Lead day-to-day enterprise vulnerability management: run and validate scans, prioritize and translate findings into remediation guidance, coordinate fixes across teams, track closure and metrics, manage a team of analysts, and drive process and tooling improvements to reduce cyber risk and meet compliance.
ROLE SUMMARY
Our Global Cyber Defense team is responsible for safeguarding Pfizer's digital assets and infrastructure through proactive threat detection, response, and risk mitigation across on-premises, cloud, and hybrid environments.
The Manager, Vulnerability Management is responsible for leading the execution of vulnerability management activities to identify, assess, prioritize, and reduce security weaknesses across the enterprise. This role oversees day‑to‑day vulnerability management operations, including scanning, analysis, prioritization, and remediation coordination. The role partners closely with engineering, infrastructure, cloud services, application, and security teams to ensure vulnerabilities are addressed in a timely, risk‑based, and compliant manner to reduce overall cyber exposure.
ROLE RESPONSIBILITIES
BASIC QUALIFICATIONS
PREFERRED QUALIFICATIONS
PHYSICAL/MENTAL REQUIREMENTS
NON-STANDARD WORK SCHEDULE, TRAVEL OR ENVIRONMENT REQUIREMENTS
OTHER JOB DETAILS
Relocation assistance may be available based on business needs and/or eligibility.
Candidates must be authorized to be employed in the U.S. by any employer.
U.S. work visa sponsorship (such as TN, O-1, H-1B, etc.) is not available for this role now or in the future.
Sunshine Act
Pfizer reports payments and other transfers of value to health care providers as required by federal and state transparency laws and implementing regulations. These laws and regulations require Pfizer to provide government agencies with information such as a health care provider's name, address and the type of payments or other value received, generally for public disclosure. Subject to further legal review and statutory or regulatory clarification, which Pfizer intends to pursue, reimbursement of recruiting expenses for licensed physicians may constitute a reportable transfer of value under the federal transparency law commonly known as the Sunshine Act. Therefore, if you are a licensed physician who incurs recruiting expenses as a result of interviewing with Pfizer that we pay or reimburse, your name, address and the amount of payments made currently will be reported to the government. If you have questions regarding this matter, please do not hesitate to contact your Talent Acquisition representative.
EEO & Employment Eligibility
Pfizer is committed to equal opportunity in the terms and conditions of employment for all employees and job applicants without regard to race, color, religion, sex, sexual orientation, age, gender identity or gender expression, national origin, disability or veteran status. Pfizer also complies with all applicable national, state and local laws governing nondiscrimination in employment as well as work authorization and employment eligibility verification requirements of the Immigration and Nationality Act and IRCA. Pfizer is an E-Verify employer. This position requires permanent work authorization in the United States.
Pfizer endeavors to make www.pfizer.com/careers accessible to all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process and/or interviewing, please email [email protected] . This is to be used solely for accommodation requests with respect to the accessibility of our website, online application process and/or interviewing. Requests for any other reason will not be returned.
To learn more about acceptable and prohibited uses of AI during the recruitment process, please review our candidate AI-use guidelines available on Pfizer Careers .
Information & Business Tech
Our Global Cyber Defense team is responsible for safeguarding Pfizer's digital assets and infrastructure through proactive threat detection, response, and risk mitigation across on-premises, cloud, and hybrid environments.
The Manager, Vulnerability Management is responsible for leading the execution of vulnerability management activities to identify, assess, prioritize, and reduce security weaknesses across the enterprise. This role oversees day‑to‑day vulnerability management operations, including scanning, analysis, prioritization, and remediation coordination. The role partners closely with engineering, infrastructure, cloud services, application, and security teams to ensure vulnerabilities are addressed in a timely, risk‑based, and compliant manner to reduce overall cyber exposure.
ROLE RESPONSIBILITIES
- Lead the day‑to‑day execution of the vulnerability management program, ensuring consistent identification, assessment, and prioritization of vulnerabilities across enterprise environments.
- Manage and develop a team of vulnerability management analysts, providing technical guidance, prioritization, coaching, and performance feedback.
- Oversee vulnerability scanning activities across infrastructure, endpoints, cloud platforms, and applications, ensuring coverage and data quality.
- Translate vulnerability findings into clear, actionable remediation guidance for technical owners, aligned to risk, exploitability, and business impact.
- Coordinate remediation efforts with Infrastructure, Cloud Services, Engineering, Endpoint Security, and other technology teams to drive timely risk reduction.
- Partner with Threat Intelligence, Threat Remediation, and Incident Response teams to incorporate threat context and active exploitation signals into prioritization decisions.
- Track remediation progress, validate closure, and identify recurring issues or systemic control gaps requiring escalation or broader corrective action.
- Ensure vulnerability management activities align with internal policies, regulatory requirements, and audit expectations.
- Maintain reporting and metrics on vulnerability trends, remediation performance, and risk posture for Cyber Defense leadership.
- Drive continuous improvement of vulnerability management processes, tooling, and workflows to increase efficiency, accuracy, and impact.
BASIC QUALIFICATIONS
- Applicant must have a bachelor's degree in Information Security, Computer Science, Engineering, Information Technology, or a related field with at least 4 years of experience in cybersecurity, with a strong focus on vulnerability management, security operations, or exposure management; OR a master's degree with at least 2 years of experience; OR as associate's degree with 8 years of experience; OR a high school diploma (or equivalent) and 10 years of relevant experience.
- Demonstrated responsibility for executing or overseeing vulnerability scanning, assessment, prioritization, and remediation tracking across infrastructure, endpoints, cloud platforms, or applications.
- Experience translating vulnerability findings into risk‑based remediation guidance for infrastructure, cloud, application, or platform engineering teams.
- Prior responsibility for coordinating remediation activities, including tracking ownership, validating fixes, managing exceptions, and escalating blocked or overdue items.
- Familiarity with vulnerability severity, exploitability concepts, and compensating controls used to manage risk when immediate remediation is not feasible.
- Experience leading analysts or serving as a technical lead responsible for task prioritization, quality assurance, and day‑to‑day delivery.
- Strong analytical, organizational, and problem‑solving skills.
- Demonstrated experience in an agile work environment possessing qualities such as a collaborative mindset, adaptability to change, and a proactive problem-solving approach.
PREFERRED QUALIFICATIONS
- Familiarity with vulnerability management in cloud or hybrid enterprise environments.
- Understanding of integrating threat context, exploitability, or attack paths into vulnerability prioritization.
- Exposure to operating in regulated or highly controlled environments such as healthcare, life sciences, or manufacturing.
- Experience supporting audit, compliance, or regulatory activities related to vulnerability management.
- Ability to identify trends and drive process or control improvements over time.
- Relevant professional certifications in cybersecurity or vulnerability management (e.g., CISSP, CISM, Security+, etc.)
PHYSICAL/MENTAL REQUIREMENTS
- No special physical requirements.
- Applicants should be capable of working through a personal laptop computer or mobile device for extended periods.
NON-STANDARD WORK SCHEDULE, TRAVEL OR ENVIRONMENT REQUIREMENTS
- Travel as required by the business (less than 5% domestic and/or international)
- Work Location Assignment: Must be able to work in assigned Pfizer office 2-3 days per week, or as needed by the business
- This role is NOT remote
OTHER JOB DETAILS
- Last Date to Apply for Job: August 17. 2026
- Work Location Assignment: Must be able to work from assigned Pfizer office 2-3 days per week, or as needed by the business
Relocation assistance may be available based on business needs and/or eligibility.
Candidates must be authorized to be employed in the U.S. by any employer.
U.S. work visa sponsorship (such as TN, O-1, H-1B, etc.) is not available for this role now or in the future.
Sunshine Act
Pfizer reports payments and other transfers of value to health care providers as required by federal and state transparency laws and implementing regulations. These laws and regulations require Pfizer to provide government agencies with information such as a health care provider's name, address and the type of payments or other value received, generally for public disclosure. Subject to further legal review and statutory or regulatory clarification, which Pfizer intends to pursue, reimbursement of recruiting expenses for licensed physicians may constitute a reportable transfer of value under the federal transparency law commonly known as the Sunshine Act. Therefore, if you are a licensed physician who incurs recruiting expenses as a result of interviewing with Pfizer that we pay or reimburse, your name, address and the amount of payments made currently will be reported to the government. If you have questions regarding this matter, please do not hesitate to contact your Talent Acquisition representative.
EEO & Employment Eligibility
Pfizer is committed to equal opportunity in the terms and conditions of employment for all employees and job applicants without regard to race, color, religion, sex, sexual orientation, age, gender identity or gender expression, national origin, disability or veteran status. Pfizer also complies with all applicable national, state and local laws governing nondiscrimination in employment as well as work authorization and employment eligibility verification requirements of the Immigration and Nationality Act and IRCA. Pfizer is an E-Verify employer. This position requires permanent work authorization in the United States.
Pfizer endeavors to make www.pfizer.com/careers accessible to all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process and/or interviewing, please email [email protected] . This is to be used solely for accommodation requests with respect to the accessibility of our website, online application process and/or interviewing. Requests for any other reason will not be returned.
To learn more about acceptable and prohibited uses of AI during the recruitment process, please review our candidate AI-use guidelines available on Pfizer Careers .
Information & Business Tech
Pfizer New York, New York, USA Office
Pfizer Hudson Yards Office



66 Hudson Blvd E, Suite 20, New York, NY, United States, 10001
Pfizer Madison, New Jersey, USA Office
1 Giralda Farms, Madison, NJ, United States, 07940
Similar Jobs at Pfizer
Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
Senior enterprise leader responsible for strategy, portfolio management, and operational execution across Internal Medicine. Lead pipeline prioritization, decision frameworks, cross-functional mobilization, and AI/data integration to accelerate R&D and commercialization. Oversee global portfolio reviews, governance, business development diligence, and operational excellence while building and leading a high-performing team and driving enterprise alignment and resource decisions.
Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
Lead end-to-end commercial assessments for early- and mid-stage obesity assets. Build target product profiles, shape development strategy with R&D, integrate forecasting/pricing/market insights, prepare governance materials, support BD due diligence, and present investment cases to senior leadership while mobilizing cross-functional resources.
Top Skills:
AI
Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
Lead development of US contracting and pricing strategy for Pfizer vaccines across retail, IDNs, GPOs, government and provider channels. Create innovative contracting models and partnership frameworks, coordinate with brand, launch, and customer teams, drive access expansion, ensure compliance, and lead cross-functional teams to execute contracting plans.
What you need to know about the NYC Tech Scene
As the undisputed financial capital of the world, New York City is an epicenter of startup funding activity. The city has a thriving fintech scene and is a major player in verticals ranging from AI to biotech, cybersecurity and digital media. It also has universities like NYU, Columbia and Cornell Tech attracting students and researchers from across the globe, providing the ecosystem with a constant influx of world-class talent. And its East Coast location and three international airports make it a perfect spot for European companies establishing a foothold in the United States.
Key Facts About NYC Tech
- Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
- Key Industries: Artificial intelligence, Fintech
- Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
- Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
- Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory




