Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Director, Exposure Management (Cybersecurity Defense)

$135.4k - $208.1k

Cardinal Health

What Cybersecurity Defense contributes to Cardinal Health

Cybersecurity Defense focuses heavily on threat detection, incident response, and implementing security measures to protect our digital assets and infrastructure at Cardinal Health. The Director, Exposure Management is responsible for establishing, leading, and overseeing the exposure management program to proactively identify, prioritize, and reduce cybersecurity risk across network, cloud, endpoint, and data environments. This role drives the strategy and execution of vulnerability management, security configuration management, cloud and network security, endpoint security, and data protection capabilities. Moreover, this Director leads core aspects of exposure management, including vulnerability identification and prioritization, security configuration management, cloud and network security monitoring, endpoint and mobile security, data loss prevention (DLP), and data security posture management (DSPM). This person plays a critical role in reducing the organization’s attack surface, improving security posture, and enabling alignment with overarching cybersecurity & GTBS strategies.

Location - Open to candidates nationwide working in a fully remote capacity, with preference towards those based in Central or Eastern time zones (willingness to travel into our Corporate HQ in Dublin, OH during certain period of the year is a plus)

Responsibilities

  • Develop and lead the exposure management strategy aligned with cybersecurity, risk management, and business objectives.

  • Define governance frameworks and processes to identify, assess, prioritize, and remediate security exposures across the organization.

  • Collaborate with cybersecurity leadership to align exposure management initiatives with broader cyber defense and risk reduction strategies.

  • Serve as an advisor to leadership on exposure trends, risk posture, and mitigation priorities.

  • Oversee enterprise vulnerability management capabilities, including identification, assessment, prioritization, and remediation tracking.

  • Define risk-based prioritization methodologies to evaluate vulnerabilities based on threat intelligence, exploitability, and business impact.

  • Oversee vulnerability scanning, reporting, and remediation processes across infrastructure, applications, and cloud environments.

  • Oversee vulnerability management tooling and engineering strategy (e.g., Rapid7) to support exposure visibility and remediation workflows.

  • Lead cloud security monitoring and posture management processes to detect misconfigurations, vulnerabilities, and anomalous activity across cloud environments.

  • Oversee CNAPP and CASB tooling strategies to monitor, control, and secure cloud applications and infrastructure.

  • Define firewall monitoring standards and rule configurations in collaboration with security architecture to ensure alignment with security policies.

  • Manage firewall and network security tooling to detect misconfigurations, policy violations, and anomalous activity.

  • Ensure alignment of cloud and network security controls with enterprise architecture and risk requirements.

  • Oversee endpoint security capabilities, including configuration management, drift detection, and enforcement of secure baselines.

  • Lead endpoint hardening, and monitoring strategies to reduce endpoint-related risks.

  • Direct mobile security initiatives to protect devices and applications through policy enforcement and monitoring.

  • Oversee endpoint and mobile security tooling strategy to enable consistent protection and compliance across the enterprise

  • Lead enterprise data protection capabilities, including endpoint, network, and cloud DLP programs.

  • Oversee design, implementation, and optimization of DLP tooling to monitor and prevent unauthorized data access, use, or exfiltration.

  • Establish and manage Data Security Posture Management (DSPM) capabilities to discover, classify, and assess sensitive data across environments.

  • Ensure alignment of data protection controls with regulatory requirements, privacy standards, and enterprise policies.

  • Define and enforce security configuration standards across systems, infrastructure, and endpoints.

  • Oversee configuration drift detection and remediation processes to maintain secure and compliant baselines.

  • Collaborate with IT and engineering teams to ensure secure configurations are embedded into system builds and deployment pipelines.

  • Drive continuous improvement of configuration management practices to reduce exposure and improve resilience.

  • Lead engineering and optimization of exposure management tools, including vulnerability management, CNAPP, CASB, DLP, and endpoint security platforms.

  • Define use cases, technical requirements, and configurations to enhance detection, monitoring, and remediation capabilities.

  • Drive automation of exposure detection, prioritization, and remediation workflows to improve efficiency and scalability.

  • Ensure integration of exposure management tools with broader cybersecurity platforms and processes.

  • Collaborate with cybersecurity, IT, engineering, and business teams to integrate exposure management into enterprise processes and initiatives.

  • Partner with risk and compliance teams to align exposure management activities with enterprise risk frameworks and regulatory requirements.

  • Provide actionable insights and reporting to leadership on exposure trends, remediation progress, and risk reduction outcomes.

  • Support audit and regulatory activities by providing documentation and evidence related to exposure management practices.

  • Define and track KPIs and KRIs related to vulnerability management, configuration compliance, and exposure reduction.

  • Provide regular reporting to leadership on security posture, exposure trends, and remediation effectiveness.

  • Identify opportunities to enhance exposure visibility, prioritization accuracy, and remediation efficiency.

  • Drive continuous improvement initiatives to mature exposure management capabilities.

  • Build and lead a high-performing exposure management team with capabilities across vulnerability management, cloud security, endpoint security, and data protection.

  • Develop team capabilities through training, mentoring, and structured career development initiatives.

  • Foster a culture of accountability, collaboration, and continuous improvement.

  • Ensure alignment of team capabilities with evolving threat landscape and organizational needs.

Qualifications

  • Ideally targeting individuals with 10+ years of experience in cybersecurity, with a focus on vulnerability management, cloud security, endpoint security, or data protection.

  • Deep expertise in exposure management practices, including vulnerability assessment, configuration management, and risk-based prioritization.

  • Strong understanding of cybersecurity frameworks (e.g., NIST CSF, ISO 27001) and regulatory requirements.

  • Experience leading security engineering and operational teams focused on exposure reduction and risk mitigation.

  • Demonstrated ability to collaborate with cross-functional teams and influence technical and business stakeholders.

  • Strong leadership, analytical, and problem-solving skills.

  • Experience in highly regulated industries, a plus.

  • Experience with modern cloud security, network security, and data protection technologies, a plus.

#LI-LP

#LI-Remote

Anticipated salary range: $135,400 - $208,100

Bonus eligible: Yes

Benefits: Cardinal Health offers a wide variety of benefits and programs to support health and well-being.

  • Medical, dental and vision coverage

  • Paid time off plan

  • Health savings account (HSA)

  • 401k savings plan

  • Access to wages before pay day with myFlexPay

  • Flexible spending accounts (FSAs)

  • Short- and long-term disability coverage

  • Work-Life resources

  • Paid parental leave

  • Healthy lifestyle programs

Application window anticipated to close: 07/01/2026 *if interested in opportunity, please submit application as soon as possible.

The salary range listed is an estimate. Pay at Cardinal Health is determined by multiple factors including, but not limited to, a candidate’s geographical location, relevant education, experience and skills and an evaluation of internal pay equity.

Candidates who are back-to-work, people with disabilities, without a college degree, and Veterans are encouraged to apply.

Cardinal Health supports an inclusive workplace that values diversity of thought, experience and background. We celebrate the power of our differences to create better solutions for our customers by ensuring employees can be their authentic selves each day. Cardinal Health is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, ancestry, age, physical or mental disability, sex, sexual orientation, gender identity/expression, pregnancy, veteran status, marital status, creed, status with regard to public assistance, genetic status or any other status protected by federal, state or local law.

To read and review this privacy notice click here (

Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Director, Exposure Management (Cybersecurity Defense) in Washington DC vacancy
  •  ...the dynamic market of autonomous robotic systems in defense we're looking for a Technical Program Manager who will be responsible for the delivery of...  ...aerospace standards, including export controls and cybersecurity requirements. Drive continuous improvement and contribute... 
    Suggested
    Contract work

    Auterion

    Arlington, VA
    2 days ago
  •  ...Director, Capture Management This role is a senior strategic pursuit leadership position focused on driving growth across Aerospace, Defense, and other safety-critical technology markets. You will lead...  ...growth opportunities ~ Exposure to high-impact, mission-critical... 
    Suggested
    Contract work
    Remote work

    Jobgether

    Washington DC
    1 day ago
  • $109.2k - $223.4k

     ...Job Description The Director for Global Defense - Japan is responsible for leading and growing strategic...  ...roles, with significant Japan market exposure. ~ Working proficiency in Japanese...  ..., governance) Stakeholder management in highly regulated environments Integrity... 
    Suggested
    Contract work
    Temporary work
    For contractors
    Local area
    Flexible hours

    Oracle

    Washington DC
    3 days ago
  •  ...Technical Account Manager Cymulate's Continuous Security Validation enables companies...  ...Cymulate is the leader in Adversarial Exposure Validation. Our platform lets enterprises...  ...their vulnerabilities and assurance that defenses are effective. This is not a standard... 
    Suggested
    Shift work
    Day shift

    Cymulate Ltd

    Washington DC
    2 days ago
  •  ...Technical Account Manager Company Overview iboss is a cloud security company that enables...  ...capabilities such as SWG, malware defense, RBI, CASB and data loss prevention to all...  ...experience with enterprise networks, systems, cybersecurity and sales engineering or technical... 
    Suggested

    iboss

    Washington DC
    4 days ago
  • $166k - $200k

    Anduril Industries is a defense technology company with a mission...  .... ABOUT THE JOB The Manager of Technical Security Systems...  ...operations. Reporting to the Director of Corporate Security, this...  ...actions. Collaborate with IT and cybersecurity teams to ensure a cohesive... 
    Full time
    Work experience placement

    Slope

    Washington DC
    2 days ago
  •  ...networking — for industrial workforces and defense personnel. We create capabilities that...  ...upon hire. Role Associate Program Manager Location Washington, DC Role Summary This...  ...and business objectives. You'll get early exposure to how a defense tech company thinks about... 
    Internship
    Flexible hours
    Shift work

    Rivet Industries, Inc.

    Washington DC
    3 days ago
  •  ...Anduril Industries is a defense technology company with a mission to transform U.S. and...  ...expands, we are seeking Technical Program Managers to focus on the challenges of...  ...software development. This position will have exposure to a wide variety of program planning, organization... 
    Full time
    Work experience placement
    Immediate start
    Relocation

    Anduril Industries

    Washington DC
    1 day ago
  •  ...HUMAN RESOURCES (HR) MANAGER MILITARY FRIENDLY & SKILLBRIDGE SPONSOR...  ...Business (SDVOSB) providing cybersecurity, Enterprise IT, and...  ...with executive leadership, Directors, and Program / Project Managers...  ...federal workforce regulations. Exposure to personnel management, civilian... 
    Contract work
    For contractors
    Local area
    Remote work

    Zermount, Inc.

    Arlington, VA
    2 days ago
  •  ...Technical Program Manager Anduril Industries is a defense technology company with a mission to transform U.S. and allied military capabilities with...  ...systems software development. This position will have exposure to a wide variety of program planning, organization, and... 
    Full time
    Work experience placement
    Immediate start
    Relocation

    Colorwave Inc

    Washington DC
    2 days ago
  •  ...University of Maryland, College Park. This internal search seeks a Director to lead the institute, which focuses on computational science across national defense, precision medicine, big data, cybersecurity, language and culture, and other areas. Position: Institute... 
    Work at office

    UM01 University of Maryland College Park (UMCP)

    College Park, MD
    10 hours ago
  •  ...expect as a Technical Program Manager SkillBridge Fellow As a...  ...complex challenges. You will gain exposure to MTSI’s employee-first...  ...prioritize mission success and cybersecurity compliance. Compliance And...  ...network within the defense industry Be considered for... 
    Full time
    For contractors
    Work experience placement
    Work at office

    Modern Technology Solutions, Inc. (MTSI)

    Alexandria, VA
    10 hours ago
  • $9k

     ...the experience, you will gain exposure to MTSI's employee‑first...  ...PMAS technologies. Program Management Track program and system performance...  ...mission success and cybersecurity compliance. Compliance and...  ...professional network within the defense industry Be considered for... 
    Full time
    For contractors
    Work experience placement
    Work at office
    Immediate start
    Flexible hours

    Modern Technology Solutions, Inc.

    Alexandria, VA
    2 days ago
  •  ...support to federal customers, with a particular focus on Defense and National Security mission sets. We leverage more...  ...Barbaricum is hiring a Senior Technical Program Manager to support enterprise IT and cybersecurity initiatives under the Military Community and Family... 
    Contract work
    For contractors

    Barbaricum

    Washington DC
    4 days ago
  •  ...Senior Director of Capture Management About the Company Multi-billion-dollar federal service contractor serving defense, intelligence, civilian, and international markets. Industry Defense & Space Type Privately Held About the Role The Company is in need of a Senior Director... 
    For contractors

    Confidential

    Washington DC
    5 days ago
  • $172.8k - $216k

     ...AI-powered data security and management. Aided by an extensive...  ...organizations defend against cybersecurity threats with comprehensive data...  .... The Government Affairs Director is a senior individual contributor...  ...technology, data security, defense, or adjacent sectors will... 
    Hourly pay
    Full time
    Work at office
    2 days per week
    3 days per week

    Cohesity

    Washington DC
    1 day ago
  • $120k

     ...Initiative (CCI) is Virginia’s central hub for cybersecurity research, innovation, and workforce...  ...CCI is seeking a dynamic and strategic Director of Outreach to lead high‑impact...  ...lasting impact. Responsibilities Build and manage relationships with industry, government,... 
    Work at office

    The Chronicle Of Higher Education, Inc.

    Arlington, VA
    1 day ago
  • $110k - $150k

    Overview NRDC (the Natural Resources Defense Council) works to safeguard the Earth, its...  ...Learn more at nrdc.org Position Summary The Director provides strategic leadership along with...  ...environment. A strong project management background with experience initiating programs... 
    Work at office
    Local area

    Natural Resources Defense

    Washington DC
    1 day ago
  • $230k - $270k

     ...platforms purpose‑built for U.S. and allied defense and intelligence missions. Whether it’s...  ...at Umbra. About the Job The Defense Director is responsible for growing and leading a...  ...business development, capture, and program management, with a focus on addressing the most... 
    Permanent employment
    Contract work
    Part time
    Work at office
    Local area
    Remote work
    Worldwide
    Flexible hours

    Umbra Lab, Inc.

    Arlington, VA
    10 hours ago
  • Cardinal Health is seeking a Director of Cyber Detection & Response to enhance their cybersecurity operations. This role involves leading detection strategies, managing the Security Operations Center, and overseeing incident response initiatives to protect the organization... 
    Remote job

    Cardinal Health

    Washington DC
    10 hours ago
  • $120k

     ...thought leadership from technology, hardware, software, services, and related industries. Position Director of Policy, Cybersecurity and Supply Chain Risk Management Location Washington, DC Job Id 172 Summary As the Director of Policy, Cybersecurity and Supply Chain... 
    For contractors
    Work experience placement
    Worldwide

    ITI

    Washington DC
    4 days ago
  • $177k - $200k

    ThinkIQ is looking for a Director of Senior Business Development to grow business in the Department of War sector. This role involves leading...  ...candidate should have over 10 years of experience in aerospace/defense, alongside a strong track record in business development. A... 

    ThinkIQ

    Washington DC
    2 days ago
  • $191k - $253k

    A defense technology company is seeking an International Advanced Effects lead for the Air Dominance and Strike Division. This role involves generating and capturing international business opportunities with a focus on missile systems, requiring travel up to 75%. Candidates... 

    Slope

    Washington DC
    4 days ago
  • $100k - $130k

     ...Academic Freedom, Tenure, and Governance - Director, Remote. AAUP is a union of higher...  ...partners to coordinate national and local defense of academic freedom, empowering members and...  ...Strategic Director and Program Coordinator, manage the day-to-day operations of CDAF. Carry... 
    Full time
    Part time
    Local area
    Immediate start
    Remote work
    Relocation

    American Association of University Professors

    Washington DC
    3 days ago
  •  ...Zetier seeks an experienced Technical Program Manager to lead and manage $10m+ contracts within the cybersecurity and operations domains supporting Department of Defense (DoD) and Intelligence Community (IC). Responsibilities include managing multi-year OCO/DCO programs... 
    Contract work
    For subcontractor
    Work at office

    Zetier

    Arlington, VA
    2 days ago
  •  ...Security Professional (CISSP), Certified Information Systems Manager (CISM), or Certified Information Systems Auditor (CISA). Required...  ...Program Manager (ST PM) to lead and manage all IT and cybersecurity-related contract personnel and program activities under Task 3... 
    Contract work
    Temporary work

    PingWind Inc

    Alexandria, VA
    4 days ago
  • $180k - $220k

     ...the systems that power modern defense operations. Our platform...  ...role Picogrid is seeking a Director of Government Solutions who...  ...Work closely with Capture Managers, Deployment Strategists, and...  ...related roles, with significant exposure to space or aerospace domains... 
    Remote job
    Permanent employment
    For contractors

    Picogrid

    Washington DC
    more than 2 months ago
  •  ...is not a job description for a specific job opening at DIU. The Talent Management Team collects resumes from interested candidates for periodic openings and would love to hear from you!* The Defense Innovation Unit (DIU) is a Department of War (DoW) organization... 

    Defensive Innovation Unit

    Arlington, VA
    3 days ago
  • $160k - $250k

     ...CHAOS Industries is redefining modern defense with a multi-product portfolio that gives...  ...proactive and detail-oriented Technical Program Manager (TPM) to lead the successful delivery of...  ...The TPM will report to the (Acting) Director the Program Execution Office (PEO).... 
    Permanent employment
    Contract work
    Work experience placement
    Casual work
    Work at office
    Relocation package

    CHAOS Industries

    Washington DC
    5 days ago
  •  ...Position Description: PingWind is seeking a Senior Technical Program Manager responsible for leading technical planning, coordination, and execution of MODES III IT, cybersecurity, cloud, and data operations, ensuring delivery of secure, compliant, and... 
    Temporary work
    Flexible hours

    PingWind Inc

    Alexandria, VA
    5 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Director, Exposure Management (Cybersecurity Defense). Be the first to apply!