Cardinal Health logo

Senior Information Security and Risk Engineer

Cardinal Health

Remote
Full-time
Senior
Manager
6+ yrs
$125k–$179kPosted 4h ago

Real job — pulled straight from Cardinal Health’s careers page · Verified September 22, 2026 · No reposts.

Job description

Cardinal Health is hiring a Senior Information Security and Risk Engineer — a full-time, remote role ($125k–$179k). Apply directly on Cardinal Health's careers page below.

Senior Engineer - Information Security & Risk

Location: US-Nationwide-FIELD

Time Type: Full time

Job Description

What Information Security and Risk contributes to Cardinal Health

Information Technology oversees the effective development, delivery, and operation of computing and information services. This function anticipates, plans, and delivers Information Technology solutions and strategies that enable operations and drive business value.

Information Security and Risk develops, implements, and enforces security controls to protect the organization's technology assets from intentional or inadvertent modification, disclosure or destruction. This job family develops system back-up and disaster recovery plans. Information Technology also conducts incident response, threat management, vulnerability scanning, virus management and intrusion detection and completes risk assessments.

Job Overview:

The Senior Engineer, Information Security & Risk is a second line of defense role responsible for defining, implementing, and evaluating the effectiveness of IT SOX controls. Reporting to the Manager, Information Security & Risk , this role drives the detail design and implementation of IT SOX controls based on relevant risks. Furthermore, the position will work closely with Manager, Information Security & Risk to support business and IT leaders for ongoing risk management process and continuous control/process improvement.

Responsibilities:

  • Control design and remediation consulting –
  • Perform IT risk assessment for pilot areas, identify control gap, and provide guidance for gap remediation
  • Work with IT stakeholders to design effective IT controls to help the IT org achieve SOX compliance goals
  • Process improvement of IT controls that increases operational efficiency and reduces the likelihood of control failure
  • Evaluate/monitor the execution of IT controls to ensure they are operating effectively
  • Support due diligence phase of company's M&A activities
  • Provide support for third party certifications (such as SOC1/2) review and issuance
  • Align with internal and external audit to understand SOX scope and audit strategy
  • Track and drive remediation of IT control issues within our IT risk governance process
  • Manage assigned junior staff(s) and contractors to ensure the quality of the work
  • Support budgeting of compliance workstream and responsible for proactively communicate budget overruns to key stakeholders
  • Support the manager in compliance posture reporting

Qualifications:

  • Bachelor’s degree in related field or equivalent work experience
  • Deep knowledge of IT SOX control and audit methodology - 6 + years of experience in related field preferred, such as IT audit and/or IT compliance function preferred
  • Strong understanding and experience with SOX is a must and knowledge on other compliance requirements/frameworks, such as HIPAA, GDPR, PCI, is a plus
  • Strong in educating/influencing of IT stakeholders to raise their awareness/mindset of IT control compliance
  • Strong root cause analysis and problem-solving skill is a must
  • Pro-level of risk-based judgement in addressing control issues and juggling competing priorities
  • Self-motivated to learn new technologies and achieve objectives
  • Ability to multi-task with organization, efficiency, accountability, and attention to detail
  •  Strong knowledge in IT technologies and concepts including networks, databases, middleware, interfaces, and applications. Knowledge/experience of IT controls for mainstream ERP, such as SAP, is a plus
  • Strong flowcharting skill is preferred
  • Experience with IT risk governance software (i.e., Archer, AuditBoard, GRC) is a plus
  • Professional certification preferred: CISA, CPA, CISM, CISSP, CRISC

Anticipated salary range: $125,300 - $178,900

Bonus eligible: yes

Benefits: Cardinal Health offers a wide variety of benefits and programs to support health and well-being.

  • Medical, dental and vision coverage

  • Paid time off plan

  • Health savings account (HSA)

  • 401k savings plan

  • Access to wages before pay day with myFlexPay

  • Flexible spending accounts (FSAs)

  • Short- and long-term disability coverage

  • Work-Life resources

  • Paid parental leave

  • Healthy lifestyle programs

Application window anticipated to close: 10/15/2026 *if interested in opportunity, please submit application as soon as possible.

The salary range listed is an estimate. Pay at Cardinal Health is determined by multiple factors including, but not limited to, a candidate’s geographical location, relevant education, experience and skills and an evaluation of internal pay equity.

Candidates who are back-to-work, people with disabilities, without a college degree, and Veterans are encouraged to apply.

Cardinal Health supports an inclusive workplace that values diversity of thought, experience and background. We celebrate the power of our differences to create better solutions for our customers by ensuring employees can be their authentic selves each day. Cardinal Health is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, ancestry, age, physical or mental disability, sex, sexual orientation, gender identity/expression, pregnancy, veteran status, marital status, creed, status with regard to public assistance, genetic status or any other status protected by federal, state or local law.

To read and review this privacy notice click here

Get Senior Information Security and Risk Engineer jobs like this

New roles from thousands of companies land hourly, straight from their careers pages. Get the freshest matches by email so you never miss one.

Email me new jobs
Flagship Pioneering logo

Director, Health Data Science

$192k–$253kCambridge, MA
✓ From careers page· 3h ago
KeyBank logo

Data Security Administrator

$80k–$150kRemote · US-eligible
✓ From careers page· 4h ago
xCures logo

AI Quality Engineer

$100k–$130kRemote · US-eligible
✓ From careers page· 4h ago
Cardinal Health logo

Senior Software Engineer

$125k–$179kRemote · US-eligible
✓ From careers page· 4h ago

Frequently asked questions

What is the salary for Senior Information Security and Risk Engineer at Cardinal Health?

The estimated salary range for Senior Information Security and Risk Engineer at Cardinal Health is $125,000 - $179,000 USD per year.

Is Senior Information Security and Risk Engineer at Cardinal Health a remote job?

Yes, Senior Information Security and Risk Engineer at Cardinal Health is a remote position. This role is open to remote candidates.

What skills are required for Senior Information Security and Risk Engineer at Cardinal Health?

The required skills for Senior Information Security and Risk Engineer at Cardinal Health include: HIPAA, GDPR, PCI DSS, SAP, CISA, CPA, CISM, CISSP.

What is the seniority level for Senior Information Security and Risk Engineer at Cardinal Health?

Senior Information Security and Risk Engineer at Cardinal Health is a Senior / Manager level position.

How do I apply for Senior Information Security and Risk Engineer at Cardinal Health?

You can view the full description and apply for Senior Information Security and Risk Engineer at Cardinal Health on EchoJobs: https://echojobs.io/job/cardinal-health-senior-engineer-information-security-risk-62nu0.