Manager, Threat Remediation
Pfizer
- Location
- United States New York New York City
- Work model
- On-Site
- Level
- Mid
- H-1B history
- 9 approvals (FY2023)
- Posted
- 4h ago
Skills
About this role
ROLE
SUMMARY Our Global Cyber Defense team is responsible for safeguarding Pfizer’s digital assets and infrastructure through proactive threat detection, response, and risk mitigation across on-premises, cloud, and hybrid environments. The Lead Analyst, Threat Remediation is responsible for leading the execution of threat remediation activities to ensure cybersecurity threats are effectively prioritized, mitigated, and resolved in a timely and risk‑based manner. This role coordinates remediation efforts across threat detection, incident response, vulnerability management, and technology teams to reduce exposure and strengthen the organization’s security posture. The role partners closely with the SOC, Cloud Services, Infrastructure, Engineering, GRC, Legal, Privacy, and business stakeholders to drive remediation outcomes, track progress, and ensure threats are addressed in alignment with regulatory requirements, internal standards, and business priorities. This role will report to the Sr. Manager, Threat Remediation.
ROLE
RESPONSIBILITIES Lead the day‑to‑day execution of threat remediation activities to ensure identified cybersecurity threats and exposures are prioritized, tracked, and resolved in a timely and risk‑based manner. Coordinate remediation efforts across threat detection, incident response, vulnerability management, and engineering teams to drive consistent and effective outcomes. Translate threat and exposure information into clear remediation actions, working with technical owners to define scope, timelines, and risk‑appropriate mitigation plans. Track remediation progress, validate completion, and identify recurring issues or systemic control gaps requiring escalation or broader corrective action. Partner closely with the SOC, Cloud Services, Infrastructure, Engineering, GRC, Legal, Privacy, and business stakeholders to ensure remediation activities align with regulatory requirements, internal standards, and business priorities. Support the investigation and remediation of high‑severity or complex threats, including coordination during active incidents or escalated risk scenarios. Maintain accurate remediation reporting, metrics, and status updates for leadership, highlighting risk trends, delays, and improvement opportunities. Drive continuous improvement of threat remediation processes, workflows, and handoffs to improve speed, consistency, and risk reduction. Escalate material risks, blocked remediation efforts, or cross‑organizational issues to the Senior Manager, Threat Remediation, with clear context and recommendations.
BASIC QUALIFICATIONS
Applicant must have a Bachelor's degree in Computer Science, Information Security, Engineering, or related technical discipline with at least 4 years of experience in cybersecurity, with hands‑on involvement in remediation, vulnerability management, security engineering, or incident response; OR a master's degree with at least 2 years of experience; OR as associate's degree with 8 years of experience; OR a high school diploma (or equivalent) and 10 years of relevant experience. Strong understanding of: Threat actor tactics, techniques, and procedures (MITRE ATT&CK) Incident response and containment strategies Vulnerability management and remediation workflows Cloud security (AWS, Azure, GCP) Endpoint, network, identity, and application security Familiarity with SOC tooling (SIEM, SOAR, EDR/XDR), vulnerability scanners, and ticketing/workflow systems. Ability to translate threat and exposure data into clear, actionable remediation plans. Strong organizational and communication skills, with the ability to manage competing priorities and escalate risks appropriately. Demonstrated experience in an agile work environment possessing qualities such as a collaborative mindset, adaptability to change, and a proactive problem-solving approach.
PREFERRED QUALIFICATIONS
Working knowledge of GxP, FDA 21 CFR Part 11, EMA, HIPAA, GDPR, and other relevant