senior associate, cyber governance and risk 4960589
Aug 8, 2026 · Pfizer Hellas
What you'll do
- Assist in defining and maintaining the organization’s GRC plan
- Support the maintenance and alignment of Pfizer’s GRC program to cybersecurity governance frameworks
- Review and update cybersecurity policies, standards, and procedural documents
- Monitor regulatory changes and industry trends to ensure compliance
- Identify potential security issues across systems, processes, and vendors
- Conduct structured risk analysis to identify security threats and vulnerabilities
- Support the creation and tracking of action plans to manage risks
- Perform risk assessments to validate security controls and compliance requirements
- Identify and assist in tracking GRC key metrics for informed decision-making
Key requirements
- 2+ years' experience
- Experience with cybersecurity control frameworks such as NIST, ISO, COBIT
- Cybersecurity policies and standards management
- Risk assessment and analysis
- GRC plan development and maintenance
- Compliance monitoring and regulatory change monitoring
- Written communication skills and stakeholder communication
- Collaboration and interpersonal skills in an agile work environment
- Problem-solving attitude and information technology knowledge
- Computer Science / Cybersecurity / Any Field
About the job
Our Global Governance, Risk, and Compliance (GRC) team provides comprehensive blueprints for cybersecurity excellence by embedding governance, risk management, and compliance into every layer. The team is responsible for ensuring risk-based decision-making is used and that security, privacy, and regulatory compliance is integrated seamlessly with Pfizer’s organization.
We are seeking a motivated Senior Associate, Risk and Governance to help strengthen the organization’s overall security governance. In this role, you will support the development and maintenance of cybersecurity policies, frameworks, and the wider GRC plan, while keeping an eye on regulatory changes. This role will assist in identifying and assessing risks, maintaining accurate risk information, and ensuring controls and compliance requirements are being followed through audits and follow‑up activities. This Senior Associate will also prepare clear insights and governance‑level metrics that support informed decision‑making.
ROLE RESPONSIBILITIES
Assist in defining and maintaining the organization’s GRC plan.
Support the maintenance and alignment of Pfizer’s GRC program to cybersecurity governance frameworks (e.g., NIST CSF, ISO 27001).
Review and update cybersecurity policies, standards, and procedural documents.
Monitor regulatory changes and industry trends to ensure the organization remains compliant and proactive in addressing emerging risks.
Identify potential security issues across systems, processes, and vendors by gathering information from assessments, audits, and internal teams.
Conduct structured risk analysis to identify potential security threats, vulnerabilities, and impacts across systems and processes.
Support the creation and tracking of action plans to reduce or manage risks, ensuring decisions and next steps are clearly documented.
Perform risk assessments to validate that defined security controls, policies, and compliance requirements are properly implemented and followed across the organization.
Identify and assist in tracking GRC key metrics, ensuring they support informed decision‑making at leadership and committee levels.
BASIC QUALIFICATIONS
Bachelor’s degree in information technology, cybersecurity, computer science, or a related field.
2+ years of experience in cybersecurity, or related field.
Experience with cybersecurity control frameworks (NIST, ISO, COBIT, etc.).
Ability to support complex programs by coordinating tasks, tracking progress, and assisting with stakeholder communications.
Solid understanding of core cybersecurity principles, technologies, and risks to effectively collaborate with technical teams and support governance activities.
Strong ability to produce clear, concise, and professional written communications and reports.
Excellent collaboration and interpersonal skills, with the ability to work effectively across levels and functions to support program objectives.
Demonstrated experience in an agile work environment possessing qualities such as a collaborative mindset, adaptability to change, and a proactive problem-solving approach.
PREFERRED QUALIFICATIONS
Demonstrated experience working in pharmaceutical, biotech, or other highly regulated industries.
Professional certifications such as CISSP, CISM, CRISC, CISA, PMP, or similar.

