Manager, CISO Program & Operations
Cardinal Health
- Location
- OH-Ohio-Work from Home
- Work model
- Remote
- Level
- Senior
- H-1B history
- 57 approvals (FY2023)
- Posted
- Sep 16, 2026
Skills
About this role
What Information Security and Risk contributes to Cardinal Health Information Technology oversees the effective development, delivery, and operation of computing and information services. This function anticipates, plans, and delivers Information Technology solutions and strategies that enable operations and drive business value. Information Security and Risk develops, implements, and enforces security controls to protect the organization's technology assets from intentional or inadvertent modification, disclosure or destruction. This job family develops system back-up and disaster recovery plans. Information Technology also conducts incident response, threat management, vulnerability scanning, virus management and intrusion detection and completes risk assessments. The Manager, CISO Program & Operations is responsible for supporting the execution, governance, and continuous improvement of the enterprise cybersecurity program. Reporting to the Director of Cybersecurity Strategy & Program Operations, this role serves as a central coordination point to ensure cybersecurity and infrastructure initiatives are effectively planned, executed, monitored, and aligned with organizational priorities and risk objectives. This role manages core CISO program capabilities including project intake, portfolio and project management, financial and vendor oversight, and performance monitoring. It plays a critical role in enabling transparency, consistency, and operational discipline across the CISO Program by establishing standardized processes, facilitating cross-functional collaboration, and delivering data-driven insights to support decision-making.
Qualifications
5+ years of experience in cybersecurity, technology risk, portfolio management, or program operations preferred. Bachelor's Degree preferred Experience supporting cybersecurity project or portfolio management, including tracking initiatives, managing priorities, and reporting performance. Strong understanding of cybersecurity frameworks (e.g., NIST CSF, ISO 27001), risk management principles, and regulatory requirements. Experience developing executive reporting materials and utilizing metrics to track program performance. Strong organizational, analytical, and problem-solving skills with attention to detail. Ability to manage multiple priorities and work effectively across cross-functional teams. Strong communication and stakeholder management skills. Experience in cybersecurity portfolio management, program governance, or strategy execution. Experience working in highly regulated industries (e.g., aviation, financial services, healthcare, or government). Familiarity with Agile methodologies and project management tools. Advanced degree (MBA, MS in Cybersecurity, Information Systems, or related field). Professional certifications such as CISSP, CISM, PMP, or PRINCE2. Responsibilities · Strategy Facilitation & Program Oversight Support facilitation of the CISO Program strategy by aligning program activities to enterprise and cybersecurity objectives. Collaborate with CISO Program leadership to establish goals, define success metrics, and monitor program performance against strategic priorities. Assist in maintaining the cybersecurity services catalog, including services, tools, and technologies utilized across the program. Support execution of processes to evaluate program performance and maintain alignment with strategic objectives. Contribute to cybersecurity capability maturity assessments and continuous improvement initiatives. · Project Intake & Demand Management Coordinate cybersecurity project intake requests across internal and external stakeholders, including business segments, auditors, vendors, and technology teams. Ensure project requests are properly documented, assessed, and aligned with cybersecurity priorities and available resources. Facilitate communication between requesting stakeholders and cybersecurity teams to support efficient intake, scoping, and