> Markdown version of [/jobs/ext/1823341-manager-cyber-policy-governance-standards](https://www.wearedevelopers.com/jobs/ext/1823341-manager-cyber-policy-governance-standards). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Manager, Cyber Policy, Governance, Standards... - **Company:** Pfizer Inc. - **Location:** New York, NY, United States - **Experience:** Experienced - **Salary:** $99,200.0 - $165,400.0 - **Contract:** Permanent contract - **Skills:** Control Objectives for Information and Related Technology (COBIT), Cyber Security, Smartsuite, Cyber Threat Analysis, CIS Benchmarks - **Published:** July 20, 2026 - **Apply:** https://www.juju.com/job/00000000gimibm ## About the Role + Bachelor's degree required + 4+ years of experience in cybersecurity, enterprise risk management, cyber risk analysis, or GRC-related roles + Strong knowledge of cybersecurity frameworks and standards, including NIST CSF 2.0, CIS, COBIT, ISO + Strong strategic thinking, analytical capability, and problem-solving skills, ability to translate technical risk insights into recommendations + Excellent communication and interpersonal skills; ability to influence across levels and functions + Experience with GRC tools like Archer, or similar technologies + Demonstrated experience in an agile work environment possessing qualities such as a collaborative mindset, adaptability to change, and a proactive problem-solving approach. PREFERRED QUALIFICATIONS + Excellent strategic thinking + Deeply analytical and credible + Fact-based decision-making + Ability to challenge, influence, and support senior leadership + Excellent communication and presentation skills + Ability to bring structure to vaguely defined problems and solve them with creative yet pragmatic approaches + Resourceful, self-motivated, and proactive - strong drive for excellence PHYSICAL/MENTAL REQUIREMENTS PHYSICAL/MENTAL REQUIREMENTS + No special physical requirements. + Applicants should be capable of working through a personal laptop computer or mobile device for extended periods. NON-STANDARD WORK SCHEDULE, TRAVEL OR ENVIRONMENT REQUIREMENTS NON-STANDARD WORK SCHEDULE, TRAVEL OR ENVIRONMENT REQUIREMENTS + Travel as required by the business (less than 5% domestic and/or international) + Work Location Assignment: Must be able to work in assigned Pfizer office 2-3 days per week, or as needed by the business ## Description Our Global Cybersecurity Governance, Risk, and Compliance (GRC) team provides comprehensive blueprints for cybersecurity excellence by embedding governance, risk management, and compliance into every layer. The team is responsible for ensuring risk-based decision-making is used and that security, privacy, and regulatory compliance is integrated seamlessly with Pfizer's organization. We are seeking an experienced Manager, Cyber Policy, Governance, Standards & Control Management to join our Cyber GRC organization. This role is responsible for leading the development, maintenance, and governance of the enterprise cybersecurity policy framework, security standards, control library, and governance processes that enable effective cyber risk management across a global pharmaceutical environment. The ideal candidate combines strong cybersecurity knowledge with governance expertise and regulatory awareness to ensure cybersecurity requirements are aligned to industry frameworks, business objectives, and evolving regulatory expectations. This leader will partner across Digital, Legal, Quality, Privacy, Risk Management, and business functions to drive a consistent and sustainable control environment. ROLE RESPONSIBILITIES + Lead the lifecycle management of enterprise cybersecurity policies, standards, baselines, and supporting governance documents. + Establish and maintain a structured policy governance framework, including review cycles, approvals, exception management, and stakeholder engagement. + Manage governance processes that provide oversight of cybersecurity program effectiveness, compliance, and risk posture. + Develop governance reporting, metrics, and key performance indicators (KPIs) to measure program maturity and control effectiveness. + Maintain the enterprise cybersecurity controls framework and control library. + Support mapping of security controls to industry frameworks and regulatory requirements, including NIST CSF 2.0, ISO 27001, NIST 800-53, CIS Controls, NIS2, and applicable pharmaceutical regulations. + Partner with control owners to define control objectives, implementation guidance, and testing requirements. + Drive improvements to control design, rationalization, and coverage to address emerging cybersecurity risks. + Collaborate with cyber risk, audit, compliance, privacy, and quality teams to address findings, control gaps, and remediation activities. + Support internal audits, regulatory inspections, assessments, and external assurance activities. + Provide governance oversight for risk exceptions, compensating controls, and remediation tracking. + Build strong partnerships across cybersecurity, technology, business, legal, privacy, and compliance functions. + Provide subject matter expertise on cybersecurity governance, policy development, and control management. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [A practical guide to writing secure Dockerfiles](https://www.wearedevelopers.com/videos/109-a-practical-guide-to-writing-secure-dockerfiles) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [OPA for the cloud natives](https://www.wearedevelopers.com/videos/713-opa-for-the-cloud-natives) - [Designing How Work Feels: The Science Behind Sanofi’s Workplace Experience](https://www.wearedevelopers.com/videos/1848-designing-how-work-feels-the-science-behind-sanofi-s-workplace-experience) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Best Companies to Work For in Berlin: Top 14 Companies in 2023 ](https://www.wearedevelopers.com/magazine/188-best-companies-to-work-for-in-berlin-top-14-companies-in-2023) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [Does The Tech Industry Have The Best Work-life Balance?](https://www.wearedevelopers.com/magazine/427-does-the-tech-industry-have-the-best-work-life-balance) - [UK Business Culture and Etiquette](https://www.wearedevelopers.com/magazine/326-uk-business-culture-and-etiquette)