Pfizer
Information & Business Tech
Associate,ThirdPartyRiskManagement
Neural analysis suggests this role is
optimal for Mid+ candidates.
“Associate, Third Party Risk Management at Pfizer. Skills: Cybersecurity, Risk assessment. Support the end-to-end lifecycle of cyber TPRM assessments. Assist in maintaining TPRM documentation, templates, and processes”
Industry & Context.
Problem-solving
Travel as required, Work in assigned Pfizer office 2-3 days per week
What They're Looking For.
Must Have
Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or a related field OR equivalent practical experience, 1-2 years of experience in information security, risk, compliance, information protection, or related disciplines, Experience with audits, assessments or compliance reviews, Experience reviewing documents, questionnaires, or technical evidence with attention to detail
Nice to Have
Experience working in pharmaceuticals industry, Experience with GRC/TPRM tools, Demonstrated experience in an agile work environment
What You'll Do.
Support the end-to-end lifecycle of cyber TPRM assessments
Assist in maintaining TPRM documentation
Support vendor assessments by gathering security documents
Review information and highlight gaps
Assist with due-diligence activities by sending questionnaires
Track responses and ensure information is complete
Assist and track remediation plans and due dates
Track open items through to closure
Ensure evidence meets documentation standards
Assist with periodic reassessments and continuous monitoring activities
Produce and maintain TPRM operational metrics and dashboards
How You'll Work.
Team & Collaboration
Work effectively across levels and functions; Collaborative mindset
Communication Scope
Business communication
Full Job Description
## **ROLE SUMMARY** Our Global Governance, Risk, and Compliance (GRC) team provides comprehensive blueprints for cybersecurity excellence by embedding governance, risk management, and compliance into every layer. The team is responsible for ensuring risk-based decision-making is used and that security, privacy, and regulatory compliance is integrated seamlessly with Pfizer’s organization. We are looking for an Associate to join our Third-Party Risk Management team, supporting key activities such as due‑diligence reviews, audit support, and maintaining accurate vendor risk records. This role involves engaging with third parties to complete risk assessments, collecting required evidence, ensuring updates are captured, and maintaining visibility into third‑party risks. ## **ROLE RESPONSIBILITIES** * Support the end‑to‑end lifecycle of cyber TPRM assessments: intake, scoping, due diligence, risk evaluation, documentation, remediation tracking, and closure. * Assist in maintaining TPRM documentation, templates, and processes to support a consistent approach across vendors. * Support vendor assessments by gathering security documents, reviewing information, and highlighting gaps that differ from the policies. * Assist with due‑diligence activities by sending questionnaires, tracking responses, and ensuring information is complete. * Assist and track remediation plans and due dates with vendors and internal stakeholders for identified gaps. * Track open items through to closure, ensuring evidence meets documentation standards. * Assist with periodic reassessments and continuous monitoring activities for higher‑risk vendors, including change‑triggered reviews (e.g., new data types, expanded scope, incidents, acquisitions). * Produce and maintain TPRM operational metrics and dashboards. ## **BASIC QUALIFICATIONS** * Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, or a related field **OR** equivalent practical experience. * 1-2 years of experienc
Applying for this Associate, Third Party Risk Management role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
How to Apply on Workday
- Workday has a multi-step form — save your progress after every section.
- "Apply With LinkedIn" can fail or lose data; manual entry is more reliable.
- Watch for the "Submit for Review" final step — hitting "Save" alone does not submit.
- Job requisition numbers are useful when following up with HR by email.
ANONYMOUS · UNFILTERED
What do employees actually say about Pfizer?
Real rants from real employees. Read before you apply.