Business Information Security Officer - Corporate Functions
McKessonAbout the role
McKesson is an impact-driven, Fortune 10 company that touches virtually every aspect of healthcare. We are known for delivering insights, products, and services that make quality care more accessible and affordable. Here, we focus on the health, happiness, and well-being of you and those we serve – we care.
What you do at McKesson matters. We foster a culture where you can grow, make an impact, and are empowered to bring new ideas. Together, we thrive as we shape the future of health for patients, our communities, and our people. If you want to be part of tomorrow’s health today, we want to hear from you.
Job Description:
McKesson’s Corporate Functions Business Information Security Officer (BISO) will lead, plan, direct, and control activities for assurance, security (information, application, and infrastructure), and compliance across McKesson Corporate Functions, including Technology, HR, Legal, Finance, Privacy, and Compliance. This Security Principal (P6) role ensures successful delivery of Information Security and IT risk management services in compliance with McKesson Cyber Security policies, standards, and the NIST framework.
The ideal candidate has high energy, strong presence, and a passion for delivering value from the cybersecurity function. They possess deep technical security, governance, and risk expertise and will be the primary advocate for security initiatives across these functions, maintaining consistent alignment with the McKesson Cyber Security organization.
The candidate will work directly with senior leaders from each of those functions and should have the requisite capabilities to succeed at that level. This individual will work as part of a large team of security professionals in a structure designed to help them succeed in delivering best-in-class security to this stakeholder group.
This role reports directly to the Senior Director of Cyber Governance and Risk Management.
Key Accountabilities:
Risk Management:
Manage corporate function cyber security and risk requirements, ensuring high-quality execution.
Co-ordinate IT risk, compliance, and audit reviews, and assist with remediation of findings.
Ensure technology programs comply with relevant laws, regulations, and McKesson cyber security policies.
Compliance:
Participate in corporate function initiatives to represent the cybersecurity function.
Ensure security programs address IT risk management findings and follow relevant laws, regulations, and policies.
Stakeholder Engagement:
Report Key Risk and cyber security performance Indicators to corporate functions leadership for informed decision-making.
Develop strong partnerships with IT leaders and ISRM service teams to manage corporate function IT and security risk.
Minimum Qualifications:
Bachelor’s Degree or equivalent experience in Information Security, Computer Science, or related field.
15+ years of relevant professional experience, including 8+ years in impactful roles interacting with senior stake
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s