Senior Associate, Offensive Security

Posted 15 Days Ago
Be an Early Applicant
Chortiatis, GRC
Hybrid
Senior level
Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
We’re in relentless pursuit of breakthroughs that change patients’ lives.
The Role
Lead and execute offensive security activities including penetration tests, red/purple team and adversary simulations across on‑prem, cloud, and hybrid environments. Validate and document findings with PoC evidence, recommend remediations, map techniques to attacker behaviors, and collaborate with detection, engineering, and risk teams to improve defenses and tooling automation.
Summary Generated by Built In
ROLE SUMMARY
Our Global Cyber Defense team is responsible for safeguarding Pfizer's digital assets and infrastructure through proactive threat detection, response, and risk mitigation across on-premises, cloud, and hybrid environments.
The Senior Associate, Offensive Security supports offensive security activities that proactively identify, validate, and help prioritize security weaknesses across the digital environment. This role contributes to penetration testing, adversary simulation, and purple team exercises that continuously assess the organization's exposure to real‑world threats. Operating within a highly regulated pharmaceutical environment, the Senior Associate partners closely with detection, remediation, engineering, and risk teams to ensure findings are clearly documented, actionable, and translated into measurable security improvements. This role will report to the Sr. Manager, Offensive Security.
ROLE RESPONSIBILITIES
  • Conduct offensive security testing activities including penetration tests and adversary simulation exercises across on‑premises, cloud, and hybrid environments.
  • Support red team and purple team engagements by executing test plans, collecting evidence, and helping evaluate defensive control effectiveness.
  • Identify, validate, and document security weaknesses, including technical details, proof of concept evidence, and clear remediation recommendations.
  • Assist with translating offensive findings into actionable improvement items for detection, engineering, and remediation teams.
  • Contribute to threat‑informed testing by mapping observed techniques to common attacker behaviors and helping highlight realistic attack paths.
  • Maintain high quality reporting standards and ensure deliverables are accurate, complete, and aligned to ethical testing expectations and internal requirements.
  • Support continuous improvement efforts for offensive security tooling, automation, repeatable test methods, and playbooks.
  • Collaborate with cross‑functional partners (e.g., detection, incident response, vulnerability management, infrastructure, cloud) to coordinate testing logistics and minimize business disruption.
  • Escalate complex technical issues, high‑risk findings, or unexpected conditions.

BASIC QUALIFICATIONS
  • Bachelor's degree in Information Security, Computer Science, Engineering, or a related field, or equivalent practical experience.
  • 2+ years of experience in cybersecurity with hands‑on focus in offensive security, penetration testing, vulnerability research, or security engineering.
  • Practical experience executing penetration tests or security assessments, including reconnaissance, exploitation validation, and reporting.
  • Strong understanding of common attack techniques and enterprise security concepts across identity, endpoints, networks, and cloud services.
  • Ability to clearly document technical findings and communicate risk and remediation guidance to technical stakeholders.
  • Working knowledge of at least one scripting/programming language commonly used for security work (e.g., Python, PowerShell, Bash).
  • Strong collaboration skills and ability to operate in a process‑driven, highly regulated environment.

PREFERRED QUALIFICATIONS
  • Strong hands‑on knowledge of:
    • Red team and adversary emulation methodologies (MITRE ATT&CK-aligned)
    • Application, cloud, network, and identity penetration testing
    • Social engineering and phishing simulations (where appropriate)
    • Tooling and frameworks commonly used in offensive security
  • Experience in pharmaceutical, biotech, life sciences, or similarly regulated industries.
  • Demonstrated capability supporting offensive security testing in cloud or hybrid environments.
  • Exposure to partnering with detection engineering / SOC teams to improve detections based on offensive findings.
  • Experience working in regulated industries (e.g., healthcare, life sciences, pharmaceuticals) or environments with high compliance expectations.
  • Relevant certifications (e.g., CISSP, OSCP, CRTO, GPEN/GXPN), or similar offensive security credentials.
  • Demonstrated interest in improving repeatability through tooling, automation, and standardized playbooks.

Please apply by sending your CV in English.
Work Location Assignment: Hybrid
Purpose
Breakthroughs that change patients' lives... At Pfizer we are a patient centric company, guided by our four values: courage, joy, equity and excellence. Our breakthrough culture lends itself to our dedication to transforming millions of lives.
Digital Transformation Strategy
One bold way we are achieving our purpose is through our company wide digital transformation strategy. We are leading the way in adopting new data, modelling and automated solutions to further digitize and accelerate drug discovery and development with the aim of enhancing health outcomes and the patient experience.
Flexibility
We aim to create a trusting, flexible workplace culture which encourages employees to achieve work life harmony, attracts talent and enables everyone to be their best working self. Let's start the conversation!
Equal Employment Opportunity
We believe that a diverse and inclusive workforce is crucial to building a successful business. As an employer, Pfizer is committed to celebrating this, in all its forms - allowing for us to be as diverse as the patients and communities we serve. Together, we continue to build a culture that encourages, supports and empowers our employees.
Disability Inclusion
Our mission is unleashing the power of all our people and we are proud to be a disability inclusive employer, ensuring equal employment opportunities for all candidates. We encourage you to put your best self forward with the knowledge and trust that we will make any reasonable adjustments to support your application and future career. Your journey with Pfizer starts here!
Pfizer endeavors to make www.pfizer.com/careers accessible to all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process and/or interviewing, please email [email protected]. This is to be used solely for accommodation requests with respect to the accessibility of our website, online application process and/or interviewing. Requests for any other reason will not be returned.
To learn more about acceptable and prohibited uses of AI during the recruitment process, please review our candidate AI-use guidelines available on Pfizer Careers .
Information & Business Tech
#BI-Hybrid

Skills Required

  • Bachelor's degree in Information Security, Computer Science, Engineering, or related field, or equivalent practical experience
  • 2+ years of experience in cybersecurity with hands‑on focus in offensive security, penetration testing, vulnerability research, or security engineering
  • Practical experience executing penetration tests or security assessments, including reconnaissance, exploitation validation, and reporting
  • Strong understanding of common attack techniques and enterprise security concepts across identity, endpoints, networks, and cloud services
  • Ability to clearly document technical findings and communicate risk and remediation guidance to technical stakeholders
  • Working knowledge of at least one scripting/programming language commonly used for security work (e.g., Python, PowerShell, Bash)
  • Strong collaboration skills and ability to operate in a process‑driven, highly regulated environment
  • Red team and adversary emulation methodologies (MITRE ATT&CK-aligned)
  • Application, cloud, network, and identity penetration testing experience
  • Social engineering and phishing simulation experience
  • Experience in pharmaceutical, biotech, life sciences, or similarly regulated industries
  • Exposure to partnering with detection engineering / SOC teams to improve detections based on offensive findings
  • Relevant certifications (e.g., CISSP, OSCP, CRTO, GPEN/GXPN) or similar offensive security credentials
  • Interest in improving repeatability through tooling, automation, and standardized playbooks

What the Team is Saying

Daniel
Anna
Esteban
Pfizer

Pfizer Compensation & Benefits Highlights

  • Healthcare Strength Official materials describe comprehensive medical, dental, vision, and mental-health support, plus fertility/family‑building and transgender‑inclusive coverage; eligible Pfizer medications are noted as available at no cost in U.S. plans. Wellness resources such as telehealth and preventative programs are also emphasized.
  • Retirement Support Company documents highlight a 401(k) with matching contributions plus an additional Retirement Savings Contribution beyond the match. Financial planning support and company‑paid life and disability insurance further bolster long‑term security.
  • Leave & Time Off Breadth Corporate pages and job postings describe paid vacation and holidays, caregiver leave, and paid parental leave for both parents. Materials also note that details can vary by role and location.

Pfizer Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: New York, NY
121,990 Employees
Year Founded: 1848

What We Do

Our purpose ensures that patients remain at the center of all we do. We live our purpose by sourcing the best science in the world; partnering with others in the healthcare system to improve access to our medicines; using digital technologies to enhance our drug discovery and development, as well as patient outcomes; and leading the conversation to advocate for pro-innovation/pro-patient policies.

Why Work With Us

We are the inventors, the problem solvers, the big thinkers — those who surmount any hurdle to deliver breakthrough medicines to the people who are counting on them the most.

Gallery

Gallery
Gallery
Gallery
Gallery
Gallery

Pfizer Offices

Hybrid Workspace

Employees engage in a combination of remote and on-site work.

Typical time on-site: 2.5 days a week
Company Office Image
HQHudson Yards
Provincia de Buenos Aires
Andover, MA
Athens, GR
Chennai, IN
Collegeville, PA
Durham, NC
Groton, CT
Madison, NJ
Madrid, ES
Mumbai, Maharashtra
Rochester, MI
San Diego, CA
Seattle, WA
Company Office Image
Tampa, FL
Center for Digital Innovation
Learn more

Similar Jobs

Pfizer Logo Pfizer

Senior Manager, CX Digital Learning Experience & Gamification Lead

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
Hybrid
6 Locations
121990 Employees
112K-207K Annually

Pfizer Logo Pfizer

Senior Director, Targets and Mechanisms Solutions

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
Hybrid
8 Locations
121990 Employees
231K-385K Annually

Pfizer Logo Pfizer

Designer

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
Hybrid
6 Locations
121990 Employees
112K-207K Annually

Pfizer Logo Pfizer

Quality Assurance Manager

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
Remote or Hybrid
28 Locations
121990 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account