Vp risk and compliance
Lensa is a career site that helps job seekers find great jobs in the US. We are not a staffing firm or agency. Lensa does not hire directly for these jobs, but promotes jobs on LinkedIn on behalf of its direct clients, recruitment ad agencies, and marketing partners. Lensa partners with DirectEmployers to promote this job for Pfizer. Clicking "Apply Now" or "Read more" on Lensa redirects you to the job board/employer site. Any information collected there is subject to their terms and privacy notice.
Role Summary Our Global Cybersecurity Governance, Risk, and Compliance (GRC) team plays a critical role in safeguarding Pfizer's digital assets, ensuring regulatory compliance, and protecting sensitive data across all business functions. As part of our strategic commitment to strengthening our cybersecurity posture, we are enhancing and modernizing our GRC program to address enterprise-wide risks across applications, data, vendors, and critical operations. We are seeking an experienced individual of Cybersecurity Governance, Risk, and Compliance to lead this transformation. The ideal candidate will have deep expertise in enterprise cyber risk management, regulatory compliance, audit readiness, and oversight of GRC technologies. This leader will drive enterprise programs across GRC, business security and data protection, application security governance, third-party risk management (TPRM), and business continuity/disaster recovery (BCP/DR). Role Responsibilities- Define and execute the enterprise GRC strategy, ensuring alignment with organizational goals and regulatory requirements.
- Lead the enterprise cyber risk management program, including risk identification, assessment, prioritization, and mitigation planning.
- Oversee all audit and compliance activities, including ISO 27001, SOC 2, PCI DSS, SOX, GxP, and other relevant standards.
- Serve as product owner for GRC platforms, ensuring configuration, integration, automation, and reporting capabilities meet enterprise needs.
- Establish and monitor cybersecurity policies, standards, and procedures, drive adoption across all business and IT units.
- Lead application security governance initiatives, embedding secure development lifecycle practices across the enterprise.
- Drive business security and data protection programs, ensuring alignment with global privacy regulations and internal controls.
- Oversee BCP/DR strategy and execution, ensuring operational resilience across critical business functions.
- Provide clear, actionable reporting and dashboards on risk, compliance, and program health to executive leadership and the board.
- Collaborate with Legal, IT, Privacy, Internal Audit, and business stakeholders to embed governance and risk management practices into daily operations.
- Build, develop, and lead a high-performing GRC team; mentor staff and create a culture of accountability, collaboration, and continuous improvement.
- Stay current on industry trends, emerging regulations, and cybersecurity best practices to proactively adapt the GRC program.
- Bachelor's degree with 15+ years of experience in cybersecurity, risk management, or related fields.
- At least 8 years of direct leadership experience managing enterprise-wide GRC or risk/compliance functions.
- Professional certifications such as CISSP (required); CISM, CRISC, or CISA strongly preferred.
- Experience leading Application Security Governance and secure development lifecycle practices.
- Strong background in Third-Party Risk Management (TPRM) programs, including vendor assessments, monitoring, and remediation.
- Deep knowledge of cybersecurity frameworks (NIST CSF, ISO 27001, SOC 2, PCI DSS, SOX) and data protection regulations (GDPR, CCPA, HIPAA).
- Strong leadership, communication, and presentation skills, with the ability to translate complex risks into business-focused insights for senior executives and boards.
- Experience with RSA Archer as the enterprise GRC platform, including ownership of configuration, workflows, and reporting.
- Experience overseeing GRC-related technologies, including Data Protection/DLP platforms and Business Continuity/Disaster Recovery solutions.
Recommended Jobs
Assistant Store Manager - Staten Island Mall
Adore Me, a subsidiary of Victoria’s Secret & Co. (NYSE: VSCO) since being acquired in December 2022, is seeking an Assistant Store Manager for their Staten Island Mall location. The Assistant St…
AI Engineer- Member of Technical Staff
About Hypha Hypha is an AI-native platform transforming asset management across the full lifecycle—acquisition, management, and exit. Focused on healthcare facilities and multifamily real estate, we…
Real Estate Associate
Join NFR, New York's fastest growing real estate startup with the highest retention rate in New York. Whether you are an experienced real estate professional or new to the industry, NFR would li…
Chief Financial Officer (CFO)
Position: Chief Financial Officer (CFO) Location: New York, USA Reports to: Chief Executive Officer Employment Type: Full-Time About Solen Software Group: Solen Software Group is an invest…
Senior Machine Learning Engineer I
Dandy is transforming the massive and antiquated dental industry—an industry worth over $200B. Backed by some of the world’s leading venture capital firms, we’re on an ambitious mission to simplify a…
After School Activities Teacher (Part Time, In-Person)
General Responsibilities: Under the supervision of the Director of Educational Development, plans and facilitates collaborative after school activity sessions for elementary, middle, and/or high sch…
Line Cook - Salad
Do you have a passion for creating delicious Italian cuisine? Prato 850, part of a thriving multi-restaurant group, is seeking a talented and motivated Line Cook to join our growing team! What yo…
Server
Vidorra ‘Cocina de Mexico’ is a modern Mexican restaurant that celebrates culture through authentic dishes, bold cocktails and a highly energized environment. The name translates to “the good life” wh…
General Utility Worker
Job Description Are you self-motivated and proud of the work you do? Here at Aramark, we take pride in the level of service and safety we provide! As a General Utility Worker on our team of other …