Senior Engineer - Information Security & Risk

Cardinal Health

Tallahassee (FL)

On-site

USD 125,000 - 179,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Medical, dental and vision coverage
Paid time off plan
Health savings account (HSA)
401k savings plan
MyFlexPay access to wages before pay
FSAs
Disability coverage
Work-Life resources
Paid parental leave
Healthy lifestyle programs

Job summary

Cardinal Health is seeking a Senior Engineer, Information Security & Risk to define and implement IT SOX controls. You will drive control design, assess risks, and coordinate with audit teams to ensure SOX compliance.

The role involves mentoring staff, budgeting for compliance workstreams, and supporting due diligence in M&A activities. The ideal candidate has 6+ years in IT SOX or IT compliance, strong IT knowledge, and the ability to translate complex controls to stakeholders.

Qualifications

  • Bachelor’s degree in related field or equivalent work experience.
  • 6+ years of IT SOX control and/or IT compliance experience preferred.
  • Strong SOX knowledge with HIPAA, GDPR, PCI familiarity a plus.
  • Able to educate IT stakeholders on control compliance.
  • Strong root cause analysis and problem solving.
  • Proven risk-based judgment and ability to balance priorities.
  • Self-motivated to learn new technologies and objectives.
  • Ability to multi-task with organization, efficiency, and detail.
  • Knowledge of IT technologies including networks, databases, middleware, and ERP controls (SAP a plus).
  • Experience with IT risk governance software (Archer, AuditBoard, ServiceNow GRC) a plus.

Responsibilities

  • Define, implement and evaluate IT SOX controls.
  • Perform IT risk assessments for pilot areas and guide remediation gaps.
  • Design effective IT controls with stakeholders to support SOX goals.
  • Improve IT control processes to increase efficiency and reduce failure risk.
  • Monitor IT control execution for effectiveness.
  • Support due diligence in M&A activities.
  • Assist third-party certifications review and issuance.
  • Coordinate with internal/external audits to define SOX scope.
  • Track remediation of IT control issues in risk governance systems.
  • Lead junior staff and contractors to ensure quality work.
  • Support budgeting for compliance workstreams and report overruns.
  • Assist the manager with compliance posture reporting.

Skills

SOX control knowledge
IT risk assessment
IT controls design
Stakeholder education
Root cause analysis
Risk-based judgement
Multi-tasking & detail orientation
ERP SAP knowledge
Flowcharting
IT risk governance tools

Education

Bachelor’s degree in related field or equivalent work experience

Tools

Archer
AuditBoard
ServiceNow GRC
SAP

Job description

US-Nationwide-FIELD

Full time

20187506

What Information Security and Risk contributes to Cardinal Health

Information Technology oversees the effective development, delivery, and operation of computing and information services. This function anticipates, plans, and delivers Information Technology solutions and strategies that enable operations and drive business value.

Information Security and Risk develops, implements, and enforces security controls to protect the organization's technology assets from intentional or inadvertent modification, disclosure or destruction. This job family develops system back-up and disaster recovery plans. Information Technology also conducts incident response, threat management, vulnerability scanning, virus management and intrusion detection and completes risk assessments.

Job Overview

The Senior Engineer, Information Security & Risk is a second line of defense role responsible for defining, implementing, and evaluating the effectiveness of IT SOX controls. Reporting to the Manager, Information Security & Risk , this role drives the detail design and implementation of IT SOX controls based on relevant risks. Furthermore, the position will work closely with Manager, Information Security & Risk to support business and IT leaders for ongoing risk management process and continuous control/process improvement.

Responsibilities
  • Control design and remediation consulting –
  • Perform IT risk assessment for pilot areas, identify control gap, and provide guidance for gap remediation
  • Work with IT stakeholders to design effective IT controls to help the IT org achieve SOX compliance goals
  • Process improvement of IT controls that increases operational efficiency and reduces the likelihood of control failure
  • Evaluate/monitor the execution of IT controls to ensure they are operating effectively
  • Support due diligence phase of company's M&A activities
  • Provide support for third party certifications (such as SOC1/2) review and issuance
  • Align with internal and external audit to understand SOX scope and audit strategy
  • Track and drive remediation of IT control issues within our IT risk governance process
  • Manage assigned junior staff(s) and contractors to ensure the quality of the work
  • Support budgeting of compliance workstream and responsible for proactively communicate budget overruns to key stakeholders
  • Support the manager in compliance posture reporting
Qualifications
  • Bachelor’s degree in related field or equivalent work experience
  • Deep knowledge of IT SOX control and audit methodology - 6 + years of experience in related field preferred, such as IT audit and/or IT compliance function preferred
  • Strong understanding and experience with SOX is a must and knowledge on other compliance requirements/frameworks, such as HIPAA, GDPR, PCI, is a plus
  • Strong in educating/influencing of IT stakeholders to raise their awareness/mindset of IT control compliance
  • Strong root cause analysis and problem-solving skill is a must
  • Pro-level of risk-based judgement in addressing control issues and juggling competing priorities
  • Self-motivated to learn new technologies and achieve objectives
  • Ability to multi-task with organization, efficiency, accountability, and attention to detail
  • Strong knowledge in IT technologies and concepts including networks, databases, middleware, interfaces, and applications. Knowledge/experience of IT controls for mainstream ERP, such as SAP, is a plus
  • Strong flowcharting skill is preferred
  • Experience with IT risk governance software (i.e., Archer, AuditBoard, ServiceNow GRC) is a plus
  • Professional certification preferred: CISA, CPA, CISM, CISSP, CRISC

Anticipated salary range: $125,300 - $178,900

Bonus eligible: yes

Benefits: Cardinal Health offers a wide variety of benefits and programs to support health and well-being.

  • Medical, dental and vision coverage
  • Paid time off plan
  • Health savings account (HSA)
  • 401k savings plan
  • Access to wages before pay day with myFlexPay
  • Flexible spending accounts (FSAs)
  • Short- and long-term disability coverage
  • Work-Life resources
  • Paid parental leave
  • Healthy lifestyle programs

The salary range listed is an estimate. Pay at Cardinal Health is determined by multiple factors including, but not limited to, a candidate’s geographical location, relevant education, experience and skills and an evaluation of internal pay equity.

Candidates who are back-to-work, people with disabilities, without a college degree, and Veterans are encouraged to apply.

Cardinal Health supports an inclusive workplace that values diversity of thought, experience and background. We celebrate the power of our differences to create better solutions for our customers by ensuring employees can be their authentic selves each day. Cardinal Health is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, ancestry, age, physical or mental disability, sex, sexual orientation, gender identity/expression, pregnancy, veteran status, marital status, creed, status with regard to public assistance, genetic status or any other status protected by federal, state or local law.

To read and review this privacy notice click (https://www.cardinalhealth.com/content/dam/corp/email/documents/corp/cardinal-health-online-application-privacy-policy.pdf)

Headquartered in Dublin, Ohio, Cardinal Health, Inc. (NYSE: CAH) is a distributor of pharmaceuticals, a global manufacturer and distributor of medical and laboratory products, and a provider of performance and data solutions for healthcare facilities.

We are a crucial link between the clinical and operational sides of healthcare, delivering end‑to‑end solutions and data‑driving insights that advance healthcare and improve lives every day. With deep partnerships, diverse perspectives and innovative digital solutions, we build connections across the continuum of care.

With more than 50 years of experience, we seize the opportunity to address healthcare's most complicated challenges — now, and in the future.

View Cardinal Health on YouTube (http://youtube.com/user/CardinalHealth)

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Engineer – Information Security & Risk
Senior Engineer – Information Security & Risk

Cardinal Health • Frankfort (KY)

On-site
USD 125,000 - 179,000
Medical, dental and vision coverage
Paid time off plan
Health savings account (HSA)
+7
Senior Engineer – Information Security & Risk
Senior Engineer – Information Security & Risk

Cardinal Health • Olympia (WA)

On-site
USD 125,000 - 179,000
Medical, dental and vision coverage
401k savings plan
Paid time off
Senior Engineer - Information Security & Risk
Senior Engineer - Information Security & Risk

Cardinal Health • Indianapolis (IN)

On-site
USD 125,000 - 179,000
Medical, dental and vision coverage
Paid time off plan
Health savings account (HSA)
+6
Senior Engineer - Information Security & Risk
Senior Engineer - Information Security & Risk

Cardinal Health • Springfield (IL)

Remote
USD 125,000 - 179,000
Medical benefits
401k savings plan
Paid time off
Senior Engineer - Information Security & Risk
Senior Engineer - Information Security & Risk

Cardinal Health, Inc. • United States

On-site
USD 125,000 - 179,000
Medical coverage
PTO
HSA
+2
Manager, Security Engineering & Platforms
Manager, Security Engineering & Platforms

Cardinal Health • Concord (NH)

Remote
USD 125,000 - 197,000
Medical, dental and vision coverage
Paid time off
401k plan
+1
Manager, Security Engineering & Platforms
Manager, Security Engineering & Platforms

Cardinal Health • Baton Rouge (LA)

Remote
USD 125,000 - 197,000
Medical, dental and vision coverage
Paid time off
Health savings account (HSA)
+7
Manager, Security Engineering & Platforms
Manager, Security Engineering & Platforms

Cardinal Health • Springfield (IL)

Remote
USD 125,000 - 197,000
Medical, dental and vision coverage
Paid time off plan
401k savings plan
+1
Director, Security Architecture
Director, Security Architecture

Cardinal Health • Indianapolis (IN)

On-site
USD 154,000 - 261,000
Medical, dental and vision coverage
401k savings plan
Paid time off
+1
Manager, Security Engineering & Platforms
Manager, Security Engineering & Platforms

Cardinal Health • Columbia (SC)

Remote
USD 125,000 - 197,000
Medical, dental and vision coverage
Paid time off
Health savings account (HSA)
+2