CoverMyMeds Technology is seeking a Senior Data Security Architect (Data Platform Security) to join our Data & Analytics organization. This highly specialized role is responsible for defining, implementing, and governing enterprise-wide data security architecture across cloud and hybrid data platforms.
Location
Preferred candidate will reside in the Columbus, OH area to support a hybrid work schedule, but full-remote candidates may be considered.
Eligibility
Applicants must be currently authorized to work in the United States on a full‑time basis without the need for employer support or sponsorship now or in the future. This includes having the legal right to work in the United States without the need for McKesson support or sponsorship for any immigration related employment authorization (H1B, O1, E3, H1B1, TN, F1 OPT, F1 STEM OPT, F1 CPT, etc.). If you will require McKesson to provide immigration support or sponsorship now or in the future, you should not apply for this position.
What You’ll Do
- Own and evolve enterprise data security architecture across Databricks, Azure Data Lake, and enterprise reporting platforms
- Design and enforce fine‑grained data access controls (RBAC, ABAC, row/column‑level security) using Unity Catalog and governed tagging frameworks
- Architect identity and access management (IAM) patterns integrating Okta, Microsoft Entra ID, SailPoint, and privileged access platforms
- Define and implement PHI/PII protection strategies, including tokenization, encryption, de‑identification, and masking across environments
- Establish secure data sharing and multi‑tenant access models for external customers, partners, and embedded analytics
- Lead architecture for data rights, entitlements, and consent‑based access controls, ensuring compliance with contractual and regulatory requirements
- Build and operationalize security controls aligned to SOX ITGC, including logical access controls, change management, and audit evidence frameworks
- Design audit‑ready security architectures supporting HIPAA, SOC 2 Type II, and FedRAMP compliance requirements
- Partner with engineering, SRE, and platform teams to embed security into CI/CD pipelines, platform onboarding, and development standards
- Define and govern data classification, tagging, and lineage‑aware security policies across medallion architectures
- Evaluate and recommend enterprise security tooling and governance platforms
- Produce architecture artifacts (decision records, control matrices, audit evidence) consumable by internal and external auditors
Basic Requirements
- Bachelor’s degree in Computer Science, Information Systems, or a related field, or equivalent experience, and typically requires 7+ years of relevant experience in data security, cybersecurity, or data architecture, with significant focus in cloud‑based environments
- Proven experience implementing data security and governance controls in regulated environments (HIPAA, healthcare strongly preferred)
- Strong expertise in SOX IT General Controls (ITGC) domains, including logical access, change management, and audit controls
- Hands‑on experience with Databricks Unity Catalog security models, including RBAC, ABAC, and data masking
- Deep knowledge of Azure cloud security architecture, including networking, identity, and secrets management
- Experience designing identity and access management solutions (Okta, Entra ID, SailPoint, privileged access tools)
- Demonstrated experience implementing encryption, tokenization, and de‑identification strategies for sensitive data
- Experience designing secure data architectures for external/customer‑facing analytics products
- Ability to translate regulatory requirements into implemented technical controls and audit artifacts
- Strong communication skills with ability to present architecture concepts to technical, business, and audit stakeholders
Preferred Skills / Experience
- Experience supporting SOC 2 Type II and/or FedRAMP compliance programs
- Knowledge of healthcare data sharing frameworks and consent models
- Experience designing data entitlement models and purpose‑based access controls at scale
- Familiarity with FHIR‑based data platforms and interoperability security
- Experience with DSPM/CSPM tools for cloud data security
- Experience implementing non‑production data masking and synthetic data solutions
- Exposure to CI/CD security architecture and service principal hardening
- Experience operating in large, matrixed enterprise governance environments
Compensation
Base Pay Range: $124,100 - $206,900
Equal Opportunity Employer
McKesson provides equal employment opportunities to applicants and employees, without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, disability, age, genetic information, or any other legally protected category. For additional information on McKesson’s full Equal Employment Opportunity policies, visit the Equal Employment Opportunity page.