Director, Cyber Risk Services (Information Security)

Cardinal Health

Northern (KY)

Hybrid

USD 137,000 - 232,000

Full time

3 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Medical, dental and vision coverage
401k savings plan
Health savings account (HSA)
Paid time off plan
Flexible spending accounts (FSAs)
Work-Life resources
Paid parental leave
myFlexPay

Job summary

Cardinal Health seeks a Director, Cyber Risk Services to design and lead the cybersecurity risk management program, aligning with enterprise risk management and regulatory requirements. You will partner with the GRC leadership to define priorities, drive governance, and elevate risk visibility across the organization.

The role requires deep expertise in cyber risk frameworks, risk remediation, and third-party risk management, with responsibility for executive-level reporting and cross-functional

Qualifications

  • 8+ years in cybersecurity, risk management, or information security.
  • Strong expertise in cyber risk frameworks and ERM integration.
  • Experience leading risk assessment, remediation, and third-party risk management.
  • Strong understanding of cybersecurity frameworks (e.g., NIST CSF, ISO 27001) and regulatory requirements.
  • Experience developing executive-level reporting and communicating risk insights to senior leadership.

Responsibilities

  • Develop and lead cybersecurity risk management strategy aligned with enterprise risk management frameworks, business objectives, and regulatory expectations.
  • Collaborate with the VP of Global Cyber GRC and enterprise stakeholders to define risk management priorities, methodologies, and governance structures.
  • Establish governance processes, roles, and accountability models to ensure consistent execution of cyber risk activities across the organization.
  • Serve as an advisor to leadership on cybersecurity risk posture, emerging threats, and mitigation strategies.
  • Define, standardize, and maintain cybersecurity risk management frameworks, methodologies, and taxonomies across the CISO Program.
  • Ensure consistency in risk identification, assessment, scoring, and reporting across cybersecurity and business segments.

Skills

Cyber risk governance
Risk management frameworks
Executive reporting
Leadership
Stakeholder management

Tools

GRC platforms

Job description

What Information Security and Risk contributes to Cardinal Health Information Security and Risk develops, implements, and enforces security controls to protect the organization's technology assets from intentional or inadvertent modification, disclosure or destruction. The Director, Cyber Risk Services is responsible for establishing, leading, and continuously improving the cybersecurity risk management program to identification, assessment, mitigation, and reporting of cyber risks. Reporting to the Vice President, Global Cybersecurity Governance, Risk & Compliance (GRC), this role drives the design and execution of risk management frameworks, methodologies, and supporting governance processes aligned with enterprise risk management (ERM), regulatory requirements, and business objectives. Furthermore, this leader oversees core cyber risk capabilities including risk framework development, risk remediation oversight, and third-party risk management. It also plays a critical role in integrating cybersecurity risk into enterprise decision‑making, enabling business‑aligned risk insights, and driving adoption of consistent risk practices. Location - Fully remote, open to candidates based nationwide

Responsibilities
  • Develop and lead the cybersecurity risk management strategy aligned with enterprise risk management frameworks, business objectives, and regulatory expectations.
  • Collaborate with the VP of Global Cyber GRC and enterprise stakeholders to define risk management priorities, methodologies, and governance structures.
  • Establish governance processes, roles, and accountability models to ensure consistent execution of cyber risk activities across the organization.
  • Serve as an advisor to leadership on cybersecurity risk posture, emerging threats, and mitigation strategies.
  • Define, standardize, and maintain cybersecurity risk management frameworks, methodologies, and taxonomies across the CISO Program.
  • Ensure consistency in risk identification, assessment, scoring, and reporting across cybersecurity and business segments.
  • Align cybersecurity risk methodologies with enterprise risk management (ERM) frameworks to enable integrated risk visibility.
  • Continuously update and improve risk frameworks to reflect evolving threats, technologies, and regulatory requirements.
  • Oversee enterprise‑wide cybersecurity risk assessments to identify threats, vulnerabilities, and control gaps.
  • Establish and maintain a centralized risk register to track, assess, and manage cybersecurity risks across systems, applications, and business processes.
  • Ensure risks are documented, prioritized, and assigned to accountable owners for remediation within the GRC tool.
  • Collaborate with business and technology stakeholders to ensure risk identification and alignment with business impact.
  • Lead development and execution of risk mitigation and remediation strategies in partnership with cybersecurity and business segment teams.
  • Oversee vulnerability remediation processes, including monitoring SLA compliance, tracking remediation outcomes, and escalating non‑compliance.
  • Ensure effective tracking and reporting of remediation efforts to reduce security risk exposure.
  • Oversee and drive issues and exception processes, ensuring documentation, approval, and alignment with defined risk tolerance levels.
  • Partner with Enterprise Risk Management (ERM) teams to align cybersecurity risks, controls, and mitigation strategies with the broader organizational risk framework.
  • Ensure cybersecurity risks are integrated into enterprise risk reporting and governance processes.
  • Support enterprise risk discussions by providing insights into cybersecurity risk trends, impacts, and mitigation progress.
  • Oversee the cybersecurity third‑party risk management (TPRM) program, including vendor risk assessments, onboarding continuous monitoring, and termination processes.
  • Establish governance for third‑party lifecycle management to ensure risks are identified and mitigated throughout vendor engagements.
  • Oversee contract reviews to validate inclusion of security and data protection requirements based on vendor criticality.
  • Collaborate with internal teams and external providers to develop joint incident response plans and ensure readiness for third‑party‑related incidents Define and maintain cybersecurity risk metrics, including KPIs and KRIs, to monitor program performance and risk posture.
  • Develop and deliver reporting to executive leadership, providing actionable insights into cybersecurity risks and trends.
  • Lead development and enhancement of GRC tools and platforms to enable efficient risk, control, and compliance management.
  • Define use cases, technical requirements, and configurations for GRC platforms to support risk monitoring and reporting.
  • Develop actionable reporting and insights that translate cybersecurity risks into meaningful business context for segment leadership.
  • Serve as a liaison between business segment and cybersecurity teams to coordinate risk management activities and ensure alignment.
  • Partner with security architecture and engineering teams to validate solutions align with security standards and risk requirements.
  • Drive integration of cybersecurity risk management into business processes, projects, and technology initiatives.
  • Collaborate with cybersecurity, IT, legal, compliance, audit, and business teams to embed risk management practices into enterprise operations.
  • Provide guidance and support to project teams to ensure cybersecurity risks are identified and addressed in new initiatives.
  • Support audit and regulatory activities by providing risk‑related documentation, insights, and remediation tracking.
  • Build and lead a high‑performing cyber risk team with capabilities across risk management, third‑party risk, and reporting.
  • Develop team capabilities through coaching, training, and structured career development initiatives.
  • Drive continuous improvement of risk management processes, tools, and methodologies to enhance program maturity and scalability.
  • Foster a culture of risk awareness, accountability, and continuous improvement across the organization.
Qualifications
  • Ideally targeting individuals with 8+ years of experience in cybersecurity, risk management, or information security, with a focus on cyber risk and governance.
  • Strong expertise in cybersecurity risk management frameworks, methodologies, and enterprise risk integration.
  • Experience leading risk assessment programs, risk remediation efforts, and third‑party risk management.
  • Strong understanding of cybersecurity frameworks (e.g., NIST CSF, ISO 27001) and regulatory requirements.
  • Experience developing executive‑level reporting and communicating risk insights to senior leadership.
  • Strong leadership, communication, and stakeholder management skills.
  • Experience as a people leader overseeing cybersecurity risk or GRC functions, preferred.
  • Experience in highly regulated industries (e.g., aviation, financial services, healthcare, or government), preferred.
  • Professional certifications such as CISSP, CISM, CRISC, or CISA - preferred.

Anticipated Salary Range $137,400 - $232,320 USD Bonus Eligible - Yes

Benefits
  • Medical, dental and vision coverage
  • Paid time off plan
  • Health savings account (HSA)
  • 401k savings plan
  • Access to wages before pay day with myFlexPay
  • Flexible spending accounts (FSAs)
  • Short- and long‑term disability coverage
  • Work-Life resources
  • Paid parental leave
  • Healthy lifestyle programs

Application window anticipated to close: 09/30/2026

The salary range listed is an estimate. Pay at Cardinal Health is determined by multiple factors including, but not limited to, a candidate’s geographical location, relevant education, experience and skills and an evaluation of internal pay equity. Candidates who are back‑to‑work, people with disabilities, without a college degree, and Veterans are encouraged to apply. Cardinal Health supports an inclusive workplace that values diversity of thought, experience and background. We celebrate the power of our differences to create better solutions for our customers by ensuring employees can be their authentic selves each day. Cardinal Health is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, ancestry, age, physical or mental disability, sex, sexual orientation, gender identity/expression, pregnancy, veteran status, marital status, creed, status with regard to public assistance, genetic status or any other status protected by federal, state or local law.

Headquartered in Dublin, Ohio, Cardinal Health, Inc. (NYSE: CAH) is a distributor of pharmaceuticals, a global manufacturer and distributor of medical and laboratory products, and a provider of performance and data solutions for healthcare facilities. We are a crucial link between the clinical and operational sides of healthcare, delivering end‑to‑end solutions and data‑driving insights that advance healthcare and improve lives every day. With deep partnerships, diverse perspectives and innovative digital solutions, we build connections across the continuum of care. With more than 50 years of experience, we seize the opportunity to address healthcare's most complicated challenges —now, and in the future.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Director, Cyber Compliance (Information Security)
Director, Cyber Compliance (Information Security)

Cardinal Health • Northern (KY)

Hybrid
USD 137,000 - 232,000
Medical, dental and vision coverage
Paid time off plan
401k savings plan
+7
Director, Cyber Compliance (Information Security)
Director, Cyber Compliance (Information Security)

Hobbsnews • Northern (KY)

Hybrid
USD 137,000 - 232,000
Medical, dental and vision coverage
401k savings plan
Paid time off
+2
Director, Cyber Compliance (Information Security)
Director, Cyber Compliance (Information Security)

Cardinal Health, Inc. • Northern (KY)

Hybrid
USD 137,000 - 232,000
Medical, dental and vision coverage
401k savings plan
HSA/FSAs
Director, Security Architecture
Director, Security Architecture

Cardinal Health • Northern (KY)

Hybrid
USD 154,000 - 261,000
Medical, dental and vision coverage
401k savings plan
Paid time off
+1
Director, Security Architecture
Director, Security Architecture

Cardinal Health, Inc. • Northern (KY)

Hybrid
USD 154,000 - 261,000
Medical, dental and vision coverage
Paid time off
Health savings account (HSA)
+7
Security Advisor
Security Advisor

Cardinal Health • New York (NY)

On-site
USD 84,000 - 120,000
Medical coverage
401k savings plan
Paid time off
+4
Senior Data Analyst - Product and Strategy Lead
Senior Data Analyst - Product and Strategy Lead

Cardinal Health • Honolulu (HI)

On-site
USD 105,000 - 150,000
Medical, dental and vision coverage
Paid time off
401k savings plan
+6
Manager, Communications Business Partner
Manager, Communications Business Partner

Cardinal Health • Dover (DE)

On-site
USD 88,000 - 125,000
Medical, dental and vision
Paid time off
Health savings account
+2
Privacy & Cybersecurity, Sr. Counsel
Privacy & Cybersecurity, Sr. Counsel

Cardinal Health • Bismarck (ND)

On-site
USD 124,000 - 176,000
Medical, dental and vision coverage
Paid time off
401k savings plan
+3
Manager, Communications Business Partner
Manager, Communications Business Partner

Cardinal Health • Providence (RI)

On-site
USD 88,000 - 125,000
Medical, dental and vision coverage
Paid time off
401k savings plan
+5