Senior Engineer - Information Security & Risk

Cardinal Health, Inc.

United States

On-site

USD 125,000 - 179,000

Full time

5 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Medical coverage
PTO
HSA
401k savings plan
MyFlexPay

Job summary

Cardinal Health, Inc. is seeking a Senior Engineer, Information Security & Risk to define, implement, and evaluate IT SOX controls across the organization.

You will report to the Manager, Information Security & Risk and partner with IT and business leaders to drive ongoing risk management and control improvements. The role requires deep IT SOX knowledge, experience in audit/compliance, and the ability to influence stakeholders while supporting due diligence for M&A activities and third-party

Qualifications

  • Bachelor’s degree in related field or equivalent work experience.
  • 6+ years of IT SOX/audit/compliance experience.
  • Strong knowledge of SOX and related frameworks (HIPAA, GDPR, PCI) a plus.
  • Strong communication and problem-solving skills; ability to influence IT stakeholders.

Responsibilities

  • Define, implement, and evaluate IT SOX controls in partnership with IT and business.
  • Perform IT risk assessments for pilot areas and identify control gaps.
  • Collaborate with IT stakeholders to design controls that meet SOX compliance goals.
  • Improve IT controls processes to increase efficiency and reduce failure risk.
  • Monitor execution of IT controls to ensure effectiveness.
  • Support due diligence in M&A activities.
  • Assist with third-party certifications (SOC1/2) reviews.
  • Align with internal/external audits to define SOX scope and strategy.
  • Track and drive remediation of IT control issues within risk governance.
  • Manage junior staff and contractors to ensure quality deliverables.
  • Support budgeting for compliance workstreams and communicate overruns.
  • Assist manager with compliance posture reporting.

Skills

IT SOX controls
IT risk assessment
auditing & compliance
stakeholder education
root cause analysis
ERP knowledge (SAP)
risk governance
multi-tasking
CISA/CISM/CISSP

Education

Bachelor’s degree in related field

Tools

Archer
AuditBoard
ServiceNow GRC

Job description

What Information Security and Risk contributes to Cardinal Health

Information Technology oversees the effective development, delivery, and operation of computing and information services. This function anticipates, plans, and delivers Information Technology solutions and strategies that enable operations and drive business value.

Information Security and Risk develops, implements, and enforces security controls to protect the organization’s technology assets from intentional or inadvertent modification, disclosure or destruction. This job family develops system back-up and disaster recovery plans. Information Technology also conducts incident response, threat management, vulnerability scanning, virus management and intrusion detection and completes risk assessments.

Job Overview

The Senior Engineer, Information Security & Risk is a second line of defense role responsible for defining, implementing, and evaluating the effectiveness of IT SOX controls. Reporting to the Manager, Information Security & Risk , this role drives the detail design and implementation of IT SOX controls based on relevant risks. Furthermore, the position will work closely with Manager, Information Security & Risk to support business and IT leaders for ongoing risk management process and continuous control/process improvement.

Responsibilities
  • Control design and remediation consulting –
  • Perform IT risk assessment for pilot areas, identify control gap, and provide guidance for gap remediation
  • Work with IT stakeholders to design effective IT controls to help the IT org achieve SOX compliance goals
  • Process improvement of IT controls that increases operational efficiency and reduces the likelihood of control failure
  • Evaluate/monitor the execution of IT controls to ensure they are operating effectively
  • Support due diligence phase of company's M&A activities
  • Provide support for third party certifications (such as SOC1/2) review and issuance
  • Align with internal and external audit to understand SOX scope and audit strategy
  • Track and drive remediation of IT control issues within our IT risk governance process
  • Manage assigned junior staff(s) and contractors to ensure the quality of the work
  • Support budgeting of compliance workstream and responsible for proactively communicate budget overruns to key stakeholders
  • Support the manager in compliance posture reporting
Qualifications
  • Bachelor’s degree in related field or equivalent work experience
  • Deep knowledge of IT SOX control and audit methodology - 6 + years of experience in related field preferred, such as IT audit and/or IT compliance function preferred
  • Strong understanding and experience with SOX is a must and knowledge on other compliance requirements/frameworks, such as HIPAA, GDPR, PCI, is a plus
  • Strong in educating/influencing of IT stakeholders to raise their awareness/mindset of IT control compliance
  • Strong root cause analysis and problem-solving skill is a must
  • Pro-level of risk-based judgement in addressing control issues and juggling competing priorities
  • Self-motivated to learn new technologies and achieve objectives
  • Ability to multi-task with organization, efficiency, accountability, and attention to detail
  • Strong knowledge in IT technologies and concepts including networks, databases, middleware, interfaces, and applications. Knowledge/experience of IT controls for mainstream ERP, such as SAP, is a plus
  • Strong flowcharting skill is preferred
  • Experience with IT risk governance software (i.e., Archer, AuditBoard, ServiceNow GRC) is a plus
  • Professional certification preferred: CISA, CPA, CISM, CISSP, CRISC
Anticipated salary range:

$125,300 - $178,900

Bonus eligible:

yes

Benefits:

Cardinal Health offers a wide variety of benefits and programs to support health and well-being.

  • Medical, dental and vision coverage

  • Paid time off plan

  • Health savings account (HSA)

  • 401k savings plan

  • Access to wages before pay day with myFlexPay

  • Flexible spending accounts (FSAs)

  • Short- and long-term disability coverage

  • Work-Life resources

  • Paid parental leave

  • Healthy lifestyle programs

Application window anticipated to close:

10/15/2026 *if interested in opportunity, please submit application as soon as possible.

The salary range listed is an estimate. Pay at Cardinal Health is determined by multiple factors including, but not limited to, a candidate’s geographical location, relevant education, experience and skills and an evaluation of internal pay equity.

Candidates who are back-to-work, people with disabilities, without a college degree, and Veterans are encouraged to apply.

Cardinal Health supports an inclusive workplace that values diversity of thought, experience and background. We celebrate the power of our differences to create better solutions for our customers by ensuring employees can be their authentic selves each day. Cardinal Health is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, ancestry, age, physical or mental disability, sex, sexual orientation, gender identity/expression, pregnancy, veteran status, marital status, creed, status with regard to public assistance, genetic status or any other status protected by federal, state or local law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Engineer - Information Security & Risk
Senior Engineer - Information Security & Risk

Cardinal Health • Montpelier (VT)

On-site
USD 125,000 - 179,000
Medical, dental and vision coverage
Paid time off plan
Health savings account (HSA)
+7
Senior Engineer - Information Security & Risk
Senior Engineer - Information Security & Risk

Cardinal Health • Columbus (OH)

On-site
USD 125,000 - 179,000
Medical, dental and vision coverage
Paid time off plan
401k savings plan
+5
Senior Engineer - Information Security & Risk
Senior Engineer - Information Security & Risk

Cardinal Health • Santa Fe (NM)

On-site
USD 125,000 - 179,000
Medical, dental and vision coverage
PTO
HSA
+7
Senior Engineer - Information Security & Risk
Senior Engineer - Information Security & Risk

Cardinal Health • Richmond (VA)

On-site
USD 125,000 - 179,000
Medical, dental and vision coverage
Paid time off plan
Health savings account (HSA)
+7
Senior Engineer – Information Security & Risk
Senior Engineer – Information Security & Risk

Cardinal Health • Olympia (WA)

On-site
USD 125,000 - 179,000
Medical, dental and vision coverage
401k savings plan
Paid time off
Senior Engineer – Information Security & Risk
Senior Engineer – Information Security & Risk

Cardinal Health • Frankfort (KY)

On-site
USD 125,000 - 179,000
Medical, dental and vision coverage
Paid time off plan
Health savings account (HSA)
+7
Senior Engineer - Information Security & Risk
Senior Engineer - Information Security & Risk

Cardinal Health • United States

On-site
USD 125,000 - 179,000
Medical coverage
Dental coverage
Vision coverage
+2
Senior Engineer - Information Security & Risk
Senior Engineer - Information Security & Risk

Cardinal Health • Northern (KY)

Hybrid
USD 125,000 - 179,000
Benefits package
Paid time off
401k savings plan
+3
Director, Cyber Compliance (Information Security)
Director, Cyber Compliance (Information Security)

Cardinal Health, Inc. • Northern (KY)

Hybrid
USD 137,000 - 232,000
Medical, dental and vision coverage
401k savings plan
HSA/FSAs
Manager, CISO Program & Operations
Manager, CISO Program & Operations

Cardinal Health, Inc. • Kentucky

On-site
USD 125,000 - 197,000
Medical coverage
Paid time off
401k plan