Sr. Manager, Information Protection

Pfizer Pfizer · Pharma · Thessaloniki Chortiatis, Greece

Senior Manager, Data Protection for Pfizer's Global Cybersecurity Governance, Risk, and Compliance team. Responsible for establishing, governing, and operationalizing the enterprise data protection program globally, ensuring sensitive data is identified, classified, protected, and governed in alignment with regulations and policies. Partners with various teams to embed information protection requirements into technology and processes, drives control assurance, and reports on risk metrics.

What you'd actually do

  1. Define, maintain, and evolve Pfizer’s enterprise information protection policies, standards, control objectives, and oversight mechanisms, ensuring consistent application across the United States, Europe, and Asia.
  2. Lead the Cyber GRC information protection program across regions, ensuring risks related to sensitive, regulated, and critical data are identified, assessed, prioritized, and tracked in alignment with regional and global requirements.
  3. Establish and oversee information protection control requirements aligned to global and regional privacy regulations (e.g., GDPR, and applicable APAC regulations), internal security policies, and enterprise risk tolerance.
  4. Partner with Privacy, Legal, Compliance, Digital, Infrastructure, and business teams across the US, Europe, and Asia to embed information protection requirements into technology platforms, solutions, and business processes.
  5. Drive information protection control assurance activities globally, including control design reviews, operating effectiveness assessments, issue management, and remediation tracking.

Skills

Required

  • Bachelor’s degree in information security, Information Technology, Cybersecurity, or related field.
  • 7+ years of experience in information security, risk, compliance, information protection, or related disciplines.
  • Demonstrated experience operating within regulated industries, with an understanding of regulatory expectations, audit requirements, and compliance obligations related to information protection, security controls, and risk management.
  • Practical knowledge of information protection concepts and controls, including data classification/labeling, access governance principles, secure data handling, audit evidence, and incident coordination.
  • Deep understanding of global data protection/privacy regulations (e.g., CCPA, GDPR, NIS2, etc.) and their application within large enterprises.
  • Excellent verbal and written communication skills, with the ability to clearly articulate complex technical and risk‑based concepts to a wide range of audiences.
  • Strong analytical, strategic thinking, and problem‑solving skills, with demonstrated ability to assess risk posture.
  • Proficiency with GRC platforms and data governance or risk reporting tools (e.g., Archer, Purview, or similar).

Nice to have

  • Professional certifications in privacy, data protection, or information security, (e.g., Certified Information Privacy Manager (CIPM), Certified Information Privacy Professional (CIPP/E or equivalent), or an academic equivalent).
  • Excellent strategic thinking.
  • Deeply analytical and credible.
  • Fact-based decision-making.
  • Deep understanding of data security objectives, governance models, and risk management considerations for complex enterprises operating in regulated industries.
  • Experience supporting enterprise data classification, data lifecycle, or information governance programs.
  • Strong executive communication and presentation skills.
  • Experience leading globally distributed teams or matrixed resources.

What the JD emphasized

  • global footprint spanning the United States, Europe, and Asia
  • global oversight
  • across regions and time zones
  • global and regional privacy regulations
  • global and regional information protection risk metrics
  • across jurisdictions
  • globally distributed team
  • enterprise initiatives
  • global footprint