Director, Application Security (Cybersecurity Defense)
$135.4k - $208.1kCardinal Health
What Cybersecurity Defense contributes to Cardinal Health
Cybersecurity Defense focuses heavily on threat detection, incident response, and implementing security measures to protect our digital assets and infrastructure at Cardinal Health. The Director, Application Security is responsible for establishing, leading, and evolving the enterprise application security strategy to embed security into the software development lifecycle (SDLC) and reduce application-layer risk across the business segments. This leader ensures that applications and APIs are designed, developed, and deployed in alignment with security policies & standards, regulatory requirements, and risk management objectives. This Director oversees segment-aligned application security capabilities across Pharma, Medical, and Commercial Technology environments, enabling consistent governance, scalable processes, and effective risk mitigation across diverse application portfolios.
Location - Open to candidates nationwide working in a fully remote capacity, with preference towards those based local to Central Ohio (willingness to travel into our Corporate HQ in Dublin, OH during certain period of the year is a plus)
Responsibilities
Lead the enterprise application security strategy aligned with cybersecurity, risk management, and business objectives.
Establish governance frameworks to embed security into the software development lifecycle (SDLC) across all application domains.
Collaborate with enterprise architecture, engineering, and product teams to align application security with technology strategies and transformation initiatives.
Serve as an advisor to executive and business leadership on application security risks, priorities, and investment decisions.
Drive a secure-by-design culture across development and engineering teams.
Oversee application security capabilities across Pharma, Medical, and Commercial Technology segments, ensuring consistent implementation of security practices.
Define segment-specific requirements and approaches to address unique regulatory, operational, and risk considerations.
Ensure alignment of application security practices across segments while enabling flexibility to support business-specific needs.
Drive standardization of processes, tooling, and reporting across segment application security teams.
Oversee enterprise application security testing programs, including SAST, DAST, SCA, and IAST across all application environments.
Ensure vulnerabilities are identified, assessed, prioritized, and remediated during the development lifecycle prior to deployment.
Establish secure coding standards and integrate security controls into CI/CD pipelines and development workflows.
Collaborate with development teams to reduce application security technical debt and improve code quality.
Oversee implementation of runtime security controls for applications and APIs, including WAF, API gateways, and runtime monitoring solutions.
Ensure security requirements are embedded into application and API design, deployment, and operational processes.
Collaborate with engineering and infrastructure teams to enforce runtime protections aligned with enterprise architecture.
Monitor runtime risks and coordinate mitigation efforts across application environments.
Lead development and integration of application security tooling, including configuration, onboarding, and operational management.
Define use cases, policies, and detection logic for application security tools to ensure effective coverage and scalability.
Drive integration of application security tools into CI/CD pipelines and DevSecOps workflows.
Ensure application security tooling aligns with enterprise security architecture and standards.
Collaborate with Security Architecture teams to define secure design patterns, reference architectures, and application security standards.
Ensure application security requirements are incorporated into solution design and architecture reviews.
Partner with engineering teams to implement secure development lifecycle (SDLC) practices and controls.
Support evaluation of new technologies and architectures to ensure alignment with security requirements.
Ensure application security practices align with regulatory requirements, compliance standards, and enterprise risk management frameworks.
Provide application security oversight for audits, regulatory assessments, and compliance reporting.
Collaborate with risk and compliance teams to translate application security risks into enterprise risk insights.
Support remediation of identified risks and ensure alignment with risk tolerance and governance processes.
Define and track KPIs and KRIs related to application security posture, vulnerability management, and SDLC integration.
Provide regular reporting to executive leadership on application security risks, trends, and program effectiveness.
Leverage data and analytics to drive continuous improvement in application security practices and outcomes.
Identify opportunities to enhance automation, efficiency, and scalability of application security processes.
Collaborate with application development, product, IT, security operations, and business teams to integrate application security into enterprise processes.
Partner with Cyber Detection & Response to ensure application security findings are integrated into monitoring and incident response workflows.
Engage with segment leaders to align application security initiatives with business priorities and risk considerations.
Support M&A activities by assessing and integrating application security controls for acquired applications.
Build and lead a high-performing application security organization with expertise across secure development, testing, and runtime protection.
Ensure alignment of team capabilities with evolving technologies, threats, and business needs.
Qualifications
Ideally targeting individuals with 10+ years of experience in cybersecurity, with a focus on application security, secure development, or DevSecOps.
Deep expertise in application security testing methodologies (SAST, DAST, SCA, IAST) and secure development practices, strongly preferred.
Strong understanding of application and API security, cloud-native architectures, and modern development frameworks.
Experience leading application security programs across large, complex organization, preferred.
Strong understanding of cybersecurity frameworks (e.g., NIST CSF, OWASP, ISO 27001) and regulatory requirements.
Demonstrated ability to collaborate with cross-functional teams and influence executive stakeholders.
Strong leadership, communication, and problem-solving skills.
#LI-LP
#LI-Remote
Anticipated salary range: $135,400 - $208,100
Bonus eligible: Yes
Benefits: Cardinal Health offers a wide variety of benefits and programs to support health and well-being.
Medical, dental and vision coverage
Paid time off plan
Health savings account (HSA)
401k savings plan
Access to wages before pay day with myFlexPay
Flexible spending accounts (FSAs)
Short- and long-term disability coverage
Work-Life resources
Paid parental leave
Healthy lifestyle programs
Application window anticipated to close: 07/01/2026 *if interested in opportunity, please submit application as soon as possible.
The salary range listed is an estimate. Pay at Cardinal Health is determined by multiple factors including, but not limited to, a candidate's geographical location, relevant education, experience and skills and an evaluation of internal pay equity.
Candidates who are back-to-work, people with disabilities, without a college degree, and Veterans are encouraged to apply.
Cardinal Health supports an inclusive workplace that values diversity of thought, experience and background. We celebrate the power of our differences to create better solutions for our customers by ensuring employees can be their authentic selves each day. Cardinal Health is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, ancestry, age, physical or mental disability, sex, sexual orientation, gender identity/expression, pregnancy, veteran status, marital status, creed, status with regard to public assistance, genetic status or any other status protected by federal, state or local law.
To read and review this privacy notice click here (
- ...TheCloud Developerwill design, develop, and deploy secure, scalable, and resilient cloud-based applications and infrastructure to support in Honoulu,... ...compliance standards in line with Department of Defense (DoD) cybersecurity requirements. Candidates should have...ApplicationMonday to Friday
$145k - $150k
...multiple enclaves with varying security classifications. To join our... ...all network devices and applications are patched, secure, and operating... ...CCNA Security. CySA+ (Cybersecurity Analyst). GICSP (Global... ...integration across the Department of Defense and stands ready to help...ApplicationFull timePart timeFor contractorsWork at officeRemote work$109k - $121k
...supporting the Department of Defense (DoD) networking... ...multiple enclaves with varying security classifications. The Network... ...CCNA Security. CySA+ (Cybersecurity Analyst). GICSP (Global Industrial... ...employer and comply with all applicable federal, state, and local fair...ApplicationFull timePart timeFor contractorsWork at officeLocal areaRemote work$100k
...mission‑critical programs across national security, defense, and public service delivery. Recent contract awards in cybersecurity and operational readiness underscore Maximus... ...~3 years of experience testing web-based applications. ~3 years of experience participating in...ApplicationContract workRemote work$100k
...mission‑critical programs across national security, defense, and public service delivery. Recent contract awards in cybersecurity and operational readiness underscore Maximus... ...and modifies RESTful APIs supporting application functionality. Performs database management...ApplicationContract workRemote work$125k
...mission‑critical programs across national security, defense, and public service delivery. Recent contract awards in cybersecurity and operational readiness underscore Maximus... ...~5 years of experience testing web-based applications. ~5 years of experience leading software...ApplicationContract workRemote work$113.15k - $135.64k
...technology and services integrators in the defense and government services industry. We... ...and trusted results to enable national security missions worldwide. Job Description... ...Evaluate technology strategy, organization, applications, and infrastructure. Coordinate on enterprise...ApplicationWork at officeWorldwideNight shift$40k
...mission‑critical programs across national security, defense, and public service delivery. Our... ...Engineer supports 24x7 enterprise cybersecurity operations by monitoring security tools... ...activities, including access changes, application removal, configuration updates, and...ApplicationContract workRemote work$90.79k
...Manager, IT Security Job ID 2026-6592 # of Openings 1 Category... ...and operating a comprehensive, riskbased cybersecurity and information protection program for... ..., and reporting across infrastructure, applications, and cloud environments. Partners with...ApplicationWork experience placement$63.8k - $105.4k
...Operations Specialist Shape the future of defense with MANTECH! Join a team dedicated to... .... Dive into exciting opportunities in Cybersecurity, IT, Data Analytics and more. Propel... ...a primary technical authority for the application of asymmetric modeling techniques. Oversees...ApplicationHourly payContract workTemporary workWork experience placementWork at officeLocal areaRemote work$63.8k - $105.4k
...Operations Specialist Shape the future of defense with MANTECH! Join a team dedicated to... .... Dive into exciting opportunities in Cybersecurity, IT, Data Analytics and more. Propel... ...a primary technical authority for the application of asymmetric modeling techniques. Oversees...ApplicationHourly payContract workTemporary workWork experience placementWork at officeLocal areaRemote work- ...solutions supporting critical defense programs. The IT Site Lead... ...operation, maintenance, and cybersecurity posture of a moderately complex... ..., availability, and security compliance of all supported... ...and stored in accordance with applicable DoD data protection and storage...ApplicationContract workFor contractorsLocal areaFlexible hoursShift work
$86.9k - $198k
...architecting, deploying, and operating security solutions across various DoW... ...the next set of advanced cybersecurity engineers to help them grow... ...our nation’s front line of defense.Work with us and build the... ...Certification**Clearance:** Applicants selected will be subject to...Full timeContract workPart timeWork at officeLocal areaRemote work$130k - $140k
...Description Role: Manager, Security Operations... ..., NC) Department: Cybersecurity - Security Operations... ...Reports to: Senior Director, Security Operations... ...regional equivalents where applicable). Security... ...accurate, validated, and defensible . Support internal...ApplicationFull time- ...Linux/UNIX environments, ensuring the stability, security, and performance of PeopleSoft and Oracle applications. You will be responsible for troubleshooting... ..., Database Administration, Network Engineering, Cybersecurity, Data Science, Applied Mathematics, etc. ALTERNATE...ApplicationTemporary workFor contractorsImmediate startFlexible hours
- ...IT Security Analyst DecisionPoint Corporation is seeking an IT... ...Air Force team supporting the defense of USAF infrastructure at... ...related technical discipline in cybersecurity or information technology.... ...(e.g., destructive programs/applications/ viruses, unauthorized...ApplicationFor contractorsLocal areaImmediate start
- ...to operate more effectively, securely, and efficiently. We support... ...federal missions across defense, civilian, and intelligence... ...scientists, data engineers, cybersecurity staff, and customer stakeholders... ...Serco team- then submit your application now for immediate...ApplicationFull timeContract workPart timeLocal areaImmediate startFlexible hours
- ...is looking for a Cloud Developer in Honolulu, Hawaii, to design and develop secure, scalable, and resilient cloud-based applications. The role includes ensuring compliance with DoD cybersecurity standards and utilizing AWS, Microsoft Azure, or Google Cloud for...Application
- ...a key player in maintaining and securing the network operations and defense systems. This role is responsible... ...and updates operating systems and applications across all assigned systems using... ...compliance with organizational goals and cybersecurity directives Minimum...ApplicationFull timePart timeRemote work
- ...solutions that integrate across enterprise IT systems, cybersecurity tools, network infrastructure, and mission applications. This position includes providing technical... ...with enterprise service management practices, security requirements, and data governance standards....Application
$152.7k - $294k
.... As part of EY Information Security, this role is focused on ensuring... ...facing services, platforms, applications, and technology capabilities... ..., digital identity, cyber defense, application security,... ...outcomes. As an Associate Director within the TARP BCCM team...ApplicationSummer holidayLocal areaFlexible hours- ...contribute to the development of cutting‑edge applications. In this role, you will work across the... ...applications for scalability and security. This position offers the opportunity... ...Information Systems, Cloud Computing, Cybersecurity, Applied Mathematics, Software Development...ApplicationTemporary workFor contractorsImmediate startFlexible hours
$157.43k - $208.43k
...services integrators in the defense and government services industry... ...results to enable national security missions worldwide. Job... ...** SOSi is seeking a Cybersecurity Lead to join our team in Fort... ...lifecycle of IT systems and applications. Ensure compliance with...ApplicationContract workCasual workWork at officeRemote workWorldwide- ...building and maintaining robust, scalable applications across both the front-end and back-end.... ...Cloud Computing, Network Engineering, Cybersecurity, Applied Mathematics, ect. ALTERNATE... ...Integrate cloud services and ensure security standards REQUIRED SKILLS Proficiency...ApplicationTemporary workFor contractorsImmediate startFlexible hours
$99k - $225k
...Enterprise Architect A well-designed, secure network is critical to enabling the Department of Defense (DoD) to accomplish its... ...of network engineering and cybersecurity, combining backbone networking... ...CCNA Certifications Clearance Applicants selected will be subject to a...Full timeContract workPart timeWork at officeLocal areaRemote work$170.6k - $390k
...working world. Join EY’s Cybersecurity consulting practice – the best... ...your career in information security! The opportunity The... ...with infrastructure, cloud, application, and security operations teams... ...zero trust principles, defense‑in‑depth, and least privilege...ApplicationSummer holidayRemote workFlexible hours- ...Permanente is expanding our Cyber Risk Defense program and seeking a highly skilled individual... ...on supporting the mission of Cyber Security and is a technical expert in managing an... .../onboarding via Cribl Stream, and application support for Splunk Enterprise. Enabling...Application
$99.3k - $158.69k
...remote endpoints in a highly regulated, defense-focused environment. This role defines... ..., aligning remediation activities with security policies, regulatory requirements, and... ...vulnerability management into broader cybersecurity and IT governance frameworks. Compensation...Contract workWork at officeRemote work- ...services. Centrally operate, maintain, secure, and administer related equipment/solutions... ...a wide array of server grade applications to include Windows/Azure Active Directory... ...) requirements. Prefer experience with cybersecurity inspections and artifact creation. Prefer...ApplicationContract workLocal areaRemote workRelocationShift work
- ...operations within a Department of Defense (DoD) environment. This role... ...systems, leadership in secure system administration, and a... ...environments, and ensure cybersecurity compliance across classified... ...an accommodation during the application process, please click here to...ApplicationWork experience placementWork at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Director, Application Security (Cybersecurity Defense). Be the first to apply!
- surveillance manager Honolulu, HI
- security operations manager Honolulu, HI
- physical security manager Honolulu, HI
- program manager with security clearance Honolulu, HI
- corporate security manager Honolulu, HI
- director information security Honolulu, HI
- security manager Honolulu, HI
- security systems manager Honolulu, HI
- vice president of application development Honolulu, HI
- oracle apps technical consultant Honolulu, HI

