yoinka

Senior Manager, Information Protection Engineering

Pfizer

Greece-Thessaloniki ChortiatisSeniorH-1B sponsor company
Sign in to applyVerified 1h ago
Location
Greece-Thessaloniki Chortiatis
Work model
On-Site
Level
Senior
H-1B history
9 approvals (FY2023)
Posted
Aug 25, 2026

Skills

Cybersecurity

About this role

ROLE

SUMMARY   Our Global Cybersecurity Governance, Risk, and Compliance team provides comprehensive blueprints for cybersecurity excellence by embedding governance, risk management, and compliance into every layer. The team is responsible for ensuring risk-based decision-making is used and that security, privacy, and regulatory compliance is integrated seamlessly with Pfizer’s organization. We are seeking a Senior Manager, Information Protection Engineering , to lead and evolve our information protection capabilities within the Cyber GRC organization. This role is critical to safeguarding sensitive scientific, clinical, patient, and business information across Pfizer’s global enterprise. The role will lead a team of highly skilled engineers and work closely with CISO organization, Privacy, Legal, Compliance, R&D, Infrastructure, and Cloud Services partners to design, implement, and operate scalable information protection solutions aligned to regulatory requirements and business priorities.

ROLE

RESPONSIBILITIES Lead the definition of enterprise information protection technical strategy, reference architectures, and control frameworks, including DLP, data discovery and classification, and encryption requirements. Establish and maintain information protection technical standards, guardrails, and design patterns that guide implementation across endpoints, cloud platforms, applications, and collaboration tools. Define policy and control requirements for encryption, key management, and secrets management in partnership with Cloud, Infrastructure, and Identity teams, ensuring alignment with information protection objectives. Lead and provide hands-on oversight of the implementation, configuration, and lifecycle governance of information protection technologies such as DLP, data classification, data discovery solutions, and AI information protection. Provide architectural guidance and design review for information protection integrations within platforms, applications, and business solutions. Influence tooling decisions through risk‑based requirements, rather than operational ownership of underlying cloud or infrastructure services. Embed security‑by‑design principles for information protection into the application and platform lifecycle, including requirements for data handling, classification, retention, and policy enforcement. Partner with Digital, Cloud Services, Infrastructure, and IT teams to ensure information protection controls are designed into platforms, not bolted on post‑deployment. Partner with Security Operations and Incident Response teams to support detection, investigation, and response to information protection incidents and policy violations. Ensure information protection capabilities align with enterprise risk management frameworks, internal security standards, and audit expectations. Collaborate with Privacy, Legal, Compliance, and Cyber GRC teams to ensure information protection controls support global regulatory and industry requirements (e.g., GDPR, HIPAA, SOX, GxP). Translate NIST, regulatory, privacy requirements, and risk requirements into clear, implementable information protection technical controls and guidance. Define and report metrics that demonstrate information protection effectiveness, risk trends, and maturity improvement to Cyber GRC and senior leadership. Lead, mentor, and develop a team of engineers and analysts focused on information protection engineering and architectural enablement, establishing clear role boundaries between control ownership and platform operational ownership to enable scale and clarity.

BASIC QUALIFICATIONS

Bachelor’s degree in Information Security, Computer Science, Engineering, or a related field, or equivalent experience. 6+ years of experience in cybersecurity or information protection–related roles, with responsibility for enterprise‑scale information protection controls. Demonstrated experience designing, implementing, and operating

Listing verified 1h ago. Applications go through the company's official careers site.

← Back to Yoinka

Senior Manager, Information Protection Engineering at Pfizer, Greece-Thessaloniki Chortiatis | Yoinka