Sr. Cyber Risk Assurance Analyst

McKesson

Atlanta (GA)

On-site

USD 99,800 - 166,300

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Annual bonus opportunities
Competitive compensation package
Diverse work environment

Job summary

A leading healthcare services company based in Atlanta is seeking a Senior Cyber Risk Assurance Analyst. The role involves conducting cybersecurity risk assessments, ensuring compliance with regulatory frameworks, and collaborating across various teams. Ideal candidates will have a Bachelor's degree in Cybersecurity or Information Systems and 7+ years of relevant experience. Competitive compensation includes a salary range of $99,800 to $166,300, along with additional benefits.

Qualifications

  • Degree or equivalent and typically requires 7+ years of relevant experience.
  • Strong knowledge of HIPAA, NIST 800-53, and risk management standards.
  • Experience with vendor risk assessments and contract reviews.

Responsibilities

  • Conduct cybersecurity risk assessments for internal systems.
  • Drive vulnerability management plan across multiple platforms.
  • Ensure compliance with all regulatory frameworks.

Skills

Cybersecurity risk management
Regulatory compliance
Analytical skills
Communication skills

Education

Bachelor's degree in Cybersecurity or Information Systems
7+ years of relevant experience

Tools

OneTrust
RSA Archer
ServiceNow GRC

Job description

Join to apply for the Sr. Cyber Risk Assurance Analyst role at McKesson.

McKesson is an impact-driven, Fortune 10 company that touches virtually every aspect of healthcare. We are known for delivering insights, products, and services that make quality care more accessible and affordable. Here, we focus on the health, happiness, and well‑being of you and those we serve – we care. What you do at McKesson matters. We foster a culture where you can grow, make an impact, and are empowered to bring new ideas. Together, we thrive as we shape the future of health for patients, our communities, and our people. If you want to be part of tomorrow’s health today, we want to hear from you.

Position Summary

McKesson is hiring for a Sr. Cyber Risk Assurance Analyst who will be responsible for collaborating across legal, compliance, and technical teams to ensure alignment with regulatory frameworks such as HIPAA, NIST 800‑53, FIPS‑140, and CMS ARS. This role requires a strong technical background and deep expertise in compliance, privacy, and risk management. The ideal candidate will translate complex government regulatory guidance (e.g., NIST CVE, CMS ARS) into actionable business and technical requirements, driving toward secure and compliant designs that are compliant with relevant reference architecture frameworks.

Key Responsibilities
  • Conduct cybersecurity risk assessments for internal systems and third‑party applications within the regulated environment.
  • Drive vulnerability management plan based on strict risk‑based classifications across multiple platforms, engaging all asset owners.
  • Contribute to the formulation of cybersecurity strategies by advising risk reduction priorities related to vulnerability trends.
  • Ensure compliance with all applicable regulatory frameworks and requirements.
  • Translate technical frameworks and regulatory guidance (e.g., NIST CVE, Zero Trust, FIPS‑140) into actionable requirements for technical and business teams.
  • Collaborate with legal, compliance, and engineering business partners to integrate requirements into contracts and system designs.
  • Support continuous audit readiness, evidence collection, and remediation planning.
  • Develop and maintain policies and procedures to support regulatory compliance and risk management.
  • Partner with multiple business units to ensure success in third‑party audits.
  • Provide risk insights and recommendations to leadership to improve organizational risk posture.
  • Foster a culture of accountability and awareness across the business unit.
Minimum Requirements
  • Degree or equivalent and typically requires 7+ years of relevant experience.
Critical Skills
  • Bachelor’s degree in Cybersecurity, Information Systems, or related field.
  • 4+ years of experience in cybersecurity risk management or assurance, preferably in a HHS or federally regulated environment.
  • Strong technical background with the ability to interpret and apply complex regulatory frameworks.
  • Knowledge of IP network infrastructure, security defense in depth architecture (e.g., firewalls, intrusion detection/prevention, end‑point protection), identity and access management, data encryption.
  • Experience with HIPAA, NIST 800‑53, FISMA, FEDRAMP, and FIPS‑140.
  • Strong knowledge of risk frameworks, standards, and authoritative risk categorization sources (e.g., NIST, ISO, FedRAMP, KVE, CVSS, CVE).
  • Proficiency with enterprise compliance platforms such as OneTrust, RSA Archer, or ServiceNow GRC.
  • Excellent analytical, documentation, and communication skills.
Additional Skills And Certifications
  • Certifications such as CISM, CRISC, or CISSP.
  • Experience conducting vendor risk assessments and contract reviews.

We are proud to offer a competitive compensation package at McKesson as part of our Total Rewards. This is determined by several factors, including performance, experience and skills, equity, regular job market evaluations, and geographical markets. The pay range shown below is aligned with McKesson's pay philosophy, and pay will always be compliant with any applicable regulations. In addition to base pay, other compensation, such as an annual bonus or long‑term incentive opportunities may be offered. For more information regarding benefits at McKesson, please click here.

Our Base Pay Range for this position

$99,800 - $166,300

McKesson is an Equal Opportunity Employer

McKesson provides equal employment opportunities to applicants and employees and is committed to a diverse and inclusive environment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, disability, age or genetic information. For additional information on McKesson’s full Equal Employment Opportunity policies, visit our Equal Employment Opportunity page.

Join us at McKesson!

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Global Security Analyst
Senior Global Security Analyst

McKesson Corporation • Richmond (VA)

Hybrid
USD 101,000 - 169,000
Bonus eligible
Competitive benefits
Senior Global Security Analyst
Senior Global Security Analyst

McKesson • Richmond (VA)

Hybrid
USD 101,000 - 169,000
Lead Cyber Security Architect
Lead Cyber Security Architect

RXinsider LTD. • Richmond (VA), Northern (KY)

Hybrid
USD 143,000 - 238,000
Sr. GRC Analyst
Sr. GRC Analyst

RXinsider LTD. • Irving (TX), Northern (KY)

Hybrid
USD 101,000 - 168,000
Sr. GRC Analyst
Sr. GRC Analyst

McKesson Corporation • Irving (TX)

On-site
USD 101,000 - 168,000
Sr. Associate Software Engineer
Sr. Associate Software Engineer

McKesson Corporation • Irving (TX)

Hybrid
USD 81,000 - 135,000
Hybrid work model
Las Colinas office two days/week
Sr. Associate Software Engineer
Sr. Associate Software Engineer

McKesson Corporation • Atlanta (GA)

Hybrid
USD 54,000 - 90,000
Sr. Financial Analyst - Strategic Finance
Sr. Financial Analyst - Strategic Finance

RXinsider LTD. • Columbus (OH)

On-site
USD 98,000 - 163,000
Clinical Systems Analyst - FCS
Clinical Systems Analyst - FCS

McKesson • Town of Florida (NY), Northern (KY)

Hybrid
USD 84,000 - 140,000
Sr. Specialist, Software Development & Engineering
Sr. Specialist, Software Development & Engineering

McKesson • North Carolina

On-site
USD 131,000 - 218,000