Senior Director, Secure MA&D

myhrabc

Conshohocken (Montgomery County)

On-site

USD 180,000 - 250,000

Full time

6 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Cencora seeks a Senior Director, Secure MA&D to own the enterprise cybersecurity strategy across the full transaction lifecycle, guiding governance, budgets, and risk management for pre-close, Day 1, and divestiture scenarios.

The role leads a global team of principals and analysts, coordinates with Legal and Finance, and sets requirements for diligence playbooks, cost models, and integration blueprints to enable faster, safer growth.

Responsibilities

  • Own and evolve the enterprise Secure MA&D strategy, operating model, and capability roadmap covering acquisitions, divestitures, carve-outs, joint ventures, and minority investments.
  • Establish the governance framework, decision rights, risk thresholds, and escalation criteria that determine when a cyber finding is deal-impacting versus a post-close remediation item.
  • Set the standard for diligence playbooks, cost models, integration blueprints, Day 1 control baselines, and executive reporting used across the transaction portfolio.
  • Own the function's annual plan, budget, tooling, and third-party bench, sized to support an unpredictable and confidential deal pipeline.
  • Define and report the metrics that demonstrate program effectiveness, including diligence cycle time, cost-estimate accuracy, Day 1 control coverage, and time to remediate inherited risk.
  • Position Secure MA&D as an enabler of inorganic growth by balancing speed of deal execution against defensible risk coverage.
  • Lead, coach, and develop a global team of Secure MA&D principals and analysts; set performance standards, career paths, and succession plans.
  • Allocate scarce specialist capacity across concurrent transactions and adjust staffing as deals accelerate, pause, or collapse.
  • Direct third-party diligence and integration partners end to end, including selection, scoping, commercial terms, quality assurance, and performance management.
  • Build a team culture of disciplined judgment, documentation, and absolute confidentiality consistent with material non-public information obligations.
  • Serve as player-coach on the largest, most sensitive, or most contested transactions.
  • Direct pre-close cybersecurity due diligence under compressed timelines, restricted target access, staged data-room release, and clean-team constraints, drawing defensible conclusions from incomplete evidence.
  • Calibrate diligence depth and approach to deal type, size, and thesis, recognizing the differences between a negotiated acquisition, a competitive auction, an asset versus stock purchase, and a carve-out from a larger parent.
  • Quantify and defend remediation, integration, tooling, licensing, labor, and run-rate cost estimates within the deal model, including capital versus operating treatment and dis-synergy impacts.
  • Ensure cyber findings are reflected in deal documents and protections, including representations and warranties, purchase price adjustments, escrow and indemnity, disclosure schedules, and closing conditions.
  • Define security requirements and exit criteria for Transition Service Agreements and reverse TSAs; direct separation planning for divestitures, including data segregation, entitlement removal, and protection of retained intellectual property.
  • Direct Day 1 readiness, including minimum viable controls, identity and network interconnection decisions, endpoint and email protections, logging and monitoring onboarding, and incident response coverage for the acquired entity.
  • Own the handoff from diligence to delivery, transferring risks, named owners, and funded remediation plans to security capability owners with accountability tracked through TSA exit and integration close.
  • Lead the security response when a target is found to have an active or historical compromise, coordinating pre-close containment, valuation impact, and disclosure implications with Legal and Corporate Development.
  • Establish the risk-acceptance and exception framework for inherited risks that cannot be remediated by Day 1, ensuring documented ownership, funding, and time-bound closure.
  • Ensure diligence and integrat

Job description

Our team members are at the heart of everything we do. At Cencora, we are united in our responsibility to create healthier futures, and every person here is essential to us being able to deliver on that purpose. If you want to make a difference at the center of health, come join our innovative company and help us improve the lives of people and animals everywhere.

Job Details
Job Summary:

The Senior Director, Secure MA&D owns the enterprise strategy, governance, and delivery of cybersecurity across the full transaction lifecycle - pre-close due diligence, Day 1 readiness, post-close integration, and divestiture separation. This role is the single accountable security leader to Corporate Development, Finance, and Legal for cyber risk that affects valuation, deal structure, closing conditions, and integration cost. The Senior Director leads a global team of principals and analysts and a bench of third-party diligence partners; sets the risk thresholds and decision rights that determine when a cyber finding is deal-impacting; advises executive leadership and the Board on aggregate transaction risk; and drives the organizational change required to bring acquired entities onto enterprise security standards.

Key Responsibilities:
Strategic Leadership and Program Ownership
  • Own and evolve the enterprise Secure MA&D strategy, operating model, and capability roadmap covering acquisitions, divestitures, carve-outs, joint ventures, and minority investments.
  • Establish the governance framework, decision rights, risk thresholds, and escalation criteria that determine when a cyber finding is deal-impacting versus a post-close remediation item.
  • Set the standard for diligence playbooks, cost models, integration blueprints, Day 1 control baselines, and executive reporting used across the transaction portfolio.
  • Own the function's annual plan, budget, tooling, and third-party bench, sized to support an unpredictable and confidential deal pipeline.
  • Define and report the metrics that demonstrate program effectiveness, including diligence cycle time, cost-estimate accuracy, Day 1 control coverage, and time to remediate inherited risk.
  • Position Secure MA&D as an enabler of inorganic growth by balancing speed of deal execution against defensible risk coverage.
People and Vendor Leadership
  • Lead, coach, and develop a global team of Secure MA&D principals and analysts; set performance standards, career paths, and succession plans.
  • Allocate scarce specialist capacity across concurrent transactions and adjust staffing as deals accelerate, pause, or collapse.
  • Direct third-party diligence and integration partners end to end, including selection, scoping, commercial terms, quality assurance, and performance management.
  • Build a team culture of disciplined judgment, documentation, and absolute confidentiality consistent with material non-public information obligations.
  • Serve as player-coach on the largest, most sensitive, or most contested transactions.
MA&D Lifecycle Execution
  • Direct pre-close cybersecurity due diligence under compressed timelines, restricted target access, staged data-room release, and clean-team constraints, drawing defensible conclusions from incomplete evidence.
  • Calibrate diligence depth and approach to deal type, size, and thesis, recognizing the differences between a negotiated acquisition, a competitive auction, an asset versus stock purchase, and a carve-out from a larger parent.
  • Quantify and defend remediation, integration, tooling, licensing, labor, and run-rate cost estimates within the deal model, including capital versus operating treatment and dis-synergy impacts.
  • Ensure cyber findings are reflected in deal documents and protections, including representations and warranties, purchase price adjustments, escrow and indemnity, disclosure schedules, and closing conditions.
  • Define security requirements and exit criteria for Transition Service Agreements and reverse TSAs; direct separation planning for divestitures, including data segregation, entitlement removal, and protection of retained intellectual property.
  • Direct Day 1 readiness, including minimum viable controls, identity and network interconnection decisions, endpoint and email protections, logging and monitoring onboarding, and incident response coverage for the acquired entity.
  • Own the handoff from diligence to delivery, transferring risks, named owners, and funded remediation plans to security capability owners with accountability tracked through TSA exit and integration close.
  • Lead the security response when a target is found to have an active or historical compromise, coordinating pre-close containment, valuation impact, and disclosure implications with Legal and Corporate Development.
Risk Management and Compliance
  • Establish the risk-acceptance and exception framework for inherited risks that cannot be remediated by Day 1, ensuring documented ownership, funding, and time-bound closure.
  • Ensure diligence and integrat
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Global Cyber M&A Security Lead
Global Cyber M&A Security Lead

Cencora • Town of Texas (WI)

On-site
USD 200,000 - 320,000
Comprehensive benefits
Professional development programs
Mentorship and training opportunities
Senior Director, Secure M&A & Integration
Senior Director, Secure M&A & Integration

MWI Buying Group • Conshohocken, Northern (KY)

Hybrid
USD 200,000 - 270,000
Comprehensive benefits
Training and development programs
Mentorship programs
+2
Senior Director, Cybersecurity M&A Strategy
Senior Director, Cybersecurity M&A Strategy

AmerisourceBergen Services Corporation • Pennsylvania

Hybrid
USD 180,000 - 270,000
Global Head of Cyber Security for M&A & Divestitures
Global Head of Cyber Security for M&A & Divestitures

myhrabc • Conshohocken

On-site
USD 180,000 - 250,000
Senior Director, M&A Cyber Risk & Security
Senior Director, M&A Cyber Risk & Security

Cencora • Indianapolis (IN)

On-site
USD 180,000 - 240,000
Medical, dental, and vision care
Backup dependent care
Adoption assistance
+3
Senior Director, Secure MA&D
Senior Director, Secure MA&D

MWI Buying Group • Conshohocken, Northern (KY)

Hybrid
USD 200,000 - 270,000
Comprehensive benefits
Training and development programs
Mentorship programs
+2
SecureMA&DLead
SecureMA&DLead

Cencora • Conshohocken

Hybrid
USD 140,000 - 190,000
Medical benefits
Dental and vision insurance
Paid time off
+2
SecureMA&DLead
SecureMA&DLead

Cencora • Carrollton (TX)

On-site
USD 130,000 - 170,000
SecureMA&DLead
SecureMA&DLead

AmerisourceBergen Corporation (Cencora) • Carrollton (TX)

On-site
USD 120,000 - 180,000
Medical insurance
Dental insurance
Vision care
+1
SecureMA&DLead
SecureMA&DLead

AmerisourceBergen Corporation (Cencora) • Conshohocken

On-site
USD 140,000 - 190,000
Backup dependent care
Parental leave
Infertility coverage