Senior Third Party Risk (TPRM) Cybersecurity Analyst

McKesson’s Corporate

Cork

Hybrid

EUR 73,000 - 121,000

Full time

4 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

McKesson seeks a Sr. Information Security Analyst to strengthen third-party risk management across our vendor ecosystem in a regulated, enterprise-scale environment.

You will design and support risk assessments, translate findings into actionable insights, and partner with procurement, legal, privacy, compliance, technology, and business teams. The role offers hybrid or remote work options, occasional travel, and a total rewards package.

Qualifications

  • Experience with NIST, ISO 27001, SOC 2 or similar frameworks.
  • Ability to translate findings into actionable risk recommendations.
  • Experience collaborating with cross-functional teams (procurement, legal, privacy).

Responsibilities

  • Design and govern third-party risk management processes.
  • Lead advanced vendor security assessments and remediation validation.
  • Evaluate vendor cybersecurity posture against frameworks and regulatory expectations.
  • Partner with procurement, legal, privacy, compliance, technology, and business stakeholders to integrate risk insights.
  • Develop continuous monitoring for critical vendors, including risk indicators and reporting.
  • Translate complex risk findings into clear recommendations for technical and non-technical audiences.
  • Support executive-ready reporting and risk summaries to improve visibility.
  • Mentor peers and contribute to standardized assessment practices.

Skills

Third-party risk
Vendor security
Cybersecurity
Risk assessment
Stakeholder comms

Education

Bachelor's degree or equivalent

Job description

McKesson is an impact-driven, Fortune 10 company that touches virtually every aspect of healthcare. We are known for delivering insights, products, and services that make quality care more accessible and affordable. Here, we focus on the health, happiness, and well-being of you and those we serve – we care. What you do at McKesson matters. We foster a culture where you can grow, make an impact, and are empowered to bring new ideas. Together, we thrive as we shape the future of health for patients, our communities, and our people. If you want to be part of tomorrow’s health today, we want to hear from you.

About the Role

McKesson is seeking a Sr. Information Security Analyst to help strengthen the security, resilience, and governance of our vendor and supplier ecosystem. In this role, you will design and support third-party risk management practices, conduct advanced vendor security assessments, and translate security findings into clear risk insights for business, technology, legal, privacy, and compliance stakeholders. You will play a key role in helping McKesson make informed decisions about third-party relationships in a regulated, enterprise-scale environment.

What You’ll Do
  • Design, enhance, and govern third-party risk management processes, standards, workflows, and reporting practices.
  • Lead advanced vendor security assessments, including control reviews, inherent/residual risk analysis, and remediation validation.
  • Evaluate vendor cybersecurity posture against recognized frameworks, regulatory expectations, and enterprise security requirements.
  • Partner with procurement, legal, privacy, compliance, technology, and business stakeholders to integrate risk insights into vendor lifecycle decisions.
  • Develop continuous monitoring approaches for critical vendors, including risk indicators, issue tracking, reporting, and escalation.
  • Translate complex cyber risk findings into clear, actionable recommendations for technical and non-technical audiences.
  • Support executive-ready reporting, metrics, dashboards, and risk summaries to improve visibility into third-party cyber risk.
  • Mentor peers and contribute to consistent, scalable assessment practices across the third-party risk program.
Basic Requirements
  • 7+ years of cybersecurity, third-party risk management, vendor security assessment, technology risk, or highly relevant technical experience.
  • Experience conducting vendor security assessments, third-party risk reviews, or cyber risk/control assessments.
  • Experience analyzing cybersecurity controls, identifying risk, documenting findings, and recommending remediation.
  • Knowledge of common security and risk frameworks such as NIST, ISO 27001, SOC 2, HITRUST, CIS, or similar.
  • Experience collaborating with cross-functional partners such as procurement, legal, privacy, compliance, technology, or business teams.
  • Ability to create clear documentation, risk summaries, and stakeholder-ready communications.
  • Bachelor’s degree or equivalent combination of education and experience.
Preferred Skills/Experience
  • Experience designing or improving a third-party risk management program, governance model, or assessment methodology.
  • Experience with continuous monitoring, vendor risk scoring, issue management, SLA tracking, or cyber risk dashboards.
  • Familiarity with healthcare, life sciences, financial services, or other regulated environments.
  • Experience assessing cloud/SaaS providers, data security controls, access management, incident response, business continuity, or privacy/security obligations.
  • Certifications such as CISSP, CISM, CRISC, CISA, CCSP, Security+, or similar.
  • Experience using GRC, vendor risk management, workflow, or reporting tools.
  • Strong analytical thinking, stakeholder influence, and ability to work through ambiguity.
Travel / Work Environment / Physical Requirements

Work arrangement may be remote, hybrid, or office-based depending on business and team needs. Occasional travel may be required for team, stakeholder, vendor, or business meetings. Role generally requires regular use of a computer and participation in virtual or in-person meetings.

Total Rewards

At McKesson, we care about the well-being of the patients and communities we serve, and that starts with caring for our people. That’s why we have a Total Rewards package that includes comprehensive benefits to support physical, mental, and financial well-being. Our Total Rewards offerings serve the different needs of our diverse employee population and ensure they are the healthiest versions of themselves.

As part of Total Rewards, we are proud to offer a competitive compensation package at McKesson. This is determined by several factors, including performance, experience and skills, equity, regular job market evaluations, and geographical markets. The pay range shown below is aligned with McKesson's pay philosophy, and pay will always be compliant with any applicable regulations. In addition to base pay, other compensation, such as an annual bonus or long-term incentive opportunities may be offered.

Our Base Pay Range for this position €72,800 - €121,300

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Third Party Risk (TPRM) Cybersecurity Analyst
Senior Third Party Risk (TPRM) Cybersecurity Analyst

Mckesson Corporation • Cork

Hybrid
EUR 73,000 - 121,000
Total Rewards package
Competitive compensation
Cybersecurity Risk Operations Lead – (Enterprise Applications)
Cybersecurity Risk Operations Lead – (Enterprise Applications)

Mckesson Corporation • Cork

On-site
EUR 62,000 - 103,000
Total Rewards package
Lead DevSecOps Engineer
Lead DevSecOps Engineer

McKesson’s Corporate • Cork

Hybrid
EUR 83,000 - 138,000
Cybersecurity Risk Operations Lead – (Enterprise Applications)
Cybersecurity Risk Operations Lead – (Enterprise Applications)

McKesson’s Corporate • Cork

On-site
EUR 62,000 - 103,000
Sr. Associate Cybersecurity IGA Tester
Sr. Associate Cybersecurity IGA Tester

McKesson’s Corporate • Cork

On-site
EUR 41,000 - 68,000
Total Rewards package
Annual bonus potential
Lead DevSecOps Engineer
Lead DevSecOps Engineer

Mckesson Corporation • Cork

On-site
EUR 83,000 - 138,000
Total Rewards benefits
Cybersecurity Risk Operations Lead – (Enterprise Applications) McKesson Medical-Surgical Inc. · Cork, Ireland Full-time · On-site €61,500–102,500 1 hour ago
Cybersecurity Risk Operations Lead – (Enterprise Applications) McKesson Medical-Surgical Inc. · Cork, Ireland Full-time · On-site €61,500–102,500 1 hour ago

Emploive • Cork

Remote
EUR 62,000 - 103,000
Vendor Cyber Risk Lead — Third-Party Security
Vendor Cyber Risk Lead — Third-Party Security

McKesson’s Corporate • Cork

Hybrid
EUR 73,000 - 121,000
Sr. Associate Cybersecurity IGA Tester
Sr. Associate Cybersecurity IGA Tester

Mckesson Corporation • Cork

On-site
EUR 41,000 - 68,000
Director, Data Engineering
Director, Data Engineering

McKesson • Cork

On-site
EUR 92,000 - 153,000