Cloud Security Engineer
Pfizer
- Location
- Greece-Thessaloniki Chortiatis
- Work model
- On-Site
- Level
- Mid
- H-1B history
- 9 approvals (FY2023)
- Posted
- Aug 13, 2026
Skills
About this role
ROLE
SUMMARY At the heart of Pfizer's Digital transformation sits Global Cloud Services, enabling modern cloud infrastructure and engineering capabilities that influence business outcomes and provide value to our business, shareholders, and patients every day. The Cloud Security Engineer plays a key role within the Cloud Engineering organization, contributing to the design, implementation and automation of secure, scalable and modern cloud platforms. This role supports multi-cloud security initiatives and helps deliver reliable, well-architected and secure solutions that enable product teams across the enterprise. The role helps engineer and secure the cloud infrastructure underpinning Pfizer's core cyber security applications, and takes part in adopting AI and agentic security tooling. The ideal candidate has hands-on cloud engineering experience, a security mindset, strong Infrastructure-as-Code proficiency , and a passion for automation, cloud-native technologies and continuous improvement.
ROLE
RESPONSIBILITIES Cloud Security Engineering Implement and enhance security controls across AWS, Azure and/or GCP following established engineering patterns and standards. Build and maintain secure Infrastructure as Code using Terraform, OpenTofu or similar tools. Contribute to development of reusable secure cloud modules, guardrails and reference architectures. Assist in designing secure, scalable and resilient cloud environments aligned to enterprise best practices. Automation & Tooling Develop and maintain security automation workflows using Python or other scripting languages. Support CI/CD and IaC security automation using platforms such as Spacelift, GitHub Actions or equivalent tools. Help embed scanning, secret protection and policy checks into developer pipelines. Operations & Compliance Implement guardrails, policies and controls to ensure secure and compliant cloud platforms. Monitor security posture, system health and platform reliability using cloud-native and third-party tooling. Triage security findings, troubleshoot infrastructure issues and collaborate with senior engineers on root cause analysis. Collaboration & Continuous Improvement Work with application teams, SRE, security and architecture groups to deliver end-to-end secure cloud solutions. Contribute to platform modernization initiatives, identifying opportunities to automate, optimize or simplify. Share knowledge, documentation and best practices to uplift security engineering maturity. Cyber Security Applications & Platforms in Scope The role engineers, secures and operates the cloud infrastructure underpinning Pfizer's core cyber security application estate, including: Ping - enterprise identity and access management / federation and single sign-on. SailPoint - identity governance and administration, access certification and lifecycle management. CyberArk - privileged access management, secrets management and credential vaulting. CrowdStrike Falcon LogScale running on Amazon EKS - large-scale security log ingestion, retention and threat hunting. Cutting-Edge & Agentic Cloud Security Capabilities This role sits at the front edge of AI-enabled security engineering. You will work with, evaluate, and operationalise emerging agentic capabilities that are reshaping how cloud security is delivered, including: Developer-embedded secret and credential protection - preventing credentials and secrets from ever reaching a repository, using GitHub Advanced Security (GHAS) push protection, secret scanning, code scanning and dependency review. Autonomous security agents for offensive testing - agent-driven penetration testing (black-box against external cloud estates and white-box against our own accounts) and continuous AI-assisted source code security review. AI red team and blue team agents within our cloud-native application protection tooling - using agentic red