Manager, Cyber Policy, Governance, Standards & Control Management

Pfizer

United States

Hybrid

USD 106,000 - 177,000

Full time

8 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Pfizer is seeking an experienced Manager, Cyber Policy, Governance, Standards & Control Management to lead the enterprise policy framework, standards, and control library within the Global Cyber GRC organization. This role drives governance processes, stakeholder engagement, and risk-driven policy development across a global pharmaceutical environment.

Responsibilities include lifecycle management of policies, mapping to NIST CSF 2.0, ISO 27001, NIST 800-53, and CIS Controls; partnering with

Qualifications

  • Bachelor's degree required.
  • 4+ years of experience in cybersecurity, enterprise risk management, cyber risk analysis, or GRC-related roles.
  • Strong knowledge of cybersecurity frameworks and standards, including NIST CSF 2.0, CIS, COBIT, ISO.
  • Excellent communication and interpersonal skills; ability to influence across levels and functions.
  • Experience with GRC tools like Archer, or similar technologies.

Responsibilities

  • Lead the lifecycle management of enterprise cybersecurity policies, standards, baselines, and supporting governance documents.
  • Establish and maintain a structured policy governance framework, including review cycles, approvals, exception management, and stakeholder engagement.
  • Manage governance processes that provide oversight of cybersecurity program effectiveness, compliance, and risk posture.
  • Develop governance reporting, metrics, and KPIs to measure program maturity and control effectiveness.
  • Maintain the enterprise cybersecurity controls framework and control library.
  • Support mapping of security controls to industry frameworks and regulatory requirements, including NIST CSF 2.0, ISO 27001, NIST 800-53, CIS Controls, NIS2, and applicable pharmaceutical regulations.
  • Partner with control owners to define control objectives, implementation guidance, and testing requirements.
  • Drive improvements to control design, rationalization, and coverage to address emerging cybersecurity risks.
  • Collaborate with cyber risk, audit, compliance, privacy, and quality teams to address findings, control gaps, and remediation activities.
  • Support internal audits, regulatory inspections, assessments, and external assurance activities.
  • Provide governance oversight for risk exceptions, compensating controls, and remediation tracking.
  • Build strong partnerships across cybersecurity, technology, business, legal, privacy, and compliance functions.
  • Provide subject matter expertise on cybersecurity governance, policy development, and control management.
  • Lead and mentor cybersecurity governance professionals and project teams.
  • Drive a culture of accountability, continuous improvement, and effective risk management.

Skills

Cybersecurity knowledge
Policy governance
Communication skills
Agile experience

Education

Bachelor's degree

Tools

Archer

Job description

ROLE SUMMARY

Our Global Cybersecurity Governance, Risk, and Compliance (GRC) team provides comprehensive blueprints for cybersecurity excellence by embedding governance, risk management, and compliance into every layer. The team is responsible for ensuring risk-based decision-making is used and that security, privacy, and regulatory compliance is integrated seamlessly with Pfizer's organization.

We are seeking an experienced Manager, Cyber Policy, Governance, Standards & Control Management to join our Cyber GRC organization. This role is responsible for leading the development, maintenance, and governance of the enterprise cybersecurity policy framework, security standards, control library, and governance processes that enable effective cyber risk management across a global pharmaceutical environment.

ROLE RESPONSIBILITIES
  • Lead the lifecycle management of enterprise cybersecurity policies, standards, baselines, and supporting governance documents.
  • Establish and maintain a structured policy governance framework, including review cycles, approvals, exception management, and stakeholder engagement.
  • Manage governance processes that provide oversight of cybersecurity program effectiveness, compliance, and risk posture.
  • Develop governance reporting, metrics, and key performance indicators (KPIs) to measure program maturity and control effectiveness.
  • Maintain the enterprise cybersecurity controls framework and control library.
  • Support mapping of security controls to industry frameworks and regulatory requirements, including NIST CSF 2.0, ISO 27001, NIST 800-53, CIS Controls, NIS2, and applicable pharmaceutical regulations.
  • Partner with control owners to define control objectives, implementation guidance, and testing requirements.
  • Drive improvements to control design, rationalization, and coverage to address emerging cybersecurity risks.
  • Collaborate with cyber risk, audit, compliance, privacy, and quality teams to address findings, control gaps, and remediation activities.
  • Support internal audits, regulatory inspections, assessments, and external assurance activities.
  • Provide governance oversight for risk exceptions, compensating controls, and remediation tracking.
  • Build strong partnerships across cybersecurity, technology, business, legal, privacy, and compliance functions.
  • Provide subject matter expertise on cybersecurity governance, policy development, and control management.
  • Lead and mentor cybersecurity governance professionals and project teams.
  • Drive a culture of accountability, continuous improvement, and effective risk management.
BASIC QUALIFICATIONS
  • Bachelor's degree required
  • 4+ years of experience in cybersecurity, enterprise risk management, cyber risk analysis, or GRC-related roles
  • Strong knowledge of cybersecurity frameworks and standards, including NIST CSF 2.0, CIS, COBIT, ISO
  • Strong strategic thinking, analytical capability, and problem-solving skills, ability to translate technical risk insights into recommendations
  • Excellent communication and interpersonal skills; ability to influence across levels and functions
  • Experience with GRC tools like Archer, or similar technologies
  • Demonstrated experience in an agile work environment possessing qualities such as a collaborative mindset, adaptability to change, and a proactive problem-solving approach.
PREFERRED QUALIFICATIONS
  • Excellent strategic thinking
  • Deeply analytical and credible
  • Fact-based decision-making
  • Ability to challenge, influence, and support senior leadership
  • Excellent communication and presentation skills
  • Ability to bring structure to vaguely defined problems and solve them with creative yet pragmatic approaches
  • Resourceful, self-motivated, and proactive - strong drive for excellence
PHYSICAL/MENTAL REQUIREMENTS

No special physical requirements.

Applicants should be capable of working through a personal laptop computer or mobile device for extended periods.

NON-STANDARD WORK SCHEDULE, TRAVEL OR ENVIRONMENT REQUIREMENTS

Travel as required by the business (less than 5% domestic and/or international)

Work Location Assignment: Must be able to work in assigned Pfizer office 2-3 days per week, or as needed by the business

This role is NOT remote

Work Location Assignment: Hybrid

The annual base salary for this position ranges from $106,000.00 to $176,600.00. In addition, this position is eligible for participation in Pfizer's Global Performance Plan with a bonus target of 15.0% of the base salary and eligibility to participate in our share b

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Policy, Governance & Controls Manager
Cyber Policy, Governance & Controls Manager

Pfizer • United States

Hybrid
USD 106,000 - 177,000
Manager, GRC Technology, Metrics, and Automation
Manager, GRC Technology, Metrics, and Automation

Biopharma Careers • New York (NY)

Hybrid
USD 99,000 - 165,000
401(k) matching contributions
Health benefits
Paid vacation
Senior Manager, GRC Technology, Metrics, and Automation
Senior Manager, GRC Technology, Metrics, and Automation

Biopharma Careers • New York (NY)

Hybrid
USD 124,000 - 207,000
Health benefits
401(k) plan with employer matching
Relocation assistance
Manager, Cybersecurity & Information Protection (US)
Manager, Cybersecurity & Information Protection (US)

Pfizer • United States

On-site
USD 140,000 - 190,000
Senior Manager, GRC Technology, Metrics, and Automation
Senior Manager, GRC Technology, Metrics, and Automation

Pfizer • New York (NY), Northern (KY)

On-site
USD 124,000 - 207,000
401(k) with Pfizer Matching Contrib.
Comprehensive benefits package
Manager, GRC Technology, Metrics, and Automation
Manager, GRC Technology, Metrics, and Automation

Pfizer • New York (NY), Northern (KY)

On-site
USD 99,000 - 165,000
401(k) match
Pfizer Retirement Savings Contribution
Paid vacation
+3
Director, Digital Audit, Inspection & Continuous Improvement
Director, Digital Audit, Inspection & Continuous Improvement

Scorpion Therapeutics • Pennsylvania

Hybrid
USD 180,000 - 240,000
Director, Digital Audit, Inspection & Continuous Improvement
Director, Digital Audit, Inspection & Continuous Improvement

Scorpion Therapeutics • New York (NY)

Hybrid
USD 180,000 - 240,000
Manager, Cybersecurity & Information Protection (US)
Manager, Cybersecurity & Information Protection (US)

Pfizer • New York (NY)

On-site
USD 106,000 - 177,000
401(k) with Pfizer Matching
Pfizer Retirement Savings Contribution
Comprehensive benefits
Manager, Cybersecurity & Information Protection (US)
Manager, Cybersecurity & Information Protection (US)

Biopharma Careers • New York (NY)

On-site
USD 106,000 - 177,000