who surmount any hurdle to deliver breakthrough medicines to the people who are counting on them the most.

Gallery

Gallery
Gallery
Gallery
Gallery
Gallery

Pfizer Offices

Hybrid Workspace

Employees engage in a combination of remote and on-site work.

Typical time on-site: 2.5 days a week
Company Office Image
HQHudson Yards
Provincia de Buenos Aires
Andover, MA
Athens, GR
Chennai, IN
Collegeville, PA
Durham, NC
Groton, CT
Madison, NJ
Madrid, ES
Mumbai, Maharashtra
Rochester, MI
San Diego, CA
Seattle, WA
Company Office Image
Tampa, FL
Center for Digital Innovation
Learn more

Similar Jobs

Pfizer Logo Pfizer

Senior Associate, Offensive Security

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
Hybrid
Chortiatis, GRC
121990 Employees

Pfizer Logo Pfizer

Associate Payroll EMEA, Italian Speaker (9 months fixed term)

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
Hybrid
Chortiatis, GRC
121990 Employees

Pfizer Logo Pfizer

Global O2C Collections Analyst & Dispute Mgt - French language (12 months fixed term)

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
Hybrid
Chortiatis, GRC
121990 Employees

Pfizer Logo Pfizer

Sustainability Senior Manager

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
Remote or Hybrid
30 Locations
121990 Employees
112K-207K Annually

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account