McKesson

McKesson

Sr. Director, Cyber Engineering

USA, VA, Richmond · Director

Sponsorship not specifiedDetected 22 days ago
GCPCloud PlatformsCI/CDDevOpsPlatform EngineeringCybersecurityNetwork SecuritySIEMSOARComplianceStakeholder ManagementOKRsBudgetingPerformance ManagementFirewallHIPAALeadershipCommunicationMentoring

About the role

  • This role requires strong technical depth in security engineering and the leadership maturity to operate at the executive level.
  • The Director establishes cybersecurity engineering strategy, multi-year roadmaps, and success metrics; governs an operating rhythm for delivery and reliability; and ensures outcomes are achieved across multiple teams (often through influence).

Responsibilities

  • Define and own the cybersecurity engineering strategy and operating model (platform engineering, control implementation, automation, reliability) aligned to business risk, technology priorities, and security architecture.
  • Own the security engineering platform portfolio: select, integrate, and manage lifecycle for security tooling and services (e.g., IAM/PAM, PKI, EDR, CSPM, vulnerability management, secrets management, WAF, DLP, SIEM/SOAR integrations) with clear service models and reliability targets.
  • Partner with architecture, engineering, and product teams to embed security into delivery (DevSecOps): define engineering standards, reusable patterns, and automated guardrails
  • ensure solutions are compliant-by-design and supported with appropriate documentation and evidence.
  • Build and lead high-performing cybersecurity engineering teams through hiring, coaching, performance management, and career development
  • Manage cross-functional stakeholder relationships (Technology leaders, risk/compliance, audit, legal/privacy, and vendors) and translate technical risk and engineering tradeoffs into business impact and investment decisions.
  • Partner with architecture, engineering, and product teams to embed security into delivery (DevSecOps): define engineering standards, reusable patterns, and automated guardrails; enable teams with reference implementations and self-service capabilities.
  • Establish governance for engineering delivery: intake and prioritization, roadmaps, architecture/engineering reviews, change management, and exception processes; ensure solutions are compliant-by-design and supported with appropriate documentation and evidence.
  • Build and lead high-performing cybersecurity engineering teams through hiring, coaching, performance management, and career development; establish standards for engineering quality, critical review, and operational discipline.
  • McKesson has announced its intent to separate MMS into an independent company - an exciting evolution that builds on MMS's strong foundation and proven leadership in the Alternate Care space.

Requirements

  • Degree or equivalent experience.
  • Typically requires 15+ years of professional experience and 10+ years of diversified leadership, planning, communication, organization, and people motivation skills or equivalent experience).
  • 15+ years of progressive cybersecurity/technology experience with demonstrated depth in building and operating security controls and platforms.
  • 10+ years leading engineering teams and/or enterprise programs, including setting strategy, defining metrics, managing budgets/vendors, and driving execution across multiple stakeholders.
  • Executive-ready communication and stakeholder management skills, including the ability to present risk, progress, and investment needs to senior leadership and influence decisions.
  • Experience establishing oversight metrics and operational rhythms (OKRs/KPIs, service reviews, delivery governance) and using data to improve engineering throughput, automation, and control effectiveness.
  • Proven capability managing vendor relationships and service contracts for security platforms and managed services, including defining requirements, budgeting, and measuring performance against SLAs/SLOs.
  • Strong understanding of privacy and data handling considerations
  • Experience partnering with detection/response and vulnerability teams to ensure engineered controls are measurable, testable, and improve incident outcomes

Nice to have

  • CISSP, CISM, GIAC/SANS, +, SSCP, or equivalent foundational security certification.

Skills

  • Education Requirements
  • Certification Requirements
  • About Medical-Surgical
  • McKesson Medical-Surgical (MMS) is a subsidiary and publicly reported segment of the McKesson Corporation.
  • Alternate Care markets are growing rapidly and MMS is proud to be a leader in this space.
  • Looking Ahead: A New Chapter for MMS

Compensation

  • The pay range shown below is aligned with McKesson's pay philosophy, and pay will always be compliant with any applicable regulations.

Benefits

  • We will also continue to be one of the largest medical-surgical distributors in the U.S., with over $11B in annual sales.
  • We are proud to offer a competitive compensation package at McKesson as part of our Total Rewards.
  • This is determined by several factors, including performance, experience and skills, equity, regular job market evaluations, and geographical markets.
  • In addition to base pay, other compensation, such as an annual bonus or long-term incentive opportunities may be offered.

Company info

  • Ensure security engineering services are reliable and operationally mature: define SLAs/SLOs, partner with SOC/CSIRT during incidents for engineering response and hardening, and drive post-incident corrective actions into durable platform improvements.
  • This separation would accelerate our mission and empower us to shape a future defined by customer-centricity, bold thinking and operational excellence.

Visa & Work Authorization

  • response and vulnerability teams to ensure engineered controls are measurable, testable, and improve incident outcomes; sponsor exercises and continuous improvement initiatives

This listing is sourced directly from McKesson's careers page and normalized into a canonical job model.