Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Director, Cyber Compliance (Information Security)

$137.4k - $232.32k
Full-time

Cardinal Health

What Information Security and Risk contributes to Cardinal Health
Information Security and Risk develops, implements, and enforces security controls to protect the organization's technology assets from intentional or inadvertent modification, disclosure or destruction.

The Director, Cyber Compliance is responsible for establishing, leading, and continuously the cybersecurity compliance program to ensure adherence to regulatory, legal, and internal policy requirements. Reporting to the Vice President, Global Cybersecurity Governance, Risk & Compliance (GRC), this role drives the design and execution of compliance frameworks, assessments, and processes to support secure and compliant business operations. Furthermore, this leader oversees regulatory compliance management, internal and external compliance assessments, privacy and SOX compliance, and specialized regulatory domains such as FDA GxP. The Director serves as a partner and advisor to cybersecurity, IT, legal, audit, and business teams to ensure compliance obligations are understood, operationalized, and continuously monitored in alignment with enterprise risk and governance strategies.

Location - Fully remote, open to candidates based nationwide

Responsibilities

  • Develop and lead a cybersecurity compliance program aligned with regulatory requirements, risk frameworks, and business objectives.
  • Establish governance structures, processes, and accountability models to enable consistent execution of compliance activities across the organization.
  • Serve as an advisor to cybersecurity and business leadership on regulatory requirements, compliance risks, and remediation priorities.
  • Drive alignment between compliance initiatives and broader cybersecurity, risk, and governance strategies.
  • Establish and maintain processes to ensure compliance with applicable cybersecurity regulations and standards (e.g., SOX, HIPAA, PCI, GDPR, CMMC).
  • Monitor regulatory changes and emerging requirements to proactively adapt compliance programs and controls.
  • Oversee compliance validation processes to ensure cybersecurity practices meet regulatory expectations.
  • Provide leadership and oversight for regulatory audits, reviews, and inquiries.
  • Enforce adherence to internal security policies, standards, and controls.
  • Develop internal compliance assessment programs to evaluate systems, applications, and processes against defined security requirements.
  • Identify compliance gaps and partner with stakeholders to define and execute remediation plans.
  • Oversee continuous monitoring of compliance posture and alignment with internal governance frameworks.
  • Oversee external compliance activities, including preparation of compliance evidence and responses to customer and third-party inquiries.
  • Lead external compliance assessments and certifications (e.g., SOC 2, PCI, CMMC), enabling compliance readiness and successful outcomes.
  • Coordinate with business and technology teams to support customer-driven compliance requirements and audits.
  • Ensure consistency and accuracy of compliance responses and documentation across the organization.
  • Oversee SOX IT General Controls (ITGC) compliance processes, including validation, monitoring, and remediation of control deficiencies.
  • Lead privacy compliance efforts to ensure systems and data handling practices align with applicable privacy regulations (e.g., HIPAA, GDPR).
  • Oversee specialized compliance programs such as FDA GxP, enabling adherence to regulatory requirements for systems supporting regulated products.
  • Collaborate with legal and regulatory teams to interpret requirements and translate them into actionable controls and processes.
  • Establish and maintain compliance readiness programs to ensure ongoing audit preparedness and regulatory alignment.
  • Monitor compliance metrics and indicators to assess program effectiveness and identify emerging risks.
  • Drive continuous improvement of compliance processes, tools, and methodologies to improve efficiency and scalability.
  • Enable integration of compliance monitoring with broader cybersecurity risk management and reporting frameworks.
  • Collaborate with cybersecurity, IT, legal, audit, and business teams to embed compliance requirements into enterprise processes and technology solutions.
  • Serve as a liaison between compliance, risk, and operational teams to ensure alignment and coordination of activities.
  • Provide guidance to project teams to ensure compliance requirements are met and incorporated into new initiatives and system implementations.
  • Oversee internal and external audit activities by providing documentation, evidence, and subject matter expertise.
  • Define and track compliance metrics and key risk indicators (KRIs) to measure program effectiveness and regulatory adherence.
  • Provide regular reporting and insights to executive leadership on compliance posture, audit outcomes, and remediation progress.
  • Establish standardized reporting frameworks to enable consistency, transparency, and accountability across compliance activities.
  • Build and lead a high-performing cybersecurity compliance team with capabilities across regulatory compliance, assessments, and audit support.
  • Develop team capabilities through coaching, training, and structured career development initiatives.
  • Foster a culture of accountability, continuous improvement, and regulatory awareness across the organization.
  • Ensure appropriate resourcing and capability alignment to support evolving compliance requirements.


Qualifications

  • Ideally targeting individuals with 8+ years of experience in cybersecurity compliance, risk management, or information security, with a focus on regulatory compliance and audit.
  • Strong expertise in cybersecurity compliance frameworks, regulatory requirements, and audit processes.
  • Experience leading compliance programs, including internal and external assessments, audit management, and remediation efforts.
  • Strong understanding of cybersecurity frameworks (e.g., NIST CSF, ISO 27001) and regulatory requirements (e.g., SOX, HIPAA, GDPR, PCI).
  • Demonstrated ability to collaborate with cross-functional teams and influence stakeholders across the organization.
  • Strong leadership, communication, and analytical skills.
  • Experience in a people leader role overseeing cybersecurity compliance or GRC functions (preferred).
  • Experience in highly regulated industries (e.g., aviation, financial services, healthcare, or government), preferred.
  • Professional certifications such as CISSP, CISM, CRISC, CISA, or similar, preferred.
  • Experience supporting specialized regulatory domains (e.g., FDA GxP, CMMC), preferred.

Anticipated Salary Range $137,400 - $232,320 USD

Bonus Eligible - Yes

Benefits: Cardinal Health offers a wide variety of benefits and programs to support health and well-being.

  • Medical, dental and vision coverage

  • Paid time off plan

  • Health savings account (HSA)

  • 401k savings plan

  • Access to wages before pay day with myFlexPay

  • Flexible spending accounts (FSAs)

  • Short- and long-term disability coverage

  • Work-Life resources

  • Paid parental leave

  • Healthy lifestyle programs

Application window anticipated to close : 09/30/2026 * if interested in opportunity, please submit application as soon as possible.

The salary range listed is an estimate. Pay at Cardinal Health is determined by multiple factors including, but not limited to, a candidate’s geographical location, relevant education, experience and skills and an evaluation of internal pay equity.

Candidates who are back-to-work, people with disabilities, without a college degree, and Veterans are encouraged to apply.

Cardinal Health supports an inclusive workplace that values diversity of thought, experience and background. We celebrate the power of our differences to create better solutions for our customers by ensuring employees can be their authentic selves each day.

Vacancy posted 8 days ago
Similar jobs that could be interesting for youBased on the Director, Cyber Compliance (Information Security) in United States vacancy
  •  ...SUMMARYThis role will serve as a key advisor on enterprise compliance, data privacy, and information security matters, helping the organization navigate an...  ...Review and negotiate vendor/third-party security terms, cyber insurance policies, and incident response... 
    Cyber
    Full time
    Contract work
    Work at office
    Local area
    Immediate start

    Greystar

    Charleston, SC
    2 days ago
  •  ...Cybersecurity Governance, Risk, and Compliance (GRC) program. This role...  ...practices. This leader drives a risk- informed culture and enables the business to innovate securely while maintaining compliance...  ...by translating technical and cyber risks into business-relevant impacts... 
    Cyber
    Local area
    Worldwide
    Flexible hours

    Intuitive Surgical

    Sunnyvale, CA
    4 days ago
  • Job Description Director, Global Governance, Risk, and Compliance (GRC) Location Westerville, OH (On-site) Reports to Global Chief Information Security Officer (CISO) Job Summary The Director of Global...  ...Committee Leadership: Lead our Cyber Risk Oversight Committee which is... 
    Cyber
    Temporary work
    Remote work

    Vertiv

    Westerville, OH
    4 days ago
  •  ...company policies. As the IT Compliance Manager , you’ll be in charge...  ...employees on best practices for security and compliance. Stay current...  ...Job function Job function Information Technology Industries Food and...  ...Intelligence, Vice President Manager - Cyber Compliance (FedRamp/CMMC)... 
    Cyber
    Full time
    Temporary work

    IMPACT STAFFING INTERNATIONAL

    Irving, TX
    2 days ago
  •  ...DescriptionServe as the IT security expert helping to create a strong information technology security...  ...to the Deputy Executive Director, Business and...  ...information security and compliance services to all supported...  ...and respond to advanced cyber threats• Coordinate and... 
    Cyber
    Work experience placement
    Work at office

    Virginia Tech

    Blacksburg, VA
    3 days ago
  • DescriptionThe Chief Compliance and Privacy Officer (CCPRCO) is accountable for the integrity, ethics...  ....Direct the enterprise HIPAA Privacy & Security Program in partnership with the Chief Information Security Officer (Cyber Security), including breach risk assessments... 
    Cyber

    The Tampa General Hospital Foundation

    Tampa, FL
    1 day ago
  • $107k - $214.5k

     ...cybersecurity professionals dedicated exclusively to serving the cyber security and information protection needs of our clients. This group includes...  ...affect their critical systems and achieving regulatory compliance related to the handling, processing and protection of... 
    Cyber
    Full time
    Work experience placement
    Internship
    Local area
    Shift work

    RSM International

    New York, NY
    3 days ago
  • $135.8k - $183.8k

    Verisign helps enable the security, stability, and resiliency of the internet...  ...manager to join an impactful Information Security Governance, Risk, and Compliance (GRC) team. In this role, you will...  ...Qualifications:Domain expertise in cyber security standard methodologies... 
    Cyber
    Work at office
    Immediate start
    Flexible hours

    VeriSign

    Reston, VA
    2 days ago
  • $61.9k - $141k

    Cybersecurity Compliance and Risk ManagerThe Opportunity: The Cybersecurity...  ..., software, and system‑level security across client infrastructures...  ...)3+ years of experience with cyber vulnerability assessment,...  ...Qualified Validator (NQV) or Information System Security Engineer (... 
    Cyber
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Newport, RI
    4 days ago
  •  ...Overview: We are seeking a Cybersecurity & Compliance Manager to oversee, maintain, and...  ..., regulatory compliance, security assessments, cyber insurance requirements, and third-party...  ...Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Information... 
    Cyber
    Fixed term contract
    Local area
    Monday to Friday

    Rivell

    Mantua, NJ
    5 days ago
  •  ...Overviewiboss is a cloud security company that enables the modern...  ...DescriptionThe Manager of Information Security & Compliance is a key leadership role...  ...systems and data. The Director of Information Security &...  ...27001, ISO 9001, SOC 1/2, Cyber Essentials, and FedRAMP to... 
    Cyber

    iBoss

    New York, NY
    3 days ago
  • $164.8k - $188.1k

    Manager, Cyber Audit and Regulatory Engagements Overview As a Manager of Cyber Audits...  ..., working closely with the Chief Information Security Officer and cross‑functional teams to...  ...vet) committed to non‑discrimination in compliance with applicable federal, state, and local... 
    Cyber
    Full time
    Temporary work
    Work at office
    Local area

    Capital One

    Plano, TX
    3 days ago
  • $164.8k - $188.1k

     ...Overview Manager, Cyber Audit and Regulatory Engagements As a Manager of Cyber...  ...You will work closely with the Chief Information Security Officer to curate topics and develop...  ...vet) committed to non-discrimination in compliance with applicable federal, state, and... 
    Cyber
    Full time
    Temporary work
    Part time
    H1b
    Work at office
    Local area

    Capital One

    Plano, TX
    more than 2 months ago
  • $118.3k - $219.8k

     ...exceptional professionals for this role. Manager, Security – Security Compliance & Risk Management Function: Information Security / Compliance & Risk Location: [Raleigh...  ...and initiatives (e.g., ISO 27001, SOC 2, Cyber Essentials) Perform regulatory horizon scanning... 
    Cyber
    Local area

    LexisNexis

    Raleigh, MS
    5 days ago
  • Head of Information Security, Risk & Compliance Glanbia plcJoin this dynamic team focused on delivering better nutrition for every step of life’s journey...  ...s security strategy, ensuring robust protection against cyber threats while maintaining regulatory and legal... 
    Cyber
    Worldwide

    Glanbia

    Dublin, GA
    4 days ago
  •  ...with intelligence analysis principles or cyber threat intelligence (CTI) principles,...  ...to collect, analyze, and assess threat information.Specific experience conducting CTI analysis...  ...findings to clients.Knowledge of information security and IT threats, attacks, and... 
    Cyber

    Maania Consultancy Services

    Arlington, VA
    3 days ago
  •  ...leading ICCU’s Governance, Risk, and Compliance (GRC) initiatives within the scope of...  ...role provides strategic oversight of cyber and IT operational risk assessments, regulatory...  ...and execute enterprisewide cyber and information security risk assessments and audits. A... 
    Cyber
    Full time
    Work experience placement
    Work at office

    Iccu

    Remote
    12 hours ago
  •  ...Management with exposure in Healthcare & info security Develop schedules and project plans to...  ...items, dependencies Work closely with information security specialists to understand and...  ...projects at regular intervals to Critical Stakeholders Experience in Cloud & Cyber Security
    Cyber

    HAN Staffing

    Bloomfield, CT
    4 days ago
  •  ...Analyst is a member of the IT Security team and works closely with...  ...core functions supporting the Information Security program. The GRC Analyst...  ...through the development and compliance of IT Security policies and...  ...Security Ops, Cyber Security or programming experience... 
    Cyber

    1872 Consulting

    Chicago, IL
    2 days ago
  •  ...Manager, IT Governance, Risk & Compliance The Manager, IT Governance...  ...resources together to ensure security, AI, and data governance are...  ...and analyze SOC reports, cyber insurance documentation, and...  ...reviews, and assessments of information systems; manage cross-functional... 
    Cyber
    Contract work

    American Institute for Chartered Propert

    Malvern, PA
    19 days ago
  •  ...any other source to fill one or more vacancies. This position is located in the Bureau of Diplomatic Technology, Office of Cyber Security Testing, Monitoring & Response (DT/CTMR) & monitors & conducts incident response for the Agency's classified/unclassified IT systems... 
    Cyber
    Work at office
    Remote work

    US Government Jobs

    United States
    5 days ago
  • Cyber Security Project Engineer TS/SCI FSPDepartment: Government Customer- HerndonLocation: Herndon, VACyber Security Project EngineerACTIVE...  ...includes malicious code detection, intrusion detection, and information security tool development and integration.Qualifications:... 
    Cyber

    Tenica and Associates

    Herndon, VA
    3 days ago
  • $200k - $250k

     ...client is looking to fill the role of Information Security Policy Manager. The Information Security...  ...examinations by providing evidence of compliance.Partner with the Information Security...  ...years of experience in information / cyber security experience, including 3+ years... 
    Cyber

    Solomon Page

    Greenwich, CT
    2 days ago
  •  ...in Tampa, FL is seeking an experienced information security professional to support DoD RMF processes, vulnerability management, and compliance activities within a federal environment...  ...to eMASS ATO packages, and assist with cyber incident response while maintaining essential... 
    Cyber

    Jobtailor

    Tampa, FL
    2 days ago
  •  ...customers and candidates have the most enjoyable and informational hiring experience that will encourage and foster...  ...for the position of Cybersecurity Analyst to provide Cyber Information Assurance (IA) and Security support on high-visibility contracts for the U.S. Navy... 
    Cyber
    Full time
    Contract work
    Work at office

    Connect Talent Solutions Llc

    Remote
    12 hours ago
  •  ...project management, applications development, infrastructure, Cyber security, and enterprise content/data management services. We have...  ...Systems (SMS, corporate ITIL certification), ISO 27001:2005 Information Security Management System (ISMS), and CMMI-DEV Level 3"... 
    Cyber
    Full time

    Comtech Inc

    Remote
    12 hours ago
  •  ...Senior Cybersecurity Risk Analyst to join the GRC organization. You will manage technical risk across the cloud and information assets, collaborating with security, engineering, IT and business teams. The role emphasizes AI-enabled risk assessments, risk mapping to controls... 
    Cyber

    Procore Technologies

    Austin, TX
    5 days ago
  • Required Qualifications:Eastern Europe-focused geopolitical and cyber threat intelligence experience Experience with cyber threat...  ..., defensive strategies, and prioritization Knowledge of information security and information technology threats, attacks, and vulnerabilities... 
    Cyber

    Maania Consultancy Services

    Arlington, VA
    4 days ago
  •  ...seeking a Senior Manager, M&A Security to lead cybersecurity...  ...individual will serve as the Information Security lead for M&A initiatives...  ...executive leadership, legal, compliance, infrastructure, application,...  ...and business teams to assess cyber risk, perform security due diligence... 
    Cyber

    Robert Half

    Cincinnati, OH
    4 days ago
  •  ...PolyDepartment: Government Customer- ChantillyLocation: Chantilly, VAPosition Description:The Cloud Information Systems Security Engineer provides support to the customer in the area of Cyber Security. Daily Tasks include, but are not limited to:Provides analytical and technical... 
    Cyber

    Tenica and Associates

    Chantilly, Loudoun County, VA
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Director, Cyber Compliance (Information Security). Be the first to apply!