Sr. Manager, M&A Cybersecurity
SolventumAbout the role
Job Description:
Sr. Manager, M&A Cybersecurity
At Solventum, we enable better, smarter, safer healthcare to improve lives. As a new company with a long legacy of creating breakthrough solutions for our customers’ toughest challenges, we pioneer game-changing innovations at the intersection of health, material and data science that change patients' lives for the better while enabling healthcare professionals to perform at their best. Because people, and their wellbeing, are at the heart of every scientific advancement we pursue.
We partner closely with the brightest minds in healthcare to ensure that every solution we create melds the latest technology with compassion and empathy. Because at Solventum, we never stop solving for you.
The Impact You’ll Make in this Role
As Sr. Manager, M&A Cybersecurity, you will be apart of the overall information security risk management program and strategy, providing skilled leadership to build high-performing team(s), and engaging IT and Business leaders across a wide spectrum of acquisition and divestiture activities. Your collaborative approach and exceptional communication skills will play a significant role in your success, as you engage and support colleagues inside and outside the organization. As part of this new Healthcare spinoff, you will have the opportunity to create an industry best-practice program that serves as a strategic enabler to inorganic business growth.
Responsibilities
- Serve as the Security Leader during the due-diligence and post close assessment process, partnering with stakeholders within IT and the business to drive integration activities and cutover timelines.
- Lead Divestiture activities, management of TSA cybersecurity requirements, and driving discovery and monitoring requirements for divested and TSA entities
- Drive cybersecurity M&A assessment framework/ methodology including mapping to a minimum necessary subset of the Enterprise Control Framework (ECF) utilizing NIST/HITRUST controls that align with Enterprise Risk Management (ERM) objectives.
- Lead a team that performs risk assessments of acquisitions and divestitures, and identify, mitigate, and track to closure risks across the enterprise, providing actionable data and recommended solutions to organization leadership.
- Define and manage a corrective action plan process to identify systemic process or capability gaps within M&A’s and drive to remediation
- Define standardized risk assessment and exception handling processes, including defining what constitutes an exception and the criteria for managing them.
- Develop and execute gold-standard information security governance strategy and program. Drive culture of transparency, integrity, and accountability.
- Establish a robust Findings & Remediation program that identifies trends in newly discovered risks, provides actionable reporting, identifies root cause, and works collaboratively to reduce inherent risk and technical debt.
- Help drive and align a security champion and/or BISO function for newly acquired businesses, to align accountability of remediation activities.
- Use expertise to scale programs up and down to meet the current regulatory environment and the risk appetite of the organization.
- Monitor regulatory changes and industry standards.
- Coordinate the transfer of information into or out of the firm in compliance with organizational policies. When necessary, ensure the proper execution of destruction orders.
- Implement supporting protocols and processes to ensure statutory, regulatory, ethical and privacy requirements are met for the management of physical and electronic information.
- Support data governance efforts across the organization, including but not limited to data classification, data retention and disposal, data sharing, records management, a
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s