- Salary
- $125k – $179k
- Location
- US-Nationwide-FIELD, United States of America
- Type
- Full-time
- Department
- Engineering
- Seniority
- Senior
- Experience
- 6+ years
- Source
- Workday
Description
What Information Security and Risk contributes to Cardinal Health
Information Technology oversees the effective development, delivery, and operation of computing and information services. This function anticipates, plans, and delivers Information Technology solutions and strategies that enable operations and drive business value.
Information Security and Risk develops, implements, and enforces security controls to protect the organization's technology assets from intentional or inadvertent modification, disclosure or destruction. This job family develops system back-up and disaster recovery plans. Information Technology also conducts incident response, threat management, vulnerability scanning, virus management and intrusion detection and completes risk assessments.
Job Overview:
The Senior Engineer, Information Security & Risk is a second line of defense role responsible for defining, implementing, and evaluating the effectiveness of IT SOX controls. Reporting to the Manager, Information Security & Risk , this role drives the detail design and implementation of IT SOX controls based on relevant risks. Furthermore, the position will work closely with Manager, Information Security & Risk to support business and IT leaders for ongoing risk management process and continuous control/process improvement.
Responsibilities:
- Control design and remediation consulting –
- Perform IT risk assessment for pilot areas, identify control gap, and provide guidance for gap remediation
- Work with IT stakeholders to design effective IT controls to help the IT org achieve SOX compliance goals
- Process improvement of IT controls that increases operational efficiency and reduces the likelihood of control failure
- Evaluate/monitor the execution of IT controls to ensure they are operating effectively
- Support due diligence phase of company's M&A activities
- Provide support for third party certifications (such as SOC1/2) review and issuance
- Align with internal and external audit to understand SOX scope and audit strategy
- Track and drive remediation of IT control issues within our IT risk governance process
- Manage assigned junior staff(s) and contractors to ensure the quality of the work
- Support budgeting of compliance workstream and responsible for proactively communicate budget overruns to key stakeholders
- Support the manager in compliance posture reporting
Qualifications:
- Bachelor’s degree in related field or equivalent work experience
- Deep knowledge of IT SOX control and audit methodology - 6 + years of experience in related field preferred, such as IT audit and/or IT compliance function preferred
- Strong understanding and experience with SOX is a must and knowledge on other compliance requirements/frameworks, such as HIPAA, GDPR, PCI, is a plus
- Strong in educating/influencing of IT stakeholders to raise their awareness/mindset of IT control compliance
- Strong root cause analysis and problem-solving skill is a must
- Pro-level of risk-based judgement in addressing control issues and juggling competing priorities
- Self-motivated to learn new technologies and achieve objectives
- Ability to multi-task with organization, efficiency, accountability, and attention to detail
- Strong knowledge in IT technologies and concepts including networks, databases, middleware, interfaces, and applications. Knowledge/experience of IT controls for mainstream ERP, such as SAP, is a plus
- Strong flowcharting skill is preferred
- Experience with IT risk governance software (i.e., Archer, AuditBoard, ServiceNow GRC) is a plus
- Professional certification preferred: CISA, CPA, CISM, CISSP, CRISC
Anticipated salary range: $125,300 - $178,900
Bonus eligible: yes
Benefits: Cardinal Health offers a wide variety of benefits and programs to support health and well-being.
Medical, dental and vision coverage
Paid time off plan
Health savings account (HSA)
401k savings plan
Access to wages before pay day with myFlexPay
Flexible spending accounts (FSAs)
Short- and long-term disability coverage
Work-Life resources
Paid parental leave
Healthy lifestyle programs
Application window anticipated to close: 10/15/2026 *if interested in opportunity, please submit application as soon as possible.
The salary range listed is an estimate. Pay at Cardinal Health is determined by multiple factors including, but not limited to, a candidate’s geographical location, relevant education, experience and skills and an evaluation of internal pay equity.
Candidates who are back-to-work, people with disabilities, without a college degree, and Veterans are encouraged to apply.
Cardinal Health supports an inclusive workplace that values diversity of thought, experience and background. We celebrate the power of our differences to create better solutions for our customers by ensuring employees can be their authentic selves each day. Cardinal Health is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, ancestry, age, physical or mental disability, sex, sexual orientation, gender identity/expression, pregnancy, veteran status, marital status, creed, status with regard to public assistance, genetic status or any other status protected by federal, state or local law.
To read and review this privacy notice click here