Senior Manager, Information Protection Engineering

Posted 2 Days Ago
Be an Early Applicant
Chortiatis, GRC
Hybrid
Senior level
Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
We’re in relentless pursuit of breakthroughs that change patients’ lives.
The Role
Leads enterprise information protection strategy, architecture, controls, and engineering across endpoints, cloud, applications, and collaboration tools. Oversees DLP, data discovery, classification, encryption, key management, and AI protection capabilities. Partners with security, privacy, legal, compliance, infrastructure, and R&D teams to embed security by design, meet regulatory requirements, support incident response, report risk metrics, and manage an engineering team.
Summary Generated by Built In
ROLE SUMMARY
Our Global Cybersecurity Governance, Risk, and Compliance team provides comprehensive blueprints for cybersecurity excellence by embedding governance, risk management, and compliance into every layer. The team is responsible for ensuring risk-based decision-making is used and that security, privacy, and regulatory compliance is integrated seamlessly with Pfizer's organization.
We are seeking a Senior Manager, Information Protection Engineering, to lead and evolve our information protection capabilities within the Cyber GRC organization. This role is critical to safeguarding sensitive scientific, clinical, patient, and business information across Pfizer's global enterprise.
The role will lead a team of highly skilled engineers and work closely with CISO organization, Privacy, Legal, Compliance, R&D, Infrastructure, and Cloud Services partners to design, implement, and operate scalable information protection solutions aligned to regulatory requirements and business priorities.
ROLE RESPONSIBILITIES
  • Lead the definition of enterprise information protection technical strategy, reference architectures, and control frameworks, including DLP, data discovery and classification, and encryption requirements.
  • Establish and maintain information protection technical standards, guardrails, and design patterns that guide implementation across endpoints, cloud platforms, applications, and collaboration tools.
  • Define policy and control requirements for encryption, key management, and secrets management in partnership with Cloud, Infrastructure, and Identity teams, ensuring alignment with information protection objectives.
  • Lead and provide hands-on oversight of the implementation, configuration, and lifecycle governance of information protection technologies such as DLP, data classification, data discovery solutions, and AI information protection.
  • Provide architectural guidance and design review for information protection integrations within platforms, applications, and business solutions.
  • Influence tooling decisions through risk‑based requirements, rather than operational ownership of underlying cloud or infrastructure services.
  • Embed security‑by‑design principles for information protection into the application and platform lifecycle, including requirements for data handling, classification, retention, and policy enforcement.
  • Partner with Digital, Cloud Services, Infrastructure, and IT teams to ensure information protection controls are designed into platforms, not bolted on post‑deployment.
  • Partner with Security Operations and Incident Response teams to support detection, investigation, and response to information protection incidents and policy violations.
  • Ensure information protection capabilities align with enterprise risk management frameworks, internal security standards, and audit expectations.
  • Collaborate with Privacy, Legal, Compliance, and Cyber GRC teams to ensure information protection controls support global regulatory and industry requirements (e.g., GDPR, HIPAA, SOX, GxP).
  • Translate NIST, regulatory, privacy requirements, and risk requirements into clear, implementable information protection technical controls and guidance.
  • Define and report metrics that demonstrate information protection effectiveness, risk trends, and maturity improvement to Cyber GRC and senior leadership.
  • Lead, mentor, and develop a team of engineers and analysts focused on information protection engineering and architectural enablement, establishing clear role boundaries between control ownership and platform operational ownership to enable scale and clarity.

BASIC QUALIFICATIONS
  • Bachelor's degree in Information Security, Computer Science, Engineering, or a related field, or equivalent experience.
  • 6+ years of experience in cybersecurity or information protection-related roles, with responsibility for enterprise‑scale information protection controls.
  • Demonstrated experience designing, implementing, and operating data loss prevention (DLP) controls across endpoints, email, cloud platforms, and collaboration tools.
  • Strong technical experience with data classification, labelling, and policy‑based enforcement across structured and unstructured data.
  • Hands‑on experience implementing and managing encryption technologies (data at rest and in transit), key management, and secure data handling controls.
  • Experience integrating information protection controls into cloud platforms, SaaS applications, and enterprise collaboration environments.
  • Experience operating security controls in large, complex, and regulated enterprise environments.
  • Proven ability to collaborate across engineering, digital, and operations teams to deliver practical and effective information protection outcomes.
  • Demonstrated experience in an agile work environment possessing qualities such as a collaborative mindset, adaptability to change, and a proactive problem-solving approach.

PREFERRED QUALIFICATIONS
  • Familiarity with cybersecurity frameworks, regulatory requirements, and risk management practices relevant to pharmaceutical or life sciences organizations.
  • Professional certifications such as CDPSE, CIPT, CIPP/E, CISSP, CISM.
  • Prior leadership experience managing or mentoring information protection engineers or security engineering teams.
  • Strong understanding of data lifecycle management, including data creation, access, sharing, retention, and secure disposal.
  • Strong analytical and communication skills, with the ability to clearly articulate information protection risks and design decisions to senior stakeholders.

WORK SCHEDULE, TRAVEL OR ENVIRONMENT REQUIREMENTS
  • Travel as required by the business (less than 20% domestic and/or international)
  • Work Location Assignment: Must be able to work in assigned Pfizer office 2-3 days per week, or as needed by the business

Please apply by sending your CV in English.
Work Location Assignment: Hybrid
Purpose
Breakthroughs that change patients' lives... At Pfizer we are a patient centric company, guided by our four values: courage, joy, equity and excellence. Our breakthrough culture lends itself to our dedication to transforming millions of lives.
Digital Transformation Strategy
One bold way we are achieving our purpose is through our company wide digital transformation strategy. We are leading the way in adopting new data, modelling and automated solutions to further digitize and accelerate drug discovery and development with the aim of enhancing health outcomes and the patient experience.
Flexibility
We aim to create a trusting, flexible workplace culture which encourages employees to achieve work life harmony, attracts talent and enables everyone to be their best working self. Let's start the conversation!
Equal Employment Opportunity
We believe that a diverse and inclusive workforce is crucial to building a successful business. As an employer, Pfizer is committed to celebrating this, in all its forms - allowing for us to be as diverse as the patients and communities we serve. Together, we continue to build a culture that encourages, supports and empowers our employees.
Disability Inclusion
Our mission is unleashing the power of all our people and we are proud to be a disability inclusive employer, ensuring equal employment opportunities for all candidates. We encourage you to put your best self forward with the knowledge and trust that we will make any reasonable adjustments to support your application and future career. Your journey with Pfizer starts here!
Pfizer endeavors to make www.pfizer.com/careers accessible to all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process and/or interviewing, please email [email protected]. This is to be used solely for accommodation requests with respect to the accessibility of our website, online application process and/or interviewing. Requests for any other reason will not be returned.
To learn more about acceptable and prohibited uses of AI during the recruitment process, please review our candidate AI-use guidelines available on Pfizer Careers .
Information & Business Tech
#BI-Hybrid

Skills Required

  • Bachelor's degree in Information Security, Computer Science, Engineering, or a related field, or equivalent experience
  • 6+ years of experience in cybersecurity or information protection-related roles with responsibility for enterprise-scale information protection controls
  • Experience designing, implementing, and operating DLP controls across endpoints, email, cloud platforms, and collaboration tools
  • Technical experience with data classification, labeling, and policy-based enforcement across structured and unstructured data
  • Hands-on experience implementing and managing encryption technologies, key management, and secure data handling controls
  • Experience integrating information protection controls into cloud platforms, SaaS applications, and enterprise collaboration environments
  • Experience operating security controls in large, complex, and regulated enterprise environments
  • Ability to collaborate across engineering, digital, and operations teams to deliver information protection outcomes
  • Experience in an agile work environment with collaboration, adaptability, and proactive problem-solving
  • Familiarity with cybersecurity frameworks, regulatory requirements, and risk management practices relevant to pharmaceutical or life sciences organizations
  • Professional certifications such as CDPSE, CIPT, CIPP/E, CISSP, or CISM
  • Prior leadership experience managing or mentoring information protection engineers or security engineering teams
  • Strong understanding of data lifecycle management, including creation, access, sharing, retention, and secure disposal
  • Strong analytical and communication skills for articulating information protection risks and design decisions to senior stakeholders

What the Team is Saying

Daniel
Anna
Esteban
Pfizer
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: New York, NY
121,990 Employees
Year Founded: 1848

What We Do

Our purpose ensures that patients remain at the center of all we do. We live our purpose by sourcing the best science in the world; partnering with others in the healthcare system to improve access to our medicines; using digital technologies to enhance our drug discovery and development, as well as patient outcomes; and leading the conversation to advocate for pro-innovation/pro-patient policies.

Why Work With Us

We are the inventors, the problem solvers, the big thinkers — those who surmount any hurdle to deliver breakthrough medicines to the people who are counting on them the most.

Gallery

Gallery
Gallery
Gallery
Gallery
Gallery

Pfizer Offices

Hybrid Workspace

Employees engage in a combination of remote and on-site work.

Typical time on-site: 2.5 days a week
Company Office Image
HQHudson Yards
Provincia de Buenos Aires
Andover, MA
Athens, GR
Chennai, IN
Collegeville, PA
Durham, NC
Groton, CT
Madison, NJ
Madrid, ES
Mumbai, Maharashtra
Rochester, MI
San Diego, CA
Seattle, WA
Company Office Image
Tampa, FL
Center for Digital Innovation
Learn more

Similar Jobs

Pfizer Logo Pfizer

Quality Assurance Manager

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
Remote or Hybrid
28 Locations
121990 Employees

Pfizer Logo Pfizer

Senior Associate, Threat Hunt & Detection

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
Hybrid
Chortiatis, GRC
121990 Employees

Pfizer Logo Pfizer

Senior Manager, IT Service Management (ITSM) Product Lead

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
In-Office or Remote
5 Locations
121990 Employees
125K-232K Annually

Pfizer Logo Pfizer

Senior Director, Applied AI - US Commercial

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
In-Office or Remote
28 Locations
121990 Employees
215K-358K Annually

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account