Lead Cyber Security Architect

McKesson

Richmond (VA)

On-site

USD 120,000 - 160,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Equal opportunity employer
Disability accommodation support

Job summary

McKesson is seeking a Lead Cyber Security Architect in Richmond, VA to oversee security architecture and ensure compliance with standards. The ideal candidate will have 10+ years in cybersecurity and strong experience in risk management, leading initiatives, and designing security controls for sensitive data.

CISSP certification is required, along with the ability to translate business objectives into secure solutions. This on-site position includes opportunities to mentor teams and influence security strategies across the organization.

Qualifications

  • 10+ years in cybersecurity with 5+ years in security architecture.
  • Strong background in technology design, implementation, and delivery.
  • CISSP certification required.

Responsibilities

  • Establish and evolve security architecture patterns and guardrails.
  • Lead architecture reviews for key initiatives.
  • Design and maintain cloud security architecture patterns.

Skills

Cybersecurity experience
Security architecture
Risk management
Compliance
Stakeholder leadership
Zero Trust design
Automation scripting
Security framework knowledge

Education

Bachelor's degree in computer science or related field

Tools

Cloud security platforms
SIEM
EDR/XDR

Job description

Lead Cyber Security Architect

Location: Richmond, VA, USA – 9954 Mayland Drive (on‑site)

Opportunity

The Lead Cyber Security Architect is a senior, advanced‑skill role responsible for establishing and evolving MMS security architecture, patterns, and guardrails that protect the business while enabling speed and innovation. The role partners with CISO, technology senior leadership, audit/compliance, product and application owners, infrastructure, and security engineering/operations teams to drive consistent security outcomes across the enterprise.

The role provides expert guidance on current security issues while anticipating future threats and technology trends. It requires thinking like an adversary, translating business objectives into security architecture decisions, and defining target‑state architectures and roadmaps.

As a leading (P5) professional, the role sets standards, mentors, and coaches, while driving measurable improvements in risk reduction and control effectiveness.

Key Responsibilities
  • Own and evolve MMS security architecture reference patterns and guardrails across cloud, network, identity, endpoint, application, and data protection.
  • Lead architecture reviews for key initiatives (new platforms, major applications, third‑party integrations, and B2B/B2C capabilities).
  • Translate security policy, risk, and regulatory obligations into practical engineering requirements, reusable design standards, and implementation guidance.
  • Define target‑state security architecture and roadmaps; drive alignment and prioritization with stakeholders.
  • Embed security in delivery through DevSecOps, advising on CI/CD controls, IaC, policy‑as‑code, secrets management, and secure SDLC practices.
  • Establish measurable security architecture outcomes and use metrics to guide continuous improvement.
  • Mentor and coach architects and engineers; perform critical self‑review and peer review of deliverables.
  • Design and maintain cloud security architecture patterns and guardrails with clear implementation guidance for delivery teams.
  • Perform other duties as assigned.
Minimum Requirements
  • Degree or equivalent with typically 10+ years of relevant experience; fewer years if a Master’s or Doctorate qualifies.
Skills and Qualifications
  • 10+ years in cybersecurity with 5+ years in security architecture, risk management, and compliance.
  • Proven ability to lead complex initiatives, drive alignment, and coach others with measurable security outcomes.
  • Hands‑on security architecture experience designing guardrails and driving adoption across multiple teams.
  • Experience designing security controls for sensitive data (PII/PHI) and supporting audits and compliance through strong documentation.
  • Zero Trust and IAM/PAM design at scale; ability to define and implement enterprise guardrails.
  • Stakeholder leadership to lead planning, architecture discussions, and obtain alignment and approvals.
  • Experience with modern security platforms and automation (SIEM, EDR/XDR, SOAR, secrets management, data protection) and scripting/automation to scale controls.
  • Strong background in technology design, implementation, and delivery (cloud, networking, identity, endpoint, application platforms).
  • Deep expertise in security controls and architecture domains across public cloud and hybrid environments.
  • Ability to communicate technical risk and trade‑offs in business terms and influence decisions.
  • Experience improving detection and response capabilities at scale and driving architectural remediation.
  • Proven ability to define and operationalize security standards, patterns, and guardrails.
  • Track record of acting with integrity, taking pride in work, and holding a high bar for quality.
  • Hands‑on ability to automate and enable teams through scripting and infrastructure‑as‑code (Bash, Python, PowerShell) and policy‑as‑code.
  • Experience designing for cyber resilience (disaster recovery, business continuity, backup/restore security, ransomware recovery).
  • Knowledge of security frameworks and regulations relevant to healthcare (NIST, ISO 27001, HITRUST, HIPAA/HITECH, PCI DSS, SOX, GDPR, SOC 2).
  • Knowledge of Windows, Linux, and container platforms (Kubernetes) and modern application patterns (API‑based, microservices, serverless).
  • Strong strategic and tactical decision‑making, assessing trade‑offs, defining compensating controls, and driving decisions to closure.
  • Experience collaborating with offensive/defensive security teams to validate controls and translate findings into architectural improvements.
  • Highly trustworthy, leads by example, and builds credibility through consistent follow‑through.
Education Requirements
  • Bachelor’s degree in computer science, information security, MIS, engineering, or related field; or equivalent practical experience.
Certification Requirements
  • CISSP (required). Preferred: CISM, GIAC/SANS certifications, and/or relevant cloud security certifications (e.g., Google Cloud Professional Cloud Security Engineer).
Equal Opportunity Employer

McKesson provides equal employment opportunities to applicants and employees, without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, disability, age, genetic information, or any other legally protected category.

McKesson is committed to being an Equal Employment Opportunity Employer and offers opportunities to all job seekers, including those with disabilities. If you need a reasonable accommodation to assist with your job search or application for employment, please contact us by sending an email to (United States) Disability_Accommodation@McKesson.com or (Canada) Accessibility@mckesson.ca. Resumes or CVs submitted to this email box will not be accepted.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. Director, Cyber Engineering
Sr. Director, Cyber Engineering

McKesson Corporation • Richmond (VA)

On-site
USD 172,000 - 287,000
Equal Opportunity Employment
Disability accommodations
Lead Cyber Security Architect
Lead Cyber Security Architect

RXinsider LTD. • Richmond (VA), Northern (KY)

Hybrid
USD 143,000 - 238,000
Senior Cyber Security Architect: Cloud & IAM Leader
Senior Cyber Security Architect: Cloud & IAM Leader

RXinsider LTD. • Richmond (VA), Northern (KY)

Hybrid
USD 143,000 - 238,000
Lead Data Architect (Healthcare)
Lead Data Architect (Healthcare)

McKesson Corporation • Irving (TX)

On-site
USD 148,000 - 246,000
Principal Digital Architect – Customer Experience
Principal Digital Architect – Customer Experience

McKesson • Irving (TX)

Hybrid
USD 187,000 - 313,000
Principal Enterprise Architect
Principal Enterprise Architect

McKesson • Irving (TX)

On-site
USD 179,000 - 298,000
Lead Cyber Security Architect: Cloud & Risk Strategy
Lead Cyber Security Architect: Cloud & Risk Strategy

McKesson • Richmond (VA)

On-site
USD 120,000 - 160,000
Equal opportunity employer
Disability accommodation support
Principal Architect, Platform Architecture
Principal Architect, Platform Architecture

McKesson • Columbus (OH)

On-site
USD 163,000 - 271,000
Senior Cyber Security Architect - Drive Security Strategy
Senior Cyber Security Architect - Drive Security Strategy

McKesson Corporation • Richmond (VA)

On-site
USD 143,000 - 239,000
Competitive compensation package
Annual bonus opportunities
Sr. Cyber Risk Assurance Analyst
Sr. Cyber Risk Assurance Analyst

McKesson • Atlanta (GA)

On-site
USD 99,000 - 167,000
Annual bonus opportunities
Competitive compensation package
Diverse work environment