manager, offensive security 4960975
8 Αυγ 2026 · Pfizer Hellas
Τι θα κάνεις
- Διοργανώνεις καθημερινές επιθεωρήσεις offensive security όπως penetration testing, red και purple team ασκήσεις, και προσομοιώσεις αντιπάλων
- Καθοδηγείς και συμβουλεύεις ομάδα μηχανικών offensive security παρέχοντας τεχνική καθοδήγηση και προτεραιοποίηση
- Οργανώνεις τον σχεδιασμό, το εύρος και την παράδοση των αξιολογήσεων offensive security με βάση τους κινδύνους και τις προτεραιότητες της επιχείρησης
- Τεκμηριώνεις, επικυρώνεις και επικοινωνείς ευρήματα offensive security σε ομάδες ανίχνευσης, αποκατάστασης και διαχείρισης κινδύνου
- Συνεργάζεσαι με ομάδες Threat Detection, Incident Response και Engineering για μετατροπή των ευρημάτων σε μετρήσιμες βελτιώσεις κινδύνου
- Υποστηρίζεις τη συνεχή βελτίωση εργαλείων, μεθοδολογιών και διαδικασιών offensive security για μεγαλύτερη κάλυψη και αποτελεσματικότητα
- Παρακολουθείς τα αποτελέσματα των ενεργειών, τα επαναλαμβανόμενα κενά ελέγχου και τις τάσεις κινδύνου και αναφέρεις σημαντικά θέματα
- Διασφαλίζεις ότι οι δραστηριότητες offensive security εκτελούνται σύμφωνα με πολιτικές, ρυθμιστικές απαιτήσεις και ηθικά πρότυπα δοκιμών
- Συμβάλλεις στην ανάπτυξη και συντήρηση τεκμηρίωσης, playbooks και προτύπων αναφοράς για offensive security
Βασικές προϋποθέσεις
- 4+ χρόνια εμπειρίας
- Μεθοδολογίες red team και προσομοίωσης αντιπάλων ευθυγραμμισμένες με MITRE ATT&CK
- Penetration testing εφαρμογών, cloud, δικτύων και ταυτοτήτων
- Κοινωνική μηχανική και προσομοιώσεις phishing όπου απαιτούνται
- Εργαλεία και frameworks offensive security συνηθισμένα στη βιομηχανία
- Cloud security σε περιβάλλοντα AWS, Azure και GCP
- Τεκμηρίωση και επικοινωνία ευρημάτων ασφάλειας σε τεχνικές και μη τεχνικές ομάδες
- Λήψη αποφάσεων βάσει ανάλυσης κινδύνου και διαχείριση προτεραιοτήτων σε ρυθμισμένο περιβάλλον
- Βελτίωση διαδικασιών offensive security για κάλυψη, ρεαλισμό και αποδοτικότητα
- Ασφάλεια Πληροφοριών / Πληροφορική / Μηχανικήκατά προτίμηση
Περιγραφή Θέσης
Our Global Cyber Defense team is responsible for safeguarding Pfizer’s digital assets and infrastructure through proactive threat detection, response, and risk mitigation across on-premises, cloud, and hybrid environments.
The Manager, Offensive Security is responsible for leading the execution of offensive security activities that proactively identify, validate, and help prioritize security weaknesses across the digital environment. This role leads day‑to‑day offensive security operations, including penetration testing, red and purple team exercises, and adversary simulation activities. Operating within a highly regulated pharmaceutical environment, the role partners closely with detection, remediation, engineering, and risk teams to ensure offensive findings are clearly communicated, actionable, and effectively translated into measurable risk reduction and improved defensive outcomes. This role will report to the Sr. Manager, Offensive Security.
ROLE RESPONSIBILITIES
Lead the day‑to‑day execution of offensive security activities, including penetration testing, red team engagements, purple team exercises, and adversary simulation efforts.
Guide or mentor a team of offensive security engineers, providing technical direction, prioritization, and coaching.
Oversee planning, scoping, and delivery of offensive security assessments to ensure activities are risk‑based, repeatable, and aligned with business priorities.
Ensure offensive security findings are clearly documented, validated, and communicated to detection, remediation, engineering, and risk teams.
Partner closely with Threat Detection, Incident Response, Vulnerability Management, and Engineering teams to translate offensive findings into actionable improvements and measurable risk reduction.
Support the continuous improvement of offensive security tools, methodologies, and processes to increase coverage, realism, and operational efficiency.
Track engagement outcomes, recurring control gaps, and risk trends, escalating material issues and insights.
Ensure offensive security activities are conducted in alignment with internal policies, regulatory expectations, and ethical testing standards.
Contribute to the development and maintenance of offensive security documentation, playbooks, and reporting standards.
BASIC QUALIFICATIONS
Bachelor’s degree in Information Security, Computer Science, Engineering, or a related field, or equivalent practical experience.
4+ years of experience in cybersecurity, with significant focus on offensive security, penetration testing, red teaming, or adversary simulation.
Strong hands‑on knowledge of:
Red team and adversary emulation methodologies (MITRE ATT&CK–aligned)
Application, cloud, network, and identity penetration testing
Social engineering and phishing simulations (where appropriate)
Tooling and frameworks commonly used in offensive security
Solid understanding of modern enterprise environments (cloud, SaaS, hybrid).
Experience documenting, validating, and communicating offensive security findings to technical and non‑technical stakeholders.
Ability to manage priorities, make risk‑based decisions, and operate effectively in a fast‑paced, highly regulated environment.
PREFERRED QUALIFICATIONS
Experience in pharmaceutical, biotech, life sciences, or similarly regulated industries.
Experience with cloud-native red teaming (AWS, Azure, GCP) and identity-centric attack paths.
Familiarity with detection engineering, SIEM/SOAR, and threat intelligence workflows.
Professional certifications such as OSCP, OSEP, CRTO, CISSP, GIAC, or similar offensive security‑focused credentials.
Strong communication skills, with the ability to clearly articulate technical risk, attack feasibility, and business impact to senior technical and non‑technical stakeholders.

