Position Title: Sr Manager Tech Consumer Risk & Assurance US
Tampa, FL, US, 33609
Senior Manager Tech Consumer Risk & Assurance US – Tampa, FL
At PMI U.S., we are building a modern nicotine business—focused on helping make a future without cigarettes a reality in America. As the U.S. businesses of Philip Morris International, we are investing in new products, science, and capabilities to provide the approximately 25 million legal age adults who still smoke with better alternatives.
Our approach is rooted in innovation, responsible marketing, and a growing U.S. footprint that spans manufacturing, technology, and commercial operations across the country.
That creates real opportunity. You’ll have the space to take ownership, develop new ideas, and contribute to work that is shaping our business and the category. We’re looking for people who are curious, collaborative, and motivated by progress—because the scale of what we’re building creates room to grow in different directions.
About the Role
The role combines strategic leadership, governance oversight and hands-on engagement across Asset Assurance, IT Resilience, Security Operations and Security Engineering. It partners closely with service managers, product group/teams, engineering, architecture, and information security (InfoSec) to strengthen security posture, improve operational resilience, assure technology asset governance and enhance security operations capability across the technology lifecycle.
The role is also expected to champion practical AI-enabled cybersecurity use cases, ensuring AI, automation and analytics are used responsibly to improve threat detection, vulnerability prioritisation, risk insights, incident readiness, control monitoring and security reporting while maintaining human oversight, data protection and policy alignment.
Your ‘day to day’:
- Senior experience in technology security, cybersecurity, IT risk, controls assurance, platform security, resilience, or related disciplines within complex enterprise environments.
- Strong knowledge of modern technology ecosystems, including cloud, SaaS, IaaS, PaaS, APIs, microservices, CI/CD, application security, and operational support models.
- Proven ability to integrate security, risk, and control requirements into Agile, DevOps, platform operations, and service management practices.
- Experience with asset governance, technology inventories, service ownership, configuration management, and technology lifecycle risk management.
- Expertise in disaster recovery, business continuity, resilience testing, recovery planning, supplier resilience assessments, and remediation management.
- Experience in security operations, incident response, vulnerability management, security monitoring, operational playbooks, and reporting.
- Strong understanding of secure engineering, threat modeling, DevSecOps, security testing, cloud security, and platform hardening.
- Practical knowledge of AI, machine learning, and generative AI applications in cybersecurity, including threat intelligence, anomaly detection, phishing and malware triage, vulnerability prioritization, SOC automation, and risk reporting.
- Ability to assess AI-enabled security tools and use cases, including benefits, limitations, data requirements, control considerations, and human oversight needs.
- Awareness of AI-related security risks, including prompt injection, data leakage, model misuse, adversarial attacks, insecure integrations, and sensitive data exposure.
- Ability to translate complex security, resilience, asset, AI, and risk data into clear, actionable insights for senior stakeholders.
- Excellent consulting, influencing, facilitation, and executive communication skills, with a pragmatic, risk-based approach.
- Ability to navigate ambiguity, manage competing priorities, and balance strategic leadership with hands-on execution.
Key Skills:
- Senior experience in cybersecurity, technology risk, controls, resilience, security operations, or platform security within complex enterprise environments.
- Strong understanding of modern technology platforms, including cloud, SaaS, APIs, microservices, CI/CD, and application security.
- Proven ability to embed security, risk, and controls into Agile, DevOps, platform operations, and service management.
- Experience in asset governance, configuration management, service ownership, and technology lifecycle risk management.
- Expertise in disaster recovery, service continuity, resilience testing, supplier resilience, and remediation tracking.
- Experience in security operations, incident response, vulnerability management, security monitoring, and reporting.
- Knowledge of secure engineering, threat modeling, DevSecOps, security testing, cloud security, and platform hardening.
- Practical understanding of AI, machine learning, and generative AI applications in cybersecurity.
- Ability to assess AI-enabled security solutions, including benefits, risks, controls, data requirements, and oversight needs.
- Awareness of AI security risks, including prompt injection, data leakage, model misuse, adversarial attacks, and insecure integrations.
Preferred Qualifications
- Bachelor's degree or equivalent experience in Information Systems, Computer Science, Cybersecurity, IT Risk, Engineering, Data Science, AI, or a related field.
- 10+ years of experience delivering cybersecurity, risk, and compliance strategies and influencing senior stakeholders.
- Broad IT leadership experience across project, product, platform, service management, or security operations.
- Strong understanding of infrastructure, applications, cloud platforms, security engineering, AI automation, and data analytics.
- Relevant certifications such as CISSP, CISM, CRISC, CISA, CBCP, ITIL, CITAM, CHAMP, or equivalent are preferred.
- AI, data, or cybersecurity certifications demonstrating expertise in responsible AI, AI security, automation, analytics, or cyber defense are advantageous.
- Knowledge of industry frameworks and standards, including ISO 27001/27002, NIST, ITIL, SOX, GDPR, OWASP, and cloud security best practices.
- Familiarity with AI governance, AI security principles, and responsible AI practices relevant to technology risk and operations.
- Experience in regulated, global, or business-critical environments where security, resilience, and risk management drive business outcomes.
Annual Base Salary Range: $136,000-170,000
Philip Morris International Inc.'s U.S. businesses are invested in America's future and advancing a smoke-free nation. The businesses are committed to providing the approximately 25 million legal-age consumers who smoke cigarettes with better, smoke-free alternatives and to ensuring the products are marketed responsibly. From PMI's global headquarters in Stamford, Connecticut, and other locations nationwide, PMI U.S. contributes leadership, jobs, investment, and innovation in the U.S. The U.S. businesses employ more than 3,000 people across America and operate product manufacturing facilities, including in Aurora, Colorado, Owensboro, Kentucky, and Wilson, North Carolina. For more information, please visit www.uspmi.com.
Philip Morris International (PMI) is an Equal Opportunity Employer.
#PMIUS
#LI-AC1
Nearest Major Market: Tampa