Job Description
Our Global Cyber Defense team (CD) is responsible for safeguarding Pfizer’s digital assets and infrastructure through proactive threat detection, response, and risk mitigation across on-premises, cloud, and hybrid environments.
The CD organization is part of a broader security organization at Pfizer called CISO. The CISO organization secures Pfizer’s most important information assets through world class talent, top security controls and an empowered culture that serves to enable Pfizer’s mission of delivering breakthroughs that change patients’ lives.
The Senior Cyber Intrusion Manager will report into the Response Threat Operations team and will focus on responding to network security events and building a deep understanding of cybersecurity attacks against Pfizer. The Senior Manager – Response Threat Operations will be expected to lead event correlation across large datasets, perform and drive complete attack lifecycle analysis, develop remediation plans, implement proactive and reactive countermeasures, and create innovative solutions to the security issues that face the Pfizer environment.
The Senior Manager – Response Threat Operations will have demonstrated aptitude to rapidly apply expertise in a complex business and technical environment with previous experience in investigations, analysis, and incident response. Strong business communication and project management skills are required to maintain effective internal and customer relationships.
In addition, this position is also responsible for developing appropriate security incident response actions and monitoring effectiveness metrics.
ROLE RESPONSIBILITIES
- Working with RTO and CD leadership, contributing significantly to setting future strategy for the CISO organization
- Prepare and analyze monthly metrics reports, using data to drive continuous process improvement and identify investment opportunities.
- Manage EMEA RTO colleague performance and growth journeys in accordance with Pfizer values, including setting semester goals, managing promotions, merit and bonus awards, and attending to disciplinary matters.
- Maintain a positive and productive team culture across the EMEA and global RTO group. Foster an environment of growth, learning, and collaboration within CD and across the wider CISO organization, act as a mentor and leader to inspire the team to deliver exceptional service, performance and achieving business objective
- Oversee local hiring decisions for EMEA RTO and contribute to hiring decisions for other CD groups as requested.
- Utilize Agile methodology to plan, manage, and execute projects across the team, ensuring efficient workflow, effective use of resource, timely delivery, and high-quality results.
- Represent RTO in EMEA region - As a pivotal leadership figure, you will spearhead business interactions and engagements for the region, fostering strong relationships and ensuring customer satisfaction.
- Drive the development of innovative and advanced automated solutions and workflows that optimize global RTO operational efficiency.
- Working closely with the RTO leaders in APAC,EMEA & AMER regions, develop, organize, and maintain a 24x7 incident response function composed of qualified personnel (colleague & contractor staff), properly trained to leverage security data from internal sensors (IDS, routers, SIEMs, firewalls, hosts) and external sources (Industry portals, threat intel feeds, etc) to identify high priority alerts and perform attack life-cycle analysis to develop/implement proactive mitigations.
- Manage day-to-day activities specific to proactive monitoring and response of known and/ or emerging threats, coordinate investigation and triage activities across wide variety of security events.
- Drive process improvement and develop internal procedures for intrusion analysis, reporting criteria, metrics, and operational rhythms
- Drive incident response, which may include implementation of containment, protection, and remediation activities. Escalate and coordinate security incidents with appropriate stakeholders.
- Contribute to the setting of long term strategic and technical goals for the Cyber Intrusion Analysis function and identify tactical steps necessary to achieve
- Utilize understanding of the life cycle of network threats, attacks, attack vectors, and methods of exploitation to conduct analysis across forensic evidence, log data, compromised hosts, and network traffic
- Review security incidents and alerts; determine their severity and impact to the Pfizer enterprise along with detailed response actions
- Required to stay up to date with current vulnerabilities, attacks, and countermeasures, along with staying current with all security related news and developments.
- Mentor analysts and provide strong guidance on technical steps, incident response processes and career advancement
- Forensic analysis; analysis of compromised machines and analysis of network traffic and log data.
- Signature/alert development to help catch threats to Pfizer’s computers and network (e.g. Yara, SNORT, etc.)
- Demonstrated commitment to training, self-study and maintaining proficiency in the technical cyber security domain.
- The Senior Manager – Response Threat Operations must be able to work well with a team, including cross-unit and cross-divisional teams, and must be able to maintain poise and composure in difficult situations, with a professional attitude at all times.
- Demonstrated ability to be able to lead a project or cross-unit team.
BASIC QUALIFICATIONS
- BS in Computer Sciences, Information Security, Information Systems, Engineering, Sciences, or related field.
- Advanced level understanding of TCP/IP, common networking ports and protocols, traffic flow, system administration, OSI model, defense-in-depth, and common security elements.
- Advanced level understanding of the life cycle of network threats, attacks, attack vectors and methods of exploitation with an understanding of intrusion set tactics, techniques, and procedures (TTPs)
- Advanced level knowledge of the Windows operating system, system utilities, admin functions
- Significant experience with open-source security analysis tools such as Wireshark, SNORT, Splunk, Kali Linux, Sift, REMnux etc.
- Experience with Computer programming and scripting languages such as C, Python, Java, etc.
- Ability to proactively solve complex problems both individually and as part of a team
- Leadership skills with the ability to prioritize and execute with minimal direction or oversight
- Outstanding communication skills, including the ability to write and verbally articulate industry terminology to interact at a technical level, management level and senior executive level
- Organizational, planning, and administrative abilities and the ability to coordinate multiple complex projects simultaneously
- Demonstrated experience in an agile work environment possessing qualities such as a collaborative mindset, adaptability to change, and a proactive problem-solving approach.
NON-STANDARD WORK SCHEDULE, TRAVEL OR ENVIRONMENT REQUIREMENTS
Standard work schedule & occasional travel required (10-20% as required)
Work Location Assignment: Hybrid
Purpose
Breakthroughs that change patients' lives.. At Pfizer we are a patient centric company, guided by our four values: courage, joy, equity and excellence. Our breakthrough culture lends itself to our dedication to transforming millions of lives.
Digital Transformation Strategy
One bold way we are achieving our purpose is through our company wide digital transformation strategy. We are leading the way in adopting new data, modelling and automated solutions to further digitize and accelerate drug discovery and development with the aim of enhancing health outcomes and the patient experience.
Flexibility
We aim to create a trusting, flexible workplace culture which encourages employees to achieve work life harmony, attracts talent and enables everyone to be their best working self. Let’s start the conversation!
Equal Employment Opportunity
We believe that a diverse and inclusive workforce is crucial to building a successful business. As an employer, Pfizer is committed to celebrating this, in all its forms – allowing for us to be as diverse as the patients and communities we serve. Together, we continue to build a culture that encourages, supports and empowers our employees.
DisAbility Confident
We are proud to be a Disability Confident Employer and we encourage you to put your best self forward with the knowledge and trust that we will make any reasonable adjustments necessary to support your application and future career. Our mission is unleashing the power of our people, especially those with unique superpowers. Your journey with Pfizer starts here!
To learn more about acceptable and prohibited uses of AI during the recruitment process, please review our candidate AI-use guidelines available on Pfizer Careers
Information & Business Tech