manager, offensive security 4960975
Aug 8, 2026 · Pfizer Hellas
What you'll do
- Lead offensive security activities including penetration testing, red team engagements, purple team exercises, and adversary simulations
- Guide and mentor offensive security engineers with technical direction and prioritization
- Oversee planning, scoping, and delivery of offensive security assessments aligned with business priorities
- Document, validate, and communicate offensive security findings to detection, remediation, engineering, and risk teams
- Partner with Threat Detection, Incident Response, Vulnerability Management, and Engineering teams to translate findings into actionable improvements
- Support continuous improvement of offensive security tools, methodologies, and processes
- Track engagement outcomes, recurring control gaps, and risk trends, escalating material issues
- Ensure compliance with internal policies, regulatory expectations, and ethical testing standards
- Contribute to the development and maintenance of offensive security documentation, playbooks, and reporting standards
Key requirements
- 4+ years' experience
- Red team and adversary emulation methodologies
- Application, cloud, network, and identity penetration testing
- Social engineering and phishing simulations
- Offensive security tooling and frameworks
- Cloud security including AWS, Azure, and GCP
- Documentation and communication of security findings
- Risk-based decision making
- Information Security / Computer Science / Engineeringpreferred
About the job
Our Global Cyber Defense team is responsible for safeguarding Pfizer’s digital assets and infrastructure through proactive threat detection, response, and risk mitigation across on-premises, cloud, and hybrid environments.
The Manager, Offensive Security is responsible for leading the execution of offensive security activities that proactively identify, validate, and help prioritize security weaknesses across the digital environment. This role leads day‑to‑day offensive security operations, including penetration testing, red and purple team exercises, and adversary simulation activities. Operating within a highly regulated pharmaceutical environment, the role partners closely with detection, remediation, engineering, and risk teams to ensure offensive findings are clearly communicated, actionable, and effectively translated into measurable risk reduction and improved defensive outcomes. This role will report to the Sr. Manager, Offensive Security.
ROLE RESPONSIBILITIES
Lead the day‑to‑day execution of offensive security activities, including penetration testing, red team engagements, purple team exercises, and adversary simulation efforts.
Guide or mentor a team of offensive security engineers, providing technical direction, prioritization, and coaching.
Oversee planning, scoping, and delivery of offensive security assessments to ensure activities are risk‑based, repeatable, and aligned with business priorities.
Ensure offensive security findings are clearly documented, validated, and communicated to detection, remediation, engineering, and risk teams.
Partner closely with Threat Detection, Incident Response, Vulnerability Management, and Engineering teams to translate offensive findings into actionable improvements and measurable risk reduction.
Support the continuous improvement of offensive security tools, methodologies, and processes to increase coverage, realism, and operational efficiency.
Track engagement outcomes, recurring control gaps, and risk trends, escalating material issues and insights.
Ensure offensive security activities are conducted in alignment with internal policies, regulatory expectations, and ethical testing standards.
Contribute to the development and maintenance of offensive security documentation, playbooks, and reporting standards.
BASIC QUALIFICATIONS
Bachelor’s degree in Information Security, Computer Science, Engineering, or a related field, or equivalent practical experience.
4+ years of experience in cybersecurity, with significant focus on offensive security, penetration testing, red teaming, or adversary simulation.
Strong hands‑on knowledge of:
Red team and adversary emulation methodologies (MITRE ATT&CK–aligned)
Application, cloud, network, and identity penetration testing
Social engineering and phishing simulations (where appropriate)
Tooling and frameworks commonly used in offensive security
Solid understanding of modern enterprise environments (cloud, SaaS, hybrid).
Experience documenting, validating, and communicating offensive security findings to technical and non‑technical stakeholders.
Ability to manage priorities, make risk‑based decisions, and operate effectively in a fast‑paced, highly regulated environment.
PREFERRED QUALIFICATIONS
Experience in pharmaceutical, biotech, life sciences, or similarly regulated industries.
Experience with cloud-native red teaming (AWS, Azure, GCP) and identity-centric attack paths.
Familiarity with detection engineering, SIEM/SOAR, and threat intelligence workflows.
Professional certifications such as OSCP, OSEP, CRTO, CISSP, GIAC, or similar offensive security‑focused credentials.
Strong communication skills, with the ability to clearly articulate technical risk, attack feasibility, and business impact to senior technical and non‑technical stakeholders.

