senior manager, threat remediation 4959035
8 Αυγ 2026 · Pfizer Hellas
Τι θα κάνεις
- Διαχειρίζεσαι τον κύκλο ζωής αντιμετώπισης απειλών από την αναγνώριση μέχρι την επίλυση.
- Μεταφράζεις πληροφορίες απειλών και ευρήματα SOC σε σχέδια αντιμετώπισης.
- Ιεραρχείς και ευθυγραμμίζεις τις ενέργειες αντιμετώπισης με βάση τον κίνδυνο και τις επιχειρηματικές επιπτώσεις.
- Συνεργάζεσαι με τις ομάδες Incident Response και SOC για τον περιορισμό και την εξάλειψη απειλών.
- Ηγείσαι των προσπαθειών αντιμετώπισης μετά από περιστατικά και αναλύεις τη ρίζα αιτίας.
- Παρακολουθείς και επικυρώνεις την ολοκλήρωση διορθωτικών ενεργειών μετά από περιστατικά.
- Συνεργάζεσαι με ΤΠ, μηχανικούς και κατόχους εφαρμογών για την επίλυση ευπαθειών.
- Εξασφαλίζεις τεκμηρίωση και έγκριση αντισταθμιστικών ελέγχων όταν υπάρχουν περιορισμοί στην αντιμετώπιση.
- Ορίζεις και αναφέρεσαι σε KPIs και KRIs για την αντιμετώπιση κινδύνων.
- Παρέχεις εκτελεστική αναφορά για την κατάσταση αντιμετώπισης, τη μείωση κινδύνου και αδυναμίες.
- Υποστηρίζεις ελέγχους, επιθεωρήσεις κανονισμών και αξιολογήσεις ασφαλείας.
- Συνεργάζεσαι με τις ομάδες ανίχνευσης και πληροφοριών απειλών για τη γεφύρωση κενών στην αντιμετώπιση.
- Συνεισφέρεις στη μακροπρόθεσμη στρατηγική κυβερνοάμυνας και στον σχεδιασμό τεχνολογικων επιλογών.
Βασικές προϋποθέσεις
- 7+ χρόνια εμπειρίας
- Διαχείριση κύκλου ζωής αντιμετώπισης απειλών και Αντιμετώπιση περιστατικών
- Διαχείριση και αντιμετώπιση ευπαθειών και Σαρωτές ευπαθειών
- Ασφάλεια cloud σε AWS, Azure και GCP
- Ασφάλεια τερματικών, δικτύου, ταυτότητας και εφαρμογών
- Εργαλεία SOC όπως SIEM, SOAR, EDR/XDR και Συστήματα ticketing/ροών εργασίας
- Ανάλυση ρίζας αιτίας (RCA) και Ιεράρχηση αντιμετώπισης βάσει κινδύνου
- Ανάπτυξη στρατηγικής κυβερνοάμυνας
- Πληροφορική / Ασφάλεια Πληροφοριών / Μηχανικήκατά προτίμηση
Περιγραφή Θέσης
Our Global Cyber Defense team is responsible for safeguarding Pfizer’s digital assets and infrastructure through proactive threat detection, response, and risk mitigation across on-premises, cloud, and hybrid environments.
The Senior Manager, Threat Remediation is responsible for owning and driving the end‑to‑end remediation of cybersecurity threats across the enterprise. This role sits at the intersection of threat detection, incident response, vulnerability management, offensive security and technology risk, ensuring that identified threats are prioritized, mitigated, and resolved in a timely, risk‑based, and compliant manner.
This role will work closely with the SOC, Cloud Services, Infrastructure, End User Computing, Engineering, GRC, Legal, Privacy, and Business stakeholders to reduce cyber risk and improve the organization’s overall security posture.
ROLE RESPONSIBILITIES
Own the threat remediation lifecycle, from intake of identified threats (incidents, alerts, vulnerabilities, control gaps) through containment, mitigation, and closure.
Translate threat intelligence, SOC findings, red team results, penetration tests, and vulnerability scans into actionable remediation plans.
Ensure remediation actions are risk‑based, prioritized, and aligned with business impact, regulatory exposure, and threat severity.
Partner with Incident Response and SOC teams during active incidents to ensure effective containment and eradication strategies.
Lead post‑incident remediation efforts, ensuring root cause analysis (RCA) is completed and systemic issues are addressed.
Track and validate completion of corrective and preventive actions (CAPAs) resulting from incidents.
Work with IT, engineering, and application owners to resolve vulnerabilities while respecting validated system change controls.
Ensure compensating controls are documented and approved where remediation is constrained due to regulatory or operational limitations.
Define and report on remediation KPIs and KRIs (e.g., mean time to remediate, overdue critical findings, repeat issues).
Provide executive‑level reporting on remediation status, risk reduction, and systemic weaknesses.
Support internal and external audits, regulatory inspections, and security assessments by demonstrating effective remediation governance.
Partner with detection, threat intelligence, and vulnerability teams to close gaps between detection and remediation.
Contribute to long‑term cyber defense strategy, including roadmap planning and technology selection.
BASIC QUALIFICATIONS
Bachelor’s degree in Computer Science, Information Security, Engineering, or a related technical discipline, or equivalent experience.
7+ years of experience in cybersecurity, with hands-on involvement in remediation, vulnerability management, security engineering, or incident response.
Strong understanding of:
Threat actor tactics, techniques, and procedures (MITRE ATT&CK)
Incident response and containment strategies
Vulnerability management and remediation workflows
Cloud security (AWS, Azure, GCP)
Endpoint, network, identity, and application security
Familiarity with SOC tooling (SIEM, SOAR, EDR/XDR), vulnerability scanners, and ticketing/workflow systems.
Demonstrated experience in an agile work environment possessing qualities such as a collaborative mindset, adaptability to change, and a proactive problem-solving approach.
Leadership experience managing or mentoring analysts and engineers.
PREFERRED QUALIFICATIONS
Working knowledge of GxP, FDA 21 CFR Part 11, EMA, HIPAA, GDPR, and other relevant regulations.
Familiarity with security frameworks, risk management practices, and regulatory expectations relevant to pharmaceutical or life sciences organizations.
Professional certifications such as CISSP, CISM, GIAC, or equivalent credentials related to security operations or risk management.



