Director, Cyber Risk Services (Information Security)

Cardinal Health

Confirmed live 2 days ago High trust
Remote

Quick summary

Work type
Remote
Location
Remote
Salary
$137,400–$232,320 / yr
Posted
3 days ago
Freshness
Confirmed live 2 days ago

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $199k
This role $185k
$126k most similar roles pay here $248k

This role pays less than 55% of similar roles. Most pay $162,162–$235,000 — the shaded band above. At the midpoint, this role pays about $185k versus about $199k for comparable roles.

Based on 238 similar postings.

Employer

About Cardinal Health

Cardinal Health is a global healthcare services and products company specializing in pharmaceutical distribution, medical products, and supply chain solutions for healthcare providers and pharmacies. Industry: Healthcare Distribution & Services

Cardinal Health currently has 36 open roles on FindRole.

Listed pay typically runs $94,900–$135,600 across 32 roles with salary data.

Most-posted roles

View all roles at Cardinal Health

At a glance

TL;DR · Director, Cyber Risk Services (Information Security)

The Director, Cyber Risk Services joins the Information Security and Risk team to establish, lead, and improve the cybersecurity risk management program. This leader is responsible for developing risk management strategies, methodologies, and governance processes aligned with enterprise risk management and regulatory requirements. Day-to-day responsibilities include overseeing risk assessment programs, managing a centralized risk register, tracking vulnerability remediation, and leading the third-party risk management program. The role involves defining cybersecurity metrics like KPIs and KRIs to provide actionable insights for executive leadership while enhancing GRC tools and platforms. Candidates must possess expertise in frameworks such as NIST CSF or ISO 27001. This position addresses the critical business problem of integrating cybersecurity risks into enterprise decision-making, ensuring that security controls protect technology assets from unauthorized modification or disclosure within a complex regulatory environment.

What you'll do

  • Develop and lead the cybersecurity risk management strategy aligned with enterprise goals and regulatory requirements.
  • Establish and maintain standardized risk management frameworks, methodologies, and taxonomies across the organization.
  • Oversee enterprise-wide risk assessments to identify threats, vulnerabilities, and control gaps.
  • Manage a centralized risk register to track, prioritize, and assign ownership for remediation tasks.
  • Lead the third-party risk management program including vendor assessments and contract reviews.
  • Monitor vulnerability remediation processes and ensure compliance with established service level agreements.
  • Define and report key performance indicators (KPIs) and key risk indicators (KRIs) to executive leadership.
  • Manage and enhance GRC tools and platforms to improve risk monitoring and reporting capabilities.

What we're looking for

  • Ideally targeting individuals with 8+ years of experience in cybersecurity, risk management, or information security.
  • Expertise in cybersecurity risk management frameworks, methodologies, and enterprise risk integration is required.
  • Experience leading risk assessment programs, risk remediation efforts, and third-party risk management is required.
  • Strong understanding of cybersecurity frameworks (e.g., NIST CSF, ISO 27001) and regulatory requirements is required.
  • Experience developing executive-level reporting and communicating risk insights to senior leadership is required.
  • Strong leadership, communication, and stakeholder management skills are required.
  • Experience as a people leader overseeing cybersecurity risk or GRC functions (preferred).
  • Experience in highly regulated industries, professional certifications (CISSP, CISM, CRISC, or CISA), or experience in healthcare/finance (preferred).

More like this

Similar roles

Director, Cyber Compliance (Information Security)

Cardinal Health

Remote 3 days ago $137,400$232,320
GRC NIST CSF ISO 27001 SOX HIPAA GDPR PCI CMMC FDA GxP SOC 2 ITGC Risk Management Audit Management Cybersecurity Compliance Information Security
8+ yrs exp Remote

Director, Cyber Risk & Analysis

Capital One Financial

McLean, VA +1 45 days ago $230,400$263,000
Artificial Intelligence Cloud Computing Data Analysis Risk Assessment Control Programs Project Management Lean Six Sigma PMP CISSP CISA CRISC CISM AIGP
10+ yrs exp

Director, IT Governance, Risk, Compliance & AI

General Dynamics

Scottsdale, AZ +1 24 days ago $201,481$218,009
NIST CMMC DFARS SOX COBIT ITIL ISO 27001 AI Governance Cybersecurity Risk Management Data Governance Cloud Governance Change Management Configuration Management Vulnerability Management Audit Coordination
10+ yrs exp Hybrid

Director, Risk

Alkami

Remote 3 days ago $151,000$189,000
Artificial Intelligence Machine Learning Generative AI AI Governance NIST ISO COSO COBIT GRC AuditBoard Optro PCI DSS SOC GLBA FFIEC Business Continuity Disaster Recovery Information Security
10+ yrs exp Remote

Lead, Third Party Cyber Risk & Analysis

Capital One Financial

McLean, VA +1 9 days ago $164,800$188,100
Cybersecurity Third Party Risk Management PCI DSS NIST ISO Information Security Risk Assessment IT Operations Management CISSP CISA CISM CTPRP CTPRA CRISC
6+ yrs exp

Director, Cybersecurity

LogicGate

Chicago, IL +1 2 days ago $190,000$240,000
SOC 2 ISO 27001 FedRAMP ISO 42001 CNAPP EDR SASE Zscaler CrowdStrike GitLab Wiz LLM AI Incident Response Vulnerability Management Security Architecture GRC SaaS
7+ yrs exp