Our Global Cyber Defense team is responsible for safeguarding Pfizer's digital assets and infrastructure through proactive threat detection, response, and risk mitigation across on-premises, cloud, and hybrid environments.
The Lead Analyst, Threat Remediation is responsible for leading the execution of threat remediation activities to ensure cybersecurity threats are effectively prioritized, mitigated, and resolved in a timely and risk‑based manner. This role coordinates remediation efforts across threat detection, incident response, vulnerability management, and technology teams to reduce exposure and strengthen the organization's security posture.
The role partners closely with the SOC, Cloud Services, Infrastructure, Engineering, GRC, Legal, Privacy, and business stakeholders to drive remediation outcomes, track progress, and ensure threats are addressed in alignment with regulatory requirements, internal standards, and business priorities. This role will report to the Sr. Manager, Threat Remediation.
ROLE RESPONSIBILITIES
- Lead the day‑to‑day execution of threat remediation activities to ensure identified cybersecurity threats and exposures are prioritized, tracked, and resolved in a timely and risk‑based manner.
- Coordinate remediation efforts across threat detection, incident response, vulnerability management, and engineering teams to drive consistent and effective outcomes.
- Translate threat and exposure information into clear remediation actions, working with technical owners to define scope, timelines, and risk‑appropriate mitigation plans.
- Track remediation progress, validate completion, and identify recurring issues or systemic control gaps requiring escalation or broader corrective action.
- Partner closely with the SOC, Cloud Services, Infrastructure, Engineering, GRC, Legal, Privacy, and business stakeholders to ensure remediation activities align with regulatory requirements, internal standards, and business priorities.
- Support the investigation and remediation of high‑severity or complex threats, including coordination during active incidents or escalated risk scenarios.
- Maintain accurate remediation reporting, metrics, and status updates for leadership, highlighting risk trends, delays, and improvement opportunities.
- Drive continuous improvement of threat remediation processes, workflows, and handoffs to improve speed, consistency, and risk reduction.
- Escalate material risks, blocked remediation efforts, or cross‑organizational issues to the Senior Manager, Threat Remediation, with clear context and recommendations.
BASIC QUALIFICATIONS
- Applicant must have a Bachelor's degree in Computer Science, Information Security, Engineering, or related technical discipline with at least 4 years of experience in cybersecurity, with hands‑on involvement in remediation, vulnerability management, security engineering, or incident response; OR a master's degree with at least 2 years of experience; OR as associate's degree with 8 years of experience; OR a high school diploma (or equivalent) and 10 years of relevant experience.
- Strong understanding of:
- Threat actor tactics, techniques, and procedures (MITRE ATT&CK)
- Incident response and containment strategies
- Vulnerability management and remediation workflows
- Cloud security (AWS, Azure, GCP)
- Endpoint, network, identity, and application security
- Familiarity with SOC tooling (SIEM, SOAR, EDR/XDR), vulnerability scanners, and ticketing/workflow systems.
- Ability to translate threat and exposure data into clear, actionable remediation plans.
- Strong organizational and communication skills, with the ability to manage competing priorities and escalate risks appropriately.
- Demonstrated experience in an agile work environment possessing qualities such as a collaborative mindset, adaptability to change, and a proactive problem-solving approach.
PREFERRED QUALIFICATIONS
- Working knowledge of GxP, FDA 21 CFR Part 11, EMA, HIPAA, GDPR, and other relevant regulations.
- Exposure to cloud, hybrid, or large‑scale enterprise environments as part of remediation or response activities.
- Experience supporting high‑severity incidents or enterprise‑wide remediation initiatives.
- Familiarity with security frameworks, risk management practices, and regulatory expectations relevant to pharmaceutical or life sciences organizations.
- Professional certifications such as CISSP, CISM, GIAC, or equivalent credentials related to security operations or risk management.
PHYSICAL/MENTAL REQUIREMENTS
- No special physical requirements.
- Applicants should be capable of working through a personal laptop computer or mobile device for extended periods.
NON-STANDARD WORK SCHEDULE, TRAVEL OR ENVIRONMENT REQUIREMENTS
- Travel as required by the business (less than 5% domestic and/or international)
- Work Location Assignment: Must be able to work in assigned Pfizer office 2-3 days per week, or as needed by the business
- This role is NOT remote
Other Job Details:
- Last Date to Apply for Job: August 24, 2026
- Work Location Assignment: Hybrid. Must be able to work from assigned Pfizer office 2-3 days per week, or as needed by the business
Relocation assistance may be available based on business needs and/or eligibility.
Candidates must be authorized to be employed in the U.S. by any employer.
U.S. work visa sponsorship (such as TN, O-1, H-1B, etc.) is not available for this role now or in the future.
Sunshine Act
Pfizer reports payments and other transfers of value to health care providers as required by federal and state transparency laws and implementing regulations. These laws and regulations require Pfizer to provide government agencies with information such as a health care provider's name, address and the type of payments or other value received, generally for public disclosure. Subject to further legal review and statutory or regulatory clarification, which Pfizer intends to pursue, reimbursement of recruiting expenses for licensed physicians may constitute a reportable transfer of value under the federal transparency law commonly known as the Sunshine Act. Therefore, if you are a licensed physician who incurs recruiting expenses as a result of interviewing with Pfizer that we pay or reimburse, your name, address and the amount of payments made currently will be reported to the government. If you have questions regarding this matter, please do not hesitate to contact your Talent Acquisition representative.
EEO & Employment Eligibility
Pfizer is committed to equal opportunity in the terms and conditions of employment for all employees and job applicants without regard to race, color, religion, sex, sexual orientation, age, gender identity or gender expression, national origin, disability or veteran status. Pfizer also complies with all applicable national, state and local laws governing nondiscrimination in employment as well as work authorization and employment eligibility verification requirements of the Immigration and Nationality Act and IRCA. Pfizer is an E-Verify employer. This position requires permanent work authorization in the United States.
Pfizer endeavors to make www.pfizer.com/careers accessible to all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process and/or interviewing, please email [email protected] . This is to be used solely for accommodation requests with respect to the accessibility of our website, online application process and/or interviewing. Requests for any other reason will not be returned.
To learn more about acceptable and prohibited uses of AI during the recruitment process, please review our candidate AI-use guidelines available on Pfizer Careers .
Information & Business Tech
#BI-Hybrid
Skills Required
- Bachelor's degree in Computer Science, Information Security, Engineering, or related technical discipline with at least 4 years of cybersecurity experience; OR master's degree with at least 2 years; OR associate's degree with 8 years; OR high school diploma and 10 years of relevant experience.
- Hands-on experience in remediation, vulnerability management, security engineering, or incident response.
- Strong understanding of threat actor tactics, techniques, and procedures (MITRE ATT&CK).
- Experience with incident response and containment strategies.
- Knowledge of vulnerability management and remediation workflows.
- Cloud security experience (AWS, Azure, GCP).
- Knowledge of endpoint, network, identity, and application security.
- Familiarity with SOC tooling (SIEM, SOAR, EDR/XDR), vulnerability scanners, and ticketing/workflow systems.
- Ability to translate threat and exposure data into clear, actionable remediation plans.
- Strong organizational and communication skills; ability to manage priorities and escalate risks appropriately.
- Demonstrated experience working in an agile environment with collaborative and adaptable mindset.
- Must be authorized to be employed in the U.S. by any employer; permanent U.S. work authorization required.
- Ability to work in assigned Pfizer office 2-3 days per week (hybrid); role is NOT remote.
- Willingness to travel as required (less than 5%).
- Working knowledge of GxP, FDA 21 CFR Part 11, EMA, HIPAA, GDPR, and other relevant regulations.
- Exposure to cloud, hybrid, or large-scale enterprise environments as part of remediation or response activities.
- Experience supporting high-severity incidents or enterprise-wide remediation initiatives.
- Familiarity with security frameworks, risk management practices, and regulatory expectations relevant to pharmaceutical or life sciences organizations.
- Professional certifications such as CISSP, CISM, GIAC, or equivalent.
Pfizer Compensation & Benefits Highlights
-
Healthcare Strength — Official materials describe comprehensive medical, dental, vision, and mental-health support, plus fertility/family‑building and transgender‑inclusive coverage; eligible Pfizer medications are noted as available at no cost in U.S. plans. Wellness resources such as telehealth and preventative programs are also emphasized.
-
Retirement Support — Company documents highlight a 401(k) with matching contributions plus an additional Retirement Savings Contribution beyond the match. Financial planning support and company‑paid life and disability insurance further bolster long‑term security.
-
Leave & Time Off Breadth — Corporate pages and job postings describe paid vacation and holidays, caregiver leave, and paid parental leave for both parents. Materials also note that details can vary by role and location.
Pfizer Insights
What We Do
Our purpose ensures that patients remain at the center of all we do. We live our purpose by sourcing the best science in the world; partnering with others in the healthcare system to improve access to our medicines; using digital technologies to enhance our drug discovery and development, as well as patient outcomes; and leading the conversation to advocate for pro-innovation/pro-patient policies.
Why Work With Us
We are the inventors, the problem solvers, the big thinkers — those who surmount any hurdle to deliver breakthrough medicines to the people who are counting on them the most.
Gallery
Pfizer Offices
Hybrid Workspace
Employees engage in a combination of remote and on-site work.









