Manager, Infrastructure Governance

Cardinal Health

Kentucky

On-site

USD 125,000 - 179,000

Full time

6 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Medical, dental and vision coverage
401k savings plan
Paid time off plan
Health savings account (HSA)
Paid parental leave
Flexible spending accounts (FSAs)

Job summary

Cardinal Health is seeking a senior Infrastructure Governance leader to guide cloud security, policy enforcement, and risk management across GCP, Azure, and AWS. You will mentor engineers, drive automation, and ensure compliance with SOX, HIPAA, HITRUST, and GDPR.

The role focuses on expanding governance scope beyond CSPM, coordinating remediation via ServiceNow, and delivering KPI/KRI reports for executives. Strong leadership and regulatory knowledge are essential.

Qualifications

  • Bachelor’s degree in related field or equivalent work experience.
  • 4–6 years in security governance, cloud security engineering, or equivalent risk role.
  • Proven leadership/mentoring of engineering teams.
  • Hands-on cloud experience across GCP, Azure, and AWS.
  • Knowledge of HIPAA, HITRUST, SOX, GDPR and related regs.

Responsibilities

  • Lead and mentor a high-performing team of Cloud Engineers and drive growth.
  • Expand governance scope beyond CSPM to include security policy enforcement and risk management.
  • Champion Automation & AI to deliver real-time compliance and auto-remediation of cloud risks.
  • Govern Firewall Rule Policies to align with network standards and direct firewall rule certification.
  • Oversee CSPM & cloud-native security tools to ensure continuous alerting and audit reporting across GCP, Azure, AWS.
  • Coordinate remediation campaigns using ServiceNow and GRC platforms for timely resolution.
  • Manage SOX server quarterly certifications and address findings with urgency.
  • Address non-compliance, deprecated protocols, least privilege, and drift from policy.
  • Ensure exception management policies are followed and remediated/renewed timely.
  • Produce monthly KPI and KRI reports and quarterly ROC reports for leadership.
  • Support FDA audits and HITRUST certifications with evidence and governance data.
  • Lead M&A security onboarding with ET/platform teams for new entities.
  • Align with Cyber Operations strategies and support UVM and related programs.

Skills

Cloud security
Governance
Leadership
GRC
Multi-cloud
Regulatory compliance

Education

Bachelor’s degree in related field

Tools

Prisma Cloud
Wiz
Sentinel

Job description

What Infrastructure Governance contributes to Cardinal Health Information Technology oversees the effective development, delivery, and operation of computing and information services. This function anticipates, plans, and delivers Information Technology solutions and strategies that enable operations and drive business value. Infrastructure Governance enforces Cardinal Health's risk and security policies to ensure compliance with internal and external regulations, and to maintain a secure infrastructure environment.

Responsibilities
  • Lead and mentor a high-performing team of Cloud Engineers, fostering professional growth and establishing a culture of proactive exposure management.
  • Drive team evolution by expanding the governance scope beyond Cloud Security Posture Management (CSPM) and firewall rule monitoring into comprehensive security policy enforcement, vulnerability, data, and application security management.
  • Champion Automation & AI to deliver real-time compliance results, reduce manual verification cycles, and accelerate auto-remediation of cloud risks.
  • Governance, Risk, & Compliance (GRC) Execution: Govern Firewall Rule Policies to guarantee alignment with network standards, and direct the rule certification program for all in-scope firewalls.
  • Oversee CSPM & Cloud-Native Security Solutions to ensure robust, continuous alerting, monitoring, and audit reporting across GCP, Azure, and AWS.
  • Orchestrate remediation campaigns for non-compliant issues, leveraging ServiceNow and GRC platforms to assign, track, and verify resolution by solution owners.
  • Manage critical certifications to ensure Sarbanes-Oxley (SOX) server quarterly certifications are executed on time, addressing any findings with urgency.
  • Analyze and address non-compliance proactively, including deprecated network protocols, violations of least privilege, or any configurations drifting from internal Information Security policies.
  • Ensure compliance with exception management policies and standards by maintaining accountability for approved exceptions and their timely remediation, renewal, or closure.
  • Audit, Reporting, & Mergers & Acquisitions (M&A): Formulate governance metrics, providing monthly Key Performance Indicator (KPI) and Key Risk Indicator (KRI) reports for internal operations, and quarterly Reports of Compliance (ROC) for executive leadership.
  • Support regulatory audits, serving as a key stakeholder and evidence provider for FDA audits and HITRUST certifications (monthly, quarterly, and annual reporting).
  • Drive M&A security onboarding, collaborating with Enterprise Technology Platform and InfoSec Operations teams to seamlessly integrate newly acquired entities onto the Infrastructure Governance platforms.
  • Align with Cyber Operations strategies, ensuring direct support of foundational programs such as Unified Vulnerability Management (UVM).
Qualifications
  • Experience: 4 to 6 years of progressive experience in security compliance governance, cloud security engineering, or an equivalent technical risk management role preferred.
  • Leadership: Demonstrated experience leading, mentoring, or technically directing a team of engineering professionals.
  • Cloud Expertise: Extensive, hands-on knowledge of multi-cloud environments, specifically Google Cloud Platform (GCP), Microsoft Azure, and Amazon Web Services (AWS).
  • Framework Proficiency: Working knowledge of security frameworks, particularly NIST CSF (Cybersecurity Framework).
  • Regulatory & Compliance Acumen: Solid understanding of industry regulations and compliance standards, including HIPAA, HITRUST, SOX, and GDPR.
  • Systems Familiarity: Experience using and integrating GRC platforms, ServiceNow, and cloud-native security tools (e.g., Prisma, Wiz, Sentinel, or cloud-native CSPMs).
What is expected of you and others at this level

Manages department operations and supervises professional employees, front line supervisors and/or business support staff. Participates in the development of policies and procedures to achieve specific goals. Ensures employees operate within guidelines. Bachelor’s degree in related field, or equivalent work experience, preferred. Interacts with subordinates, peers, customers, and suppliers at various management levels; may interact with senior management. Interactions normally involve resolution of issues related to operations and/or projects. Gains consensus from various parties involved.

Anticipated salary range

Anticipated salary range: $125,300 - $178,900 Bonus eligible: yes

Benefits

Cardinal Health offers a wide variety of benefits and programs to support health and well-being.

  • Medical, dental and vision coverage
  • Paid time off plan
  • Health savings account (HSA)
  • 401k savings plan
  • Access to wages before pay day with myFlexPay
  • Flexible spending accounts (FSAs)
  • Short- and long-term disability coverage
  • Work-Life resources
  • Paid parental leave
  • Healthy lifestyle programs
Application window

Application window anticipated to close: 9/30/2026

The salary range listed is an estimate. Pay at Cardinal Health is determined by multiple factors including, but not limited to, a candidate’s geographical location, relevant education, experience and skills and an evaluation of internal pay equity. Candidates who are back-to-work, people with disabilities, without a college degree, and Veterans are encouraged to apply.

Cardinal Health supports an inclusive workplace that values diversity of thought, experience and background. We celebrate the power of our differences to create better solutions for our customers by ensuring employees can be their authentic selves each day. Cardinal Health is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, ancestry, age, physical or mental disability, sex, sexual orientation, gender identity/expression, pregnancy, veteran status, marital status, creed, status with regard to public assistance, genetic status or any other status protected by federal, state or local law.

Company Overview

Headquartered in Dublin, Ohio, Cardinal Health, Inc. (NYSE: CAH) is a distributor of pharmaceuticals, a global manufacturer and distributor of medical and laboratory products, and a provider of performance and data solutions for healthcare facilities. We are a crucial link between the clinical and operational sides of healthcare, delivering end-to-end solutions and data-driven insights that advance healthcare and improve lives every day. With deep partnerships, diverse perspectives and innovative digital solutions, we build connections across the continuum of care. With more than 50 years of experience, we seize the opportunity to address healthcare's most complicated challenges — now, and in the future.

View Cardinal Health on YouTube

To read and review this privacy notice click here

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager, Infrastructure Governance
Manager, Infrastructure Governance

RXinsider LTD. • Kentucky

On-site
USD 125,000 - 179,000
Medical, dental and vision coverage
401k plan
Paid time off
+1
Manager, Infrastructure Governance
Manager, Infrastructure Governance

Hobbsnews • Kentucky

On-site
USD 125,000 - 179,000
Medical, dental, vision
401k
Paid time off
+7
Manager, Infrastructure Governance
Manager, Infrastructure Governance

cardinalhealth • Kentucky

Hybrid
USD 125,000 - 179,000
Medical, dental and vision coverage
401k savings plan
Paid time off plan
+3
Director, Cyber Compliance (Information Security)
Director, Cyber Compliance (Information Security)

Cardinal Health • Northern (KY)

Hybrid
USD 137,000 - 232,000
Medical, dental and vision coverage
Paid time off plan
401k savings plan
+7
Director, Cyber Risk Services (Information Security)
Director, Cyber Risk Services (Information Security)

Cardinal Health • Northern (KY)

Hybrid
USD 137,000 - 232,000
Medical, dental and vision coverage
401k savings plan
Health savings account (HSA)
+5
Director, Security Architecture
Director, Security Architecture

Cardinal Health • Denver (CO)

On-site
USD 154,000 - 261,000
Director, Security Architecture
Director, Security Architecture

Cardinal Health • Austin (TX)

On-site
USD 154,000 - 261,000
Medical, dental and vision coverage
Paid time off plan
Health savings account (HSA)
+7
Director, Security Architecture
Director, Security Architecture

Cardinal Health • Lincoln (NE)

On-site
USD 154,000 - 261,000
Medical coverage
Dental & Vision
Paid time off
+8
Director, Security Architecture
Director, Security Architecture

Cardinal Health • Dover (DE)

On-site
USD 154,000 - 261,000
Medical, dental and vision coverage
Paid time off
401k savings plan
+2
Sr Engineer, Software/Information Platform
Sr Engineer, Software/Information Platform

Cardinal Health • Northern (KY)

Hybrid
USD 123,000 - 176,000
Medical coverage
Dental coverage
Vision coverage
+8