- Company Name
- Pfizer
- Job Title
- VP, Cybersecurity Governance, Risk, and Compliance (GRC)
- Job Description
-
**Job Title**: VP, Cybersecurity Governance, Risk, and Compliance
**Role Summary**
Lead enterprise cybersecurity governance, risk management, and compliance programs to safeguard digital assets, ensure regulatory compliance, and mitigate enterprise-wide risks across applications, vendor relationships, and operations. Develop and execute strategic initiatives aligned with organizational goals and global regulatory requirements.
**Expectations**
- Bachelor’s degree in cybersecurity, risk management, or related field with 15+ years’ experience.
- Minimum 8 years of leadership managing enterprise GRC functions.
- Proven expertise in cyber risk management, regulatory compliance, audit readiness, and GRC technologies.
**Key Responsibilities**
- Define and execute enterprise GRC strategy, aligning with organizational objectives and regulatory standards.
- Oversee risk identification, assessment, and mitigation planning for cyber, data, and operational risks.
- Manage audit and compliance activities for ISO 27001, SOC 2, PCI DSS, SOX, and GxP.
- Own configuration, integration, and automation of GRC platforms (e.g., RSA Archer).
- Establish cybersecurity policies, standards, and procedures; drive adoption across business and IT units.
- Lead application security governance, embedding secure development lifecycle practices.
- Develop and sustain programs for data protection, privacy regulations (GDPR, CCPA, HIPAA), and third-party risk management.
- Spearhead business continuity/disaster recovery (BCP/DR) strategies to ensure operational resilience.
- Provide executive-level reporting on risk posture, compliance, and program performance.
- Foster cross-functional collaboration with IT, Legal, Privacy, and Audit to embed risk management practices.
- Lead high-performing GRC teams, prioritizing mentorship, accountability, and continuous improvement.
**Required Skills**
- Deep knowledge of NIST CSF, ISO 27001, SOC 2, PCI DSS, and SOX frameworks.
- Expertise in third-party risk management, including vendor assessments and mitigation.
- Experience leading secure application governance and secure development lifecycle initiatives.
- Strong communication skills to translate technical risks into business insights for executives.
- Proficiency in GRC technologies (e.g., RSA Archer, DLP platforms, BCP/DR solutions preferred).
**Required Education & Certifications**
- Bachelor’s degree in cybersecurity, IT, or related field.
- CISSP certification (required); CISM, CRISC, or CISA preferred.