Manager, CISO Program & Operations

Cardinal Health

United States

Remote

USD 125,000 - 197,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Medical/Dental/Vision coverage
401k plan
Paid time off
Health Savings Account (HSA)
Wages access (myFlexPay)
FSAs
Disability coverage
Work-Life resources
Parental leave
Wellness programs

Job summary

Cardinal Health is seeking an Manager, CISO Program & Operations to oversee strategy, governance, and continuous improvement of the enterprise cybersecurity program. The role coordinates intake, portfolio management, budgeting, and reporting while ensuring alignment with organizational priorities and risk objectives.

The position emphasizes standardized processes, cross-functional collaboration, and data-driven insights to support decision-making and program maturity within a highly regulated

Qualifications

  • 5+ years of experience in cybersecurity, technology risk, portfolio management, or program operations preferred.
  • Bachelor’s Degree preferred
  • Experience supporting cybersecurity project or portfolio management, including tracking initiatives, managing priorities, and reporting performance.
  • Strong understanding of cybersecurity frameworks (e.g., NIST CSF, ISO 27001), risk management principles, and regulatory requirements.
  • Experience developing executive reporting materials and utilizing metrics to track program performance.
  • Strong organizational, analytical, and problem-solving skills with attention to detail.
  • Ability to manage multiple priorities and work effectively across cross-functional teams.
  • Strong communication and stakeholder management skills.
  • Experience in cybersecurity portfolio management, program governance, or strategy execution.
  • Experience working in highly regulated industries (e.g., aviation, financial services, healthcare, or government).
  • Familiarity with Agile methodologies and project management tools.
  • Advanced degree (MBA, MS in Cybersecurity, Information Systems, or related field).
  • Professional certifications such as CISSP, CISM, PMP, or PRINCE2.

Responsibilities

  • Strategic facilitation & program oversight aligning activities to objectives.
  • Collaborate with leadership to define goals, metrics, and monitor performance.
  • Maintain cybersecurity services catalog across the program.
  • Ensure processes stay aligned with strategic objectives and governance.
  • Contribute to capability maturity assessments and continuous improvement.
  • Coordinate cybersecurity project intake across stakeholders and resources.
  • Support standardized project management frameworks, tools, and reporting.
  • Provide visibility into project status and performance for leadership.
  • Coordinate resource allocation and workload distribution across teams.
  • Drive adherence to defined processes to ensure consistent delivery.
  • Monitor KPIs/KRIs to assess program health and emerging risks.
  • Develop executive, business unit, and operational reporting materials.
  • Provide insights to inform prioritization, funding decisions, and strategic adjustments.
  • Ensure consistency and accuracy in program reporting across teams.
  • Track progress and escalate risks or issues as needed.
  • Develop and manage program budget, aligning with objectives and forecasts.
  • Collaborate with finance to support budgeting and reporting.
  • Establish scalable financial governance for cybersecurity needs.
  • Vendor management: maintain vendor inventory, evaluate performance, ensure alignment with contracts.
  • Assist in vendor selection, RFPs, and coordination with procurement.
  • Monitor vendor performance and issue resolution.
  • Align engagements with architecture, security requirements, and priorities.
  • Facilitate coordination across cybersecurity, IT, business units, and partners.
  • Serve as liaison to ensure alignment and effective delivery of services.
  • Support integration of cybersecurity into enterprise projects and audits.
  • Promote transparency and collaboration across teams.
  • Identify opportunities to improve processes, tools, and governance.
  • Contribute to standardized documentation and operating procedures.
  • Stay informed of cybersecurity trends, regulatory changes, and best practices.

Skills

Portfolio mgmt
Program governance
Executive reporting
Stakeholder mgmt
Agile
Regulatory knowledge
Risk management
Cross-functional work

Education

Bachelor's Degree
MBA/MS in Cybersecurity/IS
CISSP
CISM
PMP
PRINCE2

Job description

What Information Security and Risk contributes to Cardinal Health

Information Technology oversees the effective development, delivery, and operation of computing and information services. This function anticipates, plans, and delivers Information Technology solutions and strategies that enable operations and drive business value.

Information Security and Risk develops, implements, and enforces security controls to protect the organization’s technology assets from intentional or inadvertent modification, disclosure or destruction. This job family develops system back-up and disaster recovery plans. Information Technology also conducts incident response, threat management, vulnerability scanning, virus management and intrusion detection and completes risk assessments.

The Manager, CISO Program & Operations is responsible for supporting the execution, governance, and continuous improvement of the enterprise cybersecurity program. Reporting to the Director of Cybersecurity Strategy & Program Operations, this role serves as a central coordination point to ensure cybersecurity and infrastructure initiatives are effectively planned, executed, monitored, and aligned with organizational priorities and risk objectives.

This role manages core CISO program capabilities including project intake, portfolio and project management, financial and vendor oversight, and performance monitoring. It plays a critical role in enabling transparency, consistency, and operational discipline across the CISO Program by establishing standardized processes, facilitating cross-functional collaboration, and delivering data-driven insights to support decision-making.

Qualifications

5+ years of experience in cybersecurity, technology risk, portfolio management, or program operations preferred.
  • Bachelor’s Degree preferred
  • Experience supporting cybersecurity project or portfolio management, including tracking initiatives, managing priorities, and reporting performance.
  • Strong understanding of cybersecurity frameworks (e.g., NIST CSF, ISO 27001), risk management principles, and regulatory requirements.
  • Experience developing executive reporting materials and utilizing metrics to track program performance.
  • Strong organizational, analytical, and problem-solving skills with attention to detail.
  • Ability to manage multiple priorities and work effectively across cross-functional teams.
  • Strong communication and stakeholder management skills.
  • Experience in cybersecurity portfolio management, program governance, or strategy execution.
  • Experience working in highly regulated industries (e.g., aviation, financial services, healthcare, or government).
  • Familiarity with Agile methodologies and project management tools.
  • Advanced degree (MBA, MS in Cybersecurity, Information Systems, or related field).
  • Professional certifications such as CISSP, CISM, PMP, or PRINCE2.
Responsibilities
Strategy Facilitation & Program Oversight
  • Support facilitation of the CISO Program strategy by aligning program activities to enterprise and cybersecurity objectives.
  • Collaborate with CISO Program leadership to establish goals, define success metrics, and monitor program performance against strategic priorities.
  • Assist in maintaining the cybersecurity services catalog, including services, tools, and technologies utilized across the program.
  • Support execution of processes to evaluate program performance and maintain alignment with strategic objectives.
  • Contribute to cybersecurity capability maturity assessments and continuous improvement initiatives.
Project Intake & Demand Management
  • Coordinate cybersecurity project intake requests across internal and external stakeholders, including business segments, auditors, vendors, and technology teams.
  • Ensure project requests are properly documented, assessed, and aligned with cybersecurity priorities and available resources.
  • Facilitate communication between requesting stakeholders and cybersecurity teams to support efficient intake, scoping, and initiation of work.
  • Maintain centralized intake processes and ensure consistency in evaluation and prioritization of incoming requests.
Project & Portfolio Management
  • Support management of the cybersecurity project portfolio by tracking initiatives, timelines, milestones, risks, and dependencies.
  • Assist in establishing and maintaining standardized project management frameworks, tools, and reporting processes.
  • Provide visibility into project status and performance to support execution and leadership oversight.
  • Coordinate resource allocation, capacity planning, and workload distribution across cybersecurity teams.
  • Drive adherence to defined processes and methodologies to ensure consistent delivery of CISO program initiatives
CISO Program Continuous Monitoring & Reporting
  • Monitor cybersecurity and infrastructure program performance using key performance indicators (KPIs) and key risk indicators (KRIs) to assess program health, operational performance, and identify emerging risks.
  • Support development of executive, business unit, and operational reporting materials, including dashboards, metrics, and trend analysis.
  • Provide insights into program performance to inform prioritization, funding decisions, and strategic adjustments.
  • Ensure consistency and accuracy in CISO program reporting across teams and stakeholders.
  • Track progress of CISO program initiatives and support escalation of risks or issues as needed.
Budget & Financial Management
  • Support development and management of the CISO program budget, including operational and capital expenditures.
  • Assist in aligning financial plans with program objectives, resource requirements, and demand forecasts.
  • Track and evaluate program spend, forecasts, and financial performance to support informed decision-making.
  • Collaborate with finance and program leadership to support budgeting processes, financial planning, and reporting activities.
  • Establish a scalable financial governance process aligned to cybersecurity program needs.
Vendor Management & Governance
  • Support management of cybersecurity vendors by maintaining vendor inventory, tracking performance, and ensuring alignment with contractual obligations and program objectives.
  • Assist in vendor selection processes, including RFP development, evaluation, and coordination with procurement teams.
  • Monitor vendor performance, service delivery, and issue resolution across the vendor lifecycle.
  • Collaborate with internal stakeholders to ensure vendor engagements align with cybersecurity architecture, security requirements, and strategic priorities.
Stakeholder Coordination & Operational Integration
  • Facilitate coordination across cybersecurity, IT, business units, and external partners to support execution of cybersecurity initiatives.
  • Serve as a liaison between stakeholders to ensure alignment, communication, and effective delivery of cybersecurity services.
  • Support integration of cybersecurity considerations into enterprise projects, audits, and operational activities.
  • Promote transparency and collaboration across teams to enable effective program execution.
Continuous Improvement & Capability Development
  • Identify opportunities to improve CISO program processes, tools, and governance structures.
  • Support implementation of process improvements to increase efficiency, scalability, and program maturity.
  • Contribute to development of standardized documentation, playbooks, and operating procedures.
  • Stay informed of evolving cybersecurity trends, regulatory requirements, and best practices to support ongoing program evolution.

What is expected of you and others at this level

  • Manages department operations and supervises professional employees, front line supervisors and/or business support staff
  • Participates in the development of policies and procedures to achieve specific goals
  • Ensures employees operate within guidelines
  • Decisions have a short‑term impact on work processes, outcomes and customers
  • Interacts with subordinates, peers, customers, and suppliers at various management levels; may interact with senior management
  • Interactions normally involve resolution of issues related to operations and/or projects
  • Gains consensus from various parties involved

Anticipated salary range: $125,300 - $196,790

Bonus eligible: yes

Benefits: Cardinal Health offers a wide variety of benefits and programs to support health and well‑being.

  • Medical, dental and vision coverage
  • Paid time off plan
  • Health savings account (HSA)
  • 401k savings plan
  • Access to wages before pay day with myFlexPay
  • Flexible spending accounts (FSAs)
  • Short- and long‑term disability coverage
  • Work‑Life resources
  • Paid parental leave
  • Healthy lifestyle programs

Application window anticipated to close: 9/28/2026

The salary range listed is an estimate. Pay at Cardinal Health is determined by multiple factors including, but not limited to, a candidate’s geographical location, relevant education, experience and skills and an evaluation of internal pay equity.

Candidates who are back-to-work, people with disabilities, without a college degree, and Veterans are encouraged to apply.

Cardinal Health supports an inclusive workplace that values diversity of thought, experience and background. We celebrate the power of our differences to create better solutions for our customers by ensuring employees can be their authentic selves each day. Cardinal Health is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, ancestry, age, physical or mental disability, sex, sexual orientation, gender identity/expression, pregnancy, veteran status, marital status, creed, status with regard to public assistance, genetic status or any other status protected by federal, state or local law.

To read and review this privacy notice click here

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Manager, CISO Program & Operations
Manager, CISO Program & Operations

Information Technology Senior Management Forum • Kentucky

Hybrid
USD 125,000 - 197,000
Medical coverage
Dental coverage
Vision coverage
+7
Manager, CISO Program & Operations
Manager, CISO Program & Operations

Cardinal Health, Inc. • Kentucky

On-site
USD 125,000 - 197,000
Medical coverage
Paid time off
401k plan
Manager, CISO Program & Operations
Manager, CISO Program & Operations

Cardinal Health • Columbus (OH)

Remote
USD 125,000 - 197,000
Medical, dental and vision coverage
Paid time off plan
Health savings account (HSA)
+7
Manager, Security Engineering & Platforms
Manager, Security Engineering & Platforms

Cardinal Health, Inc. • United States

Remote
USD 125,000 - 197,000
Medical coverage
Dental coverage
Vision coverage
+4
Manager, Security Engineering & Platforms
Manager, Security Engineering & Platforms

Cardinal Health • Harrisburg

Remote
USD 125,000 - 197,000
Medical coverage
Dental coverage
Vision coverage
+9
Manager, Security Engineering & Platforms
Manager, Security Engineering & Platforms

Cardinal Health • Providence (RI)

Remote
USD 125,000 - 197,000
Medical, dental and vision coverage
Paid time off plan
401k savings plan
+2
Manager, Security Engineering & Platforms
Manager, Security Engineering & Platforms

Cardinal Health • Richmond (VA)

Remote
USD 125,000 - 197,000
Medical, dental and vision coverage
Paid time off
Health savings account (HSA)
+2
Manager, Security Engineering & Platforms
Manager, Security Engineering & Platforms

Cardinal Health • Nashville (TN)

Remote
USD 125,000 - 197,000
Medical, dental and vision coverage
Paid time off
401k savings plan
+1
Manager, Security Engineering & Platforms
Manager, Security Engineering & Platforms

Cardinal Health • Jackson (MS)

Remote
USD 125,000 - 197,000
Medical coverage
401k savings plan
HSA
+4
Manager, Security Engineering & Platforms
Manager, Security Engineering & Platforms

Cardinal Health • Denver (CO)

Remote
USD 125,000 - 197,000
Medical, dental and vision coverage
Paid time off plan
401k savings plan
+2