Senior Cloud Security Engineer
Pfizer Chortiatis Municipal Unit, Macedonia and Thrace, Greece
Pharmaceutical Manufacturing · 10,001+ employees
About the role
The Senior Cloud Security Engineer will design, implement, and evolve secure, scalable cloud platforms across a multi-cloud environment. They will also lead automation initiatives, define security standards, and integrate AI-enabled security capabilities into engineering workflows.
What they look for
Requirements
Candidates must have a Bachelor's degree in a technical field and at least 4 years of hands-on cloud or platform security engineering experience. Proficiency in major cloud providers, Infrastructure as Code tools like Terraform, and strong automation scripting skills are required.
Full description
ROLE SUMMARY
At the heart of Pfizer's Digital transformation sits Global Cloud Services, enabling modern cloud infrastructure and engineering capabilities that influence business outcomes and provide value to our business, shareholders, and patients every day.
The Senior Cloud Security Engineer is a technical leader within the Cloud Engineering organization, responsible for designing, building and evolving secure, scalable and highly automated cloud platforms across a multi-cloud environment. This role plays a critical part in defining cloud security standards, reference architectures and engineering best practices that enable product teams to deliver reliable, well-architected and secure solutions at scale.
The role engineers and secures the cloud infrastructure underpinning Pfizer's core cyber security applications, and helps introduce AI and agentic security capabilities into day-to-day engineering.
The ideal candidate brings deep hands-on cloud security engineering expertise, strong Infrastructure as Code and automation skills, and the ability to influence platform direction through technical leadership, mentorship and architectural contributions.
ROLE RESPONSIBILITIES
Cloud Security Engineering & Architecture
- Design, implement and evolve security controls across AWS, Azure and/or GCP, aligning with enterprise architecture principles and security standards.
- Lead the development and maintenance of secure Infrastructure as Code using Terraform, OpenTofu or similar tools, ensuring consistency, scalability and reusability.
- Own and enhance reusable secure cloud modules, guardrails and reference architectures used across the organization.
- Review and provide security guidance on cloud designs and IaC contributions from other engineers.
Automation, Detection & Tooling
- Design and implement end-to-end automation for security control provisioning, posture remediation and lifecycle management.
- Integrate security and compliance requirements into IaC and CI/CD workflows (policy as code, pipeline security gates).
- Establish and improve security observability, monitoring, detection and alerting for cloud platforms.
- Evaluate and introduce new tooling or approaches that improve security outcomes and developer experience.
Operations, Compliance & Collaboration
- Lead troubleshooting for complex cloud security issues and perform root cause analysis for incidents.
- Collaborate with security, risk and compliance teams to support audits, regulatory requirements and governance initiatives.
- Act as a technical mentor for Cloud Security Engineers, supporting skill development and engineering best practices.
- Drive security modernization initiatives, identifying opportunities to automate, optimize, standardize and simplify.
- Contribute to technical documentation, standards and knowledge sharing to uplift cloud security maturity.
Cyber Security Applications & Platforms in Scope
- The role engineers, secures and operates the cloud infrastructure underpinning Pfizer's core cyber security application estate, including:
- Ping - enterprise identity and access management / federation and single sign-on.
- SailPoint - identity governance and administration, access certification and lifecycle management.
- CyberArk - privileged access management, secrets management and credential vaulting.
- CrowdStrike Falcon LogScale running on Amazon EKS - large-scale security log ingestion, retention and threat hunting.
Cutting-Edge & Agentic Cloud Security Capabilities
- This role sits at the front edge of AI-enabled security engineering. You will work with, evaluate, and operationalize emerging agentic capabilities that are reshaping how cloud security is delivered, including:
- Developer-embedded secret and credential protection - preventing credentials and secretsfrom ever reaching a repository, using GitHub Advanced Security (GHAS) push protection, secret scanning, code scanning and dependency review.
- Autonomous security agents for offensive testing - agent-driven penetration testing (black-box against external cloud estates and white-box against our own accounts) and continuous AI-assisted source code security review.
- AI red team and blue team agents within our cloud-native application protection tooling - using agentic red teaming to continuously probe cloud configurations and workloads, and blue team agents to accelerate detection, triage and response.
- AI-assisted vulnerability remediation - evaluating and adopting emerging code-repair models that generate and validate security fixes rather than only reporting findings.
- Hyperscaler-native security agents - early access and alpha programs from AWS, Microsoft and Google that bring agentic reasoning to cloud security posture, threat detection and automated remediation.
- Agentic security engineering at scale - building the guardrails, evaluation harnesses, and human-in-the-loop controls that let autonomous agents operate safely against a regulated, global pharmaceutical cloud estate.
BASIC QUALIFICATIONS
- Bachelor's Degree in Computer Science, Engineering, IT, or equivalent practical experience.
- 4+ years of hands-on cloud, platform or cloud security engineering experience.
- Strong proficiency in at least one major cloud provider (AWS, Azure, or GCP), with production-scale experience.
- Advanced experience with Infrastructure as Code (Terraform strongly preferred).
- Strong automation and scripting skills (Python strongly preferred).
- Deep understanding of cloud networking, identity, encryption, workload security and cloud-native security services.
- Experience with security tooling such as CSPM/CNAPP, SIEM or log analytics, vulnerability management, or application security scanning.
- Experience working in global, cross-functional engineering environments.
- Ability to lead technical initiatives and make architectural decisions.
- Demonstrated experience in an agile work environment possessing qualities such as a collaborative mindset, adaptability to change, and a proactive problem-solving approach.
PREFERRED QUALIFICATIONS
- Multi-cloud security experience (AWS + Azure or GCP).
- Kubernetes / EKS security experience, including workload identity, admission control and runtime security.
- Experience supporting IAM/SSO, identity governance, privileged access management or SIEM platforms as infrastructure.
- Experience with GitHub Advanced Security, secret scanning or software supply chain security.
- Interest or experience in applying AI / agentic tooling to security engineering.
- Experience with Spacelift, OpenTofu or similar IaC automation platforms.
- Experience in GxP or other highly regulated environments.
- Relevant certifications (AWS/Azure/GCP Security Specialty, CCSP, CISSP, or equivalent).
- Curious, self-driven and committed to continuous skill development, particularly around emerging AI security capabilities.
- Strong problem-solving and analytical mindset, especially for complex cloud systems.
- Comfortable operating with high ownership and autonomy.
- Customer-focused mindset with the ability to balance engineering excellence, security and business outcomes.
Please apply by sending your CV in English.
Work Location Assignment: Hybrid
Purpose
Breakthroughs that change patients' lives... At Pfizer we are a patient centric company, guided by our four values: courage, joy, equity and excellence. Our breakthrough culture lends itself to our dedication to transforming millions of lives.
Digital Transformation Strategy
One bold way we are achieving our purpose is through our company wide digital transformation strategy. We are leading the way in adopting new data, modelling and automated solutions to further digitize and accelerate drug discovery and development with the aim of enhancing health outcomes and the patient experience.
Flexibility
We aim to create a trusting, flexible workplace culture which encourages employees to achieve work life harmony, attracts talent and enables everyone to be their best working self. Let’s start the conversation!
Equal Employment Opportunity
We believe that a diverse and inclusive workforce is crucial to building a successful business. As an employer, Pfizer is committed to celebrating this, in all its forms – allowing for us to be as diverse as the patients and communities we serve. Together, we continue to build a culture that encourages, supports and empowers our employees.
Disability Inclusion
Our mission is unleashing the power of all our people and we are proud to be a disability inclusive employer, ensuring equal employment opportunities for all candidates. We encourage you to put your best self forward with the knowledge and trust that we will make any reasonable adjustments to support your application and future career. Your journey with Pfizer starts here!
Pfizer endeavors to make www.pfizer.com/careers accessible to all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process and/or interviewing, please email disabilityrecruitment@pfizer.com. This is to be used solely for accommodation requests with respect to the accessibility of our website, online application process and/or interviewing. Requests for any other reason will not be returned.
To learn more about acceptable and prohibited uses of AI during the recruitment process, please review our candidate AI-use guidelines available on Pfizer Careers.
Information & Business Tech
Similar roles
-
GNMA IAISO Cybersecurity Program Manager
Crest Security Assurance $150K–$160K/yr
-
Cyber Security Engineer I
Durango Casino & Resort Las Vegas, Nevada, United States
-
IT Security Engineer / Penetration Tester 60% - 100% (m/w/d)
KastGroup GmbH Wallisellen, Zurich, Switzerland
-
Cybersecurity Compliance Analyst
RCG Suitland, Maryland, United States · $115K–$125K/yr
-
Security Engineer I
S.P. Richards Company Atlanta, Georgia, United States
-
Cybersecurity Analyst
Michigan Schools and Government Credit Union Troy, Michigan, United States · $79K/yr