Senior Director, Secure MA&D
Cencora
Our team members are at the heart of everything we do. At Cencora, we are united in our responsibility to create healthier futures, and every person here is essential to us being able to deliver on that purpose. If you want to make a difference at the center of health, come join our innovative company and help us improve the lives of people and animals everywhere.
Job Summary
The Senior Director, Secure MA&D owns the enterprise strategy, governance, and delivery of cybersecurity across the full transaction lifecycle - pre-close due diligence, Day 1 readiness, post-close integration, and divestiture separation. This role is the single accountable security leader to Corporate Development, Finance, and Legal for cyber risk that affects valuation, deal structure, closing conditions, and integration cost. The Senior Director leads a global team of principals and analysts and a bench of third-party diligence partners; sets the risk thresholds and decision rights that determine when a cyber finding is deal-impacting; advises executive leadership and the Board on aggregate transaction risk; and drives the organizational change required to bring acquired entities onto enterprise security standards.
Key Responsibilities
Strategic Leadership and Program Ownership
- Own and evolve the enterprise Secure MA&D strategy, operating model, and capability roadmap covering acquisitions, divestitures, carve-outs, joint ventures, and minority investments.
- Establish the governance framework, decision rights, risk thresholds, and escalation criteria that determine when a cyber finding is deal-impacting versus a post-close remediation item.
- Set the standard for diligence playbooks, cost models, integration blueprints, Day 1 control baselines, and executive reporting used across the transaction portfolio.
- Own the function's annual plan, budget, tooling, and third-party bench, sized to support an unpredictable and confidential deal pipeline.
- Define and report the metrics that demonstrate program effectiveness, including diligence cycle time, cost-estimate accuracy, Day 1 control coverage, and time to remediate inherited risk.
- Position Secure MA&D as an enabler of inorganic growth by balancing speed of deal execution against defensible risk coverage.
People and Vendor Leadership
- Lead, coach, and develop a global team of Secure MA&D principals and analysts; set performance standards, career paths, and succession plans.
- Allocate scarce specialist capacity across concurrent transactions and adjust staffing as deals accelerate, pause, or collapse.
- Direct third-party diligence and integration partners end to end, including selection, scoping, commercial terms, quality assurance, and performance management.
- Build a team culture of disciplined judgment, documentation, and absolute confidentiality consistent with material non-public information obligations.
- Serve as player-coach on the largest, most sensitive, or most contested transactions.
MA&D Lifecycle Execution
- Direct pre-close cybersecurity due diligence under compressed timelines, restricted target access, staged data-room release, and clean-team constraints, drawing defensible conclusions from incomplete evidence.
- Calibrate diligence depth and approach to deal type, size, and thesis, recognizing the differences between a negotiated acquisition, a competitive auction, an asset versus stock purchase, and a carve-out from a larger parent.
- Quantify and defend remediation, integration, tooling, licensing, labor, and run-rate cost estimates within the deal model, including capital versus operating treatment and dis-synergy impacts.
- Ensure cyber findings are reflected in deal documents and protections, including representations and warranties, purchase price adjustments, escrow and indemnity, disclosure schedules, and closing conditions.
- Define security requirements and exit criteria for Transition Service Agreements and reverse TSAs; direct separation planning for divestitures, including data segregation, entitlement removal, and protection of retained intellectual property.
- Direct Day 1 readiness, including minimum viable controls, identity and network interconnection decisions, endpoint and email protections, logging and monitoring onboarding, and incident response coverage for the acquired entity.
- Own the handoff from diligence to delivery, transferring risks, named owners, and funded remediation plans to security capability owners with accountability tracked through TSA exit and integration close.
- Lead the security response when a target is found to have an active or historical compromise, coordinating pre-close containment, valuation impact, and disclosure implications with Legal and Corporate Development.
Risk Management and Compliance
- Establish the risk-acceptance and exception framework for inherited risks that cannot be remediated by Day 1, ensuring documented ownership, funding, and time-bound closure.
- Ensure diligence and integration address the regulatory exposure relevant to the enterprise, including HIPAA and protected health information, GxP and validated systems, DSCSA, PCI DSS, SOX IT general controls, GDPR, and cross-border data transfer requirements.
- Aggregate inherited cyber risk across the transaction portfolio into the enterprise risk register and report exposure trends to executive risk committees.
- Oversee the third-party and fourth-party risk introduced through acquired vendor ecosystems, contracts, and data-sharing arrangements.
- Align Secure MA&D practices to recognized frameworks such as NIST CSF, NIST SP 800-53, ISO 27001, CIS Controls, and HITRUST, and support internal audit and regulatory inquiry into transaction risk.
Communications and Executive Engagement
- Serve as the security voice in deal committee, investment committee, and Board-level materials, presenting a clear position, a risk-adjusted cost range, and an explicit confidence level.
- Translate technical findings into valuation, timing, compliance, and operational impact for non-technical executives across Finance, Legal, Corporate Development, and Technology.
- Produce concise, decision-grade deliverables for audiences that will not read a technical report, while retaining the underlying evidence for audit and integration use.
- Brief and align security capability owners, business unit leaders, and acquired-company executives on findings, obligations, and sequencing.
- Represent the enterprise credibly while protecting confidentiality and negotiating position.
- Deliver difficult messages to deal sponsors and target leadership without stalling the transaction, and elevate with evidence when risk exceeds tolerance.
Change Management and Integration Enablement
- Lead the organizational change required to bring acquired entities onto enterprise security standards, including policy adoption, control uplift sequencing, and tooling migration.
- Build stakeholder engagement, training, and communication plans that reduce resistance, shadow IT, and control drift during integration.
- Assess acquired security talent and define retention, onboarding, and organizational design recommendations in partnership with Human Resources and security leadership.
- Manage the cultural transition from a smaller or less mature security environment to enterprise expectations, sequencing change to preserve business continuity and acquired-team morale.
- Institutionalize lessons learned after each close, feeding improvements back into playbooks, cost models, and Day 1 baselines.
Qualifications
- Bachelor's degree required; advanced degree in business or a technical discipline preferred.
- 15+ years of progressive experience in cybersecurity, technology risk, or security consulting, including 5+ years leading teams and enterprise-scale programs.
- Demonstrated experience leading cybersecurity due diligence and integration across multiple completed transactions, including at least one carve-out, divestiture, or separation.
- Working fluency in deal mechanics and terminology, including letters of intent, data-room and clean-team protocols, SPA and TSA constructs, purchase price adjustments, escrow and indemnity, and representations and warranties insurance.
- Financial acumen sufficient to build, defend, and negotiate multi-year remediation and run-rate cost estimates with Finance and Corporate Development.
- Breadth and depth across core security domains, including identity and access management, cloud and network security, endpoint, data protection, application security, security operations and incident response, vulnerability management, GRC, and third-party risk.
- Experience in a highly regulated industry; healthcare, pharmaceutical distribution, life sciences, or medical technology strongly preferred, with working knowledge of HIPAA, GxP, DSCSA, SOX, PCI DSS, and GDPR.
- Familiarity with NIST CSF, NIST SP 800-53 and 800-171, ISO 27001, CIS Controls, and HITRUST as diligence and integration baselines.
- Proven vendor management and budget ownership, including managing external assessment partners against fixed timelines and quality expectations.
- Demonstrated ability to influence and align executive stakeholders without direct authority, across global business units and geographies.
- Exceptional written and verbal communication skills, including Board and deal-committee materials, with a track record of being decisive on incomplete information.
- Proven discretion in handling material non-public information and simultaneous confidential transactions, with a clear understanding of insider-trading and information-barrier obligations.
- Relevant certifications such as CISSP, CISM, CRISC, CISA, CCSP, or PMP preferred.
- Willingness to travel and to support compressed transaction timelines, including nonstandard hours and multiple time zones.
What Cencora offers
We provide compensation, benefits, and resources that enable a highly inclusive culture and support our team members' ability to live with purpose every day. In addition to traditional offerings like medical, dental, and vision care, we also provide a comprehensive suite of benefits that focus on the physical, emotional, financial, and social aspects of wellness. This encompasses support for working families, which may include backup dependent care, adoption assistance, infertility coverage, family building support, behavioral health solutions, paid parental leave, and paid caregiver leave. To encourage your personal growth, we also offer a variety of training programs, professional development resources, and opportunities to participate in mentorship programs, employee resource groups, volunteer activities, and much more. For details, visit
Full time
Equal Employment Opportunity
Cencora is committed to providing equal employment opportunity without regard to race, color, religion, sex, sexual orientation, gender identity, genetic information, national origin, age, disability, veteran status or membership in any other class protected by federal, state or local law.
The company's continued success depends on the full and effective utilization of qualified individuals. Therefore, harassment is prohibited and all matters related to recruiting, training, compensation, benefits, promotions and transfers comply with equal opportunity principles and are non-discriminatory.
Cencora is committed to providing reasonable accommodations to individuals with disabilities during the employment process which are consistent with legal requirements. If you wish to request an accommodation while seeking employment, please call View phone number on click.appcast.io or email View email address on click.appcast.io. We will make accommodation determinations on a request-by-request basis. Messages and emails regarding anything other than accommodations requests will not be returned
Affiliated Companies
Affiliated Companies: AmerisourceBergen Services Corporation
#J-18808-Ljbffr- ...up to 99.999% high availability with mission critical capabilities built in such as security, compliance controls, and observability. For more information, visit EDB is hiring a Senior Technical Account Manager (TAM) for US. The Senior TAM is responsible for building...SeniorRemote work
- ...First Merchants Bank seeks a Senior Director Treasury Management Product to lead strategy and lifecycle for treasury management offerings. You will partner with Sales, Technology, Operations, Risk, Compliance, and Marketing to deliver competitive, scalable, and compliant...Senior
$191.1k - $320.6k
...AI, and you are the future of Salesforce.Professional Services | Global Acceleration Hub | Customer SuccessPosition SummaryThe Senior Director, Global Acceleration Hub - Revenue Cloud & Spiff Practice Leader is responsible for defining and scaling delivery acceleration,...SeniorFull timeRemote work- ...Elevance Health seeks a Staff VP Deputy CISO to lead information security strategy and execution across a regulated enterprise. You will... ...cybersecurity disciplines. The role collaborates with senior leaders, regulators, customers, and vendors to ensure policy adherence...Senior
$152.7k - $294k
...your career wherever you want it to go. Join EY and help to build a better working world. The Global Information Security Strategist is a senior role responsible for shaping and implementing the long-term information security strategy of the firm. This individual...SuggestedSummer holidayLocal areaFlexible hoursShift work$102k - $177.1k
...Function: Technology Enterprise Strategy & SecurityJob Sub Function: Security & ControlsJob Category:Scientific/TechnologyAll Job Posting... ...experienced Principal Product Security Engineer to be located in Danvers, MA. Remote work options may be considered on a case-by-case basis...Full timeLocal areaImmediate startRemote work$181.8k - $350k
...diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world. Senior Commercialization Architect, Associate Director The Senior Commercialization Architect leads the execution and performance improvement of the firm’s...SeniorFlexible hours$148.84k - $198.45k
...'re transforming how businesses connect, secure, and scale in an AI-driven world. By connecting... ...in building the future. The Role Director II, SLED Capture & Proposal Management -... ...8,295 in these states: AK CA CT DC DE IL MA MD NJ NY TX VA WA Lumen offers a...Full timeContract workTemporary workLocal areaRemote work- ...project delivery.Key Responsibilities:Client Leadership & Relationship ManagementBuild strong, trusted long-term relationships with senior client stakeholders. Advise clients on HR operating models, technology, and transformation strategies aligned with business goals....SeniorFull timeLive inWork at officeLocal area
$134k - $202k
...Drive internal service review meetings covering performance, service improvements,quality,and process ~ Partner with other senior level team membersinProduct,and Engineering as needed to troubleshoot and resolve customer incidents ~ When interacting with...SeniorRemote work- ...Senior Technician - SecurityThe Senior Technician - Security will provide efficient and high-quality installations related to integrated security systems. This position will require a high level of project involvement, including the physical installation, testing and...SeniorWork experience placementWork at officeLocal areaMonday to FridayShift work
- Senior HRBP will be responsible for strategic HR initiatives across the organization as well as their respective areas of business. They are responsible for the partnering with the HR leads to ensure effective execution of processes and recommend improvements to policies...Senior
- ...360 and others. If you're as passionate about your future as we are, join our team. KPMG is currently seeking an Associate Director, Senior Service Designer (GenAI Experience) to join our Digital Nexus technology organization. This is a hybrid work opportunity. Responsibilities...SeniorH1bLocal area
- Description About the Role Scale Computing is looking for a Senior People Operations Partner to help build a modern, scalable, and high-performing People function. This hands-on role will own and improve key People processes across the employee lifecycle, leveraging technology...SeniorLocal area
$163.4k - $322.1k
...advisory, and delivery efforts that help clients strengthen physical security programs, align security capabilities to enterprise priorities,... ..., and physical security technology. The Physical Security Senior Manager works with client stakeholders to design and enhance...SeniorLocal areaVisa sponsorship$105.4k - $207.8k
Position Summary As a Physical Security Senior Consultant in Deloitte’s Cyber Defense & Resilience team, you will help clients strengthen physical security, operational resilience, and mission assurance across critical facilities, infrastructure, and operations....SeniorLocal areaVisa sponsorship$143.4k - $236.7k
...experience in technical resilience, business resilience, enterprise security, or a related discipline within a global, matrixed technology... ...complex technical findings into crisp, accurate briefs for senior stakeholders and board-level audiences. Please note, this is an...SeniorFull time$80.4k - $293.8k
...We Are Accenture Security helps organizations prepare, protect, detect, respond, and recover along all points of the security lifecycle. Cybersecurity challenges are different for every business in every industry. Leveraging our global resources and advanced technologies...Full timeWork experience placementLive inWork at officeLocal area$105.4k - $207.8k
...cybersecurity challenges across identity, access, and platform security. Join our team to deliver solutions that help clients strengthen... ...for this role ends on 12/31/2026. Work you'll do As a Senior Engineering Management Specialist on the Deloitte Cyber team, you...SeniorLocal areaVisa sponsorship- ...onsite) in one of our tech hubs: Boston, MA; Portsmouth, NH; Columbus, OH; Indianapolis... ...aligns with enterprise standards for security, data privacy, explainability, and ethics... ...impedes delivery.Present confidently to senior leadership, distilling complex technical...Local areaShift work2 days per week
$105.4k - $207.8k
Position Summary Cyber Security & Risk Strategy Senior Consultant Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing...SeniorLocal areaVisa sponsorship- ...SaaS company on a mission to be the data platform of choice for the top law firms in the world. The Role We’re hiring a Senior Security Engineer to be the dedicated security owner for our Azure platform — running security reviews, keeping our policies and posture...SeniorImmediate startRemote work
- ..., install, monitor, and service integrated fire & life safety, security, communications, and audiovisual systems across the Midwest and... ...material estimates, and support accurate proposals. Serve as the senior technical escalation point for complex integration,...Work at office
$102.17k
...resilience, Trinnex delivers value and impact to public sector clients across the country. Job Description Join the Trinnex Security Team as a Senior Cyber Security Analyst, where you will operate at the intersection of cybersecurity and DevSecOps to protect critical...SeniorWork experience placementH1b$67.31k
Join to apply for the Senior Human Resources Business Partner role at State of Indiana Join to apply for the Senior Human Resources Business... ...resources professionals working in many capacities, including director-level, generalists, and specialists in each discipline of human...SeniorFull timeWork experience placementWork at officeLocal area$36 - $44 per hour
...Job Summary: The Senior Technician - Security; will provide efficient and high-quality installations related to integrated security systems. This position will require a high level of project involvement, including the physical installation, testing and closing-out process...SeniorWork experience placementWork at officeLocal areaMonday to FridayFlexible hoursShift workNight shift- ...communities across North America, we bring together integrated security, fire detection, building automation, and energy solutions, all... ...Full Time/Part Time Full-time Job Description Job Summary: The Senior Technician - Security; will provide efficient and high-quality...SeniorFull timePart timeWork experience placementWork at officeLocal areaMonday to FridayFlexible hoursShift workNight shift
$77.9k - $153k
Senior Information Security Analyst Job Details Job Locations: US-IL-Chicago | US-IN-Evansville | US-MN-Lake Elmo | US-IN-Indianapolis | US-IN-Lafayette Category/Function: Risk/Security Position Type: Regular Full-Time Requisition ID: 2026-19402 Workplace Type: On...SeniorFull timeWork experience placementImmediate start$186.49k - $278.88k
...Remote Full time R12802 The Director, Government Pricing leads all federally mandated... ...presenting complex regulatory risks to senior executives. Competencies... ...Recruiting Fraud Scams At Otsuka we take security and protection of your personal information...Full timeContract workTemporary workLocal areaRemote workWorldwideFlexible hours- ...Krieg DeVault LLP is seeking a visionary and highly collaborative Director of Artificial Intelligence to lead the Firm's AI strategy,... ...’s E-Verify program. With all new hires, we provide the Social Security Administration and, when applicable, the U.S. Department of Homeland...Temporary workWork at officeShift work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Director, Secure MA&D. Be the first to apply!
- grounds director Indianapolis, IN
- non profit director Indianapolis, IN
- industrial director Indianapolis, IN
- director utilization management Indianapolis, IN
- director call center Indianapolis, IN
- director talent acquisition Indianapolis, IN
- director life science Indianapolis, IN
- childcare director Indianapolis, IN
- director of administration Indianapolis, IN
- nonprofit director Indianapolis, IN



