ActiveJobs

​​Senior Cloud Security Engineering Lead​

Pfizer · Greece-Thessaloniki Chortiatis

Full-timeOn-sitePosted 13 August 2026
Apply on Company Site →

Job description

ROLE SUMMARY At the heart of Pfizer's Digital transformation sits Global Cloud Services, enabling modern cloud infrastructure and engineering capabilities that influence business outcomes and provide value to our business, shareholders, and patients every day. We are seeking a Senior Cloud Security Engineering Lead to join our growing team. This role requires a strategic technical leader proficient in securing multi-cloud environments, with a strong emphasis on security engineering, automation, and infrastructure as code. The role owns the engineering, hardening and reliability of the cloud platforms that host Pfizer's core cyber security applications, and leads the adoption of AI and agentic security tooling across the estate. The ideal candidate brings deep expertise in at least one major cloud platform (AWS, GCP, or Azure), a hands-on approach using modern engineering practices, and a proven track record in leading and mentoring technical teams. Pfizer seeks individuals that are highly self-motivated, eager to learn, and effective when working in a team environment. A strong aptitude towards self-development, continuous learning, and growth is highly desired. ROLE RESPONSIBILITIES The Senior Cloud Security Engineering Lead provides technical leadership and design expertise for the secure engineering of Pfizer's multi-cloud estate, and leads a small technical team of 3-5 cloud security engineers, providing guidance, mentorship and support in their professional development. Security Engineering & Architecture Lead the design, implementation and management of multi-cloud security solutions focusing on preventative controls, scalability and automation. Own cloud security reference architectures, guardrails and landing zone controls across AWS, Azure and GCP. Design and architect standards for secure deployment and management of multi-cloud infrastructure, embedding security into platform patterns rather than bolting it on. Drive the adoption of policy-as-code and Infrastructure as Code security using Terraform, OpenTofu, Spacelift and Python. Platform Automation & Detection Engineering Lead automation of security control deployment, posture remediation, and evidence collection across the cloud estate. Own detection engineering, logging pipelines and observability for cloud security telemetry at enterprise scale. Serve as escalation point for cloud security operational issues and lead root cause analysis for significant incidents. Leadership & Collaboration Manage and mentor a team of 3-5 cloud security engineers, providing technical leadership, coaching and career development. Partner with Cyber Security, Risk, Compliance and Architecture teams to support audits, GxP and regulatory requirements, and governance initiatives. Collaborate with global cloud engineers, developers and product teams to build secure-by-default cloud-native capabilities. Ensure continuous improvement initiatives are identified, prioritized and addressed within the cloud security environment. Stay ahead of cloud security threats, technologies and engineering practices, and set the direction for their adoption. Cyber Security Applications & Platforms in Scope The role engineers, secures and operates the cloud infrastructure underpinning Pfizer's core cyber security application estate, including: Ping - enterprise identity and access management / federation and single sign-on. SailPoint - identity governance and administration, access certification and lifecycle management. CyberArk (Palo Alto Idira) - privileged access management, secrets management and credential vaulting. CrowdStrike Amazon EKS - large-scale security log ingestion, retention and threat hunting. Cutting-Edge & Agentic Cloud Security Capabilities This role sits at the front edge of AI-enabled security engineering. You will work with, evaluate, and operationalize emerging agentic capabilities that are reshaping how cloud security is delivered, including: Developer-embedded secret and credential protection - preventing credentials and secrets from ever reaching a repository, using GitHub Advanced Security (GHAS) push protection, secret scanning, code scanning and dependency review. Autonomous security agents for offensive testing - agent-driven penetration testing (black-box against external cloud estates and white-box against our own accounts) and continuous AI-assisted source code security review. AI red team and blue team agents within our cloud-native application protection tooling - using agentic red teaming to continuously probe cloud configurations and workloads, and blue team agents to accelerate detection, triage and response. AI-assisted vulnerability remediation - evaluating and adopting emerging code-repair models that generate and validate security fixes rather than only reporting findings. Hyperscaler-native security agents - early access and alpha programs from AWS, Microsoft and Google that bring agentic reasoning to cloud security posture, threat detection and automated remediation. Agentic security engineering at scale - building the guardrails, evaluation harnesses, and human-in-the-loop controls that let autonomous agents operate safely against a regulated, global pharmaceutical cloud estate. BASIC QUALIFICATIONSBachelor's Degree in Information Technology, Computer Science, Computer Engineering, or a similar discipline. 6+ years of experience in cloud engineering, cloud security or infrastructure roles. At least 2 years of experience in a technical leadership role, managing or leading engineering teams. Deep expertise in at least one major cloud platform (AWS, GCP, or Azure) with demonstrated familiarity across multiple cloud providers. Strong experience building and deploying cloud infrastructure using industry-standard IaC tools such as Terraform, OpenTofu, or Pulumi. Strong command of cloud security fundamentals: identity and access management, network security, encryption and key management, workload and container security, and logging/monitoring. Proficiency in at least one major programming language (Python strongly preferred) for security automation and tooling. Experience securing or operating enterprise security platforms such as IAM/SSO, identity governance, privileged access management, or SIEM/log analytics. Excellent communicator with the ability to influence horizontally and vertically across a large, complex, and matrixed organization. Strong technical leadership capabilities including the ability to coach, mentor, and develop other engineers. Customer-centric mentality with a bias towards delivering value at the speed demanded by the business. Demonstrated experience in an agile work environment possessing qualities such as a collaborative mindset, adaptability to change, and a proactive problem-solving approach. PREFERRED QUALIFICATIONS Multi-cloud security experience across AWS, GCP, and Azure. Hands-on experience with Kubernetes / EKS security at scale. Experience with CNAPP / CSPM tooling and with GitHub Advanced Security or equivalent application security tooling. Experience applying AI or agentic tooling to security engineering problems. Experience qualifying cloud services capabilities for use within GxP or other highly regulated environments. Experience with Spacelift or similar IaC automation platforms. Relevant certifications (AWS/Azure/GCP Security Specialty, CISSP, CCSP, OSCP, or equivalent). Curious, self-driven and committed to continuous skill development, particularly around emerging AI security capabilities. Strong problem-solving and analytical mindset, especially for complex cloud systems. Comfortable operating with high ownership and autonomy. Customer-focused mindset with the ability to balance engineering excellence, security and business outcomes. Please apply by sending your CV in English. Work Location Assignment: Hybrid Purpose Breakthro

Verified and listed by ActiveJobs. Applications are made directly on Pfizer's own career page — we never sit in the middle.