senior associate, cyber governance and risk 4960589
8 Αυγ 2026 · Pfizer Hellas
Τι θα κάνεις
- Υποστηρίζεις την ανάπτυξη και διατήρηση του σχεδίου GRC της οργάνωσης.
- Διατηρείς και ευθυγραμμίζεις το πρόγραμμα GRC με πλαίσια κυβερνοασφάλειας όπως NIST CSF και ISO 27001.
- Ενημερώνεις και ενημερώνεις πολιτικές, πρότυπα και διαδικαστικά έγγραφα κυβερνοασφάλειας.
- Παρακολουθείς αλλαγές κανονισμών και τάσεις στη βιομηχανία για συμμόρφωση και πρόληψη κινδύνων.
- Αναγνωρίζεις πιθανά ζητήματα ασφαλείας μέσω αξιολογήσεων, ελέγχων και συνεργασίας με εσωτερικές ομάδες.
- Διεξάγεις ανάλυση κινδύνου για εντοπισμό απειλών και ευπαθειών σε συστήματα και διαδικασίες.
- Υποστηρίζεις τη δημιουργία και παρακολούθηση σχεδίων δράσης για διαχείριση κινδύνων.
- Εκτελείς αξιολογήσεις κινδύνου για τη διασφάλιση εφαρμογής πολιτικών και απαιτήσεων συμμόρφωσης.
- Καθορίζεις και παρακολουθείς βασικούς δείκτες GRC για ενίσχυση της ενημερωμένης λήψης αποφάσεων.
Βασικές προϋποθέσεις
- 2+ χρόνια εμπειρίας
- Γνώση πλαισίων ελέγχου κυβερνοασφάλειας όπως NIST, ISO και COBIT.
- Διαχείριση πολιτικών και προτύπων κυβερνοασφάλειας και διατήρηση σχεδίου GRC.
- Αξιολόγηση και ανάλυση κινδύνου και παρακολούθηση κινδύνων με υποστήριξη σχεδίων δράσης.
- Παρακολούθηση συμμόρφωσης και αλλαγών κανονισμών στον τομέα κυβερνοασφάλειας.
- Ισχυρές δεξιότητες γραπτής επικοινωνίας και παραγωγής επαγγελματικών αναφορών.
- Επικοινωνία και συντονισμός με ενδιαφερόμενα μέρη, συνεργασία και διαπροσωπικές δεξιότητες.
- Εμπειρία σε Agile εργασιακό περιβάλλον και προσέγγιση επίλυσης προβλημάτων.
- Γνώση τεχνολογιών πληροφοριών σχετικών με διακυβέρνηση και ασφάλεια.
- Πληροφορική / Ασφάλεια Πληροφοριακών Συστημάτων / Οποιοδήποτε Πεδίο
Περιγραφή Θέσης
Our Global Governance, Risk, and Compliance (GRC) team provides comprehensive blueprints for cybersecurity excellence by embedding governance, risk management, and compliance into every layer. The team is responsible for ensuring risk-based decision-making is used and that security, privacy, and regulatory compliance is integrated seamlessly with Pfizer’s organization.
We are seeking a motivated Senior Associate, Risk and Governance to help strengthen the organization’s overall security governance. In this role, you will support the development and maintenance of cybersecurity policies, frameworks, and the wider GRC plan, while keeping an eye on regulatory changes. This role will assist in identifying and assessing risks, maintaining accurate risk information, and ensuring controls and compliance requirements are being followed through audits and follow‑up activities. This Senior Associate will also prepare clear insights and governance‑level metrics that support informed decision‑making.
ROLE RESPONSIBILITIES
Assist in defining and maintaining the organization’s GRC plan.
Support the maintenance and alignment of Pfizer’s GRC program to cybersecurity governance frameworks (e.g., NIST CSF, ISO 27001).
Review and update cybersecurity policies, standards, and procedural documents.
Monitor regulatory changes and industry trends to ensure the organization remains compliant and proactive in addressing emerging risks.
Identify potential security issues across systems, processes, and vendors by gathering information from assessments, audits, and internal teams.
Conduct structured risk analysis to identify potential security threats, vulnerabilities, and impacts across systems and processes.
Support the creation and tracking of action plans to reduce or manage risks, ensuring decisions and next steps are clearly documented.
Perform risk assessments to validate that defined security controls, policies, and compliance requirements are properly implemented and followed across the organization.
Identify and assist in tracking GRC key metrics, ensuring they support informed decision‑making at leadership and committee levels.
BASIC QUALIFICATIONS
Bachelor’s degree in information technology, cybersecurity, computer science, or a related field.
2+ years of experience in cybersecurity, or related field.
Experience with cybersecurity control frameworks (NIST, ISO, COBIT, etc.).
Ability to support complex programs by coordinating tasks, tracking progress, and assisting with stakeholder communications.
Solid understanding of core cybersecurity principles, technologies, and risks to effectively collaborate with technical teams and support governance activities.
Strong ability to produce clear, concise, and professional written communications and reports.
Excellent collaboration and interpersonal skills, with the ability to work effectively across levels and functions to support program objectives.
Demonstrated experience in an agile work environment possessing qualities such as a collaborative mindset, adaptability to change, and a proactive problem-solving approach.
PREFERRED QUALIFICATIONS
Demonstrated experience working in pharmaceutical, biotech, or other highly regulated industries.
Professional certifications such as CISSP, CISM, CRISC, CISA, PMP, or similar.

