Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Director, Application Security (Cybersecurity Defense)

$135.4k - $208.1k

Cardinal Health

What Cybersecurity Defense contributes to Cardinal Health

Cybersecurity Defense focuses heavily on threat detection, incident response, and implementing security measures to protect our digital assets and infrastructure at Cardinal Health. The Director, Application Security is responsible for establishing, leading, and evolving the enterprise application security strategy to embed security into the software development lifecycle (SDLC) and reduce application-layer risk across the business segments. This leader ensures that applications and APIs are designed, developed, and deployed in alignment with security policies & standards, regulatory requirements, and risk management objectives. This Director oversees segment-aligned application security capabilities across Pharma, Medical, and Commercial Technology environments, enabling consistent governance, scalable processes, and effective risk mitigation across diverse application portfolios.

Location - Open to candidates nationwide working in a fully remote capacity, with preference towards those based local to Central Ohio (willingness to travel into our Corporate HQ in Dublin, OH during certain period of the year is a plus)

Responsibilities

  • Lead the enterprise application security strategy aligned with cybersecurity, risk management, and business objectives.

  • Establish governance frameworks to embed security into the software development lifecycle (SDLC) across all application domains.

  • Collaborate with enterprise architecture, engineering, and product teams to align application security with technology strategies and transformation initiatives.

  • Serve as an advisor to executive and business leadership on application security risks, priorities, and investment decisions.

  • Drive a secure-by-design culture across development and engineering teams.

  • Oversee application security capabilities across Pharma, Medical, and Commercial Technology segments, ensuring consistent implementation of security practices.

  • Define segment-specific requirements and approaches to address unique regulatory, operational, and risk considerations.

  • Ensure alignment of application security practices across segments while enabling flexibility to support business-specific needs.

  • Drive standardization of processes, tooling, and reporting across segment application security teams.

  • Oversee enterprise application security testing programs, including SAST, DAST, SCA, and IAST across all application environments.

  • Ensure vulnerabilities are identified, assessed, prioritized, and remediated during the development lifecycle prior to deployment.

  • Establish secure coding standards and integrate security controls into CI/CD pipelines and development workflows.

  • Collaborate with development teams to reduce application security technical debt and improve code quality.

  • Oversee implementation of runtime security controls for applications and APIs, including WAF, API gateways, and runtime monitoring solutions.

  • Ensure security requirements are embedded into application and API design, deployment, and operational processes.

  • Collaborate with engineering and infrastructure teams to enforce runtime protections aligned with enterprise architecture.

  • Monitor runtime risks and coordinate mitigation efforts across application environments.

  • Lead development and integration of application security tooling, including configuration, onboarding, and operational management.

  • Define use cases, policies, and detection logic for application security tools to ensure effective coverage and scalability.

  • Drive integration of application security tools into CI/CD pipelines and DevSecOps workflows.

  • Ensure application security tooling aligns with enterprise security architecture and standards.

  • Collaborate with Security Architecture teams to define secure design patterns, reference architectures, and application security standards.

  • Ensure application security requirements are incorporated into solution design and architecture reviews.

  • Partner with engineering teams to implement secure development lifecycle (SDLC) practices and controls.

  • Support evaluation of new technologies and architectures to ensure alignment with security requirements.

  • Ensure application security practices align with regulatory requirements, compliance standards, and enterprise risk management frameworks.

  • Provide application security oversight for audits, regulatory assessments, and compliance reporting.

  • Collaborate with risk and compliance teams to translate application security risks into enterprise risk insights.

  • Support remediation of identified risks and ensure alignment with risk tolerance and governance processes.

  • Define and track KPIs and KRIs related to application security posture, vulnerability management, and SDLC integration.

  • Provide regular reporting to executive leadership on application security risks, trends, and program effectiveness.

  • Leverage data and analytics to drive continuous improvement in application security practices and outcomes.

  • Identify opportunities to enhance automation, efficiency, and scalability of application security processes.

  • Collaborate with application development, product, IT, security operations, and business teams to integrate application security into enterprise processes.

  • Partner with Cyber Detection & Response to ensure application security findings are integrated into monitoring and incident response workflows.

  • Engage with segment leaders to align application security initiatives with business priorities and risk considerations.

  • Support M&A activities by assessing and integrating application security controls for acquired applications.

  • Build and lead a high-performing application security organization with expertise across secure development, testing, and runtime protection.

  • Ensure alignment of team capabilities with evolving technologies, threats, and business needs.

Qualifications

  • Ideally targeting individuals with 10+ years of experience in cybersecurity, with a focus on application security, secure development, or DevSecOps.

  • Deep expertise in application security testing methodologies (SAST, DAST, SCA, IAST) and secure development practices, strongly preferred.

  • Strong understanding of application and API security, cloud-native architectures, and modern development frameworks.

  • Experience leading application security programs across large, complex organization, preferred.

  • Strong understanding of cybersecurity frameworks (e.g., NIST CSF, OWASP, ISO 27001) and regulatory requirements.

  • Demonstrated ability to collaborate with cross-functional teams and influence executive stakeholders.

  • Strong leadership, communication, and problem-solving skills.

#LI-LP

#LI-Remote

Anticipated salary range: $135,400 - $208,100

Bonus eligible: Yes

Benefits: Cardinal Health offers a wide variety of benefits and programs to support health and well-being.

  • Medical, dental and vision coverage

  • Paid time off plan

  • Health savings account (HSA)

  • 401k savings plan

  • Access to wages before pay day with myFlexPay

  • Flexible spending accounts (FSAs)

  • Short- and long-term disability coverage

  • Work-Life resources

  • Paid parental leave

  • Healthy lifestyle programs

Application window anticipated to close: 07/01/2026 *if interested in opportunity, please submit application as soon as possible.

The salary range listed is an estimate. Pay at Cardinal Health is determined by multiple factors including, but not limited to, a candidate's geographical location, relevant education, experience and skills and an evaluation of internal pay equity.

Candidates who are back-to-work, people with disabilities, without a college degree, and Veterans are encouraged to apply.

Cardinal Health supports an inclusive workplace that values diversity of thought, experience and background. We celebrate the power of our differences to create better solutions for our customers by ensuring employees can be their authentic selves each day. Cardinal Health is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, ancestry, age, physical or mental disability, sex, sexual orientation, gender identity/expression, pregnancy, veteran status, marital status, creed, status with regard to public assistance, genetic status or any other status protected by federal, state or local law.

To read and review this privacy notice click here (

Vacancy posted 5 days ago
Similar jobs that could be interesting for youBased on the Director, Application Security (Cybersecurity Defense) in Denver, CO vacancy
  • $88.6k - $147.6k

     ...opportunities businesses face in cybersecurity. Join our team to deliver...  ..., and proactively manage to secure success. Recruiting for...  ...Work you'll do Require a Defensive Cyber Operations (DCO) SME with...  ...and performance metrics where applicable. Consults on IT and cyber... 
    Application
    Local area

    PowerToFly

    Denver, CO
    5 days ago
  • $130k - $175k

     ...and business data, demand for national security-focused risk analysis and mitigation is...  ...reviews, export and technology controls, and Cybersecurity Maturity Model Certification (CMMC)....  ...comprehensive security assessments of applications and software, including: (i) reviewing... 
    Application
    Full time
    Part time
    Flexible hours

    Alvarez & Marsal

    Greenwood Village, CO
    5 days ago
  • $113.9k - $200.91k

     ...connecting our technologies, our security and our humanity. While others...  ...in delivering custom cloud web applications tailored to meet our aerospace & defense industry customers' needs. The...  ...actions - Experience with software cybersecurity best practices and government... 
    Application
    Full time
    Contract work
    Temporary work
    Work experience placement
    Work at office
    Remote work
    Relocation
    Flexible hours
    Shift work

    Lockheed Martin Corporation

    Littleton, CO
    4 days ago
  • $95k - $116k

     ...is seeking a motivated Linux Applications Administrator to join our...  ...hosted applications within the Defense Travel Management Office (...  ...logging software that captures security events and feeds into DMDC-...  ...IT Design & Installation, Cybersecurity Engineering & Support, Application... 
    Application
    Work at office
    Monday to Friday
    Flexible hours

    KaiHonua

    Denver, CO
    5 days ago
  •  ...functions, including managing all applications within the collaboration...  ...operational. Develop the security architecture and manage access...  ...of DoD web policies, cybersecurity policies and regulations along...  ...100+ sites in the areas of Defense, Citizen Services, and Transportation... 
    Application
    Full time
    Contract work
    Part time
    Local area
    Flexible hours

    Serco

    Denver, CO
    1 day ago
  • $124k - $280k

     ...Specialty/Competency: Cybersecurity & Privacy Industry/Sector: Not Applicable Time Type: Full time Travel Requirements: Up to 40% At PwC, our people...  .... They work to identify vulnerabilities, develop secure systems, and provide proactive solutions to... 
    Application
    Full time
    H1b

    PwC

    Denver, CO
    5 days ago
  •  ...needs of federal civilian, defense, and intelligence community...  ...transformation projects and design secure, scalable cloud...  ...incident response, ensuring robust cybersecurity measures. Mentor and work...  ...integrate cloud services into the application lifecycle, enhancing... 
    Application
    Full time
    Interim role
    Flexible hours

    Seneca Holdings LLC

    Denver, CO
    5 days ago
  • $155k - $410k

     ...Specialty/Competency: Cybersecurity & Privacy Industry/Sector: Not Applicable Time Type: Full time Travel Requirements: Up to 40% At PwC, our people...  .... They work to identify vulnerabilities, develop secure systems, and provide proactive solutions to... 
    Application
    Full time
    Temporary work
    H1b

    PwC

    Denver, CO
    6 days ago
  • $190k - $260k

     ...the latest technology: we help defense users respond in kind....  ...expertise deploying DevSecOps, cybersecurity, and cloud infrastructure, giving...  ...responsibility for cloud infrastructure, application hosting, user access and authorization and security tooling among other features.... 
    Application
    Temporary work
    For contractors
    Local area
    Remote work
    2 days per week

    SimpleSense

    Denver, CO
    6 days ago
  • $125k

     ...mission‑critical programs across national security, defense, and public service delivery. Recent contract awards in cybersecurity and operational readiness underscore Maximus...  ...~5 years of experience testing web-based applications. ~5 years of experience leading software... 
    Application
    Contract work
    Remote work

    MAXIMUS

    Denver, CO
    7 days ago
  • $135k - $163k

     ...motivated individual to serve as a Cybersecurity Subject Matter Expert (SME) supporting the Defense Travel Management Office (DTMO...  ...RMF activities, supporting security assessments, and coordinating...  ...clearance is/may be required. Applicants selected will be subject to a... 
    Application
    Work at office
    Flexible hours

    KaiHonua

    Denver, CO
    5 days ago
  • $99k - $232k

     ...Specialty/Competency: Cybersecurity & Privacy Industry/Sector: Not Applicable Time Type: Full time Travel Requirements: Up to 40% At PwC, our people...  .... They work to identify vulnerabilities, develop secure systems, and provide proactive solutions to... 
    Application
    Full time
    H1b

    PwC

    Denver, CO
    22 days ago
  • $40k

     ...mission‑critical programs across national security, defense, and public service delivery. Our...  ...Engineer supports 24x7 enterprise cybersecurity operations by monitoring security tools...  ...activities, including access changes, application removal, configuration updates, and... 
    Application
    Contract work
    Remote work

    MAXIMUS

    Denver, CO
    4 days ago
  • $103.5k - $181.1k

     ...looking for an amazingly talented Cybersecurity Engineer to join our team! In...  ...and technologies. Perform security testing on cloud infrastructure, applications, and containerized...  ...or business architectures, and defensible architecture concepts (e.g., Elastic... 
    Application
    Local area
    Worldwide
    Flexible hours

    Parsons Company

    Aurora, CO
    4 days ago
  • $135k - $175k

     ...75,000 Company Overview: Cornerstone Defense is the Employer of Choice within the Intelligence...  ...combat our nation's toughest and most secure problems. If you are looking for a place...  ..., WIGS/Angular. Experience with cybersecurity, DevSecOps, and CI/CD processes.... 

    Cornerstone Defense

    Aurora, CO
    5 days ago
  •  ...Technology Solutions LLC, we deliver secure, innovative solutions in support of national defense and intelligence missions. As...  .... Drinking Water Database & Application Specialist Join Our Pipeline...  ...Ensure compliance with cybersecurity and privacy requirements Collaborate... 
    Application
    For contractors

    Lucayan Technology Solutions LLC

    Denver, CO
    2 days ago
  • $95k - $116k

     ...join our team as a Windows Applications Administrator. This role offers...  ...‑critical systems for the Defense Travel Management Office (DTMO...  ...stability, performance, and security throughout the software life...  ...IT Design & Installation, Cybersecurity Engineering & Support, Application... 
    Application
    Work at office
    Monday to Friday
    Flexible hours

    KaiHonua

    Denver, CO
    2 days ago
  •  ...Systems—Launch and Missile Defense Systems has an exciting career...  ...to IT resources, cybersecurity, and data management activities...  ...Please include your current security clearance and IAT or relevant...  ...certifications on your resume, if applicable. Bachelor’s Degree in a STEM... 
    Application
    Remote work
    Worldwide
    Relocation

    JSfirm.com

    Denver, CO
    1 day ago
  • $115k - $130k

     ...Folsom, CA Voyager is an innovative defense, national security and space technology company...  ...continuous improvement Partner with the cybersecurity team to ensure IT operations practices...  ...candidate’s ability to comply with all applicable export control requirements,... 
    Long term contract
    Remote work
    Flexible hours
    Night shift

    Voyager Technologies, Inc.

    Denver, CO
    19 hours ago
  •  ...Senior Manager, Security Architecture & Engineering Build the Future with AspenView Technology...  ..., Security Platform Engineering, Application Security & Secure SDLC / DevSecOps,...  ...What you bring: Experience: 12+ years in cybersecurity with 5+ years leading security architecture... 
    Application
    Work at office
    Remote work
    Flexible hours

    AspenView Technology Partners, Inc.

    Denver, CO
    2 days ago
  • $125k

     ...Manager of Security Engineering & Operations Opportunity: Manager...  ...FocusConnect is a Denver‑based MSP and cybersecurity partner helping growing...  ...development, manufacturing, defense industrial base, education,...  ...most enjoy working through. Application window FocusConnect expects... 
    Application
    Contract work

    Frey Consulting Group

    Denver, CO
    2 days ago
  •  ...STARS III and deep capabilities in IT, Cybersecurity, Healthcare, Geospatial, and Environmental...  ...and modernization of HRD’s enterprise applications. This role provides technical...  ...and journeyman developers.  ~ Ensure secure, scalable, and efficient code across platforms... 
    Application
    Contract work
    For contractors

    Essnova Solutions

    Littleton, CO
    5 days ago
  • $85k - $95k

     ...will be responsible for the stability, security, and lifecycle management of core infrastructure...  ...platforms supporting business‑critical applications. This critical position plays a key...  ...reliability, system modernization, and cybersecurity resilience across data center and cloud... 
    Application
    Full time
    Work at office
    Remote work

    Davis Partnership Architects

    Denver, CO
    2 days ago
  • $75k - $95k

     ...software deployments, enterprise applications, or technical integrations...  ...integrations, cloud technologies, cybersecurity, project engineering, or...  ...care. We also support and help defense, authorities, and critical social functions to secure their communication against eavesdropping... 
    Application
    Internship

    Sectra

    Denver, CO
    3 days ago
  •  ...latest technology: we help defense users respond in kind. Simplesense...  ...deploying DevSecOps, cybersecurity, and cloud infrastructure,...  ...Connectivity projects that enable secure, resilient access between...  ...complies with all applicable equal employment opportunity... 
    Application
    Temporary work
    For contractors
    Local area
    Remote work
    2 days per week

    SimpleSense

    Denver, CO
    7 days ago
  •  ...Linux/UNIX environments, ensuring the stability, security, and performance of PeopleSoft and Oracle applications. You will be responsible for troubleshooting...  ..., Database Administration, Network Engineering, Cybersecurity, Data Science, Applied Mathematics, etc. ALTERNATE... 
    Application
    Temporary work
    For contractors
    Immediate start
    Flexible hours

    Cymertek

    Aurora, CO
    3 days ago
  • $130k - $140k

     ...Description Role: Manager, Security Operations...  ..., NC) Department: Cybersecurity - Security Operations...  ...Reports to: Senior Director, Security Operations...  ...regional equivalents where applicable). Security...  ...accurate, validated, and defensible . Support internal... 
    Application
    Full time

    Pearson

    Denver, CO
    4 days ago
  • $153.5k - $198.55k

     ...supporting the mission of Cyber Security andis a technical expert...  ...onboarding via Cribl Stream, and application support for Splunk Enterprise...  ...meeting with Cyber Risk Defense Center (CRDC) teams. Supports...  ...with senior leadership (e.g., Director level and above) Knowledge... 
    Application
    Full time
    Work experience placement
    Remote work
    Shift work

    Kaiser Permanente

    Greenwood Village, CO
    6 days ago
  • $130k - $165k

    Voyager is an innovative defense, national security and space technology company committed to advancing...  ...IT Compliance / GRC Analyst to lead cybersecurity governance, regulatory compliance,...  ...Please click “Apply” to submit your application. The salary range represents the... 
    Application
    Permanent employment
    Contract work
    For contractors
    For subcontractor

    Voyager Technologies

    Denver, CO
    5 days ago
  •  ...to operate more effectively, securely, and efficiently. We support...  ...federal missions across defense, civilian, and intelligence...  ...scientists, data engineers, cybersecurity staff, and customer stakeholders...  ...Serco team- then submit your application now for immediate... 
    Application
    Full time
    Contract work
    Part time
    Local area
    Immediate start
    Flexible hours

    Serco

    Denver, CO
    7 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Director, Application Security (Cybersecurity Defense). Be the first to apply!