McKesson
Sr. Director, Cyber Engineering
USA, VA, Richmond · Director
Sponsorship not specifiedDetected 22 days ago
GCPCloud PlatformsCI/CDDevOpsPlatform EngineeringCybersecurityNetwork SecuritySIEMSOARComplianceStakeholder ManagementOKRsBudgetingPerformance ManagementFirewallHIPAALeadershipCommunicationMentoring
About the role
- This role requires strong technical depth in security engineering and the leadership maturity to operate at the executive level.
- The Director establishes cybersecurity engineering strategy, multi-year roadmaps, and success metrics; governs an operating rhythm for delivery and reliability; and ensures outcomes are achieved across multiple teams (often through influence).
Responsibilities
- Define and own the cybersecurity engineering strategy and operating model (platform engineering, control implementation, automation, reliability) aligned to business risk, technology priorities, and security architecture.
- Own the security engineering platform portfolio: select, integrate, and manage lifecycle for security tooling and services (e.g., IAM/PAM, PKI, EDR, CSPM, vulnerability management, secrets management, WAF, DLP, SIEM/SOAR integrations) with clear service models and reliability targets.
- Partner with architecture, engineering, and product teams to embed security into delivery (DevSecOps): define engineering standards, reusable patterns, and automated guardrails
- ensure solutions are compliant-by-design and supported with appropriate documentation and evidence.
- Build and lead high-performing cybersecurity engineering teams through hiring, coaching, performance management, and career development
- Manage cross-functional stakeholder relationships (Technology leaders, risk/compliance, audit, legal/privacy, and vendors) and translate technical risk and engineering tradeoffs into business impact and investment decisions.
- Partner with architecture, engineering, and product teams to embed security into delivery (DevSecOps): define engineering standards, reusable patterns, and automated guardrails; enable teams with reference implementations and self-service capabilities.
- Establish governance for engineering delivery: intake and prioritization, roadmaps, architecture/engineering reviews, change management, and exception processes; ensure solutions are compliant-by-design and supported with appropriate documentation and evidence.
- Build and lead high-performing cybersecurity engineering teams through hiring, coaching, performance management, and career development; establish standards for engineering quality, critical review, and operational discipline.
- McKesson has announced its intent to separate MMS into an independent company - an exciting evolution that builds on MMS's strong foundation and proven leadership in the Alternate Care space.
Requirements
- Degree or equivalent experience.
- Typically requires 15+ years of professional experience and 10+ years of diversified leadership, planning, communication, organization, and people motivation skills or equivalent experience).
- 15+ years of progressive cybersecurity/technology experience with demonstrated depth in building and operating security controls and platforms.
- 10+ years leading engineering teams and/or enterprise programs, including setting strategy, defining metrics, managing budgets/vendors, and driving execution across multiple stakeholders.
- Executive-ready communication and stakeholder management skills, including the ability to present risk, progress, and investment needs to senior leadership and influence decisions.
- Experience establishing oversight metrics and operational rhythms (OKRs/KPIs, service reviews, delivery governance) and using data to improve engineering throughput, automation, and control effectiveness.
- Proven capability managing vendor relationships and service contracts for security platforms and managed services, including defining requirements, budgeting, and measuring performance against SLAs/SLOs.
- Strong understanding of privacy and data handling considerations
- Experience partnering with detection/response and vulnerability teams to ensure engineered controls are measurable, testable, and improve incident outcomes
Nice to have
- CISSP, CISM, GIAC/SANS, +, SSCP, or equivalent foundational security certification.
Skills
- Education Requirements
- Certification Requirements
- About Medical-Surgical
- McKesson Medical-Surgical (MMS) is a subsidiary and publicly reported segment of the McKesson Corporation.
- Alternate Care markets are growing rapidly and MMS is proud to be a leader in this space.
- Looking Ahead: A New Chapter for MMS
Compensation
- The pay range shown below is aligned with McKesson's pay philosophy, and pay will always be compliant with any applicable regulations.
Benefits
- We will also continue to be one of the largest medical-surgical distributors in the U.S., with over $11B in annual sales.
- We are proud to offer a competitive compensation package at McKesson as part of our Total Rewards.
- This is determined by several factors, including performance, experience and skills, equity, regular job market evaluations, and geographical markets.
- In addition to base pay, other compensation, such as an annual bonus or long-term incentive opportunities may be offered.
Company info
- Ensure security engineering services are reliable and operationally mature: define SLAs/SLOs, partner with SOC/CSIRT during incidents for engineering response and hardening, and drive post-incident corrective actions into durable platform improvements.
- This separation would accelerate our mission and empower us to shape a future defined by customer-centricity, bold thinking and operational excellence.
Visa & Work Authorization
- response and vulnerability teams to ensure engineered controls are measurable, testable, and improve incident outcomes; sponsor exercises and continuous improvement initiatives
Apply directly at McKesson →Create a free account for alerts like thisView McKesson immigration profile
This listing is sourced directly from McKesson's careers page and normalized into a canonical job model.