ForgeApply · Job listing
Director, Third-Party Risk Management and Technical Information Security Lead
Pfizer
Tailor your resume to this posting in about a minute.
ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for Pfizer's site. Free trial, no card required.
About this role
Use Your Power for Purpose Our Global Governance, Risk, and Compliance (GRC) team provides comprehensive blueprints for cybersecurity excellence by embedding governance, risk management, and compliance into every layer. The team is responsible for ensuring risk-based decision-making is used and that security, privacy, and regulatory compliance is integrated seamlessly with Pfizer’s organization. We are seeking an experienced Director, Third Party Risk Management (TPRM) and Technical Information Security Lead (TISL). T his is a leadership role combining enterprise‑level ownership of the Third‑Party Risk Management program with business‑facing technical security risk leadership across critical initiatives and platforms. This role will set the overall third-party security strategy, standards, and operating models for managing cyber risk across a complex ecosystem of vendors, partners, and internal technologies, while acting as a trusted security advisor to executive and senior business leaders. This role is pivotal in balancing risk, regulatory compliance, speed, and innovation in a highly regulated environment. What You Will Achieve
TPRM Program Strategy & Ownership
• Own the enterprise Third Party Risk Management (TPRM) security strategy, program, and operating model. • Align TPRM with enterprise cyber risk appetite, business priorities, and pharmaceutical regulatory expectations. • Establish scalable approaches for risk tiering, assessment depth, reassessment cadence, continuous monitoring, and exception governance. • Align the TPRM program with Pfizer’s enterprise cyber risk appetite and business strategy.
Third‑Party Cyber Risk Oversight & Governance
• Provide executive‑level oversight and approval for high‑risk and critical vendor risk assessments. • Lead governance for risk treatment decisions, including remediation prioritization, compensating controls, and formal risk acceptances. • Escalate material vendor risks to enterprise risk committees and executive leadership, enabling informed decision‑making.
Technical Information Security Lead
• Serve as a senior Technical Information Security Lead for high‑impact business initiatives, platforms, and transformations. • Serve as the trusted cybersecurity risk advisor to executive-level business and technology leaders. • Translate complex technical risks into executive‑level insights and decision‑ready recommendations.
Leadership & Influence
• Serve as an executive GRC partner to Procurement, Legal, Privacy, Quality, Security, Internal Audit, and Business Leadership. • Influence contract standards and onboarding requirements to embed security, privacy, and resilience controls into third‑party agreements. • Represent GRC in executive forums, governance bodies, and cross‑functional steering committees. • Set strategic priorities and outcomes; delegate execution while maintaining accountability. • Drive talent development, succession planning, and capability maturity across the function.
Here Is What You Need (Minimum Requirements) • Bachelor’s degree with at least 8+ years of experience; OR a Master’s degree with more than 7+ years of experience; OR a Ph.D. with 5+ years of experience. • 8+ years of experience in cybersecurity, cyber risk, GRC, TPRM, security architecture, IT risk, or audit, ideally within the pharmaceutical or other highly regulated industries. • Experience leading and developing teams, including direct people management responsibility for technical and cybersecurity professionals.
• Demonstrated experience leading complex risk programs involving multiple stakeholders and competing priorities. • Strong strategic thinking, analytical, and problem‑solving capabilities with the ability to interpret risk data and drive informed decision‑making. • Exceptional communication and interpersonal skills, with the ability to collaborate effectively across functions. • Strong organizational and leadership skills, including the ability to guide teams, manage change, and drive continuous program improvement. • Demonstrated experience in an agile work environment possessing qualities such as a collaborative mindset, adaptability to change, and a proactive problem-solving approach.
Bonus Points If You Have (Preferred Requirements) • Advanced degree (MBA, MS in Risk Management, Information Security, or related discipline). • Experience developing or maturing enterprise‑wide TPRM or broader risk governance programs in complex, global organizations. • Background in highly regulated industries with strong familiarity with regulatory expectations related to third‑party oversight. • Relevant certifications such as CISSP, CISM, CRISC, CISA, PMP, or other governance/risk credentials. • Experience leading or supporting the adoption of AI and digital technologies to improve operational efficiency, risk management, decision-making, or security outcomes preferred.
PHYSICAL/MENTAL REQUIREMENTS • No special physical requirements • Applicants should be capable of working through a personal laptop computer or mobile device for extended periods.
NON-STANDARD WORK SCHEDULE, TRAVEL OR ENVIRONMENT REQUIREMENTS • Travel as required by the business (less than 5% domestic and/or international) • Work Location Assignment: Must be able to work in assigned Pfizer office 2-3 days per week, or as needed by the business • This role is NOT remote
Work Location Assignment: Hybrid 
The annual base salary for this position ranges from $176,600.00 to $294,300.00. In addition, this position is eligible for participation in Pfizer’s Global Performance Plan with a bonus target of 20.0% of the base salary and eligibility to participate in our share based long term incentive program. We offer comprehensive and generous benefits and programs to help our colleagues lead healthy lives and to support each of life’s moments. Benefits offered include a 401(k) plan with Pfizer Matching Contributions and an additional Pfizer Retirement Savings Contribut
Salary insight
The midpoint of this range ($235k) is about 35% above the median disclosed salary for New York roles listed on ForgeApply ($175k across 4,956 jobs).
Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.
Ready to apply to Pfizer?
Tailor my resume for this roleSimilar jobs
- Director, Information Security & Technology — Gamechanger · Remote
- Director of Information Security — Panthalassa · Portland, OR
- Director, Information Technology & Security — Affirm · Remote
- Security Risk Management Lead — Affirm · Remote
- Senior Analyst, Third-Party Risk Management (TPRM) — Doordashusa · Remote
- Senior Manager, Information Security and Compliance — Parabilismed · Remote
- Director, Internal Controls & Risk Management — 103644278 · New York, NY
- Director, Internal Controls & Risk Management — Flamingo · New York, NY
More like this: More jobs at Pfizer · Browse all jobs