Manager, Infrastructure Governance

cardinalhealth

Kentucky

Hybrid

USD 125,000 - 179,000

Full time

5 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Medical, dental and vision coverage
401k savings plan
Paid time off plan
HSA
FSAs
Parental leave

Job summary

Cardinal Health is seeking a senior Infra Governance leader to guide cloud security engineering and drive governance across CSPM, firewalls, and M&A onboarding. You will implement policy, remediation, and compliance programs to reduce risk across GCP, Azure, and AWS.

The role requires deep knowledge of NIST CSF and regulated environments, with an emphasis on automation, SOX/HIPAA compliance, and strong team leadership.

Qualifications

  • Experience in security governance, cloud security engineering, or risk management.
  • Leadership experience directing engineering professionals.
  • Strong knowledge of multi-cloud environments (GCP, Azure, AWS).
  • Familiarity with NIST CSF and regulatory compliance (HIPAA, HITRUST, SOX, GDPR).
  • Proficiency with GRC platforms and ServiceNow integration.

Responsibilities

  • Lead and mentor a team of Cloud Engineers and drive governance expansion.
  • Enforce security policies, vulnerability, data, and application security management.
  • Champion automation and AI to deliver real-time compliance results.
  • Oversee CSPM and cloud-native security solutions across GCP, Azure, AWS.
  • Manage audits, M&A onboarding, and regulatory reporting requirements.

Skills

Cloud security engineering
GRC governance
Leadership
GCP
Azure
AWS
NIST CSF
Regulatory compliance

Education

Bachelor's degree

Tools

ServiceNow
Prisma
Wiz
Sentinel
CSPMs

Job description

What Infrastructure Governance contributes to Cardinal Health Information Technology oversees the effective development, delivery, and operation of computing and information services. This function anticipates, plans, and delivers Information Technology solutions and strategies that enable operations and drive business value.

Infrastructure Governance enforces Cardinal Health's risk and security policies to ensure compliance with internal and external regulations, and to maintain a secure infrastructure environment.

Responsibilities

Lead and mentor a high-performing team of Cloud Engineers, fostering professional growth and establishing a culture of proactive exposure management.

Drive team evolution by expanding the governance scope beyond Cloud Security Posture Management (CSPM) and firewall rule monitoring into comprehensive security policy enforcement, vulnerability, data, and application security management.

Champion Automation & AI to deliver real-time compliance results, reduce manual verification cycles, and accelerate auto-remediation of cloud risks.

Governance, Risk, & Compliance (GRC) Execution

Govern Firewall Rule Policies to guarantee alignment with network standards, and direct the rule certification program for all in-scope firewalls.

Oversee CSPM & Cloud-Native Security Solutions to ensure robust, continuous alerting, monitoring, and audit reporting across GCP, Azure, and AWS.

Orchestrate remediation campaigns for non-compliant issues, leveraging ServiceNow and GRC platforms to assign, track, and verify resolution by solution owners.

Manage critical certifications to ensure Sarbanes-Oxley (SOX) server quarterly certifications are executed on time, addressing any findings with urgency.

Analyze and address non-compliance proactively, including deprecated network protocols, violations of least privilege, or any configurations drifting from internal Information Security policies.

Ensure compliance with exception management policies and standards by maintaining accountability for approved exceptions and their timely remediation, renewal, or closure.

Audit, Reporting, & Mergers & Acquisitions (M&A)

Formulate governance metrics, providing monthly Key Performance Indicator (KPI) and Key Risk Indicator (KRI) reports for internal operations, and quarterly Reports of Compliance (ROC) for executive leadership.

Support regulatory audits, serving as a key stakeholder and evidence provider for FDA audits and HITRUST certifications (monthly, quarterly, and annual reporting).

Drive M&A security onboarding, collaborating with Enterprise Technology Platform and InfoSec Operations teams to seamlessly integrate newly acquired entities onto the Infrastructure Governance platforms.

Align with Cyber Operations strategies, ensuring direct support of foundational programs such as Unified Vulnerability Management (UVM).

Qualifications
  • Experience: 4 to 6 years of progressive experience in security compliance governance, cloud security engineering, or an equivalent technical risk management role preferred.
  • Leadership: Demonstrated experience leading, mentoring, or technically directing a team of engineering professionals.
  • Cloud Expertise: Extensive, hands-on knowledge of multi-cloud environments, specifically Google Cloud Platform (GCP), Microsoft Azure, and Amazon Web Services (AWS).
  • Framework Proficiency: Working knowledge of security frameworks, particularly NIST CSF (Cybersecurity Framework).
  • Regulatory & Compliance Acumen: Solid understanding of industry regulations and compliance standards, including HIPAA, HITRUST, SOX, and GDPR.
  • Systems Familiarity: Experience using and integrating GRC platforms, ServiceNow, and cloud-native security tools (e.g., Prisma, Wiz, Sentinel, or cloud-native CSPMs).
What is expected of you and others at this level

Manages department operations and supervises professional employees, front line supervisors and/or business support staff

Participates in the development of policies and procedures to achieve specific goals

Ensures employees operate within guidelines

Bachelor's degree in related field, or equivalent work experience, preferred

Interacts with subordinates, peers, customers, and suppliers at various management levels; may interact with senior management

Interactions normally involve resolution of issues related to operations and/or projects

Gains consensus from various parties involved

Salary and Benefits

Anticipated salary range: $125,300 - $178,900

Bonus eligible: yes

Cardinal Health offers a wide variety of benefits and programs to support health and well-being.

Benefits
  • Medical, dental and vision coverage
  • Paid time off plan
  • Health savings account (HSA)
  • 401k savings plan
  • Access to wages before pay day with myFlexPay
  • Flexible spending accounts (FSAs)
  • Short- and long-term disability coverage
  • Work-Life resources
  • Paid parental leave
  • Healthy lifestyle programs
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager, Infrastructure Governance
Manager, Infrastructure Governance

RXinsider LTD. • Kentucky

On-site
USD 125,000 - 179,000
Medical, dental and vision coverage
401k plan
Paid time off
+1
Manager, Infrastructure Governance
Manager, Infrastructure Governance

Hobbsnews • Kentucky

On-site
USD 125,000 - 179,000
Medical, dental, vision
401k
Paid time off
+7
Manager, Infrastructure Governance
Manager, Infrastructure Governance

Cardinal Health • Kentucky

On-site
USD 125,000 - 179,000
Medical, dental and vision coverage
401k savings plan
Paid time off plan
+3
Director, Cyber Compliance (Information Security)
Director, Cyber Compliance (Information Security)

Cardinal Health • Northern (KY)

Hybrid
USD 137,000 - 232,000
Medical, dental and vision coverage
Paid time off plan
401k savings plan
+7
Director, Cyber Compliance (Information Security)
Director, Cyber Compliance (Information Security)

Hobbsnews • Northern (KY)

Hybrid
USD 137,000 - 232,000
Medical, dental and vision coverage
401k savings plan
Paid time off
+2
Director, Cyber Risk Services (Information Security)
Director, Cyber Risk Services (Information Security)

Cardinal Health • Northern (KY)

Hybrid
USD 137,000 - 232,000
Medical, dental and vision coverage
401k savings plan
Health savings account (HSA)
+5
Director, Security Architecture
Director, Security Architecture

Cardinal Health, Inc. • Northern (KY)

Hybrid
USD 154,000 - 261,000
Medical, dental and vision coverage
Paid time off
Health savings account (HSA)
+7
Director, Cyber Compliance (Information Security)
Director, Cyber Compliance (Information Security)

Cardinal Health, Inc. • Northern (KY)

Hybrid
USD 137,000 - 232,000
Medical, dental and vision coverage
401k savings plan
HSA/FSAs
Director, Security Architecture
Director, Security Architecture

Cardinal Health • Northern (KY)

Hybrid
USD 154,000 - 261,000
Medical, dental and vision coverage
401k savings plan
Paid time off
+1
Director, Security Architecture
Director, Security Architecture

Cardinal Health • United States

On-site
USD 154,000 - 261,000