lead analyst, cyber threat intelligence 4960799
Aug 8, 2026 · Pfizer Hellas
What you'll do
- Define and execute cyber threat intelligence strategy aligned to business priorities and regulatory obligations
- Establish intelligence requirements focused on threats to pharmaceutical R&D, clinical operations, manufacturing, and third-party ecosystems
- Lead analysis of threat actors, campaigns, malware, and TTPs emphasizing nation-state, ransomware, insider, and supply-chain threats
- Partner with SOC and Detection Engineering to translate intelligence into use cases, alert tuning, and threat hunting hypotheses
- Support Incident Response by providing adversary context, next steps, and mitigation guidance
- Collaborate with Vulnerability Management to prioritize remediation based on active exploitation and threat relevance
- Manage relationships with threat intelligence vendors, industry ISACs, and trusted peer communities
- Advise cyber leadership on threat trends, business impact, and risk implications
- Define and track CTI metrics such as intelligence utilization and detection impact
- Continuously improve intelligence processes, tooling, and integration with cyber defense workflows
- Ensure CTI activities comply with policies, data handling requirements, and ethical standards
Key requirements
- 4+ years' experience
- Cyber threat intelligence and threat analysis of actors, campaigns, malware, and TTPs
- Knowledge of intelligence lifecycle processes and use of threat intelligence platforms
- Experience with open-source intelligence (OSINT) and commercial feeds
- Collaboration with security operations center (SOC), incident response, and vulnerability management teams
- Knowledge of MITRE ATT&CK framework
- Strong communication, organizational, and collaboration skills across global teams
- Cybersecurity knowledge and proactive problem-solving mindset
- Cybersecurity / Information Security / Computer Sciencepreferred
Benefits
- Travel as required by the business (less than 5%).
- Work in assigned Pfizer office 2-3 days per week or as needed by the business.
About the job
Our Global Cyber Defense team is responsible for safeguarding Pfizer’s digital assets and infrastructure through proactive threat detection, response, and risk mitigation across on-premises, cloud, and hybrid environments.
The Cyber Threat Intelligence (CTI) Lead is responsible for the development and execution of a threat intelligence program that enables proactive cyber defense across a global pharmaceutical enterprise. This role is responsible for transforming external and internal threat data into actionable intelligence that protects intellectual property, clinical trial systems, patient data, manufacturing operations, and the supply chain.
As part of the Cyber Defense organization, this role partners closely with the SOC and Incident Response, Vulnerability Management, Cloud Services, Endpoint Security, and GRC teams to anticipate adversary activity, inform detection and response, and guide strategic security decisions.
ROLE RESPONSIBILITIES
Define and execute the cyber threat intelligence strategy, aligned to business priorities, risk tolerance, and regulatory obligations.
Establish intelligence requirements focused on threats to pharmaceutical R&D, clinical operations, manufacturing, and third‑party ecosystems.
Lead analysis of threat actors, campaigns, malware, and TTPs, with emphasis on nation‑state, ransomware, insider, and supply‑chain threats relevant to life sciences.
Partner with SOC and Detection Engineering teams to translate intelligence into use‑case development, alert tuning, and threat‑hunting hypotheses.
Support Incident Response during active investigations by providing adversary context, likely next steps, and mitigation guidance.
Collaborate with Vulnerability Management to prioritize remediation based on active exploitation and threat relevance.
Manage relationships with threat intelligence vendors, industry ISACs, and trusted peer communities.
Serve as a trusted advisor to cyber leadership by clearly articulating threat trends, business impact, and risk implications.
Define and track CTI metrics (e.g., intelligence utilization, detection impact, stakeholder satisfaction).
Continuously improve intelligence processes, tooling, and integration with cyber defense workflows.
Ensure CTI activities align with internal policies, data handling requirements, and ethical standards.
BASIC QUALIFICATIONS
Bachelor’s degree in Cybersecurity, Information Security, Computer Science, or a related field, or equivalent practical experience.
4+ years of experience in cyber threat intelligence, security operations, threat detection, or related cybersecurity roles.
Strong understanding of cyber threat actors, attack techniques, and intelligence analysis concepts.
Experience working with threat intelligence sources, including open‑source intelligence and commercial feeds.
Ability to translate technical threat intelligence into clear, actionable insights for diverse stakeholders.
Strong organizational and communication skills, with the ability to manage priorities in a dynamic threat environment.
Demonstrated ability to effectively manage and collaborate with global, cross‑regional teams, including flexibility to participate in meetings aligned to global time zone needs.
Demonstrated experience in an agile work environment possessing qualities such as a collaborative mindset, adaptability to change, and a proactive problem-solving approach.
PREFERRED QUALIFICATIONS
Experience operating or supporting a formal Cyber Threat Intelligence capability within an enterprise environment.
Familiarity with threat intelligence platforms, intelligence lifecycle processes, and structured analytic techniques.
Knowledge of frameworks such as MITRE ATT&CK for adversary and tactic mapping.
Prior experience leading or mentoring analysts or serving in a technical lead or team‑lead capacity.
Experience collaborating with SOC, incident response, vulnerability management, or offensive security teams.
Exposure to regulated or highly controlled environments (e.g., healthcare, life sciences, financial services).
Relevant professional certifications (e.g., CISSP, CISM, GCTI, GCIH, or equivalent intelligence‑ or security‑focused credentials).
WORK SCHEDULE, TRAVEL REQUIREMENTS
Travel as required by the business (less than 5% domestic and/or international)
Work Location Assignment: Must be able to work in assigned Pfizer office 2-3 days per week, or as needed by the business

