Manager, Cyber Policy, Governance, Standards & Control Management

Pfizer

Confirmed live yesterday High trust
Closes tomorrow Hybrid

Quick summary

Work type
Hybrid
Location
New York, NY
Salary
$106,000–$176,600 / yr
Posted
2 days ago
Freshness
Confirmed live yesterday
Closes
Sep 12, 2026 (soon)

Market check

Salary context

Below market

How this pay compares to similar roles

Similar $182k
This role $141k
$93k most similar roles pay here $228k

This role pays less than 87% of similar roles. Most pay $156,100–$208,800 — the shaded band above. At the midpoint, this role pays about $141k versus about $182k for comparable roles.

Based on 240 similar postings.

Employer

About Pfizer

Pfizer Inc. is one of the world''s largest biopharmaceutical companies, researching, developing, manufacturing, and marketing medicines and vaccines across multiple therapeutic areas including oncology, cardiology, and infectious diseases. Industry: Biopharmaceuticals

Pfizer currently has 27 open roles on FindRole.

Listed pay typically runs $106,000–$176,600 across 27 roles with salary data.

Most-posted roles

View all roles at Pfizer

At a glance

TL;DR · Manager, Cyber Policy, Governance, Standards & Control Management

Manager, Cyber Policy, Governance, Standards & Control Management joins the Global Cybersecurity Governance, Risk, and Compliance team to manage the lifecycle of enterprise cybersecurity policies, standards, and control libraries within a global pharmaceutical environment. This role involves developing governance frameworks, establishing review cycles, managing risk exceptions, and creating metrics to measure program maturity. The individual will map security controls to industry frameworks including NIST CSF 2.0, ISO 27001, NIST 800-53, CIS Controls, and NIS2 while ensuring alignment with pharmaceutical regulations. Key responsibilities include partnering with internal teams to address control gaps, supporting audits, and mentoring professionals. Required skills include experience with GRC tools like Archer, knowledge of COBIT, and the ability to translate technical risk into actionable recommendations. The role requires a proactive approach to maintain a consistent and sustainable security posture across diverse business functions.

What you'll do

  • Manage the lifecycle of enterprise cybersecurity policies, standards, baselines, and supporting governance documents.
  • Establish and maintain a structured policy governance framework including review cycles and exception management.
  • Develop reporting, metrics, and key performance indicators to measure program maturity and control effectiveness.
  • Maintain the enterprise cybersecurity controls framework and manage the associated control library.
  • Map security controls to industry frameworks such as NIST CSF 2.0, ISO 27001, and pharmaceutical regulations.
  • Partner with control owners to define objectives, implementation guidance, and testing requirements for security controls.
  • Drive improvements to control design and rationalization to address emerging cybersecurity risks.
  • Provide governance oversight for risk exceptions, compensating controls, and remediation tracking activities.

What we're looking for

  • Bachelor's degree required.
  • 4+ years of experience in cybersecurity, enterprise risk management, cyber risk analysis, or GRC-related roles.
  • Strong knowledge of cybersecurity frameworks and standards including NIST CSF 2.0, CIS, COBIT, and ISO.
  • Experience with GRC tools like Archer or similar technologies.
  • Demonstrated experience in an agile work environment.
  • Must be authorized to work in the United States.
  • Excellent strategic thinking (preferred).
  • Ability to challenge, influence, and support senior leadership (preferred).

More like this

Similar roles

Director, Cyber Compliance (Information Security)

Cardinal Health

Remote 3 days ago $137,400$232,320
GRC NIST CSF ISO 27001 SOX HIPAA GDPR PCI CMMC FDA GxP SOC 2 ITGC Risk Management Audit Management Cybersecurity Compliance Information Security
8+ yrs exp Remote

Manager, Cyber Risk & Analysis

Capital One Financial

McLean, VA +1 32 days ago $164,800$188,100
NIST 800-53 NIST CSF ISO COBIT Cybersecurity Risk Management Audit System Transformation Software Engineering
4+ yrs exp

Senior Manager, Policy and Controls Governance

MongoDB

Remote 45 days ago $114,000$224,000
GRC Jira SOC2 ISO 27001 PCI DSS HIPAA NIST CSF Policy Management Risk Management Audit Readiness Compliance Frameworks Reporting KPIs KRIs Dashboards Change Control
10+ yrs exp Remote

Cyber Compliance Oversight Manager

3M

Maplewood, MN +1 3 days ago $164,612$201,193
ISO 27001 NIST CSF SOX PCI CMMC TISAX SWIFT CISSP CISA CISM Cybersecurity Compliance Monitoring Control Assessment Audit Project Management SLAs KPIs
5+ yrs exp

Cyber Policy Enforcement Lead, VP

State Street

Quincy, MA 30 days ago $120,000$202,500
GRC NIST ISO 27001 COBIT Cybersecurity Governance Risk Management Policy Management Control Monitoring Compliance Audit CISSP CISM CRISC CGEIT CISA Reporting KPIs Automation
10+ yrs exp