Jobs and Careers
AM

Information Security Sr. Specialist

AmerisourceBergen
Czechiafull_timeVerifiedPosted 5 Mar 2024

About the role

<p>Our team members are at the heart of everything we do. At Cencora, we are united in our responsibility to create healthier futures, and every person here is essential to us being able to deliver on that purpose. If you want to make a difference at the center of health, come join our innovative company and help us improve the lives of people and animals everywhere. Apply today!</p><p></p><p></p><h1>What you will be doing</h1><p></p><p></p><p>Under general direction of the ISO, this position is responsible for implementation and management of multiple services, capabilities, controls and relevant components of the Information Security management framework at the enterprise level supporting one or more assigned Cencora business units and affiliates.</p><p>Specific areas of responsibility include but are not limited to:</p><ul><li><p>Driving implementation and management of appropriate processes and controls which help to assure that information, created, acquired or maintained by authorized users, is used in accordance with its intended purpose.</p></li><li><p>Proactive identification of information security risks and protecting information and infrastructure from external / internal threats by implementing processes which help to manage and reduce the overall risk impact.</p></li><li><p>Contributing to initiatives which help to ensure compliance with contractual, statutory and regulatory requirements, regarding information availability, integrity and confidentiality.</p></li><li><p>Operational responsibility for the development, implementation and delivery of appropriate security services and solutions to IT and directly to the business units and affiliates.</p></li><li><p>Executing actions to enforce policies, guidelines, standards, processes, procedures, best practices and services in the areas of application, infrastructure, systems and services security.</p></li></ul><p></p><p><u>PRIMARY DUTIES AND RESPONSIBILITIES:</u></p><ul><li><p>Participate in the implementation of an Information Security Management System (ISMS) which includes appropriate policies, procedures, operational considerations, IT change control, and IT risk and compliance management programs. These efforts include (but are not limited to): Information Security Governance processes, Policies &amp; Procedures, Audits, Metrics and reporting in direct alignment with contractual, regulatory and compliance requirements.</p></li><li><p>Directly partner with the affiliate Finance, Legal, Audit and Compliance teams to support Internal and External Audits (SOX, COBIT, IT Controls).</p></li><li><p>Support the Business Unit and IT teams through the process of prioritizing security initiatives based on relevant business risk and regulatory compliance issues, financial implications, and alignment with the strategic plan.</p></li><li><p>Support strategic and tactical security, risk mitigation and regulatory compliance guidance for all IT projects, including the evaluation of information security policies, processes, operating procedures and governance controls.</p></li><li><p>Contribute to the development, implementation and management of relevant metrics to measure the efficiency and effectiveness of the information security management systems (ISMS), risk management and related compliance programs.</p></li><li><p>Drive the implementation and management of an enterprise Information Security &amp; Privacy Training &amp; Awareness program to assure the workforce is knowledgeable of policies, best practices, and relevant security and data privacy guidance appropriate to their role in the organization.</p></li><li><p>Drive the tracking and resolution of Audit findings and remediation activities and support external and customer security audits.</p></li></ul><p></p><p></p><h1>What your background should look like </h1><p></p><p></p><p><u>EXPERIENCE AND EDUCATIONAL REQUIREMENTS:</u></p><p>In one of the following areas: Information Security, Cyber Security, Security Governance and Solutions or Identity and Access Management</p><ul><li><p>3-5 years progressively responsible experience in the implementation and management of Information Security Shared services for a global corporation (Fortune 500)</p></li><li><p>Experience working in functional business and technical teams in a large and complex environment to deliver related capabilities and services.</p></li><li><p>Demonstrated success in professional contribution to an Information Security Framework, solution and service for a cross functional corporation.</p></li><li><p>Extensive experience with Healthcare regulatory and information security guidelines, audits as well as external audit processes and requirements</p></li><li><p>Demonstrated successful implementation of security control frameworks and standards such as ISO 27001, ISO 17799, COBIT, ITIL, NIST and PCI.</p></li><li><p>Certification in Information Security relevant areas such as Audit (CISA), Security Management (CISM), Security Professional

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

AmerisourceBergen

View company profile →