Director, Third-Party Risk Management and Technical Information Security Lead - pfizer
Listed on 2026-09-10
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Use Your Power for Purpose
Our Global Governance, Risk, and Compliance (GRC) team provides comprehensive blueprints for cybersecurity excellence by embedding governance, risk management, and compliance into every layer. The team is responsible for ensuring risk-based decision-making is used and that security, privacy, and regulatory compliance is integrated seamlessly with Pfizer’s organization.
We are seeking an experienced Director, Third Party Risk Management (TPRM) and Technical Information Security Lead (TISL). T his is a leadership role combining enterprise‑level ownership of the Third‑Party Risk Management program with business‑facing technical security risk leadership across critical initiatives and platforms.
This role will set the overall third‑party security strategy, standards, and operating models for managing cyber risk across a complex ecosystem of vendors, partners, and internal technologies, while acting as a trusted security advisor to executive and senior business leaders. This role is pivotal in balancing risk, regulatory compliance, speed, and innovation in a highly regulated environment.
What You Will Achieve TPRM Program Strategy & Ownership- Own the enterprise Third Party Risk Management (TPRM) security strategy, program, and operating model.
- Align TPRM with enterprise cyber risk appetite, business priorities, and pharmaceutical regulatory expectations.
- Establish scalable approaches for risk tiering, assessment depth, reassessment cadence, continuous monitoring, and exception governance.
- Align the TPRM program with Pfizer’s enterprise cyber risk appetite and business strategy.
- Provide executive‑level oversight and approval for high‑risk and critical vendor risk assessments.
- Lead governance for risk treatment decisions, including remediation prioritization, compensating controls, and formal risk acceptances.
- Escalate material vendor risks to enterprise risk committees and executive leadership, enabling informed decision‑making.
- Serve as a senior Technical Information Security Lead for high‑impact business initiatives, platforms, and transformations.
- Serve as the trusted cybersecurity risk advisor to executive‑level business and technology leaders.
- Translate complex technical risks into executive‑level insights and decision‑ready recommendations.
- Serve as an executive GRC partner to Procurement, Legal, Privacy, Quality, Security, Internal Audit, and Business Leadership.
- Influence contract standards and onboarding requirements to embed security, privacy, and resilience controls into third‑party agreements.
- Represent GRC in executive forums, governance bodies, and cross‑functional steering committees.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).