Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

VP - Cybersecurity Governance, Risk & Compliance

$176.4k - $298.32k

Cardinal Health

What Information Security and Risk contributes to Cardinal Health

Information Technology oversees the effective development, delivery, and operation of computing and information services. This function anticipates, plans, and delivers Information Technology solutions and strategies that enable operations and drive business value.

Information Security and Risk develops, implements, and enforces security controls to protect the organization's technology assets from intentional or inadvertent modification, disclosure or destruction. This job family develops system back-up and disaster recovery plans. Information Technology also conducts incident response, threat management, vulnerability scanning, virus management and intrusion detection and completes risk assessments.

Job Summary

The Vice President - Cybersecurity Governance, Risk & Compliance is a senior executive responsible for establishing, leading, and evolving the enterprise-wide cybersecurity governance, risk management, compliance, resilience, and third-party oversight strategy. This individual will ensure that cybersecurity risks are effectively identified, managed, and communicated in alignment with business objectives, regulatory requirements, and enterprise risk frameworks.

The role requires a seasoned leader with deep expertise in cybersecurity GRC, including risk management, regulatory compliance, policy and standards, third-party risk oversight, cyber resilience, disaster recovery, and security awareness. This individual will play a critical role in embedding security and risk-informed decision-making across the business, enabling scalable governance processes, and ensuring organizational readiness for evolving regulatory, operational, and threat landscapes. The ideal candidate brings divers perspectives gained through leadership experience across multiple organizations, industries, regulatory environments or large-scale transformation initiatives. This position reports to the SVP, Chief Information Security Officer (CISO).

Responsibilities

Organizational Leadership & Governance

  • Support CISO in operating a cybersecurity governance program that defines policies, standards, roles, and accountability structures across the enterprise

  • Serve as an advisor to executive leadership and the board on cybersecurity risk posture, regulatory exposure, and compliance readiness

  • Establish and maintain governance processes that ensure alignment between cybersecurity initiatives, enterprise risk management, and business objectives

  • Drive integration of cybersecurity governance into enterprise decision-making, transformation initiatives, and operational processes

  • Foster a culture of accountability, transparency, and risk awareness across the organization

Cyber Policy, Standards & Controls Governance

  • Maintain, and enforce cybersecurity policies and standards aligned with regulatory requirements, industry frameworks, and enterprise objectives

  • Oversee policy lifecycle management, including development, review, approval, communication, and enforcement

  • Establish and maintain a centralized controls inventory to track security controls and associated requirements across systems and applications. Ensure effective communication and adoption of policies and standards across business and technology teams

Cyber Risk Management & ERM Integration

  • Operationalize a standardized cybersecurity risk management framework, taxonomy, and methodology aligned to enterprise risk management practices

  • Oversee cyber risk assessments, including identification, evaluation, and prioritization of threats and vulnerabilities

  • Establish and maintain GRC platform to track risks, remediation activities, and risk ownership across cybersecurity and business teams

  • Oversee risk response and remediation strategies so that appropriate mitigation plans are developed, executed, and monitored

  • Partner with Enterprise Risk Management (ERM) to align cyber risks with broader organizational risk frameworks and reporting structures

Regulatory Compliance & Assurance

  • Oversee cybersecurity compliance programs to support adherence to applicable regulatory, legal, and industry requirements (e.g., SOX, HIPAA, PCI, HITRUST, SOC 2)

  • Establish and maintain processes for internal and external compliance assessments, including audit support, evidence management, and remediation tracking

  • Oversee internal compliance management efforts to enforce adherence to security policies, standards, and controls

  • Direct external compliance activities, including customer assessments, regulatory reviews, and third-party audits

  • Ensure continuous monitoring of the regulatory landscape to proactively adapt compliance programs and controls

Cyber Third Party Risk Management

  • Oversee the cybersecurity third-party risk management (TPRM) program, including risk assessments, onboarding, monitoring, and offboarding processes

  • Establish governance for third-party lifecycle management to ensure risks are identified, assessed, and mitigated throughout vendor engagements

  • Oversee contract reviews to validate inclusion of security and data protection requirements

  • Collaborate with internal stakeholders and external providers to develop joint incident response plans and ensure alignment with enterprise security expectations

  • Drive integration of third-party risk insights into overall cybersecurity risk posture and reporting

Cyber Resilience, Disaster Recovery & Crisis Management

  • Define and lead enterprise cyber resilience strategy, including IT resilience assessments and dependency mapping to identify critical system vulnerabilities

  • Oversee development and maintenance of disaster recovery (DR) and business continuity plans for IT systems and operational environments

  • Direct execution of disaster recovery testing and simulation exercises to validate effectiveness of recovery strategies and plans

  • Oversee crisis management coordination, including establishment of governance structures, escalation protocols, and communication processes for major incidents

  • Ensure alignment between resilience, incident response, and business continuity strategies

Metrics, Reporting & GRC Tooling

  • Establish and oversee cybersecurity metrics and reporting frameworks, including KPIs and KRIs, to measure program performance and risk posture

  • Provide regular reporting and insights to executive leadership and the board to support strategic decision-making

  • Oversee the design, implementation, and optimization of GRC tools and platforms to enable efficient risk, compliance, and control management

  • Leverage data analytics to drive transparency, prioritization, and continuous improvement across GRC functions

Cyber Training, Awareness & Culture

  • Support and oversee the enterprise-wide cybersecurity training and awareness programs to promote secure behaviors and risk awareness

  • Oversee role-based and executive training initiatives to ensure accountability and understanding of cybersecurity responsibilities

  • Direct phishing simulation programs and awareness campaigns to strengthen organizational resilience against social engineering threats

  • Promote continuous learning and capability development across cybersecurity and business teams

Stakeholder Engagement & Business Integration

  • Partner with business units, IT, legal, audit, and compliance teams to embed cybersecurity governance, risk, and compliance practices into business operations

  • Serve as a liaison between cybersecurity and enterprise stakeholders to ensure alignment on risk priorities and compliance requirements

  • Collaborate with security architecture and engineering teams to ensure solutions align with established security standards and policies

  • Drive consistent communication, reporting, and alignment across global cybersecurity and business teams

Talent Leadership & Program Maturity

  • Build and lead a global GRC organization with capabilities spanning risk management, compliance, resilience, third-party risk, and governance

  • Develop team capabilities through coaching, structured career development, and role-based training

  • Drive continuous improvement of GRC processes, frameworks, and tools to enhance program maturity and scalability

  • Establish succession planning and leadership development to sustain long-term organizational capability

Qualifications

  • 12+ years of progressive experience in cybersecurity, risk management, compliance, or information security leadership roles preferred

  • Demonstrated expertise in cybersecurity governance, risk management frameworks, regulatory compliance, and enterprise risk integration

  • Proven experience developing and leading enterprise-wide GRC programs, including risk assessment, compliance, and governance processes

  • Strong understanding of cybersecurity frameworks (e.g., NIST CSF, ISO 27001) and regulatory requirements

  • Demonstrated experience presenting to executive leadership, audit committees, and board members

  • Strong leadership, communication, and stakeholder management skills with the ability to influence across the organization

  • Experience serving in a senior cyber leadership role (e.g., VP, Head of GRC, or equivalent) reporting to a CISO, CIO or CRO

  • Demonstrated experience operating at the executive leadership level, driving strategic outcomes, influencing enterprise risk & governance, and tech compliance discussions with senior executives, boards and regulators

  • Experience in highly regulated industries (e.g., aviation, financial services, healthcare, or government)

  • Advanced degree (MBA, MS in Cybersecurity, Information Systems, or related field) preferred

  • Professional certifications such as CISSP, CISM, CRISC, CISA, or similar

  • Experience implementing or managing GRC platforms and enterprise risk tools

What is expected of you and others at this level

  • Provides leadership and direction for multiple operational units or disciplines through; Directors may manage Managers

  • Manages an organizational budget

  • Approves significant policies and procedures that will result in the achievement of organizational goals

  • Develops and implements functional and/or operational strategy

  • Decisions have a serious impact on overall success or failure on area of accountability and external stakeholders

  • Interacts with all levels of internal and/or external leaders

  • Influence senior level leaders regarding matters of significance

Anticipated salary range: $176,400 - $298,320

Bonus eligible: Yes

Benefits: Cardinal Health offers a wide variety of benefits and programs to support health and well-being.

  • Medical, dental and vision coverage

  • Paid time off plan

  • Health savings account (HSA)

  • 401k savings plan

  • Access to wages before pay day with myFlexPay

  • Flexible spending accounts (FSAs)

  • Short- and long-term disability coverage

  • Work-Life resources

  • Paid parental leave

  • Healthy lifestyle programs

Application window anticipated to close: 6/12/26 *if interested in opportunity, please submit application as soon as possible. The salary range listed is an estimate. Pay at Cardinal Health is determined by multiple factors including, but not limited to, a candidate's geographical location, relevant education, experience and skills and an evaluation of internal pay equity.

Candidates who are back-to-work, people with disabilities, without a college degree, and Veterans are encouraged to apply.

Cardinal Health supports an inclusive workplace that values diversity of thought, experience and background. We celebrate the power of our differences to create better solutions for our customers by ensuring employees can be their authentic selves each day. Cardinal Health is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, ancestry, age, physical or mental disability, sex, sexual orientation, gender identity/expression, pregnancy, veteran status, marital status, creed, status with regard to public assistance, genetic status or any other status protected by federal, state or local law.

To read and review this privacy notice click here (

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the VP - Cybersecurity Governance, Risk & Compliance in Boston, MA vacancy
  • $110k - $207.5k

     ...VP - Head of Legal Technology Corporate Functions Technology...  ...embedding strong security, risk, and compliance capabilities across all...  .... Partner with Cybersecurity, Risk, Audit, and Compliance...  ...Business Partnership & Governance Serve as the primary... 
    Suggested
    Full time
    Contract work
    Temporary work
    Work at office
    Flexible hours

    State Street Corporation

    Quincy, MA
    3 days ago
  • $250k - $260k

     ...of NextGen managed services, delivering cybersecurity-first, cloud, infrastructure, AI-driven...  ...offerings to improve outcomes (speed, quality, risk) and drive accretive revenue, margin...  ...offerings.  ~ Define and lead AI governance, internal enablement, and client-facing... 
    Suggested

    THRIVE

    Boston, MA
    2 days ago
  • $110k - $207.5k

    VP - Head of Legal TechnologyCorporate Functions TechnologyLocation...  ...embedding strong security, risk, and compliance capabilities across all...  ...resiliency.Partner with Cybersecurity, Risk, Audit, and...  ...intake, prioritization, and governance processes for Legal demand.... 
    Suggested
    Contract work
    Temporary work
    Work at office
    Flexible hours

    STATE STREET CORPORATION

    Quincy, MA
    4 days ago
  •  ...Senior Vice President, Legal and Chief Compliance Officer (CCO) About the Company Nationally recognized healthcare services...  ...-level role that directly impacts organizational strategy, governance, and risk posture. The successful candidate will be a trusted advisor... 
    Suggested

    Confidential

    Boston, MA
    1 day ago
  •  ...VP, US Medical Affairs Come and Save Lives with Us! SERB is...  ...evidence generation while ensuring compliance with regulatory, legal, and...  ...deep experience navigating governance, scale, and complexity while maintaining...  ...scientific integrity and risk management. Establish clear... 
    Suggested
    Local area
    Immediate start
    Worldwide

    SERB Pharmaceuticals

    Boston, MA
    4 days ago
  •  ...VP, Technology Growth and Strategy About the Company Global talent marketplace connecting businesses with top freelance professionals...  ...solution innovation in areas such as AI, cloud modernization, cybersecurity, and enterprise integration. The VP will also be instrumental... 
    Freelance
    Remote work

    Confidential

    Boston, MA
    1 day ago
  • $110k - $188.75k

     ...The Vice President, Risk & Compliance Operations is a Research and Insights leadership role with responsibility for critical governance, risk, and compliance operations. This role owns Third...  ...support across the organization. The VP partners closely with senior stakeholders... 
    Temporary work
    Flexible hours

    State Street Corporation

    Cambridge, MA
    2 days ago
  • $120k - $210k

     ...Who we are looking for State Street Global Technology Services (GTS) is seeking a skilled and proven Technology Risk Remediation Governance Manager, Vice President to uplift its risk and regulatory portfolio governance while bringing connectivity and consistency... 
    Temporary work
    Flexible hours

    State Street Corporation

    Quincy, MA
    3 days ago
  • $200k - $230k

    Black Kite is hiring a VP, Channel to own and lead our channel...  ...channel organizations in cybersecurity or SaaS. Partners are central...  ...structures, and partner portal governance. Build partner engagement models...  ...cybersecurity, third‑party risk management, or cyber risk... 
    Flexible hours

    Blackkite

    Boston, MA
    5 days ago
  • A leading global asset manager is seeking a VP Client Service Manager to drive impactful change through exceptional client service. You will oversee a portfolio of asset manager clients, ensuring high standards of service across Custody and Fund Administration. The ideal... 

    JPMorgan Chase & Co.

    Boston, MA
    5 days ago
  • STATE STREET CORPORATION is seeking a Senior Leader to drive technology strategy across corporate functions such as GHR, Audit, Risk, and Compliance. This role requires significant experience in managing execution and stakeholder engagement, focused on managing a large... 

    STATE STREET CORPORATION

    Boston, MA
    4 days ago
  • $297.5k - $402.5k

     ...the SVP, General Counsel, Corporate and Governance, this role will evolve, lead and execute...  ...accountability for employment-related legal risk management, governance, policy...  ...closely with HR, Talent Acquisition, Ethics & Compliance, and business leaders across the organization... 
    Full time
    Temporary work
    Local area
    Flexible hours

    Alnylam

    Cambridge, MA
    3 days ago
  •  ...PMO Lead based in Boston, MA. This role is crucial for program governance and involves authority over framework and quality gates. The PMO...  ...like JIRA and Confluence. High-impact communication skills and risk management expertise are essential for success. #J-18808-... 

    State Street

    Boston, MA
    1 day ago
  • $230k

     ...and experiments into a governed, reusable, and...  ...productivity platforms. The VP will build and lead a...  ..., Data, Architecture, Risk Governance, and business...  ..., Legal, Risk, Compliance, Data, Architecture, and...  ...observability, automation, cybersecurity, identity, privacy,... 
    Full time
    Temporary work
    For contractors
    Work at office
    Remote work
    Home office
    Flexible hours

    The Mutual Group

    Boston, MA
    5 days ago
  • $350k

     ...implementation of process improvement initiatives to enhance patient safety and quality measures across the continuum of care. Assures compliance with TJC, OSHA, DPH, and state and federal regulations. Partners with Compliance for audits as needed and/or directed. In... 
    Work at office
    Local area

    Mass General Brigham (Enterprise Services)

    Boston, MA
    1 day ago
  •  ...companies with a significant headcount. Board-level confidence, the ability to lead high-impact special projects, and a proactive approach to risk management are essential. Hiring Manager Title CEO Travel Percent Less than 10% Functions Operations Ecommerce Marketing... 

    Confidential

    Boston, MA
    1 day ago
  • Job Type Full-time Description This is a full-time, onsite leadership role based in Cambridge, MA. Given the hands-on, collaborative nature of this position, we are not considering remote, hybrid-remote, or relocation candidates at this time. Only applicants...
    Full time
    Relocation

    Marengo Therapeutics, Inc.

    Cambridge, MA
    2 days ago
  •  ...seeking a visionary and deeply technical leader to join our Global Cybersecurity organization. As the Sr. Director, Platform Security &...  ...and model training to deployment and continuous monitoring. Governance & Operations: Establish a scalable operating model for AI... 
    Local area

    Liberty Information Technology Limited

    Boston, MA
    1 day ago
  •  ...communications, and resolving cross-functional blockers. The role is fully remote and requires a proactive individual who can surface risks and close gaps effectively. Hiring Manager Title Chief Executive Officer (CEO) Travel Percent Less than 10% Functions... 
    Remote work

    Confidential

    Boston, MA
    2 days ago
  • Downtown Boulder Partnership seeks a Chief Executive Officer (CEO) in Boston, MA to lead a dynamic company focused on wellness and innovation. The ideal candidate will exhibit strong leadership and financial management skills, crucial for operational success and growth....
    Full time
    Part time

    Downtown Boulder Partnership

    Boston, MA
    1 day ago
  • $115k - $150k

     ...High degree of integrity, discretion, and good judgment in handling sensitive information Ability to anticipate needs, identify risks early, and solve problems quickly and independently Education Preferred: ~ B.A or B.S degree or equivalent experience... 
    Work at office
    Local area
    Remote work
    Shift work
    1 day per week

    Harbourvest

    Boston, MA
    2 days ago
  • $100k - $175k

     ...across tools such as Glean, ChatGPT, CoPilot, and Zoom AI. The VP will collaborate closely with Data, Infrastructure, Security, and...  ...ensure enterprise systems are AI-ready—balancing innovation with governance and scalability. The ideal candidate has strong technical... 
    Work at office
    Local area
    Remote work
    2 days per week

    Accordion USA

    Boston, MA
    5 days ago
  • $160k - $200k

     ...re a women-founded and led agency serving innovators across B2B and B2C technology, AI, digital healthcare, financial services, cybersecurity, and manufacturing. Our award-winning, data-driven strategies help clients become market leaders. Our approach blends senior-... 
    Full time
    Work at office

    Tier One Partners

    Boston, MA
    1 day ago
  • $68k - $150k

     ...regulatory standards. Advises team on process changes needed to ensure compliance with any new standards. Leads working relationships with...  ...presenting fund reports to Board of Directors to ensure good governance and communication of fund status. No direct reports. Provides... 
    Temporary work
    Work experience placement

    BNY

    Boston, MA
    5 days ago
  •  ...About the Company Internationally renowned data security & governance company Industry Computer & Network Security Type...  ...Equity-backed About the Role The Company is seeking a Global VP, FP&A to join their team. This executive will be a key partner... 

    Confidential

    Boston, MA
    2 days ago
  •  ...across functional partners and ensure adherence to the firm's risk, controls, compliance, and regulatory requirements Effectively manage...  ...Assists senior department leadership with project staffing and governance decisions. Leads/influences less experienced members of... 
    Work at office

    Chase

    Boston, MA
    3 days ago
  •  ...Categories ~ Education Specialties computer technology electronics manufacturing electrical engineering cybersecurity opticianry hvac& refrigeration construction management automotive technology electric vehicles software development... 

    Confidential

    Boston, MA
    1 day ago
  • $297k - $340k

     ...KOLs and lead clinical investigators. Requirements • MD training in psychiatry and/or neuroscience required. • 8+ (ED) 10+(VP) years of clinical development experience within a biotech/pharmaceutical setting with a strong track record of successful clinical program... 
    Casual work

    Seaport Therapeutics

    Boston, MA
    4 days ago
  •  ...minimum of 10 years' professional experience, with at least 5 years in senior leadership, and a proven track record in regulatory compliance, safety management, and data analysis. They must possess strong collaboration and communication skills, be detail-oriented, and... 
    Work at office
    Flexible hours

    Confidential

    Newton, MA
    1 day ago
  • Overview The Committee for Public Counsel Services, the public defender agency of Massachusetts, is seeking a Chief Operating Officer to provide strategic advice and support to the Chief Counsel on the management of daily operations of the agency. We fight...
    Remote work

    Committee for Public Counsel Services

    Boston, MA
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to VP - Cybersecurity Governance, Risk & Compliance. Be the first to apply!