For Business
Senior Manager, Information Protection Engineering
At A Glance
We are seeking a Senior Manager, Information Protection Engineering, to lead and evolve our client’s information protection capabilities within the Cyber GRC organization. This role is critical to safeguarding sensitive scientific, clinical, patient, and business information across our client’s global enterprise. The role will lead a team of highly skilled engineers and work closely with CISO organization, Privacy, Legal, Compliance, R&D, Infrastructure, and Cloud Services partners to design, implement, and operate scalable information protection solutions aligned to regulatory requirements and business priorities.
Application Deadline: 10/01/2027
We are the 1st Hub for Developers! Our motto is “From Developers to Developers”! Our vision is to provide real career opportunities for candidates that want to take the next step in their career. Code.Career is the first process that you will speak with developers (only!) and tech (freak) experts!
Employment Type: Full-Time
Our client, is one of the world’s leading biopharmaceutical companies, dedicated to discovering, developing, and delivering innovative medicines and vaccines that improve and extend patients’ lives. With a presence in more than 100 countries and a history spanning over 175 years, our client combines cutting-edge science, technology, and global expertise to address some of the world’s most challenging healthcare needs. The company fosters a culture of innovation, collaboration, and continuous learning, empowering its people to drive breakthroughs that make a meaningful impact on global health.
Join a global leader in pharmaceuticals, and immerse yourself in a dynamic experience where you’ll contribute to groundbreaking projects that impact the lives of millions!
Key Responsibilities
- Lead the definition of enterprise information protection technical strategy, reference architectures, and control frameworks, including DLP, data discovery and classification, and encryption requirements.
- Establish and maintain information protection technical standards, guardrails, and design patterns that guide implementation across endpoints, cloud platforms, applications, and collaboration tools.
- Define policy and control requirements for encryption, key management, and secrets management in partnership with Cloud, Infrastructure, and Identity teams, ensuring alignment with information protection objectives.
- Lead and provide hands-on oversight of the implementation, configuration, and lifecycle governance of information protection technologies such as DLP, data classification, data discovery solutions, and AI information protection.
- Provide architectural guidance and design review for information protection integrations within platforms, applications, and business solutions.
- Influence tooling decisions through risk‑based requirements, rather than operational ownership of underlying cloud or infrastructure services.
- Embed security‑by‑design principles for information protection into the application and platform lifecycle, including requirements for data handling, classification, retention, and policy enforcement.
- Partner with Digital, Cloud Services, Infrastructure, and IT teams to ensure information protection controls are designed into platforms, not bolted on post‑deployment.
- Partner with Security Operations and Incident Response teams to support detection, investigation, and response to information protection incidents and policy violations.
- Ensure information protection capabilities align with enterprise risk management frameworks, internal security standards, and audit expectations.
- Collaborate with Privacy, Legal, Compliance, and Cyber GRC teams to ensure information protection controls support global regulatory and industry requirements (e.g., GDPR, HIPAA, SOX, GxP).
- Translate NIST, regulatory, privacy requirements, and risk requirements into clear, implementable information protection technical controls and guidance.
- Define and report metrics that demonstrate information protection effectiveness, risk trends, and maturity improvement to Cyber GRC and senior leadership.
Required Qualifications
- Bachelor’s degree in Information Security, Computer Science, Engineering, or a related field, or equivalent experience.
- 6+ years of experience in cybersecurity or information protection–related roles, with responsibility for enterprise‑scale information protection controls.
- Demonstrated experience designing, implementing, and operating data loss prevention (DLP) controls across endpoints, email, cloud platforms, and collaboration tools.
- Strong technical experience with data classification, labelling, and policy‑based enforcement across structured and unstructured data.
- Hands‑on experience implementing and managing encryption technologies (data at rest and in transit), key management, and secure data handling controls.
- Experience integrating information protection controls into cloud platforms, SaaS applications, and enterprise collaboration environments.
- Experience operating security controls in large, complex, and regulated enterprise environments.
- Proven ability to collaborate across engineering, digital, and operations teams to deliver practical and effective information protection outcomes.
- Demonstrated experience in an agile work environment possessing qualities such as a collaborative mindset, adaptability to change, and a proactive problem-solving approach.
Preferred Qualifications
- Familiarity with cybersecurity frameworks, regulatory requirements, and risk management practices relevant to pharmaceutical or life sciences organizations.
- Professional certifications such as CDPSE, CIPT, CIPP/E, CISSP, CISM.
Prior leadership experience managing or mentoring information protection engineers or security engineering teams. - Strong understanding of data lifecycle management, including data creation, access, sharing, retention, and secure disposal.
- Strong analytical and communication skills, with the ability to clearly articulate information protection risks and design decisions to senior stakeholders.
Nice-to-Have Skills
- Proven ability to collaborate across engineering, digital, and operations teams to deliver practical and effective information protection outcomes.
- Demonstrated experience in an agile work environment possessing qualities such as a collaborative mindset, adaptability to change, and a proactive problem-solving approach.
Salary (Ind.): 50000-65000 € / Per year Gross
Upon further discussion with our client.
Applying for
Your details
We’ll only use this to follow up about this role.

