Senior Third Party Risk (TPRM) Cybersecurity Analyst
The Future of Health Starts with You
·Today
- Salary
- €73k – €121k
- Location
- Cork, IRL - 3300 Cork Airport Business Pk (C210), Ireland
- Workplace
- Hybrid
- Type
- Full-time
- Department
- IT
- Seniority
- Senior
- Source
- Workday
Description
McKesson is an impact-driven, Fortune 10 company that touches virtually every aspect of healthcare. We are known for delivering insights, products, and services that make quality care more accessible and affordable. Here, we focus on the health, happiness, and well-being of you and those we serve – we care.
What you do at McKesson matters. We foster a culture where you can grow, make an impact, and are empowered to bring new ideas. Together, we thrive as we shape the future of health for patients, our communities, and our people. If you want to be part of tomorrow’s health today, we want to hear from you.
About the Role
McKesson is seeking a Sr. Information Security Analyst to help strengthen the security, resilience, and governance of our vendor and supplier ecosystem.
In this role, you will design and support third-party risk management practices, conduct advanced vendor security assessments, and translate security findings into clear risk insights for business, technology, legal, privacy, and compliance stakeholders.
You will play a key role in helping McKesson make informed decisions about third-party relationships in a regulated, enterprise-scale environment.
What You’ll Do
- Design, enhance, and govern third-party risk management processes, standards, workflows, and reporting practices.
- Lead advanced vendor security assessments, including control reviews, inherent/residual risk analysis, and remediation validation.
- Evaluate vendor cybersecurity posture against recognized frameworks, regulatory expectations, and enterprise security requirements.
- Partner with procurement, legal, privacy, compliance, technology, and business stakeholders to integrate risk insights into vendor lifecycle decisions.
- Develop continuous monitoring approaches for critical vendors, including risk indicators, issue tracking, reporting, and escalation.
- Translate complex cyber risk findings into clear, actionable recommendations for technical and non-technical audiences.
- Support executive-ready reporting, metrics, dashboards, and risk summaries to improve visibility into third-party cyber risk.
- Mentor peers and contribute to consistent, scalable assessment practices across the third-party risk program.
Basic Requirements
- 7+ years of cybersecurity, third-party risk management, vendor security assessment, technology risk, or highly relevant technical experience.
- Experience conducting vendor security assessments, third-party risk reviews, or cyber risk/control assessments.
- Experience analyzing cybersecurity controls, identifying risk, documenting findings, and recommending remediation.
- Knowledge of common security and risk frameworks such as NIST, ISO 27001, SOC 2, HITRUST, CIS, or similar.
- Experience collaborating with cross-functional partners such as procurement, legal, privacy, compliance, technology, or business teams.
- Ability to create clear documentation, risk summaries, and stakeholder-ready communications.
- Bachelor’s degree or equivalent combination of education and experience.
Preferred Skills/Experience
- Experience designing or improving a third-party risk management program, governance model, or assessment methodology.
- Experience with continuous monitoring, vendor risk scoring, issue management, SLA tracking, or cyber risk dashboards.
- Familiarity with healthcare, life sciences, financial services, or other regulated environments.
- Experience assessing cloud/SaaS providers, data security controls, access management, incident response, business continuity, or privacy/security obligations.
- Certifications such as CISSP, CISM, CRISC, CISA, CCSP, Security+, or similar.
- Experience using GRC, vendor risk management, workflow, or reporting tools.
- Strong analytical thinking, stakeholder influence, and ability to work through ambiguity.
Travel / Work Environment / Physical Requirements
- Work arrangement may be remote, hybrid, or office-based depending on business and team needs.
- Occasional travel may be required for team, stakeholder, vendor, or business meetings.
- Role generally requires regular use of a computer and participation in virtual or in-person meetings.
At McKesson, we care about the well-being of the patients and communities we serve, and that starts with caring for our people. That’s why we have a Total Rewards package that includes comprehensive benefits to support physical, mental, and financial well-being. Our Total Rewards offerings serve the different needs of our diverse employee population and ensure they are the healthiest versions of themselves.
As part of Total Rewards, we are proud to offer a competitive compensation package at McKesson. This is determined by several factors, including performance, experience and skills, equity, regular job market evaluations, and geographical markets. The pay range shown below is aligned with McKesson's pay philosophy, and pay will always be compliant with any applicable regulations. In addition to base pay, other compensation, such as an annual bonus or long-term incentive opportunities may be offered.
Our Base Pay Range for this position
€72,800 - €121,300McKesson has become aware of online recruiting-related scams in which individuals who are not affiliated with or authorized by McKesson are using McKesson’s (or affiliated entities, like CoverMyMeds or RxCrossroads) name in fraudulent emails, job postings or social media messages. In light of these scams, please bear the following in mind:
McKesson Talent Advisors will never solicit money or credit card information in connection with a McKesson job application.
McKesson Talent Advisors do not communicate with candidates via online chatrooms or using email accounts such as Gmail or Hotmail. Note that McKesson does rely on a virtual assistant (Gia) for certain recruiting-related communications with candidates.
McKesson job postings are posted on our career site: careers.mckesson.com.