Senior Security Engineer, Customer Security Assurance
Cardinal HealthAbout the role
Headquartered in Dublin, Ohio, Cardinal Health, Inc. (NYSE: CAH) is a global, integrated healthcare services and products company, providing customized solutions for hospitals, health systems, pharmacies, ambulatory surgery centers, clinical laboratories and physician offices worldwide.
The company provides clinically-proven medical products and pharmaceuticals and cost-effective solutions that enhance supply chain efficiency from hospital to home. Cardinal Health connects patients, providers, payers, pharmacists and manufacturers for integrated care coordination and better patient management. Backed by nearly 100 years of experience, with approximately 50,000 employees in 46 countries, Cardinal Health ranks among the top 15 on the Fortune 500.
We currently have a full-time job opening for a Senior Security Engineer of Customer Security Assurance
Department overview:
Information Security and Risk Management (ISRM) at Cardinal Health enables Cardinal Health to securely deliver healthcare products and solutions that improve the lives of people every day by ensuring security and controls are embedded into Cardinal Health’s people, process and technology. The Cyber Risk and Customer Security Assurance team fulfils our mission to strengthen our shield against cyber threats by providing a framework of processes and methodologies to manage Cardinal Health’s cybersecurity risks through issue and exception management, policy and standard creation, and customer third party risk assessment engagement.
Job overview:
Sr. Engineer, Customer Security Assurance, applies knowledge of Information Security, Risk Management, and Information Technology to lead the maturity of our Customer Security Assurance program. The primary responsibility of this role is to lead the Customer Security Assurance function and collaborate with a variety of Cardinal Health business units to address the requirements and needs that are established by our customers. Customer requirements include the completion of IT vendor third party risk assessments, advising on third party certifications (i.e. SOC2 and HITRUST), providing direction on remediation procedures, negotiation of contract terms, and collaborating with our customers to address any Cyber Risk related inquiries.
This role is a senior position within the team and will work with all members of the Information Security team as well as legal, sales and customer support resources throughout the Cardinal Health enterprise.
Responsibilities:
- Develop and implement an effective strategy/process for addressing our customers’ IT security and controls concerns
- Identify, establish, and report on key performance indicators to ensure we are meeting our business’ expectations as regards Customer Security Assurance
- Looking for efficiencies and driving the business and security teams to meet our current and future customer needs.
- Mentoring junior members of the team
- Establish and develop relationships with various members of the business (i.e., legal, sales, business leaders) and quickly become knowledgeable about the respective IT environment, controls and processes
- Effectively and efficiently complete third-party risk assessments provided by our customers
- Advise the business on the selection, planning, execution and, if necessary, remediation of a third-party certification (i.e. SOC2, HITRUST)
- Work with internal and customer legal counsel to align on mutually agreeable legal security and controls language to protect both organizations
- Effectively communicate identified gaps and planned remediation procedures to application owners and to leadership
- Understand when issues need to be escalated and/or communicated to Cardinal Health leadership
Qualifications:
- Excellent written and verbal communication skills
- Experience in Information Technology and Information Security
- Experience implementing and maintaining processes at large enterprises
- Experience with IT security principles, practices, technologies, programs and procedures, accompanied by an understanding of risk management methodologies and cybersecurity assessment frameworks
- High-quality analytical skills, relationship management competencies
- Familiarity with IT Security and Governance audits standards including SOC2, ISO 27002, NIST Cybersecurity Framework, HITRUST, etc.
- Relevant Information Security Certifications
Anticipated salary range: $121,600 - $182,385
Bonus eligible: Yes
Benefits: Cardinal Health offers a wide variety of benefits and programs to support health and well-being.
- Medical, dental and vision cov
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s