Manager, Vulnerability Management at Pfizer | NY, US | Rezi

Manager, Vulnerability Management at Pfizer

Manager, Vulnerability Management

Pfizer · NY, US

Today

Manager, Vulnerability Management

Pfizer · NY, US

20 hours ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

The Manager, Vulnerability Management leads the execution of vulnerability management activities to identify, assess, prioritize, and reduce security weaknesses across the enterprise. This role oversees day-to-day vulnerability management operations, including scanning, analysis, prioritization, and remediation coordination, partnering with various technology teams to reduce cyber exposure.

Responsibilities

  • Lead the day-to-day execution of the vulnerability management program, ensuring consistent identification, assessment, and prioritization of vulnerabilities across enterprise environments.
  • Manage and develop a team of vulnerability management analysts, providing technical guidance, prioritization, coaching, and performance feedback.
  • Oversee vulnerability scanning activities across infrastructure, endpoints, cloud platforms, and applications, ensuring coverage and data quality.
  • Translate vulnerability findings into clear, actionable remediation guidance for technical owners, aligned to risk, exploitability, and business impact.
  • Coordinate remediation efforts with Infrastructure, Cloud Services, Engineering, Endpoint Security, and other technology teams to drive timely risk reduction.
  • Partner with Threat Intelligence, Threat Remediation, and Incident Response teams to incorporate threat context and active exploitation signals into prioritization decisions.
  • Track remediation progress, validate closure, and identify recurring issues or systemic control gaps requiring escalation or broader corrective action.
  • Ensure vulnerability management activities align with internal policies, regulatory requirements, and audit expectations.
  • Maintain reporting and metrics on vulnerability trends, remediation performance, and risk posture for Cyber Defense leadership.
  • Drive continuous improvement of vulnerability management processes, tooling, and workflows to increase efficiency, accuracy, and impact.

Requirements

  • Bachelor's degree in Information Security, Computer Science, Engineering, Information Technology, or a related field with at least 4 years of experience in cybersecurity, with a strong focus on vulnerability management, security operations, or exposure management; OR a master's degree with at least 2 years of experience; OR an associate's degree with 8 years of experience; OR a high school diploma (or equivalent) and 10 years of relevant experience.
  • Demonstrated responsibility for executing or overseeing vulnerability scanning, assessment, prioritization, and remediation tracking across infrastructure, endpoints, cloud platforms, or applications.
  • Experience translating vulnerability findings into risk-based remediation guidance for infrastructure, cloud, application, or platform engineering teams.
  • Prior responsibility for coordinating remediation activities, including tracking ownership, validating fixes, managing exceptions, and escalating blocked or overdue items.
  • Familiarity with vulnerability severity, exploitability concepts, and compensating controls used to manage risk when immediate remediation is not feasible.
  • Experience leading analysts or serving as a technical lead responsible for task prioritization, quality assurance, and day-to-day delivery.
  • Strong analytical, organizational, and problem-solving skills.
  • Demonstrated experience in an agile work environment possessing qualities such as a collaborative mindset, adaptability to change, and a proactive problem-solving approach.
  • Familiarity with vulnerability management in cloud or hybrid enterprise environments.
  • Understanding of integrating threat context, exploitability, or attack paths into vulnerability prioritization.
  • Exposure to operating in regulated or highly controlled environments such as healthcare, life sciences, or manufacturing.
  • Experience supporting audit, compliance, or regulatory activities related to vulnerability management.
  • Ability to identify trends and drive process or control improvements over time.
  • Applicants should be capable of working through a personal laptop computer or mobile device for extended periods.
  • Travel as required by the business (less than 5% domestic and/or international).
  • Candidates must be authorized to be employed in the U.S. by any employer.
  • U.S. work visa sponsorship is not available for this role now or in the future.

Skills

  • Vulnerability Management
  • Cybersecurity
  • Security Operations
  • Exposure Management
  • Vulnerability Scanning
  • Risk Assessment
  • Remediation Tracking
  • Cloud Platforms
  • Application Security
  • Threat Intelligence
  • Incident Response
  • Agile Methodologies
  • Problem-Solving

Location

  • On-site (2-3 days per week)

Work Type

  • Hybrid
  • Full-time

Experience Level

  • Manager
  • 4+ years (with Bachelor's)
  • 2+ years (with Master's)
  • 8+ years (with Associate's)
  • 10+ years (with High School Diploma)

Education Level

  • Bachelor's degree in Information Security, Computer Science, Engineering, Information Technology, or related field
  • Master's degree
  • Associate's degree
  • High School Diploma or equivalent

Salary/Compensations

  • $116,000.00 - $193,400.00
  • Bonus target of 15.0% of base salary
  • Eligibility for share-based long-term incentive program

Benefits

  • 401(k) plan with Pfizer Matching Contributions
  • Additional Pfizer Retirement Savings Contribution
  • Paid vacation, holiday, and personal days
  • Paid caregiver/parental and medical leave
  • Health benefits including medical, prescription drug, dental, and vision coverage
  • Relocation assistance may be available

About the Company

  • Pfizer is a global company focused on safeguarding digital assets and infrastructure through proactive threat detection, response, and risk mitigation.

Equal Opportunity

  • Pfizer is committed to equal opportunity in the terms and conditions of employment for all employees and job applicants without regard to race, color, religion, sex, sexual orientation, age, gender identity or gender expression, national origin, disability or veteran status.
  • Pfizer also complies with all applicable national, state and local laws governing nondiscrimination in employment as well as work authorization and employment eligibility verification requirements of the Immigration and Nationality Act and IRCA.
  • Pfizer is an E-Verify employer.
  • This position requires permanent work authorization in the United States.