Director, Exposure Management (Cybersecurity Defense)
$135.4k - $208.1kCardinal Health
What Cybersecurity Defense contributes to Cardinal Health
Cybersecurity Defense focuses heavily on threat detection, incident response, and implementing security measures to protect our digital assets and infrastructure at Cardinal Health. The Director, Exposure Management is responsible for establishing, leading, and overseeing the exposure management program to proactively identify, prioritize, and reduce cybersecurity risk across network, cloud, endpoint, and data environments. This role drives the strategy and execution of vulnerability management, security configuration management, cloud and network security, endpoint security, and data protection capabilities. Moreover, this Director leads core aspects of exposure management, including vulnerability identification and prioritization, security configuration management, cloud and network security monitoring, endpoint and mobile security, data loss prevention (DLP), and data security posture management (DSPM). This person plays a critical role in reducing the organization's attack surface, improving security posture, and enabling alignment with overarching cybersecurity & GTBS strategies.
Location - Open to candidates nationwide working in a fully remote capacity, with preference towards those based in Central or Eastern time zones (willingness to travel into our Corporate HQ in Dublin, OH during certain period of the year is a plus)
Responsibilities
Develop and lead the exposure management strategy aligned with cybersecurity, risk management, and business objectives.
Define governance frameworks and processes to identify, assess, prioritize, and remediate security exposures across the organization.
Collaborate with cybersecurity leadership to align exposure management initiatives with broader cyber defense and risk reduction strategies.
Serve as an advisor to leadership on exposure trends, risk posture, and mitigation priorities.
Oversee enterprise vulnerability management capabilities, including identification, assessment, prioritization, and remediation tracking.
Define risk-based prioritization methodologies to evaluate vulnerabilities based on threat intelligence, exploitability, and business impact.
Oversee vulnerability scanning, reporting, and remediation processes across infrastructure, applications, and cloud environments.
Oversee vulnerability management tooling and engineering strategy (e.g., Rapid7) to support exposure visibility and remediation workflows.
Lead cloud security monitoring and posture management processes to detect misconfigurations, vulnerabilities, and anomalous activity across cloud environments.
Oversee CNAPP and CASB tooling strategies to monitor, control, and secure cloud applications and infrastructure.
Define firewall monitoring standards and rule configurations in collaboration with security architecture to ensure alignment with security policies.
Manage firewall and network security tooling to detect misconfigurations, policy violations, and anomalous activity.
Ensure alignment of cloud and network security controls with enterprise architecture and risk requirements.
Oversee endpoint security capabilities, including configuration management, drift detection, and enforcement of secure baselines.
Lead endpoint hardening, and monitoring strategies to reduce endpoint-related risks.
Direct mobile security initiatives to protect devices and applications through policy enforcement and monitoring.
Oversee endpoint and mobile security tooling strategy to enable consistent protection and compliance across the enterprise
Lead enterprise data protection capabilities, including endpoint, network, and cloud DLP programs.
Oversee design, implementation, and optimization of DLP tooling to monitor and prevent unauthorized data access, use, or exfiltration.
Establish and manage Data Security Posture Management (DSPM) capabilities to discover, classify, and assess sensitive data across environments.
Ensure alignment of data protection controls with regulatory requirements, privacy standards, and enterprise policies.
Define and enforce security configuration standards across systems, infrastructure, and endpoints.
Oversee configuration drift detection and remediation processes to maintain secure and compliant baselines.
Collaborate with IT and engineering teams to ensure secure configurations are embedded into system builds and deployment pipelines.
Drive continuous improvement of configuration management practices to reduce exposure and improve resilience.
Lead engineering and optimization of exposure management tools, including vulnerability management, CNAPP, CASB, DLP, and endpoint security platforms.
Define use cases, technical requirements, and configurations to enhance detection, monitoring, and remediation capabilities.
Drive automation of exposure detection, prioritization, and remediation workflows to improve efficiency and scalability.
Ensure integration of exposure management tools with broader cybersecurity platforms and processes.
Collaborate with cybersecurity, IT, engineering, and business teams to integrate exposure management into enterprise processes and initiatives.
Partner with risk and compliance teams to align exposure management activities with enterprise risk frameworks and regulatory requirements.
Provide actionable insights and reporting to leadership on exposure trends, remediation progress, and risk reduction outcomes.
Support audit and regulatory activities by providing documentation and evidence related to exposure management practices.
Define and track KPIs and KRIs related to vulnerability management, configuration compliance, and exposure reduction.
Provide regular reporting to leadership on security posture, exposure trends, and remediation effectiveness.
Identify opportunities to enhance exposure visibility, prioritization accuracy, and remediation efficiency.
Drive continuous improvement initiatives to mature exposure management capabilities.
Build and lead a high-performing exposure management team with capabilities across vulnerability management, cloud security, endpoint security, and data protection.
Develop team capabilities through training, mentoring, and structured career development initiatives.
Foster a culture of accountability, collaboration, and continuous improvement.
Ensure alignment of team capabilities with evolving threat landscape and organizational needs.
Qualifications
Ideally targeting individuals with 10+ years of experience in cybersecurity, with a focus on vulnerability management, cloud security, endpoint security, or data protection.
Deep expertise in exposure management practices, including vulnerability assessment, configuration management, and risk-based prioritization.
Strong understanding of cybersecurity frameworks (e.g., NIST CSF, ISO 27001) and regulatory requirements.
Experience leading security engineering and operational teams focused on exposure reduction and risk mitigation.
Demonstrated ability to collaborate with cross-functional teams and influence technical and business stakeholders.
Strong leadership, analytical, and problem-solving skills.
Experience in highly regulated industries, a plus.
Experience with modern cloud security, network security, and data protection technologies, a plus.
#LI-LP
#LI-Remote
Anticipated salary range: $135,400 - $208,100
Bonus eligible: Yes
Benefits: Cardinal Health offers a wide variety of benefits and programs to support health and well-being.
Medical, dental and vision coverage
Paid time off plan
Health savings account (HSA)
401k savings plan
Access to wages before pay day with myFlexPay
Flexible spending accounts (FSAs)
Short- and long-term disability coverage
Work-Life resources
Paid parental leave
Healthy lifestyle programs
Application window anticipated to close: 07/01/2026 *if interested in opportunity, please submit application as soon as possible.
The salary range listed is an estimate. Pay at Cardinal Health is determined by multiple factors including, but not limited to, a candidate's geographical location, relevant education, experience and skills and an evaluation of internal pay equity.
Candidates who are back-to-work, people with disabilities, without a college degree, and Veterans are encouraged to apply.
Cardinal Health supports an inclusive workplace that values diversity of thought, experience and background. We celebrate the power of our differences to create better solutions for our customers by ensuring employees can be their authentic selves each day. Cardinal Health is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, ancestry, age, physical or mental disability, sex, sexual orientation, gender identity/expression, pregnancy, veteran status, marital status, creed, status with regard to public assistance, genetic status or any other status protected by federal, state or local law.
To read and review this privacy notice click here (
$135.4k - $208.1k
...What Cybersecurity Defense contributes to Cardinal Health Cybersecurity Defense focuses heavily... ...infrastructure at Cardinal Health. The Director, Cyber Detection & Response is... ...for SOC, incident response, and threat management functions. Serve as an advisor to leadership...SuggestedTemporary workLocal areaImmediate startRemote workFlexible hours- ...LMI is seeking a Technical Program Manager to support a DOD Army Program. The Technical... ...and collaboration, LMI serves the defense, space, healthcare, and energy sectors—helping... ...policies, and ethics as they relate to cybersecurity. Knowledge of cybersecurity principles...SuggestedContract workFor contractorsWork experience placementShift work
$145k - $220k
Technical Program Manager Job Locations US-DC-Washington, DC Job ID 2026-139... ...agility and collaboration, LMI serves the defense, space, healthcare, and energy sectors-... ...standards * Ensure compliance with cybersecurity, data governance, and AI risk management...SuggestedFull timeContract workFor contractorsWork at officeLocal area- ...Senior Technical Program Manager – IT & Cyber Support Barbaricum is a rapidly growing... ...federal customers, with a particular focus on Defense and National Security mission sets. We... ...Manager to support enterprise IT and cybersecurity initiatives under the Military Community...SuggestedContract workFor contractors
- ...Technical Program Manager Arlington, Virginia To drive our growth strategy in the... ...market of autonomous robotic systems in defense we're looking for a Technical Program Manager... ..., including export controls and cybersecurity requirements. Drive continuous improvement...SuggestedContract work
$172.4k - $360.8k
...technology and ingenuity for clients across defense, national security, public safety,... ...implement, and maintain secure network and cybersecurity architectures for federal government... ...and stakeholders. Excellent people management and relationship development skills...Live inWork at officeLocal area$109.2k - $223.4k
...Job Description The Director for Global Defense - Japan is responsible for leading and growing... ...roles, with significant Japan market exposure. Working proficiency in Japanese... ...forecasting, governance) Stakeholder management in highly regulated environments...Contract workTemporary workFor contractorsLocal areaFlexible hours- ...security capabilities such as SWG, malware defense, RBI, CASB and data loss prevention to... ...The Federal Technical Account Manager will play an advisory role to our federal... ...experience with enterprise networks, systems, cybersecurity and sales engineering or technical account...Remote work
$9k
...the experience, you will gain exposure to MTSI's employee-first... ...technologies. Program Management: Track program and system... ...prioritize mission success and cybersecurity compliance.... ...professional network within the defense industry Be considered for...Full timeFor contractorsWork experience placementWork at officeImmediate startWorldwideFlexible hours- ...Technical Program Manager - SkillBridge Anduril Industries is a defense technology company with a mission to transform U.S. and allied military capabilities... ...systems software development. This position will have exposure to a wide variety of program planning, organization...Immediate startRelocation
- ...Program Manager At RTX, the world's largest aerospace and defense company, 185,000 great minds are united by purpose and inspired to make a difference solving... ...progress tracking. What You Will Learn: Exposure to cutting-edge technical work and innovative...For subcontractorNight shift
- HUMAN RESOURCES (HR) MANAGER MILITARY FRIENDLY & SKILLBRIDGE SPONSOR... ...Business (SDVOSB) providing cybersecurity, Enterprise IT, and... ...with executive leadership, Directors, and Program / Project Managers... ...federal workforce regulations. Exposure to personnel management,...Contract workFor contractorsLocal areaRemote work
- ...University of Maryland, College Park. This internal search seeks a Director to lead the institute, which focuses on computational science across national defense, precision medicine, big data, cybersecurity, language and culture, and other areas. Position: Institute...Work at office
- Anduril Industries is a defense technology company with a mission to transform U.S. and... ...expands, we are seeking Technical Program Managers to focus on the challenges of... ...software development. This position will have exposure to a wide variety of program planning, organization...Full timeWork experience placementImmediate startRelocation
$9k
...the experience, you will gain exposure to MTSI's employee‑first... ...PMAS technologies. Program Management Track program and system performance... ...mission success and cybersecurity compliance. Compliance and... ...professional network within the defense industry Be considered for...Full timeFor contractorsWork experience placementWork at officeImmediate startFlexible hours$114k - $221k
...technology and ingenuity for clients across defense, national security, public safety,... ...results and mission impact. Backlog management, roadmap ownership, KPI definition, experimentation... ...search, catalog/lineage tooling. Exposure to LLM evaluation frameworks, prompt...Live inWork at officeLocal area- ...About The Role: Innovative Defense Technologies (IDT), a leading software defense technology company, is seeking a Director of Contracts to be part of our Business Strategy team... ...audit readiness across the portfolio. ~Manage and oversee all prime contract and...Full timeContract workFor contractorsWork at officeImmediate start
$120k
...Director of Outreach Job no: 536326 Work type: Administrative & Professional Senior management: Vice President for Research Department: Commonwealth Cyber... ...CCI) is Virginia's central hub for cybersecurity research, innovation, and workforce...Work at office- ...Senior Director of Capture Management About the Company Multi-billion-dollar federal service contractor serving defense, intelligence, civilian, and international markets. Industry Defense & Space Type Privately Held About the Role The Company is...For contractors
- ...Director, Cyber Threat Intelligence (CTI) The Director, Cyber... ...capability that enables proactive defense of BNY's global platforms,... ...grade assessments; sets and manages intelligence requirements;... ...in intelligence studies, cybersecurity, international relations, or...Shift work
$180k - $280k
...Asia Pacific. The ideal candidate will have over 10 years of experience in defense or international business, showcasing strong leadership and communication skills. Responsibilities include managing high-level engagements and collaborating with senior teams to further...$152.7k - $294k
...Exceptional program leadership and stakeholder management skills. Proven ability to lead cross‑... ...domains and technologies - including cybersecurity architecture, risk management, identity... ...in a large multinational company, with exposure to global teams and an understanding of...Summer holidayFlexible hoursShift work- ...Industry Non-Profit Organization Management Type Non Profit Founded 1982... ...nonprofit events programs and defense About the Role The Company is seeking... ...includes working closely with the Board of Directors to leverage relationships, leading external...
- ...one another. If you are driven to shape the future of aerospace, defense, and national security through innovation in domestic supply... ...Are Looking For: Phoenix Tailings is looking for a Senior Director of Government Affairs to lead and execute our federal engagement...
$130.9k - $154k
...looking for an Internal Audit IT Associate Manager to join the Internal Audit team focusing... ...for the Audit Committee and Board of Directors. Validate the effectiveness of control... ...with both first and second lines of defense to maximize meetings utility, testing efficiencies...Local area- FTI Consulting, Inc is seeking a Director in Cybersecurity based in Washington, DC. The role involves leading complex cybersecurity engagements, managing teams, and developing investigative strategies within a collaborative environment. Ideal candidates will have over...
$144k - $180k
United Way Worldwide is looking for a Senior Director, Privacy and Cybersecurity in Alexandria, VA. This role requires extensive expertise in developing and managing privacy and cyber initiatives, compliance with privacy regulations, and leading a team. The ideal candidate...Worldwide$120k
...thought leadership from technology, hardware, software, services, and related industries. Position Director of Policy, Cybersecurity and Supply Chain Risk Management Location Washington, DC Job Id 172 Summary As the Director of Policy, Cybersecurity and Supply Chain...For contractorsWork experience placementWorldwide$191k - $253k
A defense technology company is seeking an International Advanced Effects lead for the Air Dominance and Strike Division. This role involves generating and capturing international business opportunities with a focus on missile systems, requiring travel up to 75%. Candidates...$180k - $250k
A defense technology firm located in Arlington, Virginia, is looking for a Director of Fielded Autonomy. This leadership role entails overseeing the integration of core autonomy software into customer-facing platforms and guiding the engineering team through the entire...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Director, Exposure Management (Cybersecurity Defense). Be the first to apply!
- director lease administration Washington DC
- erp director Washington DC
- residence director Washington DC
- director of foundation relations Washington DC
- director of benefits Washington DC
- nonprofit director Washington DC
- director of video production Washington DC
- senior director it Washington DC
- director biotech Washington DC
- alliance director Washington DC


