Zoetis Inc

Cyber Risk & Remediation Service Lead

Zoetis Inc$120K — $150K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor’s degree in Computer Sciences, Information Security, or related field.
  • 5+ years in information security or enterprise risk management.
  • 3+ years leading teams or senior programs in a global environment.
  • 8+ years in cyber/technology risk management with a focus on human risk programs.
  • Experience managing a cyber risk register and driving remediation timelines.

Responsibilities

  • Establish and maintain the enterprise cyber risk governance model.
  • Create and update the Cyber Risk Register with detailed risk information.
  • Lead risk review forums and drive decisions with stakeholders.
  • Partner with teams to develop and prioritize remediation plans.
  • Oversee M&A cyber risk activities including due diligence and tracking.
  • Lead the Security Awareness & Training program and phishing initiatives.
  • Produce metrics and reports on risk posture and program effectiveness.

Benefits

  • Flexible working hours to liaise with global teams.
  • Opportunities for professional development and continuous learning.
  • Dynamic work environment in a leading pharmaceutical company.
Full Job Description

States considered: PA

Role Description

POSITION SUMMARY

Zoetis is seeking a Cyber Risk & Remediation service lead who will be accountable for the enterprise cyber risk operating cadence, building and maintaining the cyber risk register, driving risk treatment decisions, and ensuring risks are remediated within defined timelines. This leader owns and matures programs spanning Cyber Risk & Remediation, M&A Security risk, and Security Awareness & Training. The role partners closely with technology and business teams to identify risk, assign accountable owners, track remediation progress, and provide clear reporting to Cyber leadership.

POSITION RESPONSIBILITIES

Cyber Risk Governance & Risk Register Ownership

  • Establish the cyber risk governance model (risk taxonomy, scoring/ratings, risk acceptance thresholds, escalation paths).
  • Create, own, and maintain the Cyber Risk Register, ensuring each risk has:
    • defined risk statement and business impact
    • inherent/residual rating
    • accountable risk owner
    • treatment plan (mitigate/accept/transfer/avoid)
    • target remediation date / SLA and evidence of closure
  • Lead recurring risk review forums with technology and business stakeholders; drive risk decisions and document outcomes.

Remediation Program Leadership:

  • Partner with infrastructure, application, and engineering teams to create and prioritize remediation plans.
  • Define remediation SLAs by severity and risk tier and ensure adherence; proactively remove blockers impacting remediation progress.
  • Oversee enterprise cyber exposure management for infrastructure and platforms, including governance of Minimum Security Baselines (MSBs) and continuous security assessment capabilities (e.g., vulnerability and configuration scanning, posture monitoring, and exposure discovery).
  • Translate technical findings into actionable cyber risks, ensuring they are tracked through remediation programs, reported through governance forums, and escalated to technology and business stakeholders when remediation SLAs or risk tolerance thresholds are exceeded.

M&A Security Risk

  • Lead cyber risk activities for M&A: due diligence security findings intake, risk register entry, ownership assignment, and remediation/integration tracking through closure.
  • Standardize M&A security assessment and reporting templates.
  • Oversee the implementation and tracking of security controls.

Security Awareness, Training, and Phishing (Human Risk)

  • Own and lead the enterprise Security Awareness & Training program, including development of role-based, targeted, and risk-informed training initiatives.
  • Oversee the phishing simulation program, driving measurable reductions in risky user behaviors and strengthening the organization’s human security posture.
  • Develop and maintain human risk metrics and KRIs, integrating insights into enterprise cyber risk reporting and informing continuous improvement of awareness strategies.

Metrics & Continuous Improvement:

  • Produce executive-ready reporting on risk posture, top risks, remediation SLA performance, and program effectiveness. 
  • Enable on-demand metrics using industry standard frameworks (MITRE, NIST, etc.)
  • Establish strong partnership and trust across business units and stakeholders.

Mentorship & Leadership:

  • Lead and develop a team and/or matrixed resources supporting cyber risk governance, remediation oversight, and human-risk programs.
  • Operate as a player-coach, capable of both leading the program and personally contributing to key initiatives such as risk analysis, governance facilitation, remediation coordination, and executive reporting.
  • Create and maintain policies, protocols, and standard operating procedures that enable consistent and scalable cyber risk management practices.
  • Manage vendors and partners supporting awareness platforms, phishing simulations, and cyber risk workflow tooling.
  • Foster a culture of accountability, operational excellence, and continuous learning, encouraging collaboration and knowledge sharing across the team.

EDUCATION AND EXPERIENCE

Indicate the formal education, certification or license required and/or preferred. Include the minimum number of years of relevant experience required for the position (where legally permissible).

Education:

  • Bachelor’s degree in Computer Sciences, Information Security, Information Systems, Engineering, Sciences or relevant professional experience.

Experience:

  • 5+ years of experience in information security, technology risk, or enterprise risk, with demonstrated ownership of addressing risk across a global organization and driving cross-functional remediation to closure within defined timelines.
  • 3+ years of people leadership and/or senior program leadership in a global environment, with demonstrated ability to influence and deliver outcomes through matrixed teams.
  • 8+ years of experience (or equivalent depth of expertise) in cyber/technology risk management, with emphasis on human risk programs (awareness, training, phishing) and broader cyber risk governance (risk identification, assessment, tracking, and treatment).

TECHNICAL SKILLS REQUIREMENTS

  • Demonstrated ability to build and operate a cyber risk register and drive closure within defined remediation timelines (SLAs), including governance, escalation, and evidence-based closure.
  • Experience running Security Awareness & Training and phishing programs with measurable outcomes (completion, behavior change, reporting rates, reduced susceptibility).
  • Experience supporting security due diligence and M&A integration risk tracking, including intake of findings, ownership assignment, and remediation through closure.
  • Ability to interpret and communicate technical risk using vulnerability and control data—comfortable with trends, prioritization, and executive-level reporting; able to leverage analytics/data visualization tools (e.g., Power BI, Tableau) personally or through team support.
  • Working knowledge of common security frameworks and compliance requirements (e.g., NIST, ISO 27001, PCI-DSS, HIPAA) and ability to map findings to controls and risk statements.
  • Proven experience coordinating remediation across technical and business teams, managing SLAs, improving remediation workflows, and driving accountability, without needing to be the deepest VM analyst.
  • Solid understanding of vulnerability management concepts and lifecycle (discovery, validation, prioritization, exception handling, remediation, verification) with the ability to review team output and challenge/coach appropriately.
  • Understanding of security policy, enterprise security strategy, architecture concepts, and governance practices, including risk acceptance and exception processes.
  • Broad knowledge of security technologies and principles and risk considerations across on-prem and cloud; familiarity with control frameworks and basic threat modeling concepts.
  • Ability to translate emerging issues (vulnerabilities/exploit trends) into practical guidance, playbooks, and operational improvements—partnering with SMEs as needed.
  • Comfort operating in complex enterprise environments: able to troubleshoot at a high level, ask the right technical questions, and mobilize the right experts (hands-on depth not required).
  • Strong program/project management skills with the ability to manage multiple priorities, run governance cadences, and deliver measurable outcomes.
  • Strong written/verbal communication and influence skills; able to present clearly, negotiate effectively, and drive decisions across levels and functions.
  • High standards of ethics, professionalism, and integrity.
  • Experience in regulated industries (e.g., pharmaceuticals) is desirable.
  • Ability to articulate business-focused security outcomes that guide program direction and improve risk posture.

PHYSICAL POSITION REQUIREMENTS

  • Primarily office-based work involving sitting, computer use, and meetings.
  • Ability to work flexible hours as needed to coordinate with global teams and support audit readiness activities.
  • Occasional travel may be required for audits, regulatory meetings, or integration activities.
  • No unusual physical demands or attendance requirements expected.

Travel Requirements: 5%-10%

 

Full time

 

 

Regular

 

 

Colleague

 

 

About Zoetis Inc

Zoetis Inc Careers

Join the dynamic team at Zoetis Inc, a global leader in animal health services, where innovation, leadership, and care converge to advance animal healthcare worldwide. At Zoetis, we offer unparalleled job opportunities that foster professional growth and personal achievement.

Work You’ll Do

At Zoetis Inc, you will be part of a culture that values diversity, innovation, and leadership. Our team is committed to delivering targeted solutions that enhance animal health through a broad range of products and services. As a member of our team, you will collaborate with skilled professionals to drive change and lead the industry in strategic directions.

Career Growth and Development

Zoetis Inc is dedicated to the professional growth of its employees. We provide extensive training and development programs, including leadership training and diversity workshops, to ensure our team members are equipped for success in their careers and are prepared to meet the challenges of the global market.

Innovative Work Environment

Our commitment to innovation is at the core of our operations. Zoetis Inc is a place where creative thinking and practical solutions meet to create a thriving work environment. Our employees are encouraged to pursue innovative projects that align with our mission of nurturing the world and humankind by advancing animal care.

Join Our Team

Explore job opportunities and open positions across various fields within Zoetis Inc. Whether you’re looking for a professional role in scientific research, marketing, sales, or customer service, we have a position that will match your skills and passions. Our hiring process is designed to identify and attract passionate, curious, and solution-driven team players.

Internship Programs

Kickstart your career with Zoetis Inc through our internship programs. Gain hands-on experience, develop essential industry skills, and build a professional network that will serve as a valuable resource throughout your career. Internships at Zoetis are a gateway to full-time employment and offer a unique insight into the animal health industry.

Benefits and Culture

Choosing a career at Zoetis Inc means more than just employment. It means being part of a team that values your well-being and professional development. Our employees enjoy a range of benefits designed to support their health, well-being, and financial future. At Zoetis, you’ll work in an inclusive environment that fosters a sense of belonging and encourages collaborative and independent work.

Stay Connected

Keep up to date with the latest career tips, industry insights, and company news—all from the people who work at Zoetis Inc. Subscribe to our careers blog and personalize your subscription to receive job alerts and insider tips tailored to your preferences.

Apply Now

Ready to take the next step in your career? Search for open positions that match your skills and interests on our Jobs at Zoetis Inc page. Prepare your resume, sharpen your interview skills, and join a world-leading team in animal health.

Zoetis Inc—Where Careers Grow

At Zoetis Inc, we’re not just about animal health; we’re about supporting your health and career ambitions. See what exciting and rewarding opportunities await you in a company that’s committed to growth, innovation, and leadership in the animal health industry.
Learn more about Zoetis Inc
Size
12,100 employees
Market Cap
$67.3 billion
Industry
Net Income
$1.6 billion
5 Year Trend
+9.7%
Revenue
$6.6 billion
NASDAQ

Similar Jobs

More Jobs at Zoetis Inc

More Information Technology Jobs

Find similar Cyber Risk & Remediation Service Lead jobs: