
Sr. Director, Security and Compliance
Pfizer, New York, NY, United States
**ROLE SUMMARY*** Establish the vision and operational cadence for a team of
Security and Compliance Partners who are assigned global business units, regions and functional areas* Implement a technology driven solution to support* Build strong relationships with senior leaders to integrate security and compliance considerations into business operations and strategic initiatives.* Lead the development of practical, risk-based guidance that enables the business to meet regulatory and security requirements while supporting innovation.* Partner with key leaders throughout the organization to execute on strategic goals and priorities for the Cyber GRC function.* Develop and execute a vision to modernize and scale cyber and digital compliance.* Ensure alignment with pharmaceutical regulatory requirements, including GxP, data integrity, privacy, and global regulatory expectations.* Partner with Quality, Legal, Privacy, and Enterprise Risk Management teams to ensure consistent application of governance and controls.* Support the identification, assessment, and management of cybersecurity, IT and compliance risks affecting business processes, systems, and data.* Promote consistent processes, documentation, and reporting while allowing flexibility for local regulatory requirements.* Set clear role expectations, performance objectives, and development plans for team members.* Foster a culture of collaboration, accountability, and continuous improvement.* Provide regular updates to senior leadership on cybersecurity and compliance risks, trends, and key initiatives.* Define and monitor key metrics to demonstrate security and compliance posture to leadership.* Develop executive and committee-level reporting as needed.* Bachelor’s degree required* 12+ years of experience in Cybersecurity, IT, GRC, compliance, quality, or risk management roles within regulated industries, preferably in pharmaceutical industry* Experience partnering directly with business leaders in a complex, global organization* Proven ability to lead complex programs with multiple stakeholders and competing priorities* Strong understanding of cybersecurity and IT risk management and compliance concepts in a pharmaceutical or life sciences environment* Excellent communication and interpersonal skills; ability to influence across levels and functions* CISM, CRISC or CISSP Certification* Proficiency in project management tools (e.g., Smartsheet, MS Project), data analysis platforms, and MS Office Suite* Demonstrated experience in an agile work environment possessing qualities such as a collaborative mindset, adaptability to change, and a proactive problem-solving approach.* Experience supporting GxP-regulated environments (GMP, GCP, GLP) and validated systems – Life Sciences or Consumer Products preferred* Familiarity with global regulations and standards such as GDPR, HIPAA, SOX, ISO 27001, and NIST* Experience working with Quality Management Systems (QMS) and regulatory inspection processes* Professional certifications such as CISSP, CISM, CRISC, or similar* Strong interpersonal and communication skills* Ability to translate technical and regulatory requirements into business-friendly guidance* Executive presence and stakeholder management* Global mindset and ability to work across cultures* Collaborative leadership style* Continuously seeks new knowledge and approaches, leveraging innovation to enhance efficiency, effectiveness and impact* Travel as required by the business (domestic and/or international) – Estimated at 25%* Work Location Assignment: Must be able to work in assigned Pfizer office 2-3 days per week, or as needed by the business* This role is NOT remote**EEO & Employment Eligibility**Pfizer is committed to equal opportunity in the terms and conditions of employment for all employees and job applicants without regard to race, color, religion, sex, sexual orientation, age, gender identity or gender expression, national origin, disability or veteran status.
Pfizer also complies with all applicable national, state and local laws governing nondiscrimination in employment as well as work authorization and employment eligibility verification requirements of the Immigration and Nationality Act and IRCA.
Pfizer is an E-Verify employer.
This position requires permanent work authorization in the United States.Pfizer endeavors to make
accessible to all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process and/or interviewing, please email disabilityrecruitment@pfizer.com. This is to be used solely for accommodation requests with respect to the accessibility of our website, online application process and/or interviewing. Requests for any other reason will not be returned.Pfizer careers are like no other. In our culture of individual ownership, we believe in our ability to improve future healthcare, and potential to transform millions of lives. We’re looking for new talent to join our global community, to unearth new innovative therapies that make the world a healthier place. #J-18808-Ljbffr
Security and Compliance Partners who are assigned global business units, regions and functional areas* Implement a technology driven solution to support* Build strong relationships with senior leaders to integrate security and compliance considerations into business operations and strategic initiatives.* Lead the development of practical, risk-based guidance that enables the business to meet regulatory and security requirements while supporting innovation.* Partner with key leaders throughout the organization to execute on strategic goals and priorities for the Cyber GRC function.* Develop and execute a vision to modernize and scale cyber and digital compliance.* Ensure alignment with pharmaceutical regulatory requirements, including GxP, data integrity, privacy, and global regulatory expectations.* Partner with Quality, Legal, Privacy, and Enterprise Risk Management teams to ensure consistent application of governance and controls.* Support the identification, assessment, and management of cybersecurity, IT and compliance risks affecting business processes, systems, and data.* Promote consistent processes, documentation, and reporting while allowing flexibility for local regulatory requirements.* Set clear role expectations, performance objectives, and development plans for team members.* Foster a culture of collaboration, accountability, and continuous improvement.* Provide regular updates to senior leadership on cybersecurity and compliance risks, trends, and key initiatives.* Define and monitor key metrics to demonstrate security and compliance posture to leadership.* Develop executive and committee-level reporting as needed.* Bachelor’s degree required* 12+ years of experience in Cybersecurity, IT, GRC, compliance, quality, or risk management roles within regulated industries, preferably in pharmaceutical industry* Experience partnering directly with business leaders in a complex, global organization* Proven ability to lead complex programs with multiple stakeholders and competing priorities* Strong understanding of cybersecurity and IT risk management and compliance concepts in a pharmaceutical or life sciences environment* Excellent communication and interpersonal skills; ability to influence across levels and functions* CISM, CRISC or CISSP Certification* Proficiency in project management tools (e.g., Smartsheet, MS Project), data analysis platforms, and MS Office Suite* Demonstrated experience in an agile work environment possessing qualities such as a collaborative mindset, adaptability to change, and a proactive problem-solving approach.* Experience supporting GxP-regulated environments (GMP, GCP, GLP) and validated systems – Life Sciences or Consumer Products preferred* Familiarity with global regulations and standards such as GDPR, HIPAA, SOX, ISO 27001, and NIST* Experience working with Quality Management Systems (QMS) and regulatory inspection processes* Professional certifications such as CISSP, CISM, CRISC, or similar* Strong interpersonal and communication skills* Ability to translate technical and regulatory requirements into business-friendly guidance* Executive presence and stakeholder management* Global mindset and ability to work across cultures* Collaborative leadership style* Continuously seeks new knowledge and approaches, leveraging innovation to enhance efficiency, effectiveness and impact* Travel as required by the business (domestic and/or international) – Estimated at 25%* Work Location Assignment: Must be able to work in assigned Pfizer office 2-3 days per week, or as needed by the business* This role is NOT remote**EEO & Employment Eligibility**Pfizer is committed to equal opportunity in the terms and conditions of employment for all employees and job applicants without regard to race, color, religion, sex, sexual orientation, age, gender identity or gender expression, national origin, disability or veteran status.
Pfizer also complies with all applicable national, state and local laws governing nondiscrimination in employment as well as work authorization and employment eligibility verification requirements of the Immigration and Nationality Act and IRCA.
Pfizer is an E-Verify employer.
This position requires permanent work authorization in the United States.Pfizer endeavors to make
accessible to all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process and/or interviewing, please email disabilityrecruitment@pfizer.com. This is to be used solely for accommodation requests with respect to the accessibility of our website, online application process and/or interviewing. Requests for any other reason will not be returned.Pfizer careers are like no other. In our culture of individual ownership, we believe in our ability to improve future healthcare, and potential to transform millions of lives. We’re looking for new talent to join our global community, to unearth new innovative therapies that make the world a healthier place. #J-18808-Ljbffr