{"21582602":{"jobPath":"/jobs/21582602/it-administrator-i","source":"naylor","job":"21582602","jobTitle":"IT Administrator I"},"21585710":{"jobPath":"/jobs/21585710/security-supervisor","source":"naylor","job":"21585710","jobTitle":"Security Supervisor"},"21584202":{"jobPath":"/jobs/21584202/security-officer-dispatcher","source":"naylor","job":"21584202","jobTitle":"Security Officer/Dispatcher"},"21585553":{"jobPath":"/jobs/21585553/identity-and-access-management-analyst-its-university-at-albany","source":"naylor","job":"21585553","jobTitle":"Identity and Access Management Analyst - ITS - University at Albany"},"21586444":{"jobPath":"/jobs/21586444/senior-analyst-it-client-support","source":"naylor","job":"21586444","jobTitle":"Senior Analyst, IT Client Support"},"21585554":{"jobPath":"/jobs/21585554/researcher-center-for-technology-in-government-university-at-albany","source":"naylor","job":"21585554","jobTitle":"Researcher - Center for Technology in Government - University at Albany"},"21585416":{"jobPath":"/jobs/21585416/library-security-officer","source":"naylor","job":"21585416","jobTitle":"Library Security Officer"},"21584745":{"jobPath":"/jobs/21584745/data-center-it-specialist","source":"naylor","job":"21584745","jobTitle":"Data Center IT Specialist"},"21585420":{"jobPath":"/jobs/21585420/it-operations-analyst-management-analyst-2","source":"naylor","job":"21585420","jobTitle":"IT Operations Analyst - Management Analyst 2"},"21587542":{"jobPath":"/jobs/21587542/information-technology-manager","source":"naylor","job":"21587542","jobTitle":"Information Technology Manager"},"21582217":{"jobPath":"/jobs/21582217/coordinator-for-student-government-student-organizations-student-activities-great-dane-union-university-at-albany","source":"naylor","job":"21582217","jobTitle":"Coordinator for Student Government & Student Organizations - Student Activities/Great Dane Union - University at Albany"},"21579202":{"jobPath":"/jobs/21579202/senior-analyst-it-client-services","source":"naylor","job":"21579202","jobTitle":"Senior Analyst, IT Client Services"},"21584759":{"jobPath":"/jobs/21584759/manager-security-safety","source":"naylor","job":"21584759","jobTitle":"Manager - Security & Safety"},"21579189":{"jobPath":"/jobs/21579189/senior-analyst-it-client-services","source":"naylor","job":"21579189","jobTitle":"Senior Analyst, IT Client Services"},"21585104":{"jobPath":"/jobs/21585104/network-security-engineer-fortinet-cisco","source":"naylor","job":"21585104","jobTitle":"Network Security Engineer (Fortinet/Cisco)"},"21582452":{"jobPath":"/jobs/21582452/security-ambassador-1st-shift-mon-fri-6-30am-3pm","source":"naylor","job":"21582452","jobTitle":"Security Ambassador - 1st Shift (Mon-Fri 6:30am-3pm)"},"21582112":{"jobPath":"/jobs/21582112/sr-information-security-analyst","source":"naylor","job":"21582112","jobTitle":"Sr. Information Security Analyst"},"21585345":{"jobPath":"/jobs/21585345/risk-manager-city-of-san-jos-department-of-finance","source":"naylor","job":"21585345","jobTitle":"Risk Manager- City of San José, Department of Finance"},"21584237":{"jobPath":"/jobs/21584237/information-security-engineer","source":"naylor","job":"21584237","jobTitle":"Information Security Engineer"},"21581864":{"jobPath":"/jobs/21581864/cyber-security-analyst","source":"naylor","job":"21581864","jobTitle":"Cyber Security Analyst"},"21586217":{"jobPath":"/jobs/21586217/it-manager","source":"naylor","job":"21586217","jobTitle":"IT Manager"},"21584580":{"jobPath":"/jobs/21584580/clinical-research-monitoring-and-auditing-specialist-abramson-cancer-center","source":"naylor","job":"21584580","jobTitle":"Clinical Research Monitoring and Auditing Specialist (Abramson Cancer Center)"},"21587570":{"jobPath":"/jobs/21587570/deputy-administrator-augusta-richmond-county-consolidated-government","source":"naylor","job":"21587570","jobTitle":"Deputy Administrator - Augusta-Richmond County Consolidated Government"},"21587433":{"jobPath":"/jobs/21587433/director-of-it-customer-service","source":"naylor","job":"21587433","jobTitle":"Director of IT Customer Service"},"21585177":{"jobPath":"/jobs/21585177/campus-security-officer-full-time","source":"naylor","job":"21585177","jobTitle":"Campus Security Officer Full-time"}}
Manager, Information Security & Risk - IT Compliance
Cardinal Health
Application
Details
Posted: 16-Aug-25
Location: United States - Nationwide
Internal Number: 20165553
Company Overview:
Cardinal Health, Inc. (NYSE: CAH) is a global healthcare services and products company. We provide customized solutions for hospitals, healthcare systems, pharmacies, ambulatory surgery centers, clinical laboratories, physician offices and patients in the home. We are a distributor of pharmaceuticals and specialty products; a global manufacturer and distributor of medical and laboratory products; an operator of nuclear pharmacies and manufacturing facilities; and a provider of performance and data solutions. Working to be healthcare?s most trusted partner, our customer-centric focus drives continuous improvement and leads to innovative solutions that improve the lives of people every day. With approximately 50,000 employees worldwide, Cardinal Health ranks among the top fifteen in the Fortune 500.
Department Overview:
Information Technology oversees the effective development, delivery, and operation of computing and information services. This function anticipates, plans, and delivers Information Technology solutions and strategies that enable operations and drive business value.
Information Security and Risk develops, implements, and enforces security controls to protect the organization's technology assets from intentional or inadvertent modification, disclosure, or destruction. This job family develops system back-up and disaster recovery plans, conducts incident responses, threat management, vulnerability scanning, virus management and intrusion detection as well as completes risk assessments. The IT Governance and Compliance function within the organization develops, enhances, and maintains security policies and IT compliance programs in alignment with regulatory, legal, and contractual requirements, while collaborating closely with key stakeholders to maintain a security and compliant technology environment.
We are committed to building a resilient, secure, and compliant digital ecosystem, and you will play a critical role in safeguarding our information and supporting our mission to improve the lives of people every day.
We are seeking a strategic and experiencedManager of IT Compliance, and in this role, you will have the opportunity to lead meaningful work, collaborate across functions, and help shape the future of our IT compliance strategy.
Job Overview:
Manager of IT Compliance will lead the development, execution, and continuous improvement of our enterprise IT compliance programs. This role will set the strategy in collaboration with the leader as well as provide direction and oversight across a broad set of compliance domains, including IT Privacy regulations (i.e., HIPAA, GDPR, etc.), third party certification management (e.g., HITRUST, SOC 2), and proactively driving compliance to emerging regulatory obligations. The manager will lead a high-performing team and work cross-functionally with legal, privacy, audit, and IT stakeholders to ensure the organization maintains a strong and proactive compliance posture.
Key Responsibilities:
People Leadership: Lead and develop a team of IT compliance professionals. Foster an inclusive, collaborative, accountable and high-performing team culture.
Program Leadership: Set strategic direction in collaboration with the leader for the IT Compliance function, aligning program objectives with organizational goals and evolving regulatory requirements.
IT Privacy Compliance Program: Oversee the design, implementation, enhancement, and maintenance of the IT privacy compliance program to enable compliance with key IT privacy regulation requirements (e.g., HIPAA, GDPR), while partnering with key partners and stakeholders.
Third-Party Certifications Management: Set strategic direction in collaboration with the leader for management of external certifications such as HITRUST and SOC 2, including program governance, planning, readiness, remediation oversight, cost and support model, and ongoing maintenance of the certifications.
IT Compliance Assessment: Direct and oversee the execution of compliance assessments and gap assessments for existing regulations from an IT perspective, collaborating with key stakeholders and partners throughout the organization.
Regulatory Monitoring: Proactively identify, assess, and operationalize compliance to new or evolving regulatory requirements that impact the organization?s IT environment, collaborating with key stakeholders and partners throughout the organization.
Reporting and Metrics: Establish KPIs and KRIs as well as reporting processes to provide ongoing updates to leadership on health of the IT compliance program effectiveness, risk exposure, and compliance trends and posture.
Advisory Services: Serve as a key advisor to stakeholders across Privacy, Legal, Audit, IT and Business Units to confirm regulatory and contractual obligations are understood and addressed in IT processes and controls.
Qualifications:
Bachelor?s Degree in related field or equivalent work experience
10+ years? experience in IT Governance, Risk and Compliance functional roles such as IT Compliance, IT Risk Management, IT Audit, Enterprise Risk Management, etc preferred.
Proven leadership experience with the ability to foster an inclusive and engaging culture.
Prior experience working with Internal or External Audit functions are a plus.
Deep knowledge of risk and control frameworks as well as key regulatory requirements that impact healthcare organizations.
Direct experience in managing third-party certifications such as HITRUST and SOC 2 is preferred including readiness and gap assessments to managing certifications.
Strong understanding of IT environments, systems, data governance practices
Strong interpersonal skills and presentation skills with ability to tailor message for the audience are foundational for success.
Strong and effective communication skills with ability to influence and drive actions.
Ability to identify and engage cross functional teams to solve problems that meet organizational objectives.
Ability to identify alternative solutions to solve a given problem when traditional solution may not be feasible.
Security, compliance, or risk certifications such as CIPT (Certified Information Privacy Technologist), CISA (Certified Information Systems Auditor), CISSP (Certified Information Systems Security Professional) and/or CIPP (Certified Information Privacy Professional) certifications are preferred.
Anticipated salary range:$121,600 - $182,385
Bonus eligible:Yes
Benefits:Cardinal Health offers a wide variety of benefits and programs to support health and well-being.
Medical, dental and vision coverage
Paid time off plan
Health savings account (HSA)
401k savings plan
Access to wages before pay day with myFlexPay
Flexible spending accounts (FSAs)
Short- and long-term disability coverage
Work-Life resources
Paid parental leave
Healthy lifestyle programs
Application window anticipated to close:9/25/2025 *if interested in opportunity, please submit application as soon as possible.
The salary range listed is an estimate. Pay at Cardinal Health is determined by multiple factors including, but not limited to, a candidate?s geographical location, relevant education, experience and skills and an evaluation of internal pay equity.
Candidates who are back-to-work, people with disabilities, without a college degree, and Veterans are encouraged to apply.
Cardinal Health supports an inclusive workplace that values diversity of thought, experience and background. We celebrate the power of our differences to create better solutions for our customers by ensuring employees can be their authentic selves each day. Cardinal Health is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, ancestry, age, physical or mental disability, sex, sexual orientation, gender identity/expression, pregnancy, veteran status, marital status, creed, status with regard to public assistance, genetic status or any other status protected by federal, state or local law.
Headquartered in Dublin, Ohio, Cardinal Health, Inc. (NYSE: CAH) is a distributor of pharmaceuticals, a global manufacturer and distributor of medical and laboratory products, and a provider of performance and data solutions for healthcare facilities.We are a crucial link between the clinical and operational sides of healthcare, delivering end-to-end solutions and data-driving insights that advance healthcare and improve lives every day. With deep partnerships, diverse perspectives and innovative digital solutions, we build connections across the continuum of care. With more than 50 years of experience, we seize the opportunity to address healthcare's most complicated challenges – now, and in the future.As a global, growing company, we’re able to offer rewarding careers that let you make a positive impact on our customers and communities.