Rodeo
Get started

Pfizer

Lead Threat Response Operations Analyst

Sandwich
Posted about 24 hours ago
Sign up to applySee more jobs like this
Get notified of more jobs like this · No spam, ever

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

Role Summary

Our Global Cyber Defense team is responsible for safeguarding Pfizer's digital assets and infrastructure through proactive threat detection, incident response, and risk mitigation across on-premises, cloud, and hybrid environments.

As a Lead Threat Response Operations Analyst within Pfizer’s Global Cyber Defense organization, you will serve as a senior individual contributor, providing technical leadership for the investigation and response to sophisticated cyber threats. While this is not a people-management role, you will lead complex investigations, coordinate the response to security incidents on a global scale, and provide technical guidance to analysts and partner teams. You will bring deep expertise in cyber threat analysis, incident response, malware investigations and adversary tradecraft, with the ability to operate confidently across complex business and technical environments.

Working alongside Threat Detection, Digital Forensics, Security Engineering and other partner teams, you will identify, contain and eradicate threats while providing strategic recommendations to strengthen Pfizer’s cyber resilience.

Role Responsibilities

  • Correlate and analyse security telemetry from endpoint, identity, network, cloud, email and threat intelligence sources to identify, investigate and respond to malicious activity.
  • Apply knowledge of adversary tactics, techniques and procedures (TTPs) to reconstruct attack lifecycles, determine attack pathways, identify root cause and develop strategic detection and mitigation recommendations.
  • Lead the assessment of cyber security incidents, determining severity, business impact, threat scope, and appropriate response and escalation actions.
  • Apply advanced knowledge of networking, operating systems and security architectures to analyse technical evidence, identify attack vectors and guide effective containment, eradication and remediation actions.
  • Communicate complex technical findings, incident impacts, response decisions and remediation recommendations clearly to technical teams, business stakeholders and senior leadership.
  • Drive continuous improvement of Threat Response processes, investigation methodologies, operational procedures, reporting standards, and playbooks to enhance the effectiveness and maturity of the cyber incident response capability.
  • Co-ordinate effectively across technical and business teams to coordinate cyber incident response activities, maintaining professionalism and sound judgement during high-pressure situations.
  • Lead complex cyber security projects and cross-functional workstreams, ensuring timely delivery of objectives and operational improvements.
  • Support the triage of cyber security tickets, providing technical guidance on priority, scope, investigation, escalation and appropriate response actions.
  • Provide technical guidance, coaching and knowledge sharing to analysts and partner teams to strengthen investigation quality and Threat Response capability.
  • Participate in a scheduled on-call rotation, including weekends, providing timely response, investigation, escalation, and coordination of cyber security incidents.
  • Maintain and continuously develop technical expertise in cyber security, threat response, and emerging attack techniques through ongoing training, research, and professional development.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

Basic Qualifications

  • Bachelor’s degree in cyber security, computer forensics, computer science, Information Security, Information Systems, Engineering, Sciences or related field.
  • Some relevant experience in cyber security operations, incident response or threat investigation, with demonstrated experience leading complex investigations.
  • Advanced understanding of TCP/IP, network protocols and traffic flows, operating systems, cloud and identity technologies, enterprise security architectures and defence-in-depth principles.
  • Advanced knowledge of Windows operating systems, system administration, security controls, native utilities and investigative artefacts.
  • Demonstrated ability to analyse and correlate large volumes of security log data using security information and event management (SIEM) platforms, such as CrowdStrike Falcon Next-Gen SIEM, Splunk, Google SecOps and draw accurate, evidence-based conclusions.
  • Experience using endpoint detection and response (EDR) platforms, such as CrowdStrike Falcon, Microsoft Defender for Endpoint or VMware Carbon Black, to investigate malicious activity, analyse endpoint telemetry and support incident containment and remediation.
  • Experience using security analysis and investigation tools such as Wireshark, Snort, Splunk, Kali Linux, SIFT Workstation, REMnux and Volatility or comparable commercial and open-source technologies, including tools used for memory forensics and malware analysis.
  • Advanced understanding of the life cycle of network threats, attacks, attack vectors and methods of exploitation with an understanding of intrusion set tactics, techniques and procedures (TTPs).
  • Demonstrated ability to analyse and resolve complex technical problems, working independently and collaboratively within cross-functional teams.
  • Maintain and continuously develop technical expertise in cyber security, threat response and emerging attack techniques through ongoing training, research and professional development.
  • Strong written, verbal and interpersonal communication skills, together with demonstrated organisational and planning abilities and the capacity to coordinate multiple complex investigations and workstreams simultaneously.
  • Excellent communication and presentation skills with the ability to present to a variety of internal audiences including senior executives.
  • Demonstrated experience leading and delivering complex cyber security projects and cross-functional workstreams, achieving both short-term objectives and longer-term operational improvements.
  • Practical experience using the Linux command line to support security investigations, data analysis and the operation of cyber security tools.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Preferred Qualification

  • Participation in practical cyber security exercises, such as red team and blue team simulations, capture-the-flag challenges, cyber ranges or incident response exercises.
  • Experience using scripting or programming languages, such as Python or PowerShell, to support security investigations, analyse security data and automate repetitive tasks.

Work Location Assignment

Hybrid

Purpose

Breakthroughs that change patients' lives... At Pfizer we are a patient centric company, guided by our four values: courage, joy, equity and excellence. Our breakthrough culture lends itself to our dedication to transforming millions of lives.

Digital Transformation Strategy

One bold way we are achieving our purpose is through our company wide digital transformation strategy. We are leading the way in adopting new data, modelling and automated solutions to further digitize and accelerate drug discovery and development with the aim of enhancing health outcomes and the patient experience.

Flexibility

We aim to create a trusting, flexible workplace culture which encourages employees to achieve work life harmony, attracts talent and enables everyone to be their best working self. Let’s start the conversation!

Equal Employment Opportunity

We believe that a diverse and inclusive workforce is crucial to building a successful business. As an employer, Pfizer is committed to celebrating this, in all its forms – allowing for us to be as diverse as the patients and communities we serve. Together, we continue to build a culture that encourages, supports and empowers our employees.

DisAbility Confident

We are proud to be a Disability Confident Employer and we encourage you to put your best self forward with the knowledge and trust that we will make any reasonable adjustments necessary to support your application and future career. Our mission is unleashing the power of our people, especially those with unique superpowers. Your journey with Pfizer starts here!

To learn more about acceptable and prohibited uses of AI during the recruitment process, please review our candidate AI-use guidelines available on Pfizer Careers.

Information & Business Tech


(Note: The content is presented as-is, without any modifications or additions.)

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Location

Sandwich, England, United Kingdom

Sign up to applySee more jobs like this