yoinka

Director, Cyber Risk Services (Information Security)

Cardinal Health

US-Nationwide-FIELDStaffH-1B sponsor company
Sign in to applyVerified 1h ago
Location
US-Nationwide-FIELD
Work model
On-Site
Level
Staff
H-1B history
57 approvals (FY2023)
Posted
Sep 8, 2026

Skills

Cybersecurity

About this role

What Information Security and Risk contributes to Cardinal Health Information Security and Risk develops, implements, and enforces security controls to protect the organization's technology assets from intentional or inadvertent modification, disclosure or destruction. The Director, Cyber Risk Services is responsible for establishing, leading, and continuously improving the cybersecurity risk management program to identification, assessment, mitigation, and reporting of cyber risks. Reporting to the Vice President, Global Cybersecurity Governance, Risk & Compliance (GRC), this role drives the design and execution of risk management frameworks, methodologies, and supporting governance processes aligned with enterprise risk management (ERM), regulatory requirements, and business objectives. Furthermore, this leader oversees core cyber risk capabilities including risk framework development, risk remediation oversight, and third-party risk management. It also plays a critical role in integrating cybersecurity risk into enterprise decision-making, enabling business-aligned risk insights, and driving adoption of consistent risk practices. Location - Fully remote, open to candidates based nationwide   Responsibilities Develop and lead the cybersecurity risk management strategy aligned with enterprise risk management frameworks, business objectives, and regulatory expectations. Collaborate with the VP of Global Cyber GRC and enterprise stakeholders to define risk management priorities, methodologies, and governance structures. Establish governance processes, roles, and accountability models to ensure consistent execution of cyber risk activities across the organization. Serve as an advisor to leadership on cybersecurity risk posture, emerging threats, and mitigation strategies. Define, standardize, and maintain cybersecurity risk management frameworks, methodologies, and taxonomies across the CISO Program. Ensure consistency in risk identification, assessment, scoring, and reporting across cybersecurity and business segments. Align cybersecurity risk methodologies with enterprise risk management (ERM) frameworks to enable integrated risk visibility. Continuously update and improve risk frameworks to reflect evolving threats, technologies, and regulatory requirements. Oversee enterprise-wide cybersecurity risk assessments to identify threats, vulnerabilities, and control gaps. Establish and maintain a centralized risk register to track, assess, and manage cybersecurity risks across systems, applications, and business processes. Ensure risks are documented, prioritized, and assigned to accountable owners for remediation within the GRC tool. Collaborate with business and technology stakeholders to ensure risk identification and alignment with business impact. Lead development and execution of risk mitigation and remediation strategies in partnership with cybersecurity and business segment teams. Oversee vulnerability remediation processes, including monitoring SLA compliance, tracking remediation outcomes, and escalating non-compliance. Ensure effective tracking and reporting of remediation efforts to reduce security risk exposure. Oversee and drive issues and exception processes, ensuring documentation, approval, and alignment with defined risk tolerance levels. Partner with Enterprise Risk Management (ERM) teams to align cybersecurity risks, controls, and mitigation strategies with the broader organizational risk framework. Ensure cybersecurity risks are integrated into enterprise risk reporting and governance processes. Support enterprise risk discussions by providing insights into cybersecurity risk trends, impacts, and mitigation progress. Oversee the cybersecurity third-party risk management (TPRM) program, including vendor risk assessments, onboarding, continuous monitoring, and termination processes. Establish governance for third-party lifecycle management to ensure risks are identified and mitigated throughout vendor

Listing verified 1h ago. Applications go through the company's official careers site.

← Back to Yoinka

Director, Cyber Risk Services (Information Security) at Cardinal Health, US-Nationwide-FIELD | Yoinka