VP, Cybersecurity Governance, Risk, and Compliance
3 days ago
Role Summary
Our Global Cybersecurity Governance, Risk, and Compliance (GRC) team plays a critical role in safeguarding Pfizer's digital assets, ensuring regulatory compliance, and protecting sensitive data across all business functions. As part of our strategic commitment to strengthening our cybersecurity posture, we are enhancing and modernizing our GRC program to address enterprise-wide risks across applications, data, vendors, and critical operations.
We are seeking an experienced individual of Cybersecurity Governance, Risk, and Compliance to lead this transformation. The ideal candidate will have deep expertise in enterprise cyber risk management, regulatory compliance, audit readiness, and oversight of GRC technologies. This leader will drive enterprise programs across GRC, business security and data protection, application security governance, third-party risk management (TPRM), and business continuity/disaster recovery (BCP/DR).
Role Responsibilities
- Define and execute the enterprise GRC strategy, ensuring alignment with organizational goals and regulatory requirements.
- Lead the enterprise cyber risk management program, including risk identification, assessment, prioritization, and mitigation planning.
- Oversee all audit and compliance activities, including ISO 27001, SOC 2, PCI DSS, SOX, GxP, and other relevant standards.
- Serve as product owner for GRC platforms, ensuring configuration, integration, automation, and reporting capabilities meet enterprise needs.
- Establish and monitor cybersecurity policies, standards, and procedures, drive adoption across all business and IT units.
- Lead application security governance initiatives, embedding secure development lifecycle practices across the enterprise.
- Drive business security and data protection programs, ensuring alignment with global privacy regulations and internal controls.
- Oversee BCP/DR strategy and execution, ensuring operational resilience across critical business functions.
- Provide clear, actionable reporting and dashboards on risk, compliance, and program health to executive leadership and the board.
- Collaborate with Legal, IT, Privacy, Internal Audit, and business stakeholders to embed governance and risk management practices into daily operations.
- Build, develop, and lead a high-performing GRC team; mentor staff and create a culture of accountability, collaboration, and continuous improvement.
- Stay current on industry trends, emerging regulations, and cybersecurity best practices to proactively adapt the GRC program.
Basic Qualifications
- Bachelor's degree with 15+ years of experience in cybersecurity, risk management, or related fields.
- At least 8 years of direct leadership experience managing enterprise-wide GRC or risk/compliance functions.
- Professional certifications such as CISSP (required); CISM, CRISC, or CISA strongly preferred.
- Experience leading Application Security Governance and secure development lifecycle practices.
- Strong background in Third-Party Risk Management (TPRM) programs, including vendor assessments, monitoring, and remediation.
- Deep knowledge of cybersecurity frameworks (NIST CSF, ISO 27001, SOC 2, PCI DSS, SOX) and data protection regulations (GDPR, CCPA, HIPAA).
- Strong leadership, communication, and presentation skills, with the ability to translate complex risks into business-focused insights for senior executives and boards.
Preferred Qualifications
- Experience with RSA Archer as the enterprise GRC platform, including ownership of configuration, workflows, and reporting.
- Experience overseeing GRC-related technologies, including Data Protection/DLP platforms and Business Continuity/Disaster Recovery solutions.
Last date to apply: October 17, 2025
The annual base salary for this position ranges from $256,100.00 to $426, In addition, this position is eligible for participation in Pfizer's Global Performance Plan with a bonus target of 30.0% of the base salary and eligibility to participate in our share based long term incentive program. We offer comprehensive and generous benefits and programs to help our colleagues lead healthy lives and to support each of life's moments. Benefits offered include a 401(k) plan with Pfizer Matching Contributions and an additional Pfizer Retirement Savings Contribution, paid vacation, holiday and personal days, paid caregiver/parental and medical leave, and health benefits to include medical, prescription drug, dental and vision coverage. Learn more at Pfizer Candidate Site – U.S. Benefits | ). Pfizer compensation structures and benefit packages are aligned based on the location of hire. The United States salary range provided does not apply to Tampa, FL or any location outside of the United States.
Relocation assistance may be available based on business needs and/or eligibility.
Sunshine Act
Pfizer reports payments and other transfers of value to health care providers as required by federal and state transparency laws and implementing regulations. These laws and regulations require Pfizer to provide government agencies with information such as a health care provider's name, address and the type of payments or other value received, generally for public disclosure. Subject to further legal review and statutory or regulatory clarification, which Pfizer intends to pursue, reimbursement of recruiting expenses for licensed physicians may constitute a reportable transfer of value under the federal transparency law commonly known as the Sunshine Act. Therefore, if you are a licensed physician who incurs recruiting expenses as a result of interviewing with Pfizer that we pay or reimburse, your name, address and the amount of payments made currently will be reported to the government. If you have questions regarding this matter, please do not hesitate to contact your Talent Acquisition representative.
EEO & Employment Eligibility
Pfizer is committed to equal opportunity in the terms and conditions of employment for all employees and job applicants without regard to race, color, religion, sex, sexual orientation, age, gender identity or gender expression, national origin, disability or veteran status. Pfizer also complies with all applicable national, state and local laws governing nondiscrimination in employment as well as work authorization and employment eligibility verification requirements of the Immigration and Nationality Act and IRCA. Pfizer is an E-Verify employer. This position requires permanent work authorization in the United States.
Pfizer endeavors to make accessible to all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process and/or interviewing, please email This is to be used solely for accommodation requests with respect to the accessibility of our website, online application process and/or interviewing. Requests for any other reason will not be returned.
Information & Business Tech
-
Regulatory cybersecurity compliance PM
5 days ago
New York, New York, United States Talan Full time $100,000 - $155,000Company Description Talan is an international consulting group in innovation and transformation through technology. For 20 years, Talan has been advising companies and administrations. The group supports them and implements their transformation and innovation projects internationally.Present on five continents, the group achieved a turnover of 600 million...
-
Third Party Risk Analyst
4 days ago
New York, New York, United States Agency Cybersecurity Full time $60,000 - $80,000 per year*About Agency Cybersecurity:*Agency Cybersecurity is fast growing ventured back startup that provides best-in-class cybersecurity and compliance. Our software and services simplify complex compliance frameworks including SOC2, ISO 27001, HIPAA, and others, empowering businesses to scale securely and confidently. We're backed by top tier investors like Y...
-
Director, Governance, Risk, and Compliance
6 days ago
New York, New York, United States adswizz Full time $182,000 - $245,000 per yearNew York, New YorkRegular Employee Full-TimeR HybridWho We Are:SiriusXM and its brands (Pandora, SiriusXM Media, AdsWizz, Simplecast, and SiriusXM Connect are leading a new era of audio entertainment and services by delivering the most compelling subscription and ad-supported audio entertainment experience for listeners - in the car, at home, and anywhere on...
-
Junior Cybersecurity Analyst
5 days ago
New York, New York, United States Agency Cybersecurity Full time $20 - $25Location: On-Site in Flatiron, NYCPosition Type: Hourly, Full-Time Experience Level: Entry-levelCompensation: $20-25 per hourJob Summary:As a junior cybersecurity analyst at Agency, you will be crucial in bridging the gap between technology, our customers, and our internal business operations. You will work closely with multiple stakeholders to provide...
-
Sr. Analyst, Cybersecurity
4 days ago
New York, New York, United States News Corp Full time $150,000 - $170,000 per yearEqual Opportunity EmployerAll qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, national origin, protected veteran status, or disability status. EEO/Disabled/VetsJob Description :*Job Title: Senior Cybersecurity AnalystLocation - NYCHybrid - 3 days in office*As a global media and information...
-
BIA Wholesale Credit Risk VP
5 days ago
New York, New York, United States Barclays Full time $150,000 - $210,000Job DescriptionPurpose of the roleTo support the development of audits aligned to the bank's standards and objectives by working collaboratively with colleagues, providing accurate information and recommendations, and complying with policies and procedures.AccountabilitiesAudit development and delivery support, including financial statements, accounting...
-
New York, New York, United States Barclays Full time $145,000 - $200,000Job DescriptionPurpose of the roleTo provide data-led expert oversight and check and challenge on business and compliance matters to evidence that the organisation is operating in a compliance with Barclays legal, regulatory and ethical responsibilities. AccountabilitiesIdentification and assessment of compliance risks through thorough reviews of business...
-
Cybersecurity Contractor
1 day ago
New York, New York, United States RSC Solutions Full time $120,000 - $180,000 per yearShort Term ContractRemoteClient is looking for a Cybersecurity Contractor, you will support the project team by ensuring the security and integrity of information systems and data. Conduct security assessments and vulnerability analyses to identify potential risks. Implement and maintain cybersecurity measures, including firewalls, encryption, and intrusion...
-
VP, Enterprise Risk Management
5 days ago
New York, New York, United States Coda Search│Staffing Full time $150,000 - $250,000 per yearOur client is a publicly traded real estate investment platform with a diversified portfolio of mortgage-related assets and a growing advisory and mortgage-origination footprint. Through recent strategic acquisitions, the firm has expanded into residential mortgage origination, real estate credit asset management, and third-party advisory services. The...
-
VP Compliance Officer
24 hours ago
New York, New York, United States JCW Group Full time $150,000 - $200,000 per yearOur client, a broker-dealer is seeking a Senior Compliance Officer to join its U.S. compliance team. The firm provides equity and fixed income sales and trading, capital markets underwriting, and third-party research distribution to institutional clients, operating within a strong culture of compliance and integrity.Key Responsibilities:Advise business lines...