Senior Engineer, Information Security & Risk

Cardinal Health

Confirmed live yesterday High trust

Quick summary

Work type
On-site
Location
Salary
$125,300–$178,900 / yr
Posted
3 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Below market

How this pay compares to similar roles

Similar $176k
This role $152k
$115k most similar roles pay here $220k

This role pays less than 68% of similar roles. Most pay $149,206–$202,975 — the shaded band above. At the midpoint, this role pays about $152k versus about $176k for comparable roles.

Based on 240 similar postings.

Employer

About Cardinal Health

Cardinal Health is a global healthcare services and products company specializing in pharmaceutical distribution, medical products, and supply chain solutions for healthcare providers and pharmacies. Industry: Healthcare Distribution & Services

Cardinal Health currently has 40 open roles on FindRole.

Listed pay typically runs $105,100–$151,250 across 36 roles with salary data.

Most-posted roles

View all roles at Cardinal Health

At a glance

TL;DR · Senior Engineer, Information Security & Risk

The Senior Engineer - Information Security & Risk serves as a second line of defense within the Information Security and Risk team. This role is responsible for defining, implementing, and evaluating the effectiveness of IT SOX controls while driving detailed design and remediation consulting to ensure compliance goals are met. The individual will perform risk assessments, manage junior staff and contractors, support M&A due diligence, and oversee third-party certifications like SOC1/2. Key responsibilities include process improvement, tracking remediation issues, and reporting on compliance posture. Required expertise includes deep knowledge of IT SOX control and audit methodology, root cause analysis, and flowcharting. The role requires familiarity with networks, databases, middleware, and ERP systems like SAP. Preferred tools include Archer, AuditBoard, or ServiceNow GRC, alongside certifications such as CISA, CPA, CISM, CISSP, or CRISC.

What does a Engineer earn?

Median $180500 from 255 postings across 54 companies.

See salary data

What you'll do

  • Perform IT risk assessments for pilot areas to identify control gaps and provide remediation guidance.
  • Design and implement effective IT controls to ensure organizational SOX compliance goals are met.
  • Improve existing IT controls to increase operational efficiency and reduce the likelihood of failure.
  • Monitor and evaluate the execution of IT controls to ensure they operate effectively.
  • Support due diligence for M&A activities and review third-party certifications like SOC1/2.
  • Align with internal and external auditors to define SOX scope and audit strategies.
  • Track and drive the remediation of IT control issues within the risk governance process.
  • Manage junior staff and contractors while overseeing the budget for compliance workstreams.

What we're looking for

  • Bachelor’s degree in a related field or equivalent work experience.
  • Deep knowledge of IT SOX control and audit methodology.
  • Strong understanding and experience with SOX is required.
  • Strong root cause analysis and problem-solving skills are required.
  • Strong knowledge of IT technologies including networks, databases, middleware, interfaces, and applications.
  • 6+ years of experience in a related field such as IT audit or IT compliance (preferred).
  • Knowledge of other compliance frameworks like HIPAA, GDPR, or PCI (plus).
  • Professional certifications such as CISA, CPA, CISM, CISSP, or CRISC (preferred).

More like this

Similar roles

Senior Information Systems Security Engineer

Leidos

23 days ago $131,300$237,350
Risk Management Framework (RMF) CNSSI 1253 DoD 8500 Zero Trust Cloud Computing Cybersecurity Risk Assessment Information Assurance Incident Response
10+ yrs exp

Manager, Infrastructure Governance

Cardinal Health

Remote (OH) 9 days ago $125,300$178,900
AWS Azure GCP ServiceNow CSPM GRC NIST CSF HIPAA HITRUST SOX GDPR Prisma Wiz Sentinel Cloud Security Automation AI Vulnerability Management
4+ yrs exp Remote

Lead IT SOX Risk Advisory

Intuit

Mountain View, CA +2 79 days ago $175,500$237,000
SOX ITGC ICFR PCAOB Risk Management Project Management AI Tools ChatGPT Claude Copilot Audit Internal Audit Control Design Automated Controls Information Systems CISA CISSP AWS Certified Cloud Practitioner
8+ yrs exp Hybrid

Director, Cyber Compliance (Information Security)

Cardinal Health

Remote 11 days ago $137,400$232,320
GRC NIST CSF ISO 27001 SOX HIPAA GDPR PCI CMMC FDA GxP SOC 2 ITGC Risk Management Audit Management Cybersecurity Compliance Information Security
8+ yrs exp Remote

Senior Information Security Engineer

Booz Allen Hamilton

McLean, VA +1 6 days ago $99,000$225,000
Check Point Infoblox DNS IPAM Firewalls WAF Zero Trust Cloudflare AWS Azure GCP Cybersecurity AI Network Security