Manager, GRC Technology, Metrics, and Automation
pfizer.wd1.myworkdayjobs.com
ROLE SUMMARY Our Global Governance, Risk, and Compliance (GRC) team provides comprehensive blueprints for cybersecurity excellence by embedding governance, risk management, and compliance into every layer. The team is responsible for ensuring risk-based decision-making is used and that security, privacy, and regulatory compliance is integrated seamlessly with Pfizer’s organization. We are seeking a Manager, Technology, Metrics, and Automation who will guide how the organization leverages data, automation, and technical platforms to advance security and risk management outcomes.
The role oversees the design and governance of data pipelines, reporting systems, and automated workflows that ensure accurate, reliable, and timely information flows throughout the environment. By integrating technology solutions with operational processes, this role enables teams to monitor performance, identify systemic risks, and make informed decisions that strengthen organizational resilience.
ROLE RESPONSIBILITIES Define and execute the technology roadmap for Cyber GRC tooling, aligned to enterprise risk priorities, regulatory requirements, and operating model maturity. Partner with IT and platform teams on system upgrades, integrations, data feeds, and configuration enhancements. Define and govern a comprehensive set of Cyber GRC metrics, KPIs, and KRIs that provide actionable insights into Pfizer’s GRC environment.
Ensure metrics are risk‑aligned, standardized, and decision‑useful, not just activity‑based. Develop executive‑level dashboards for senior leadership, risk committees, and governance forums. Identify and drive automation opportunities across Cyber GRC processes to reduce manual effort, improve data quality, and increase consistency. Lead implementation of workflow automation, approvals, notifications, evidence collection, and reporting capabilities.
Ensure alignment between GRC data and enterprise data standards. Partner with data/analytics teams to enable scalable reporting solutions (e.g., BI tools, dashboards, automation pipelines). Serve as a key partner to Cybersecurity leadership, IT, Infrastructure, Cloud Services, Privacy, Quality, and Internal Audit. Translate stakeholder needs into practical technology and reporting solutions. Influence adoption and consistent use of GRC platforms across global teams.
Act as a key contributor during internal audits, external audits, and regulatory inspections, ensuring metrics and system outputs are defensible and traceable. BASIC QUALIFICATIONS Applicant must have a bachelor's degree with at least 4 years of experience; OR a master's degree with at least 2 years of experience; OR a PhD with 0+ years of experience; OR as associate's degree with 8 years of experience; OR a high school diploma (or equivalent) and 10 years of relevant experience.
4+ years of experience in information technology or cybersecurity. Ability to manage multiple priorities, work with cross-functional teams, and deliver high-quality outputs. Strong experience with GRC platforms, reporting, and workflow automation. Demonstrated ability to design metrics and dashboards that support executive decision ‑ making. Strong stakeholder management and communication skills, including executive ‑ level presentations.
Experience operating in a highly regulated, matrixed enterprise environment. Demonstrated experience in an agile work environment possessing qualities such as a collaborative mindset, adaptability to change, and a proactive problem-solving approach. PREFERRED QUALIFICATIONS Bachelor’s degree in information technology, cybersecurity, computer science, or a related field. Demonstrated experience working in pharmaceuticals industry.
Professional certifications such as CISSP, CISM, CRISC, CISA, PMP, or similar. Hands ‑ on experience with tools such as ServiceNow GRC, Archer, Power BI, Tableau, or similar. Experience in large, complex, or regulated environments. NON-STANDARD WORK SCHEDULE, TRA