McKesson

Sr. Specialist, Product Security Engineering

Remote Columbus, OH
USD 134k - 224k
JavaScript Terraform Ansible Python Bash
Description

McKesson is an impact-driven, Fortune 10 company that touches virtually every aspect of healthcare. We are known for delivering insights, products, and services that make quality care more accessible and affordable. Here, we focus on the health, happiness, and well-being of you and those we serve – we care.

What you do at McKesson matters. We foster a culture where you can grow, make an impact, and are empowered to bring new ideas. Together, we thrive as we shape the future of health for patients, our communities, and our people. If you want to be part of tomorrow’s health today, we want to hear from you.

Rx Savings Solutions (RxSS), part of McKesson’s CoverMyMeds business segment, is at the forefront of digital healthcare advancement. We are committed to redefining how consumers interact with health care products by providing accessible and affordable solutions. Founded and operated by a team of pharmacists and software engineers, our software-as-a-service (SaaS) products provide collaborative, cost-saving solutions for purchasing prescription drugs. 

We are currently seeking a Sr Specialist, Product Security Engineer to support sales efforts by providing technical expertise and solutions related to cybersecurity, and spearhead the automation of security policies and compliance audits to ensure robust protection and adherence to industry standards. This role involves designing and implementing security policies as code, developing automated solutions for client, SOC2, and SOX audits, and collaborating with cross-functional teams to integrate security practices into the development lifecycle. The ideal candidate will possess extensive experience in product security engineering that includes customer stakeholder engagement, strong knowledge of security frameworks, and proficiency in automation tools and scripting languages. This position requires excellent client-facing skills, problem-solving skills, technical leadership, and the ability to stay current with evolving security trends and regulations.

*Our preferred candidate will reside in Columbus, OH or Overland Park, KS areas. Position will primarily allow for remote working with occasional in-office support for presence for key meetings.

*We are unable to provide sponsorship now or in the future for this position.  

Key Responsibilities:

As a Sr Specialist, Product Security Engineer, your daily to-dos will shift with business needs, but here’s a snapshot of what to expect:

Security Development

  • Lead the design, implementation, and maintenance of security policies as code to ensure consistent and automated enforcement across all products.

  • Create policy as code as given by McKesson Cyber Security, to allow for consistent and automated enforcement of security measures across all products. By using code to define security policies, the engineer can ensure that these policies are applied uniformly and can be easily updated and maintained. This also facilitates automated checks and enforcement, reducing the risk of human error and ensuring that security standards are consistently met.

Audit

  • Develop and manage automated solutions for security questionnaires, SOC2, and SOX audits, ensuring compliance with industry standards and regulations.

  • Will create and oversee automated systems that handle security questionnaires and audits related to SOC2 and SOX, with the goal being to ensure our company's products and processes comply with industry standards and regulations. By automating these solutions, the engineer can streamline the process, reduce manual effort, and minimize the risk of errors. This also helps in maintaining up-to-date compliance with evolving standards and regulations, ensuring that the company remains in good standing with regulatory bodies.

Governance

  • Consult with cross-functional teams, Directors and above, to integrate security practices into the software development lifecycle.

  • Work closely with various teams, such as development, operations, and quality assurance, to ensure that security measures are embedded throughout the software development process.

  • Ensure security is a fundamental part of the develop lifecycle, from initial design to deployment and maintenance.

  • Ensure security is considered at every state of development by collaborating with teams to identify potential security risks early on, implement best practices, and ensure security is considered at every stage of development. This approach helps in building secure products and reduces the likelihood of vulnerabilities being introduced during development.

Security Architecture

  • Be the go-to person for any questions or issues related to security for Rx Savings Solutions, providing advice and solutions to address inquiries and incidents.

  • Possess deep understanding of security principles and practices, as well as the ability to communicate effectively with different stakeholders.

  • Act as a point of contact to ensure security concerns are promptly addressed and that the organization can respond quickly and effectively to any security incidents.

Mentoring

  • Provides training and development opportunities to help junior engineers build their skills and knowledge in security practices.

  • Offers constructive feedback, support, and guidance on security-related tasks and projects.

  • Fosters a culture where junior engineers are encouraged to stay updated on the latest security trends, continuously improve their practices, and actively contribute to the overall security posture of the organization.

Required Education and Experience:

  • Bachelor’s degree in Computer Science, Information Security or related field and experience, and 7+ years of relative experience in product security engineering with a focus on automation and compliance.

  • Strong knowledge of security frameworks and standards, including SOC2, SOX, and other relevant regulations.

  • Proficiency in scripting and programming languages (e.g., Python, Bash, JavaScript) for automation purposes.

  • Experience with infrastructure as code (IaC) tools such as Terraform, Ansible, or similar.

  • Familiarity with CI/CD pipelines and DevSecOps practices.

  • Excellent problem-solving skills and attention to detail.

  • Strong communication and interpersonal skills.

We are proud to offer a competitive compensation package at McKesson as part of our Total Rewards. This is determined by several factors, including performance, experience and skills, equity, regular job market evaluations, and geographical markets. The pay range shown below is aligned with McKesson's pay philosophy, and pay will always be compliant with any applicable regulations. In addition to base pay, other compensation, such as an annual bonus or long-term incentive opportunities may be offered. For more information regarding benefits at McKesson, please click here.

Our Base Pay Range for this position

$134,600 - $224,400

McKesson is an Equal Opportunity Employer

 

McKesson provides equal employment opportunities to applicants and employees and is committed to a diverse and inclusive environment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, disability, age or genetic information. For additional information on McKesson’s full Equal Employment Opportunity policies, visit our Equal Employment Opportunity page.

 

Join us at McKesson!

McKesson
McKesson
Biotechnology Health Care Information Technology

0 applies

9 views

There are more than 50,000 engineering jobs:

Subscribe to membership and unlock all jobs

Engineering Jobs

60,000+ jobs from 4,500+ well-funded companies

Updated Daily

New jobs are added every day as companies post them

Refined Search

Use filters like skill, location, etc to narrow results

Become a member

🥳🥳🥳 452 happy customers and counting...

Overall, over 80% of customers chose to renew their subscriptions after the initial sign-up.

To try it out

For active job seekers

For those who are passive looking

Cancel anytime

Frequently Asked Questions

  • We prioritize job seekers as our customers, unlike bigger job sites, by charging a small fee to provide them with curated access to the best companies and up-to-date jobs. This focus allows us to deliver a more personalized and effective job search experience.
  • We've got about 70,000 jobs from 5,000 vetted companies. No fake or sleazy jobs here!
  • We aggregate jobs from 5,000+ companies' career pages, so you can be sure that you're getting the most up-to-date and relevant jobs.
  • We're the only job board *for* software engineers, *by* software engineers… in case you needed a reminder! We add thousands of new jobs daily and offer powerful search filters just for you. 🛠️
  • Every single hour! We add 2,000-3,000 new jobs daily, so you'll always have fresh opportunities. 🚀
  • Typically, job searches take 3-6 months. EchoJobs helps you spend more time applying and less time hunting. 🎯
  • Check daily! We're always updating with new jobs. Set up job alerts for even quicker access. 📅

What Fellow Engineers Say

Sid avatar
Sid
Very nice portal for searching jobs in this rough market.
Mar 6, 2025
Michael Duran avatar
Michael Duran
Software Engineer
I've been using this job search site for a while now, and it’s honestly one of the best out there! The clean and easy-to-navigate UI makes the whole job-hunting process so much smoother. Plus, the job postings are always up-to-date, so I never feel like I’m wasting time. The cherry on top is the owner—super kind and always quick to respond. Definitely recommend checking it out if you're on the job hunt!
Aug 21, 2024
Sai avatar
Sai
It’s really great website for finding jobs based on skills it’s really helpful give a go
Aug 21, 2024
Adinadh avatar
Adinadh
What I like most about Echo Jobs is how easy it is to use. The platform helps me quickly find jobs that match my skills and interests, thanks to its great recommendations and filters. Yes, I would definitely recommend Echo Jobs to a friend. It makes job searching simple and efficient, making it a great tool for anyone looking for a new job.
Jul 23, 2024
As a student navigating the job market, I've found LinkedIn increasingly frustrating due to numerous fake postings by consultancies. In contrast, this job posting website has been a game-changer for me. It offers genuine opportunities and a straightforward application process, making it much easier to find and apply for real jobs. Highly recommend it to fellow students seeking reliable job listings!
Jul 16, 2024
Cliff Gor avatar
Echo Jobs has been exceptional in my job hunt where it provides one platform to job hunt and I don't have to open 10 websites just to look for a job. It has also helped me focus much on the job skill and the location filtering out the onsite jobs and remote ones. The only feature that I would request is to display fully remote jobs that are not restricted to a country since the one available shows ie, Remote, US yet. But if it could show remote only, that would be helpful not only to me but to other people applying for full remote and not tied to only US candidates
Apr 22, 2024
I found EchoJobs in 2022, and I love it. It has a lot of remote jobs. It's exclusive to software and technology jobs (helpful for devs like me). What I like the most are its filters and its API. If you're a tech professional seeking remote work, I highly recommend giving it a try to EchoJobs.
Mar 4, 2024
Would definitely recommend it! Excellent product, dedicated founder, Jobs are easier to find. Congrats 🎉 to the entire team!
Mar 3, 2024
Brandon Banks avatar
Brandon Banks
Echo Jobs is really impressive. It provides a great user experience with an ability to quickly search through the many job postings. There is an impressive amount of jobs here and it is quickly updated. The details in the each job posting is helpful when determining if it is worth pursuing. I would highly recommend using Echo Jobs to find the next step in your career.
Mar 2, 2024
Tyler Young avatar
Tyler Young
tylerayoung.com
Best wishes with EchoJobs—it's become my favorite job board overnight!
Dec 16, 2023
Simply put, it's the most up to date tech jobs aggregator I’ve found. I'm like... "I don't have to check 10+ jobs boards daily just to see if there's a new job listing? sign me up!" The filters are also quite helpful! The UI is very clean and straightforward. Love it!
Oct 5, 2023