Senior Director of Cybersecurity Assessments and Assurance
AmerisourceBergenAbout the role
Our team members are at the heart of everything we do. At Cencora, we are united in our responsibility to create healthier futures, and every person here is essential to us being able to deliver on that purpose. If you want to make a difference at the center of health, come join our innovative company and help us improve the lives of people and animals everywhere. Apply today!
Job Details
Position Summary:
We are seeking an experienced and strategic Senior Director of Cybersecurity Assessments and Assurance to lead and enhance the organization’s cybersecurity assessment and assurance program. This role will oversee key functions, including third-party risk assessments, contract reviews, compliance assessments, vendor continuous monitoring, and management of third-party certifications (e.g., SOC 1, SOC 2, ISO 27001, NIST). The Senior Director will also ensure that the organization adheres to IT regulatory compliance requirements, including HIPAA, PCI, GxP, and other applicable standards.
Reporting to the Chief Information Security Officer (CISO), this role is critical to ensuring the organization’s cybersecurity posture remains robust and aligned with business objectives, regulatory obligations, and industry best practices. The Senior Director will collaborate with internal and external stakeholders to reduce risk, enhance compliance, and build customer trust.
Key Responsibilities:
Cybersecurity Assessments and Assurance
Develop and lead a comprehensive cybersecurity assessments and assurance program to evaluate the security posture of the organization and its vendors.
Oversee infrastructure and application compliance assessments to ensure alignment with security policies, frameworks, and regulatory standards.
Design and execute annual critical assessments of key systems, applications, and processes, identifying gaps and driving remediation efforts.
Manage the organization's third-party certifications (e.g., SOC 1, SOC 2, ISO 27001, NIST), ensuring timely attainment and renewal through effective coordination with internal teams and external auditors.
Third-Party Risk Management
Own the third-party risk assessment process, ensuring thorough onboarding, evaluation, and periodic reassessment of vendors.
Oversee continuous monitoring of critical vendors to evaluate their adherence to contractual obligations, security requirements, and industry standards.
Collaborate with procurement, legal, and vendor management teams to review and negotiate cybersecurity and data privacy clauses in contracts.
Develop and maintain a risk-based methodology to prioritize and focus efforts on high-risk vendors and critical third-party relationships.
IT Regulatory Compliance
Ensure compliance with applicable IT regulatory requirements, including but not limited to HIPAA, PCI-DSS, GxP, GDPR, and CCPA.
Monitor the evolving landscape of cybersecurity regulations and standards, providing guidance to internal stakeholders on compliance obligations.
Lead internal and external audits related to regulatory compliance, ensuring timely responses, remediation, and reporting.
Collaborate with legal and compliance teams to address regulatory inquiries, assessments, and reporting needs.
Continuous Monitoring and Metrics
Implement and oversee a continuous monitoring program for critical systems, applications, and third-party relationships, leveraging tools and automation where possible.
Establish and track key performance indicators (KPIs) and key risk indicators (KRIs) to measure the effectiveness of cybersecurity assessments, vendor management, and compliance programs.
Provide regular reporting to senior leadership on the organization’s cybersecurity posture, highlighting risks, trends, and remediation progress.
Leadership and Collaboration
Lead and mentor a high-performing team of cybersecurity professionals responsible for assessments, assurance, a
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s