ForgeApply · Job listing
Manager, Cybersecurity & Information Protection (US)
Pfizer (Internaljobs)
See all 157 open roles at Pfizer (Internaljobs) →
Tailor your resume for this Pfizer (Internaljobs) job in about a minute.
ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for Pfizer (Internaljobs)'s site. Free trial, no card required.
About this role
ROLE SUMMARY
Our Global Cybersecurity Governance, Risk, and Compliance (GRC) team provides comprehensive blueprints for cybersecurity excellence by embedding governance, risk management, and compliance into every layer. The team is responsible for ensuring risk-based decision-making is used and that security, privacy, and regulatory compliance is integrated seamlessly with Pfizer's organization.
We are seeking a Manager, Information Protection & Technology Privacy, to lead and oversee the enterprise information protection program and serve as the primary Technology & Cyber Privacy Advisor within the Cyber GRC organization. This role ensures that sensitive data — across intellectual property, regulated data, and confidential business information — is appropriately classified, protected, and handled in alignment with Pfizer policies, regulatory expectations, and risk tolerance.
This role partners closely with Data Protection Engineering, Privacy, Legal, IT, Security Operations, and the DPO office to operationalize controls, drive adoption of data protection standards, ensure ongoing compliance across a complex, regulated pharmaceutical environment, and support Business Units in navigating privacy obligations across multiple jurisdictions.
ROLE RESPONSIBILITIES • Act as a trusted advisor on cybersecurity, information protection, and data privacy matters across the United States. • Partner with Business, Digital & Technology, Privacy, Legal, and Compliance stakeholders to provide pragmatic cybersecurity and information protection guidance for strategic initiatives, business transformations, and technology projects. • Assess and manage cybersecurity and information protection risks associated with business initiatives, applications, digital solutions, and third-party engagements. • Ensure compliance with applicable cybersecurity and data protection regulations across the United States, including CCPA/CPRA, HIPAA, state-level privacy laws (e.g., VCDPA, CPA, CTDPA), and related regulatory requirements. • Support regulatory inspections, audits, compliance reviews, and regulatory engagements as required. • Lead cybersecurity and data protection compliance programs, including regulatory assessments, filings, remediation planning, and related compliance activities. • Monitor emerging cybersecurity threats, regulatory developments, and compliance risks, and drive security awareness, risk management, and information protection initiatives across the organization. • Support on defining information protection controls for our organization to ensure regulatory compliance. • Experience with DLP and data discovery tools, as well as data labeling and tagging solutions, including deployment and ongoing support. • Support in the development of data protection policies and standards. • Support cybersecurity incident response, escalation, and remediation activities when required. • This role requires flexibility to collaborate with stakeholders and support business needs across multiple time zones, including occasional coordination with Latin America-based teams.
BASIC QUALIFICATIONS • Bachelor's degree in Information Security, Computer Science, Information Systems, Risk Management, or a related field with 4+ years of experience in cybersecurity, information security, data protection, privacy, regulatory compliance, risk management, or related disciplines, with at least 2 years in a supervisory or project leadership capacity; OR a master's degree with at least 2 years of experience; OR an associate's degree with 8 years of experience; OR a high school diploma (or equivalent) and 10 years of relevant experience. • Strong knowledge of cybersecurity governance, risk management, compliance frameworks, and applicable regulatory requirements. • Strong understanding of cybersecurity and data protection regulations, including CCPA/CPRA, HIPAA, and related U.S. state and federal requirements. Preferred knowledge of data protection and cybersecurity regulations across Latin America (e.g., LGPD in Brazil, Mexico's Federal Law on Protection of Personal Data, and other regional frameworks). • Experience supporting cybersecurity assessments, audits, regulatory inspections, compliance programs, or risk management initiatives. • Strong experience and hands on familiarity with technologies to build data discovery, classification and data loss prevention programs will be highly considered during the evaluation process. • Working knowledge of data encryption concepts and approaches across different environments. • Strong stakeholder management, communication, and influencing skills, with the ability to work effectively across business and technology functions in a global environment. • Strong project coordination across business and technical teams. • Professional proficiency in English; Spanish or Portuguese language is a plus.
PREFERRED QUALIFICATIONS • Professional certifications such as CISSP, CISA, CISM, CRISC, CIPP/E, CIPM, or equivalent are preferred. • Experience supporting cybersecurity, information protection, data privacy, or regulatory compliance programs within the pharmaceutical, healthcare, or life sciences industry is strongly preferred. • Hands‑on experience with GRC platforms (e.g., Archer). • Familiarity with privacy, intellectual property protection, and regulated data environments.
PHYSICAL/MENTAL REQUIREMENTS • No special physical requirements. • Applicants should be capable of working through a personal laptop computer or mobile device for extended periods.
NON-STANDARD WORK SCHEDULE, TRAVEL OR ENVIRONMENT REQUIREMENTS • Travel as required by the business (less than 5% domestic and/or international) • Work Location Assignment: Must be able to work in assigned Pfizer office 2-3 days per week, or as needed by the business • This role is NOT remote

The annual base salary for this position ranges from $106,000.00 to $176,600.00. In addition, this position is eligible for participation in Pfizer’s
Salary insight
The midpoint of this range ($141k) is about 12% below the median disclosed salary for New York roles listed on ForgeApply ($160k across 9,800 jobs).
See full Security Engineer salary data for New York →
Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.
Tailor your resume for this Pfizer (Internaljobs) role before you apply.
Tailor my resume for this jobSimilar jobs
- Manager, Cybersecurity — Litera · Colorado, United States
- Manager, Cyber Security — ICF · Reston, VA
- Senior Manager, Information Security — HD Supply · Atlanta-GA-US
- Senior Manager, Information Security and Compliance — Parabilismed · Remote
- Manager, Cyber Risk & Analysis — Capital One · McLean, VA | Richmond, VA
- Manager of Information Security — Clasp Group · Remote
- Manager - Cyber Operations — Iberdrola Group · Rochester, New York, United States
- Sr Manager Information Security — Itron · Austin, Texas, United States | Raleigh, North Carolina, United States | Liberty Lake, Washington, United States
More like this: Security & Cybersecurity Jobs · Security & Cybersecurity Jobs in New York · Browse all jobs
Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)