The Global Information Security (GIS) organization delivers proactive cyber defense for the global Pfizer enterprise. Our mission is to secure all of Pfizer’s digital information assets ranging from the manufacturing floor to the core data centers, and out to our patient facing solutions. We achieve this mission through a team of world-class talent that focuses on building strong partnerships to build security into all aspects of our business. Across GIS we utilize top-tier technologies, industry leading best practices, advanced analytics, and the promotion of a cybersecurity ownership culture to drive results for the enterprise. The Sr. Associate, Security Testing will perform cybersecurity manual and automated vulnerability assessments for business solutions. The assessments will focus on protecting the company information assets using a threat-based approach and recommend risk reduction actions. The Sr. Analyst will work within a team and directly with business technology application and technology teams. The position will report to the Global Information Security Testing Manager. At Pfizer, you will find a company as focused on its internal culture as it is on its external reputation. You will have the opportunity to partner with colleagues of diverse backgrounds and abilities, people who contribute to all aspects of what we do—from drug development to marketing, technology to sales, and so much more. Primary responsibilities include: Leverage industry best practices by performing manual and automated security testing for web and mobile applications, architectures, specialty solutions including internet of things and wearable devices as well as participate in critical asset reviews Research new security threats, vulnerabilities, and exploit techniques to identify new weaknesses and recommend remediation or mitigation Create scripting code and methodologies for new testing techniques Perform critical application penetration tests and provide visibility metrics and outcomes to Digital Leadership Upgrade, maintain and recommend security tools to support testing as well as AI adoption Manage assessments performed and deliver results to customers on time, assist customers with recommendations and retest as needed Develop communications and present to key shareholders for assessments. Answering to new attack surfaces and help implement new requirements as needed Ability to work both independently and in a team-oriented, joint environment Partner with global team members to drive secure outcomes based on industry best practices Partner with the Incident Response team on developing new detections based on trending attack surface Partner with Attack Surface Reduction (ASR) to support the adoption of DevSecOps practices across the Enterprise by leveraging Pentesting results Create and maintain internal security testing infrastructure such as Collaborator or C2 instances Collaborate with the ASR team to actively monitor the security posture of Pfizer’s code repositories BASIC QUALIFICATIONS Some experience of information and cybersecurity related experience BS in Computer Sciences, Information Security, Information Systems, Engineering, Sciences, or related field Applicant must have one of the following: Bachelor’s degree with some relevant experience Master’s degree with limited relevant experience Associate's degree with strong relevant experience Strong relevant experience with a high school diploma or equivalent Experience performing security assessments Experience in the Software Development Lifecycle and supporting technologies Programming or scripting in python, ruby, or PowerShell Strong leadership skills with the ability to prioritize and execute with minimal direction or oversight Ability to interpret log data and draw analytical conclusions Maintain awareness of industry frameworks and best practices: Threat Modeling, NIST, OWASP, SANS Security Model Maintain awareness of industry trends and emerging technologies including web services, mobile, wearables, isolated architectures, databases security, IoT Understanding of operating systems, network protocols, and applications development Experience with security testing tool, proxies, port scanners, vulnerability scanners, exploit frameworks Ability to proactively solve complex problems both individually and as part of a team Demonstrated commitment to training, self-study and maintaining proficiency in the cyber security domain Effective oral, written, and interpersonal communications skills are required as well as organizational, planning, and administrative abilities and the ability to coordinate multiple complex projects simultaneously High level of integrity and strong ethical values Work Location Assignment: Hybrid Purpose Breakthroughs that change patients' lives At Pfizer we are a patient centric company, guided by our four values: courage, joy, equity and excellence. Our breakthrough culture lends itself to our dedication to transforming millions of lives. Digital Transformation Strategy One bold way we are achieving our purpose is through our company wide digital transformation strategy. We are leading the way in adopting new data, modelling and automated solutions to further digitize and accelerate drug discovery and development with the aim of enhancing health outcomes and the patient experience. Flexibility We aim to create a trusting, flexible workplace culture which encourages employees to achieve work life harmony, attracts talent and enables everyone to be their best working self. Let’s start the conversation! Equal Employment Opportunity We believe that a diverse and inclusive workforce is crucial to building a successful business. As an employer, Pfizer is committed to celebrating this, in all its forms – allowing for us to be as diverse as the patients and communities we serve. Together, we continue to build a culture that encourages, supports and empowers our employees. DisAbility Confident We are proud to be a Disability Confident Employer and we encourage you to put your best self forward with the knowledge and trust that we will make any reasonable adjustments necessary to support your application and future career. Our mission is unleashing the power of our people, especially those with unique superpowers. Your journey with Pfizer starts here! Information & Business Tech