- Salary
- $137k – $232k
- Location
- US-Nationwide-FIELD, United States of America
- Type
- Full-time
- Department
- Security
- Seniority
- Director
- Experience
- 8+ years
- Source
- Workday
Description
What Information Security and Risk contributes to Cardinal Health
Information Security and Risk develops, implements, and enforces security controls to protect the organization's technology assets from intentional or inadvertent modification, disclosure or destruction.
The Director, Cyber Risk Services is responsible for establishing, leading, and continuously improving the cybersecurity risk management program to identification, assessment, mitigation, and reporting of cyber risks. Reporting to the Vice President, Global Cybersecurity Governance, Risk & Compliance (GRC), this role drives the design and execution of risk management frameworks, methodologies, and supporting governance processes aligned with enterprise risk management (ERM), regulatory requirements, and business objectives.
Furthermore, this leader oversees core cyber risk capabilities including risk framework development, risk remediation oversight, and third-party risk management. It also plays a critical role in integrating cybersecurity risk into enterprise decision-making, enabling business-aligned risk insights, and driving adoption of consistent risk practices.
Location - Fully remote, open to candidates based nationwide
Responsibilities
- Develop and lead the cybersecurity risk management strategy aligned with enterprise risk management frameworks, business objectives, and regulatory expectations.
- Collaborate with the VP of Global Cyber GRC and enterprise stakeholders to define risk management priorities, methodologies, and governance structures.
- Establish governance processes, roles, and accountability models to ensure consistent execution of cyber risk activities across the organization.
- Serve as an advisor to leadership on cybersecurity risk posture, emerging threats, and mitigation strategies.
- Define, standardize, and maintain cybersecurity risk management frameworks, methodologies, and taxonomies across the CISO Program.
- Ensure consistency in risk identification, assessment, scoring, and reporting across cybersecurity and business segments.
- Align cybersecurity risk methodologies with enterprise risk management (ERM) frameworks to enable integrated risk visibility.
- Continuously update and improve risk frameworks to reflect evolving threats, technologies, and regulatory requirements.
- Oversee enterprise-wide cybersecurity risk assessments to identify threats, vulnerabilities, and control gaps.
- Establish and maintain a centralized risk register to track, assess, and manage cybersecurity risks across systems, applications, and business processes.
- Ensure risks are documented, prioritized, and assigned to accountable owners for remediation within the GRC tool.
- Collaborate with business and technology stakeholders to ensure risk identification and alignment with business impact.
- Lead development and execution of risk mitigation and remediation strategies in partnership with cybersecurity and business segment teams.
- Oversee vulnerability remediation processes, including monitoring SLA compliance, tracking remediation outcomes, and escalating non-compliance.
- Ensure effective tracking and reporting of remediation efforts to reduce security risk exposure.
- Oversee and drive issues and exception processes, ensuring documentation, approval, and alignment with defined risk tolerance levels.
- Partner with Enterprise Risk Management (ERM) teams to align cybersecurity risks, controls, and mitigation strategies with the broader organizational risk framework.
- Ensure cybersecurity risks are integrated into enterprise risk reporting and governance processes.
- Support enterprise risk discussions by providing insights into cybersecurity risk trends, impacts, and mitigation progress.
- Oversee the cybersecurity third-party risk management (TPRM) program, including vendor risk assessments, onboarding, continuous monitoring, and termination processes.
- Establish governance for third-party lifecycle management to ensure risks are identified and mitigated throughout vendor engagements.
- Oversee contract reviews to validate inclusion of security and data protection requirements based on vendor criticality.
- Collaborate with internal teams and external providers to develop joint incident response plans and ensure readiness for third-party-related incidents
- Define and maintain cybersecurity risk metrics, including KPIs and KRIs, to monitor program performance and risk posture.
- Develop and deliver reporting to executive leadership, providing actionable insights into cybersecurity risks and trends.
- Lead development and enhancement of GRC tools and platforms to enable efficient risk, control, and compliance management.
- Define use cases, technical requirements, and configurations for GRC platforms to support risk monitoring and reporting.
- Develop actionable reporting and insights that translate cybersecurity risks into meaningful business context for segment leadership.
- Serve as a liaison between business segment and cybersecurity teams to coordinate risk management activities and ensure alignment.
- Partner with security architecture and engineering teams to validate solutions align with security standards and risk requirements.
- Drive integration of cybersecurity risk management into business processes, projects, and technology initiatives.
- Collaborate with cybersecurity, IT, legal, compliance, audit, and business teams to embed risk management practices into enterprise operations.
- Provide guidance and support to project teams to ensure cybersecurity risks are identified and addressed in new initiatives.
- Support audit and regulatory activities by providing risk-related documentation, insights, and remediation tracking.
- Build and lead a high-performing cyber risk team with capabilities across risk management, third-party risk, and reporting.
- Develop team capabilities through coaching, training, and structured career development initiatives.
- Drive continuous improvement of risk management processes, tools, and methodologies to enhance program maturity and scalability.
- Foster a culture of risk awareness, accountability, and continuous improvement across the organization.
Qualifications
- Ideally targeting individuals with 8+ years of experience in cybersecurity, risk management, or information security, with a focus on cyber risk and governance.
- Strong expertise in cybersecurity risk management frameworks, methodologies, and enterprise risk integration.
- Experience leading risk assessment programs, risk remediation efforts, and third-party risk management.
- Strong understanding of cybersecurity frameworks (e.g., NIST CSF, ISO 27001) and regulatory requirements.
- Experience developing executive-level reporting and communicating risk insights to senior leadership.
- Strong leadership, communication, and stakeholder management skills.
- Experience as a people leader overseeing cybersecurity risk or GRC functions, preferred.
- Experience in highly regulated industries (e.g., aviation, financial services, healthcare, or government), preferred.
- Professional certifications such as CISSP, CISM, CRISC, or CISA - preferred.
Anticipated Salary Range $137,400 - $232,320 USD
Bonus Eligible - Yes
Benefits: Cardinal Health offers a wide variety of benefits and programs to support health and well-being.
Medical, dental and vision coverage
Paid time off plan
Health savings account (HSA)
401k savings plan
Access to wages before pay day with myFlexPay
Flexible spending accounts (FSAs)
Short- and long-term disability coverage
Work-Life resources
Paid parental leave
Healthy lifestyle programs
Application window anticipated to close: 09/30/2026 * if interested in opportunity, please submit application as soon as possible.
The salary range listed is an estimate. Pay at Cardinal Health is determined by multiple factors including, but not limited to, a candidate’s geographical location, relevant education, experience and skills and an evaluation of internal pay equity.
Candidates who are back-to-work, people with disabilities, without a college degree, and Veterans are encouraged to apply.
Cardinal Health supports an inclusive workplace that values diversity of thought, experience and background. We celebrate the power of our differences to create better solutions for our customers by ensuring employees can be their authentic selves each day. Cardinal Health is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, ancestry, age, physical or mental disability, sex, sexual orientation, gender identity/expression, pregnancy, veteran status, marital status, creed, status with regard to public assistance, genetic status or any other status protected by federal, state or local law.
To read and review this privacy notice click here