Senior Director of Cyber Risk Management
AmerisourceBergenAbout the role
Our team members are at the heart of everything we do. At Cencora, we are united in our responsibility to create healthier futures, and every person here is essential to us being able to deliver on that purpose. If you want to make a difference at the center of health, come join our innovative company and help us improve the lives of people and animals everywhere. Apply today!
Job Details
Position Summary:
The Senior Director of Cyber Risk Management will lead the organization’s efforts to identify, assess, manage, and mitigate cyber risks while ensuring the effective operation of Governance, Risk, and Compliance (GRC) functions. This role will oversee critical areas of risk management, including risk/issue management, GRC tooling, security policy development, GRC reporting, audit findings management, firewall/change requests, policy exceptions, and risk intake quality assurance (QA). The ideal candidate will bring strategic vision, operational excellence, and leadership to align cybersecurity practices with business objectives and regulatory requirements.
Reporting to the Vice President of Information Security, this role will collaborate across business units, IT, and cybersecurity teams to ensure risks are effectively addressed and compliance standards are met.
Key Responsibilities:
Risk and Issue Management:
Lead the identification, assessment, and prioritization of cyber risks and issues across the enterprise.
Implement and maintain processes for tracking, mitigating, and resolving risks and issues.
Ensure effective risk intake processes, including quality assurance (QA) reviews of submitted risks to validate accuracy, completeness, and alignment with organizational risk criteria.
Develop frameworks for consistent risk classification, prioritization, and escalation to appropriate stakeholders.
GRC Tooling:
Manage the implementation, optimization, and ongoing maintenance of Governance, Risk, and Compliance (GRC) tooling (e.g., ServiceNow).
Ensure GRC tools are configured to support risk management workflows, reporting, and compliance tracking.
Collaborate with internal teams to enhance tool functionality, automate processes, and improve user experience.
Security Policy and Standards:
Develop, implement, and maintain information security policies, standards, and procedures aligned with industry frameworks (e.g., NIST CSF, ISO 27001, CIS Controls).
Ensure policies and standards address regulatory requirements, contractual obligations, and emerging threats.
Collaborate with business units to ensure adoption and compliance with security policies and standards.
Periodically review and update policies to reflect changes in the threat landscape, business operations, or regulatory requirements.
GRC Reporting:
Oversee the creation and delivery of GRC reports to senior leadership, stakeholders, and regulatory bodies.
Develop and maintain dashboards that provide visibility into risk management metrics, compliance status, and security performance.
Ensure reporting aligns with organizational objectives and informs decision-making at all levels.
Audit Findings Management:
Manage the lifecycle of IT audit findings, ensuring timely remediation and closure.
Collaborate with internal teams to address findings from internal audits, external audits, and regulatory assessments.
Track audit findings in GRC tools and provide regular updates to stakeholders on remediation progress.
Identify trends in audit findings and recommend improvements to reduce recurring issues.
Firewall/Change Requests:
Oversee the review and approval process for firewall and security-related change requests.
Ensure change requests align with security policies, standards, and risk management practices.
Collaborate with IT and network teams to validate the security impact of proposed changes.
Maintain documentation and tracking of change requests for audit and reporting purposes.
Policy Exceptions:
Manage the policy exception process, including intake, review, approval, and tracking.
Evaluate exception requests to ensure risks are understood and compensating controls are in place.
Provide recommendations to senior leadership for high-risk exceptions and escalate appropriately.
Periodically review approved exceptions to assess ongoing relevance and compliance.
Risk Intake and QA:
Oversee the
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s