Manager, Cybersecurity & Information Protection (APAC&EMEA)-Base SH or BJ
- China - Beijing - Beijing
- China - Shanghai - Shanghai

Our Purpose
Our Values
Pfizer Digital
Benefits
ROLE SUMMARY
Our Global Cybersecurity Governance, Risk, and Compliance (GRC) team provides comprehensive blueprints for cybersecurity excellence by embedding governance, risk management, and compliance into every layer. The team is responsible for ensuring risk-based decision-making is used and that security, privacy, and regulatory compliance is integrated seamlessly with Pfizer's organization.
We are seeking a Manager, Information Protection & Technology Privacy, to lead and oversee the enterprise information protection program and serve as the primary Technology & Cyber Privacy Advisor within the Cyber GRC organization. This role ensures that sensitive data — across intellectual property, regulated data, and confidential business information — is appropriately classified, protected, and handled in alignment with Pfizer policies, regulatory expectations, and risk tolerance.
This role partners closely with Data Protection Engineering, Privacy, Legal, IT, Security Operations, and the DPO office to operationalize controls, drive adoption of data protection standards, ensure ongoing compliance across a complex, regulated pharmaceutical environment, and support Business Units in navigating privacy obligations across multiple jurisdictions.
ROLE RESPONSIBILITIES
- Act as a trusted advisor on cybersecurity, information protection, and data privacy matters across APAC and EMEA.
- Partner with Business, Digital & Technology, Privacy, Legal, and Compliance stakeholders to provide pragmatic cybersecurity and information protection guidance for strategic initiatives, business transformations, and technology projects.
- Assess and manage cybersecurity and information protection risks associated with business initiatives, applications, digital solutions, and third-party engagements.
- Ensure compliance with applicable cybersecurity and data protection regulations across APAC and EMEA, including CSL, DSL, PIPL, GDPR, NIS2, and related regulatory requirements.
- Support regulatory inspections, audits, compliance reviews, and regulatory engagements as required.
- Lead cybersecurity and data protection compliance programs, including regulatory assessments, filings, remediation planning, and related compliance activities.
- Monitor emerging cybersecurity threats, regulatory developments, and compliance risks, and drive security awareness, risk management, and information protection initiatives across the organization.
- Support defining information protection controls for our organization to ensure regulatory compliance.
- Support in the development of data protection policies and standards.
- Support cybersecurity incident response, escalation, and remediation activities when required.
- This role requires flexibility to collaborate with stakeholders and support business needs across multiple time zones.
BASIC QUALIFICATIONS
- Bachelor’s degree in Information Security, Computer Science, Information Systems, Risk Management, or a related field.
- 7+ years of experience in cybersecurity, information security, data protection, privacy, regulatory compliance, risk management, or related disciplines, with at least 2 years in a supervisory or project leadership capacity.
- Strong knowledge of cybersecurity governance, risk management, compliance frameworks,and applicable regulatory requirements.
- Strong understanding of cybersecurity and data protection regulations, including CSL, DSL, PIPL, GDPR, DPDPA, NIS2, and related requirements.
- Experience supporting cybersecurity assessments, audits, regulatory inspections, compliance programs, or risk management initiatives.
- Experience and hands on familiarity with DLP and data discovery tools, as well as data labeling and tagging solutions, including deployment and ongoing support.
- Working knowledge of data encryption concepts and approaches across different environments.
- Strong stakeholder management, communication, and influencing skills, with the ability to work effectively across business and technology functions in a global environment.
- Strong project coordination across business and technical teams.
- Professional proficiency in English.
PREFERRED QUALIFICATIONS
- Professional certifications such as CISSP, CISA, CISM, CRISC, CIPP/E, CIPM, or equivalent are preferred.
- Experience supporting cybersecurity, information protection, data privacy, or regulatory compliance programs within the pharmaceutical, healthcare, or life sciences industry is strongly preferred.
- Hands‑on experience with GRC platforms (e.g., Archer).
- Familiarity with privacy, intellectual property protection, and regulated data environments.
Pfizer is an equal opportunity employer and complies with all applicable equal employment opportunity legislation in each jurisdiction in which it operates.
To learn more about acceptable and prohibited uses of AI during the recruitment process, please review our candidate AI-use guidelines available on Pfizer Careers.

Information & Business TechBreakthroughs that change patients’ lives
Research confirms what intuition tells us: that purpose-driven companies perform better, are more innovative, attract and retain the best people, and know how to unleash the power of those people. Pfizer’s purpose—Breakthroughs that change patients' lives—fuels everything we do and reflects our passion for building on our legacy as one of the greatest contributors of good to the world.
Each word in our purpose has meaning and reflects the value we strive to bring to patients and society:
“Breakthroughs” - These are the innovations, scientific and commercial, that we seek to deliver every day. All colleagues, regardless of role, level or location, strive for breakthroughs every day.
“Change” - We want to do more than simply improve patients’ medical conditions; we want to dramatically change their lives for the better.
“Patients’ lives” - We consider not only patients, but everyone they touch—including their families, caregivers, and friends—and everything they love to do. It’s an intentionally holistic view.
Our purpose ensures that patients remain at the center of all we do. We live our purpose by sourcing the best science in the world; partnering with others in the healthcare system to improve access to our medicines; using digital technologies to enhance our drug discovery and development, as well as patient outcomes; and leading the conversation to advocate for pro-innovation/pro-patient policies.
Every decision we make and every action we take is done with the patient in mind—and to nurture an environment where breakthroughs can thrive.
Our Values
To fully realize Pfizer’s purpose, we have established a clear set of expectations regarding “what” we need to achieve for patients and “how” we will go about achieving those goals.
The “how” is represented by four simple, powerful values—courage, excellence, equity, and joy—that define our company and our culture.
Courage: Breakthroughs start by challenging convention, especially in the face of uncertainty or adversity. This happens when we think big, speak up, and are decisive.
Excellence: We can only change patients’ lives when we perform at our best together. This happens when we focus on what matters, agree who does what, and measure our outcomes.
Equity: We believe that every person deserves to be seen, heard, and cared for. This happens when we are inclusive, act with integrity, and reduce healthcare disparities.
Joy: We give ourselves to our work, but it also gives to us. We find joy when we take pride, recognize one another, and have fun.
Pfizer Digital
Pfizer Digital takes immense pride in being at the forefront of innovation, harnessing cutting-edge smart technology that profoundly impacts the lives of our patients.
With the transformative potential of digital solutions, we revolutionize how we discover, develop, and deliver medicines, enabling us to achieve breakthroughs faster and more efficiently.
By streamlining and automating transactional processes, we create valuable time and resources, empowering our talented team to focus on meaningful work that truly makes a difference in healthcare and beyond.
Benefits at Pfizer
Pfizer offers competitive compensation and benefits programs designed to meet the diverse needs of our colleagues. Our Pay for Performance Philosophy and Practices reward colleagues based on the contributions they make to our business.
Our Competitive Benefits Programs help our colleagues by:
- Promoting Health and Wellness to help colleagues maintain and improve their physical and mental wellbeing. Pfizer offerings include health and disability insurance, preventative health programs, medical screenings, free or reduced-cost vaccinations, discounts on Pfizer products, mental health support, nutrition and fitness counseling and more.
- Strengthening Colleagues’ Financial Security by providing company contributions to retirement plans, life insurance and financial planning education to help colleagues achieve their financial goals.
- Providing Benefits and Time off for the Moments that Matter to ensure Pfizer colleagues have the time away from the office to recharge, recover and return to work as the best version of themselves. Vacation, Holiday time and Sick time are just the beginning, with a 12 week parental leave policy for both parents of a new born, 10 day of caregiver leave for those times when your family needs you whether it’s a child, spouse or parent, bereavement leave, and additional country-specific programs.
- And so much more, depending on your country and site, Pfizer offers childcare facilities or discount programs, on-site health and/or fitness centers, movement and mindfulness solutions, “Log in for your Day” work flexibility and so much more.
For U.S. based jobs, view an overview of Pfizer’s U.S. benefits program (opens in a new window)
