Sr. Manager, Information Protection

Reposted Yesterday
Be an Early Applicant
Chortiatis, GRC
Hybrid
Senior level
Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
We’re in relentless pursuit of breakthroughs that change patients’ lives.
The Role
The Senior Manager, Information Protection leads the Cyber GRC data protection program, ensuring compliance with global privacy regulations and risk management across Pfizer's operations. Responsibilities include defining policies, overseeing governance, conducting control assurance, and collaborating with stakeholders to integrate information protection requirements. This role also involves mentoring a global team and reporting on risk metrics.
Summary Generated by Built In
ROLE SUMMARY
Our Global Cybersecurity Governance, Risk, and Compliance team provides comprehensive blueprints for cybersecurity excellence by embedding governance, risk management, and compliance into every layer. The team is responsible for ensuring risk-based decision-making is used and that security, privacy, and regulatory compliance is integrated seamlessly with Pfizer's organization.
We are seeking an experienced Senior Manager, Data Protection to serve in a strategic leadership role within the Cyber GRC organization, responsible for establishing, governing, and operationalizing Pfizer's enterprise data protection program across a global footprint spanning the United States, Europe, and Asia. This role ensures that sensitive data is identified, classified, protected, and governed in alignment with regional and global privacy regulations, internal security policies, and enterprise risk management expectations.
The Senior Manager, Data Protection provides global oversight of data protection governance, policy, risk assessment, and control assurance across structured and unstructured data environments. Working across regions and time zones, this role partners closely with Privacy, Legal, Compliance, Digital, Infrastructure, and Business stakeholders to embed consistent information protection requirements into technology platforms, business processes, and enterprise risk decisions. Through scalable governance, measurable controls, and clear accountability, this role enables risk‑based decisions and protects sensitive, regulated data worldwide.
ROLE RESPONSIBILITIES
  • Define, maintain, and evolve Pfizer's enterprise information protection policies, standards, control objectives, and oversight mechanisms, ensuring consistent application across the United States, Europe, and Asia.
  • Lead the Cyber GRC information protection program across regions, ensuring risks related to sensitive, regulated, and critical data are identified, assessed, prioritized, and tracked in alignment with regional and global requirements.
  • Establish and oversee information protection control requirements aligned to global and regional privacy regulations (e.g., GDPR, and applicable APAC regulations), internal security policies, and enterprise risk tolerance.
  • Partner with Privacy, Legal, Compliance, Digital, Infrastructure, and business teams across the US, Europe, and Asia to embed information protection requirements into technology platforms, solutions, and business processes.
  • Drive information protection control assurance activities globally, including control design reviews, operating effectiveness assessments, issue management, and remediation tracking.
  • Define and report global and regional information protection risk metrics, enabling leadership visibility into enterprise-wide risk posture.
  • Support regulatory inquiries, audits, and assessments across jurisdictions by providing information protection governance evidence and risk posture insights.
  • Lead, coach, and mentor a globally distributed team of information protection and GRC professionals, fostering a strong culture of collaboration and continuous improvement.
  • Influence enterprise initiatives by providing risk-based assessments of new technologies, digital transformation, and data-driven business models across regions.

BASIC QUALIFICATIONS
  • Bachelor's degree in information security, Information Technology, Cybersecurity, or related field.
  • 7+ years of experience in information security, risk, compliance, information protection, or related disciplines.
  • Demonstrated experience operating within regulated industries, with an understanding of regulatory expectations, audit requirements, and compliance obligations related to information protection, security controls, and risk management.
  • Practical knowledge of information protection concepts and controls, including data classification/labeling, access governance principles, secure data handling, audit evidence, and incident coordination.
  • Deep understanding of global data protection/privacy regulations (e.g., CCPA, GDPR, NIS2, etc.) and their application within large enterprises.
  • Excellent verbal and written communication skills, with the ability to clearly articulate complex technical and risk‑based concepts to a wide range of audiences.
  • Strong analytical, strategic thinking, and problem‑solving skills, with demonstrated ability to assess risk posture.
  • Proficiency with GRC platforms and data governance or risk reporting tools (e.g., Archer, Purview, or similar).

PREFERRED QUALIFICATIONS
  • Professional certifications in privacy, data protection, or information security, (e.g., Certified Information Privacy Manager (CIPM), Certified Information Privacy Professional (CIPP/E or equivalent), or an academic equivalent).
  • Excellent strategic thinking.
  • Deeply analytical and credible.
  • Fact-based decision-making.
  • Deep understanding of data security objectives, governance models, and risk management considerations for complex enterprises operating in regulated industries.
  • Experience supporting enterprise data classification, data lifecycle, or information governance programs.
  • Strong executive communication and presentation skills.
  • Experience leading globally distributed teams or matrixed resources.

NON-STANDARD WORK SCHEDULE, TRAVEL OR ENVIRONMENT REQUIREMENTS
  • Travel as required by the business (less than 5% domestic and/or international)

Please apply by sending your CV in English.
Work Location Assignment: Hybrid
Purpose
Breakthroughs that change patients' lives... At Pfizer we are a patient centric company, guided by our four values: courage, joy, equity and excellence. Our breakthrough culture lends itself to our dedication to transforming millions of lives.
Digital Transformation Strategy
One bold way we are achieving our purpose is through our company wide digital transformation strategy. We are leading the way in adopting new data, modelling and automated solutions to further digitize and accelerate drug discovery and development with the aim of enhancing health outcomes and the patient experience.
Flexibility
We aim to create a trusting, flexible workplace culture which encourages employees to achieve work life harmony, attracts talent and enables everyone to be their best working self. Let's start the conversation!
Equal Employment Opportunity
We believe that a diverse and inclusive workforce is crucial to building a successful business. As an employer, Pfizer is committed to celebrating this, in all its forms - allowing for us to be as diverse as the patients and communities we serve. Together, we continue to build a culture that encourages, supports and empowers our employees.
Disability Inclusion
Our mission is unleashing the power of all our people and we are proud to be a disability inclusive employer, ensuring equal employment opportunities for all candidates. We encourage you to put your best self forward with the knowledge and trust that we will make any reasonable adjustments to support your application and future career. Your journey with Pfizer starts here!
Information & Business Tech

What the Team is Saying

Daniel
Anna
Esteban
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: New York, NY
121,990 Employees
Year Founded: 1848

What We Do

Our purpose ensures that patients remain at the center of all we do. We live our purpose by sourcing the best science in the world; partnering with others in the healthcare system to improve access to our medicines; using digital technologies to enhance our drug discovery and development, as well as patient outcomes; and leading the conversation to advocate for pro-innovation/pro-patient policies.

Why Work With Us

We are the inventors, the problem solvers, the big thinkers — those who surmount any hurdle to deliver breakthrough medicines to the people who are counting on them the most.

Gallery

Gallery
Gallery
Gallery
Gallery
Gallery

Pfizer Offices

Hybrid Workspace

Employees engage in a combination of remote and on-site work.

Typical time on-site: Not Specified
Company Office Image
HQHudson Yards
Provincia de Buenos Aires
Andover, MA
Athens, GR
Chennai, IN
Collegeville, PA
Cork, IE
Dublin, IE
Durham, NC
Groton, CT
Kildare, IE
Madison, NJ
Madrid, ES
Mumbai, Maharashtra
Rochester, MI
San Diego, CA
Seattle, WA
Company Office Image
Heights Union East
Center for Digital Innovation
Learn more

Similar Jobs

Pfizer Logo Pfizer

Director, AI Engineering--Clinical Development and Operations (CD&O)

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
Hybrid
4 Locations
121990 Employees
177K-294K Annually

Pfizer Logo Pfizer

Pharmacovigilance Risk Management Product Lead, Sr. Manager

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
Hybrid
7 Locations
121990 Employees
355K-355K Annually

Pfizer Logo Pfizer

Senior Cloud Engineer

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
Hybrid
Chortiatis, GRC
121990 Employees

Pfizer Logo Pfizer

Sr. Associate HR Services EMEA (Italian speaker)

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
Hybrid
Chortiatis, GRC
121990 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account