McKesson

McKesson

Lead Cyber Security Architect

USA, VA, Richmond

Sponsorship not specifiedDetected 22 days ago
PythonBashPowerShellCode ReviewGCPKubernetesCI/CDLinuxDevOpsCybersecurityNetwork SecuritySIEMSOARComplianceExcelZero TrustHIPAALeadershipCommunicationMentoringAdaptability

About the role

  • This role provides expert guidance on current security issues while anticipating where threats and technology are heading to proactively shape MMS security strategy.

Responsibilities

  • Own and evolve MMS security architecture reference patterns and guardrails across cloud, network, identity, endpoint, application, and data protection
  • ensure designs are secure-by-design and compliant-by-design.
  • Lead architecture reviews for key initiatives (new platforms, major applications, third-party integrations, and B2B/B2C capabilities)
  • Translate security policy, risk, and regulatory obligations into practical engineering requirements, reusable design standards, and implementation guidance (e.g., templates, runbooks, and secure reference implementations).
  • drive organizational alignment and prioritization with security, technology, and business stakeholders.
  • partner with engineering teams to increase automation and reduce friction.
  • perform critical self-review and peer review of deliverables to ensure high quality, accuracy, and alignment to enterprise security standards.
  • Design and maintain cloud security architecture patterns and guardrails (e.g., IAM and privileged access, organization policies, network segmentation, encryption and key management, logging/monitoring, vulnerability management, and posture management) with clear implementation guidance for delivery teams.
  • Perform other duties as assigned.
  • Own and evolve MMS security architecture reference patterns and guardrails across cloud, network, identity, endpoint, application, and data protection; ensure designs are secure-by-design and compliant-by-design.

Requirements

  • Ability to communicate technical risk and tradeoffs in business terms, influence decisions at multiple levels, and facilitate productive outcomes across security, engineering, and business stakeholders.
  • Experience improving detection and response capabilities at scale (SIEM, EDR/XDR, SOAR, threat intelligence), including driving architectural remediation and hardening based on incidents and post-incident reviews.
  • Proven ability to define and operationalize security standards, patterns, and guardrails (including exception processes), and to ensure adoption through reviews, coaching, documentation, and automation.
  • Track record of acting with integrity, taking pride in work, seeking to excel, being curious and adaptable, and holding a high bar for quality through critical self-review and thoughtful peer review.
  • Hands-on ability to automate and enable teams through scripting and infrastructure-as-code (e.g., Bash, Python, PowerShell) and policy-as-code approaches.
  • Experience designing for cyber resilience (disaster recovery, business continuity, backup/restore security, and ransomware recovery considerations).

Nice to have

  • Alternate Care markets are growing rapidly and MMS is proud to be a leader in this space.
  • Mentor and coach architects and engineers
  • Degree or equivalent and typically requires 10+ years of relevant experience.
  • Less years required if has relevant Master's or Doctorate qualifications
  • Hands-on security architecture experience, including designing guardrails/reference architectures and driving adoption across multiple teams.
  • Demonstrated experience designing security controls for sensitive data (PII/PHI) and supporting audits and compliance efforts through strong documentation and evidence-based controls.
  • Experience with modern security platforms and automation (e.g., SIEM, EDR/XDR, SOAR, secrets management, and data protection) plus scripting/automation to scale controls.
  • CISM, GIAC/SANS certifications, and/or relevant cloud security certifications.

Skills

  • 10+ years in cybersecurity with 5+ years in security architecture, including risk management and compliance.

Compensation

  • We will also continue to be one of the largest medical-surgical distributors in the U.S., with over $11B in annual sales.

Benefits

  • McKesson is an impact-driven, Fortune 10 company that touches virtually every aspect of healthcare.
  • Here, we focus on the health, happiness, and well-being of you and those we serve - we care.
  • Together, we thrive as we shape the future of health for patients, our communities, and our people.
  • If you want to be part of tomorrow's health today, we want to hear from you.
  • About Medical-Surgical
  • McKesson Medical-Surgical (MMS) is a subsidiary and publicly reported segment of the McKesson Corporation.
  • We will also continue to be one of the largest medical-surgical distributors in the U.S., with over $11B in annual sales.

Company info

  • We are known for delivering insights, products, and services that make quality care more accessible and affordable.
  • This separation would accelerate our mission and empower us to shape a future defined by customer-centricity, bold thinking and operational excellence.

Equal opportunity

  • careers.mckesson.com.
  • McKesson is an Equal Opportunity Employer
  • McKesson provides equal employment opportunities to applicants and employees, without regard to race, color, religion, sex, sexual orientation, gender identit

This listing is sourced directly from McKesson's careers page and normalized into a canonical job model.