Pfizer
Manager,ThirdPartyRiskManagement
Neural analysis suggests this role is
optimal for Mid candidates.
“Manager, Third Party Risk Management at Pfizer. Skills: Third Party Risk Management, Risk assessment, Vendor oversight, Policy development, Program execution, Stakeholder management. Define and maintain third‑party risk management policies and procedures. Oversee the execution of the TPRM program”
What You'll Achieve.
Ensuring risk-based decision-making is used; Security, privacy, and regulatory compliance is integrated seamlessly; Organization focused on understanding vendor risks; Applying a structured approach to assessments; Maintaining reliable documentation that supports continuity and compliance; Ensure third‑party risk decisions are guided by the framework; Ensure vendor relationships follow organizational requirements; Support consistent oversight across all engagements; Summarize third‑party risk posture, program performance, key issues, and emerging trends; Ensure third‑party risks are understood and managed; Ensure security and cyber requirements are embedded into contracts; Provide actionable insights
Industry & Context.
Proactive problem-solving approach
What They're Looking For.
Must Have
Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, or a related field., 5+ years of experience in information security, risk, compliance, information protection, or related disciplines., Experience with frameworks and standards such as NIST Cybersecurity Framework or ISO 27001., Experience developing and maintaining vendor risk policies, SOPs, and compliance frameworks., Ability to manage multiple priorities, work with cross-functional teams, and deliver high-quality outputs., Capability to align cybersecurity strategy with business objectives and operational resilience goals., leadership, communication, and presentation skills, with the ability to translate complex security concepts into business-focused insights for senior executives., Excellent communication and interpersonal ability to influence across levels and functions., Demonstrated experience in an agile work environment possessing qualities such as a collaborative mindset, adaptability to change, and a proactive problem-solving approach.
Nice to Have
Demonstrated experience working in pharmaceuticals industry and large, complex, or regulated environments., Professional certifications such as CISSP, CISM, CRISC, CISA, PMP, or similar., Hands‑on experience with TPRM/GRC platforms (e. g. , Archer).
What You'll Do.
Define and maintain third‑party risk management policies and procedures
Oversee the execution of the TPRM program
Review inherent risk evaluations and due‑diligence assessments
Review high‑risk assessments
Lead governance for risk treatment decisions
Ensure vendor records
and risk findings are accurate
Coordinate communication with vendors
concise reporting for leadership
Partner with procurement
and business stakeholders
Partner with Legal and Procurement to ensure security and cyber requirements are embedded into contracts
Identify opportunities to strengthen the TPRM process
Present on TPRM program to senior and executive leadership
How You'll Work.
Team & Collaboration
Partner with procurement, legal, security, and business stakeholders; Partner with Legal and Procurement to ensure security and cyber requirements are embedded into contracts; Work with cross-functional teams
Communication Scope
Excellent communication and interpersonal ability to influence across levels and functions; Ability to translate complex security concepts into business-focused insights for senior executives; Prepare clear, concise reporting for leadership; Present on TPRM program to senior and executive leadership
Full Job Description
## **ROLE SUMMARY** Our Global Governance, Risk, and Compliance (GRC) team provides comprehensive blueprints for cybersecurity excellence by embedding governance, risk management, and compliance into every layer. The team is responsible for ensuring risk-based decision-making is used and that security, privacy, and regulatory compliance is integrated seamlessly with Pfizer’s organization. We are seeking a Manager, Third Party Risk Management, who provides direction for how the organization evaluates and oversees its external vendors. This role maintains the framework that guides third party risk decisions, ensures vendor relationships follow organizational requirements, and supports consistent oversight across all engagements. It keeps the organization focused on understanding vendor risks, applying a structured approach to assessments, and maintaining reliable documentation that supports continuity and compliance. ## **ROLE RESPONSIBILITIES** * Define and maintain third‑party risk management policies and procedures that outline how vendors are assessed, classified, and monitored. * Oversee the execution of the TPRM program. * Review inherent risk evaluations and due‑diligence assessments to confirm that relevant security, privacy, compliance, and operational risks are properly identified and documented. * Review high‑risk assessments, ensuring findings are well‑articulated, evidence‑based, and aligned with internal standards. * Lead governance for risk treatment decisions, including remediation plans, compensating controls, and formal risk acceptances/exceptions. * Ensure vendor records, assessments, contracts, and risk findings are accurate, complete, and maintained in accordance with TPRM expectations and regulatory requirements. * Coordinate communication with vendors to request clarifications, gather required evidence, and follow up on remediation activities. Prepare clear, concise reporting for leadership that summarizes third‑party risk posture, program perfo
Applying for this Manager, Third Party Risk Management role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
How to Apply on Workday
- Workday has a multi-step form — save your progress after every section.
- "Apply With LinkedIn" can fail or lose data; manual entry is more reliable.
- Watch for the "Submit for Review" final step — hitting "Save" alone does not submit.
- Job requisition numbers are useful when following up with HR by email.
ANONYMOUS · UNFILTERED
What do employees actually say about Pfizer?
Real rants from real employees. Read before you apply.