Lead Cyber Security Architect
Location: Richmond, VA, USA – 9954 Mayland Drive (on‑site)
Opportunity
The Lead Cyber Security Architect is a senior, advanced‑skill role responsible for establishing and evolving MMS security architecture, patterns, and guardrails that protect the business while enabling speed and innovation. The role partners with CISO, technology senior leadership, audit/compliance, product and application owners, infrastructure, and security engineering/operations teams to drive consistent security outcomes across the enterprise.
The role provides expert guidance on current security issues while anticipating future threats and technology trends. It requires thinking like an adversary, translating business objectives into security architecture decisions, and defining target‑state architectures and roadmaps.
As a leading (P5) professional, the role sets standards, mentors, and coaches, while driving measurable improvements in risk reduction and control effectiveness.
Key Responsibilities
- Own and evolve MMS security architecture reference patterns and guardrails across cloud, network, identity, endpoint, application, and data protection.
- Lead architecture reviews for key initiatives (new platforms, major applications, third‑party integrations, and B2B/B2C capabilities).
- Translate security policy, risk, and regulatory obligations into practical engineering requirements, reusable design standards, and implementation guidance.
- Define target‑state security architecture and roadmaps; drive alignment and prioritization with stakeholders.
- Embed security in delivery through DevSecOps, advising on CI/CD controls, IaC, policy‑as‑code, secrets management, and secure SDLC practices.
- Establish measurable security architecture outcomes and use metrics to guide continuous improvement.
- Mentor and coach architects and engineers; perform critical self‑review and peer review of deliverables.
- Design and maintain cloud security architecture patterns and guardrails with clear implementation guidance for delivery teams.
- Perform other duties as assigned.
Minimum Requirements
- Degree or equivalent with typically 10+ years of relevant experience; fewer years if a Master’s or Doctorate qualifies.
Skills and Qualifications
- 10+ years in cybersecurity with 5+ years in security architecture, risk management, and compliance.
- Proven ability to lead complex initiatives, drive alignment, and coach others with measurable security outcomes.
- Hands‑on security architecture experience designing guardrails and driving adoption across multiple teams.
- Experience designing security controls for sensitive data (PII/PHI) and supporting audits and compliance through strong documentation.
- Zero Trust and IAM/PAM design at scale; ability to define and implement enterprise guardrails.
- Stakeholder leadership to lead planning, architecture discussions, and obtain alignment and approvals.
- Experience with modern security platforms and automation (SIEM, EDR/XDR, SOAR, secrets management, data protection) and scripting/automation to scale controls.
- Strong background in technology design, implementation, and delivery (cloud, networking, identity, endpoint, application platforms).
- Deep expertise in security controls and architecture domains across public cloud and hybrid environments.
- Ability to communicate technical risk and trade‑offs in business terms and influence decisions.
- Experience improving detection and response capabilities at scale and driving architectural remediation.
- Proven ability to define and operationalize security standards, patterns, and guardrails.
- Track record of acting with integrity, taking pride in work, and holding a high bar for quality.
- Hands‑on ability to automate and enable teams through scripting and infrastructure‑as‑code (Bash, Python, PowerShell) and policy‑as‑code.
- Experience designing for cyber resilience (disaster recovery, business continuity, backup/restore security, ransomware recovery).
- Knowledge of security frameworks and regulations relevant to healthcare (NIST, ISO 27001, HITRUST, HIPAA/HITECH, PCI DSS, SOX, GDPR, SOC 2).
- Knowledge of Windows, Linux, and container platforms (Kubernetes) and modern application patterns (API‑based, microservices, serverless).
- Strong strategic and tactical decision‑making, assessing trade‑offs, defining compensating controls, and driving decisions to closure.
- Experience collaborating with offensive/defensive security teams to validate controls and translate findings into architectural improvements.
- Highly trustworthy, leads by example, and builds credibility through consistent follow‑through.
Education Requirements
- Bachelor’s degree in computer science, information security, MIS, engineering, or related field; or equivalent practical experience.
Certification Requirements
- CISSP (required). Preferred: CISM, GIAC/SANS certifications, and/or relevant cloud security certifications (e.g., Google Cloud Professional Cloud Security Engineer).
Equal Opportunity Employer
McKesson provides equal employment opportunities to applicants and employees, without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, disability, age, genetic information, or any other legally protected category.
McKesson is committed to being an Equal Employment Opportunity Employer and offers opportunities to all job seekers, including those with disabilities. If you need a reasonable accommodation to assist with your job search or application for employment, please contact us by sending an email to (United States) Disability_Accommodation@McKesson.com or (Canada) Accessibility@mckesson.ca. Resumes or CVs submitted to this email box will not be accepted.