Jobs and Careers
PF

Director, Application Security

Pfizer
Collegeville, United Statesfull_timeVerifiedPosted 20 Aug 2024
💰 $269,400/yr($161,600/yr$269,400/yr)

About the role

ROLE SUMMARY

Pfizer’s Global Information Security (GIS) organization delivers proactive cyber defense for the global enterprise. Our mission is to secure all of Pfizer’s digital information assets, from scientific breakthroughs to manufacturing, and out to the patients we serve. We achieve this through world-class talent, top-tier technologies, best practices, and fostering a cybersecurity ownership culture across the company.

The Director of Application Security will lead efforts to fortify the security posture of Pfizer's on-premise and cloud critical applications and infrastructure. This includes hardening application security, eliminating configuration errors, ensuring proper authorizations, and establishing comprehensive logging for incident responders.

The Director will also drive the development of Application Security Services strategy, including: policy, conducting security assessments, hardening Pfizer’s key line of business applications, leading red team exercises, addressing application vulnerabilities, and enhancing operational processes.


Collaboration with the DevOps team and the broader developer community at Pfizer is crucial for success, ensuring adherence to policy and evolving security standards. This position requires thought leadership, technical expertise and strong communication skills to support Secure Business Enablement (SBE) initiatives. The incumbent will report to the Sr. Director, Secure Business Enablement and be part of the Global Information Security (GIS) organization within Pfizer Enterprise Platforms & Security.

ROLE RESPONSIBILITIES

Primary responsibilities involve spearheading the implementation of comprehensive security measures for Pfizer's critical applications and supporting infrastructure. This includes strategizing and overseeing the development of security policies, leading application security assessments and red team operations, and implementing advanced logging and monitoring systems for effective incident response. The role emphasizes driving initiatives to eliminate configuration errors, enforcing strict authorization protocols, and integrating security best practices into the development lifecycle with DevSecOps teams. Working closely with Digital Leads, Principal Engineers, and Product Owners, the incumbent ensures technical decisions support overarching security strategic priorities.

  • Own and develop strategic application security policies, ensuring they are effectively communicated and adopted across all teams
  • Lead and inspire DevSecOps teams to integrate secure API development and deployment practices
  • Foster a culture of continuous improvement in application security across the organization
  • Oversee and mentor junior team members fostering a culture where colleagues can thrive and continue to sharpen application security skillsets
  • Engage with regulatory bodies to ensure applications adhere to security compliance and regulatory requirements
  • Own the development and delivery of training curricula to enhance application security awareness among developers and stakeholders
  • Evaluate and integrate new security technologies to enhance application protection measures, staying ahead of emerging threats
  • Coordinate with other Digital business lines to ensure holistic and integrated security measures are applied consistently
  • Spearhead comprehensive security assessments and vulnerability testing for critical applications, mentoring teams in best practices
  • Guide strategic application incident response initiatives, providing high-level technical direction and support during security incidents
  • Oversee the development and implementation of advanced monitoring and logging mechanisms for real-time threat detection
  • Drive initiatives to eradicate configuration errors and strengthen application security through robust authorization protocols
  • Conduct high-level application security audits and integrate findings into the broader application security strategy
  • Guide the implementation of security patches and updates, ensuring timely and effective application protection
  • Conduct application architectural design reviews, ensuring security and compliance are integral to the development process
  • Exercise sound judgment and decision-making, leveraging knowledge, experience, policies, procedures, and Pfizer's core values (Courage, Excellence, Equity, & Joy)
  • Ownership and accountability for SaaS Application Security Strategy including: Integrations, On/Off-boarding, Operations and emphasizing collaborative protection of cloud-based services (AppOmni)

BASIC QUALIFICATIONS

  • Bachelor’s Degree in cybersecurity, computer science, information systems, or a related field
  • 10+ years of experience in application security, software deve

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Pfizer

View company profile →