Назад
Company hidden
2 дня назад

Director, Third-Party Risk Management and Technical Information Security Lead (Cybersecurity)

176 600 - 294 300$
Формат работы
hybrid
Тип работы
fulltime
Грейд
director
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Director, Third-Party Risk Management and Technical Information Security Lead (Cybersecurity): Owning Pfizer’s enterprise third-party cyber risk strategy and advising senior leaders on security risks across critical initiatives and platforms with an accent on risk governance, regulatory alignment, and vendor oversight. Focus on designing scalable risk assessment models, governing remediation and risk acceptance, and translating complex technical risks into executive-level decisions.

Location: New York City, United States; hybrid work with attendance at an assigned hirify.global office 2–3 days per week or as required by the business. This role is not remote.

Annual base salary: $176,600–$294,300, plus a 20% bonus target and eligibility for a share-based long-term incentive program.

Company

hirify.global is a global pharmaceutical company with a highly regulated environment and enterprise cybersecurity, governance, risk, and compliance functions.

What you will do

  • Own the enterprise Third-Party Risk Management security strategy, program, and operating model.
  • Align third-party risk management with cyber risk appetite, business priorities, and pharmaceutical regulatory expectations.
  • Establish scalable risk tiering, assessment, reassessment, continuous monitoring, and exception governance approaches.
  • Provide executive oversight of high-risk and critical vendor assessments, remediation priorities, compensating controls, and formal risk acceptances.
  • Act as the senior Technical Information Security Lead and trusted cybersecurity advisor for major initiatives, platforms, and transformations.
  • Partner with Procurement, Legal, Privacy, Quality, Security, Internal Audit, and business leaders while developing talent and improving capability maturity.

Requirements

  • Bachelor’s degree with 8+ years of experience, master’s degree with more than 7+ years, or Ph.D. with 5+ years.
  • 8+ years of experience in cybersecurity, cyber risk, GRC, TPRM, security architecture, IT risk, or audit.
  • Experience leading and developing teams, including direct management of technical and cybersecurity professionals.
  • Experience leading complex risk programs with multiple stakeholders and competing priorities.
  • Strong strategic, analytical, problem-solving, communication, organizational, and leadership skills.
  • Permanent U.S. work authorization is required. U.S. work visa sponsorship is not available now or in the future.

Nice to have

  • Advanced degree in business administration, risk management, information security, or a related discipline.
  • Experience maturing enterprise-wide TPRM or risk governance programs in complex global organizations.
  • Experience in highly regulated industries and familiarity with third-party oversight requirements.
  • Certifications such as CISSP, CISM, CRISC, CISA, PMP, or other governance and risk credentials.
  • Experience using AI and digital technologies to improve efficiency, risk management, decision-making, or security outcomes.

Culture & Benefits

  • Hybrid work arrangement with less than 5% domestic and/or international travel.
  • Participation in hirify.global’s Global Performance Plan with a 20% bonus target.
  • Eligibility for a share-based long-term incentive program.
  • Benefits include a 401(k) with hirify.global contributions, paid vacation and holidays, caregiver/parental and medical leave, and medical, prescription, dental, and vision coverage.
  • Relocation assistance may be available based on business needs and eligibility.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →