Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Director, Application Security (Cybersecurity Defense)

$135.4k - $208.1k

Cardinal Health

What Cybersecurity Defense contributes to Cardinal Health

Cybersecurity Defense focuses heavily on threat detection, incident response, and implementing security measures to protect our digital assets and infrastructure at Cardinal Health. The Director, Application Security is responsible for establishing, leading, and evolving the enterprise application security strategy to embed security into the software development lifecycle (SDLC) and reduce application-layer risk across the business segments. This leader ensures that applications and APIs are designed, developed, and deployed in alignment with security policies & standards, regulatory requirements, and risk management objectives. This Director oversees segment-aligned application security capabilities across Pharma, Medical, and Commercial Technology environments, enabling consistent governance, scalable processes, and effective risk mitigation across diverse application portfolios.

Location - Open to candidates nationwide working in a fully remote capacity, with preference towards those based local to Central Ohio (willingness to travel into our Corporate HQ in Dublin, OH during certain period of the year is a plus)

Responsibilities

  • Lead the enterprise application security strategy aligned with cybersecurity, risk management, and business objectives.

  • Establish governance frameworks to embed security into the software development lifecycle (SDLC) across all application domains.

  • Collaborate with enterprise architecture, engineering, and product teams to align application security with technology strategies and transformation initiatives.

  • Serve as an advisor to executive and business leadership on application security risks, priorities, and investment decisions.

  • Drive a secure-by-design culture across development and engineering teams.

  • Oversee application security capabilities across Pharma, Medical, and Commercial Technology segments, ensuring consistent implementation of security practices.

  • Define segment-specific requirements and approaches to address unique regulatory, operational, and risk considerations.

  • Ensure alignment of application security practices across segments while enabling flexibility to support business-specific needs.

  • Drive standardization of processes, tooling, and reporting across segment application security teams.

  • Oversee enterprise application security testing programs, including SAST, DAST, SCA, and IAST across all application environments.

  • Ensure vulnerabilities are identified, assessed, prioritized, and remediated during the development lifecycle prior to deployment.

  • Establish secure coding standards and integrate security controls into CI/CD pipelines and development workflows.

  • Collaborate with development teams to reduce application security technical debt and improve code quality.

  • Oversee implementation of runtime security controls for applications and APIs, including WAF, API gateways, and runtime monitoring solutions.

  • Ensure security requirements are embedded into application and API design, deployment, and operational processes.

  • Collaborate with engineering and infrastructure teams to enforce runtime protections aligned with enterprise architecture.

  • Monitor runtime risks and coordinate mitigation efforts across application environments.

  • Lead development and integration of application security tooling, including configuration, onboarding, and operational management.

  • Define use cases, policies, and detection logic for application security tools to ensure effective coverage and scalability.

  • Drive integration of application security tools into CI/CD pipelines and DevSecOps workflows.

  • Ensure application security tooling aligns with enterprise security architecture and standards.

  • Collaborate with Security Architecture teams to define secure design patterns, reference architectures, and application security standards.

  • Ensure application security requirements are incorporated into solution design and architecture reviews.

  • Partner with engineering teams to implement secure development lifecycle (SDLC) practices and controls.

  • Support evaluation of new technologies and architectures to ensure alignment with security requirements.

  • Ensure application security practices align with regulatory requirements, compliance standards, and enterprise risk management frameworks.

  • Provide application security oversight for audits, regulatory assessments, and compliance reporting.

  • Collaborate with risk and compliance teams to translate application security risks into enterprise risk insights.

  • Support remediation of identified risks and ensure alignment with risk tolerance and governance processes.

  • Define and track KPIs and KRIs related to application security posture, vulnerability management, and SDLC integration.

  • Provide regular reporting to executive leadership on application security risks, trends, and program effectiveness.

  • Leverage data and analytics to drive continuous improvement in application security practices and outcomes.

  • Identify opportunities to enhance automation, efficiency, and scalability of application security processes.

  • Collaborate with application development, product, IT, security operations, and business teams to integrate application security into enterprise processes.

  • Partner with Cyber Detection & Response to ensure application security findings are integrated into monitoring and incident response workflows.

  • Engage with segment leaders to align application security initiatives with business priorities and risk considerations.

  • Support M&A activities by assessing and integrating application security controls for acquired applications.

  • Build and lead a high-performing application security organization with expertise across secure development, testing, and runtime protection.

  • Ensure alignment of team capabilities with evolving technologies, threats, and business needs.

Qualifications

  • Ideally targeting individuals with 10+ years of experience in cybersecurity, with a focus on application security, secure development, or DevSecOps.

  • Deep expertise in application security testing methodologies (SAST, DAST, SCA, IAST) and secure development practices, strongly preferred.

  • Strong understanding of application and API security, cloud-native architectures, and modern development frameworks.

  • Experience leading application security programs across large, complex organization, preferred.

  • Strong understanding of cybersecurity frameworks (e.g., NIST CSF, OWASP, ISO 27001) and regulatory requirements.

  • Demonstrated ability to collaborate with cross-functional teams and influence executive stakeholders.

  • Strong leadership, communication, and problem-solving skills.

#LI-LP

#LI-Remote

Anticipated salary range: $135,400 - $208,100

Bonus eligible: Yes

Benefits: Cardinal Health offers a wide variety of benefits and programs to support health and well-being.

  • Medical, dental and vision coverage

  • Paid time off plan

  • Health savings account (HSA)

  • 401k savings plan

  • Access to wages before pay day with myFlexPay

  • Flexible spending accounts (FSAs)

  • Short- and long-term disability coverage

  • Work-Life resources

  • Paid parental leave

  • Healthy lifestyle programs

Application window anticipated to close: 07/01/2026 *if interested in opportunity, please submit application as soon as possible.

The salary range listed is an estimate. Pay at Cardinal Health is determined by multiple factors including, but not limited to, a candidate's geographical location, relevant education, experience and skills and an evaluation of internal pay equity.

Candidates who are back-to-work, people with disabilities, without a college degree, and Veterans are encouraged to apply.

Cardinal Health supports an inclusive workplace that values diversity of thought, experience and background. We celebrate the power of our differences to create better solutions for our customers by ensuring employees can be their authentic selves each day. Cardinal Health is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, ancestry, age, physical or mental disability, sex, sexual orientation, gender identity/expression, pregnancy, veteran status, marital status, creed, status with regard to public assistance, genetic status or any other status protected by federal, state or local law.

To read and review this privacy notice click here (

Vacancy posted 5 days ago
Similar jobs that could be interesting for youBased on the Director, Application Security (Cybersecurity Defense) in Columbus, OH vacancy
  • $125k

     ...mission‑critical programs across national security, defense, and public service delivery. Recent contract awards in cybersecurity and operational readiness underscore Maximus...  ...~5 years of experience testing web-based applications. ~5 years of experience leading software... 
    Application
    Contract work
    Remote work

    MAXIMUS

    Columbus, OH
    7 days ago
  • $125k

     ...mission‑critical programs across national security, defense, and public service delivery. Recent contract awards in cybersecurity and operational readiness underscore Maximus...  ...~5 years of experience testing web-based applications. ~5 years of experience leading software... 
    Application
    Contract work
    Remote work

    MAXIMUS

    Columbus, OH
    7 days ago
  • $40k

     ...mission‑critical programs across national security, defense, and public service delivery. Our...  ...Engineer supports 24x7 enterprise cybersecurity operations by monitoring security tools...  ...activities, including access changes, application removal, configuration updates, and... 
    Application
    Contract work
    Remote work

    MAXIMUS

    Columbus, OH
    4 days ago
  • Shape the future of network security at one of the world's most complex and consequential...  ...security services aligned with firm cybersecurity objectives and regulatory requirements...  ...automation rate Build strong relationships with application development teams, Infrastructure... 
    Application

    Fairygodboss

    Columbus, OH
    1 day ago
  •  ...CGI Njoyn is seeking an experienced Cybersecurity Engineer to address complex information assurance challenges. This role requires strong analytical problem-solving skills and security engineering support from planning to integration. Located in Columbus, Ohio, candidates... 
    Suggested

    CGI Njoyn

    Columbus, OH
    2 days ago
  • $130k - $140k

     ...Description Role: Manager, Security Operations...  ..., NC) Department: Cybersecurity - Security Operations...  ...Reports to: Senior Director, Security Operations...  ...regional equivalents where applicable). Security...  ...accurate, validated, and defensible . Support internal... 
    Application
    Full time

    Pearson

    Columbus, OH
    4 days ago
  •  ...Enterprise and Cloud IT services, Cybersecurity, Special Operations Forces (...  ...the US Government Defense, Intelligence and Aerospace...  ...DLA stakeholders to ensure secure, reliable, and compliant operation...  ...operations. Support Hours: Applicant shall be available during... 
    Application
    Contract work
    Local area

    Nemean Solutions, LLC

    Columbus, OH
    4 days ago
  •  ...to operate more effectively, securely, and efficiently. We support...  ...federal missions across defense, civilian, and intelligence...  ...scientists, data engineers, cybersecurity staff, and customer stakeholders...  ...Serco team- then submit your application now for immediate... 
    Application
    Full time
    Contract work
    Part time
    Local area
    Immediate start
    Flexible hours

    Serco

    Columbus, OH
    7 days ago
  •  ...utilities, logistics, aerospace, defense, and energy. For decades, we...  ...are delivered effectively, securely, and in alignment with...  ...Compliance Operations Coordinate Cybersecurity operations with MSP and...  ...Business Systems & Applications Oversee operational support... 
    Application
    Work at office

    KANAWHA SCALES & SYSTEMS LLC

    Columbus, OH
    25 days ago
  •  ...Cybersecurity Operational Lead Bring your expertise...  ..., and third lines of defense to assess global cybersecurity...  ...monitoring across security configuration and...  ...assessments to Executive Directors, Managing Directors,...  ...protected under applicable law. We also make reasonable... 

    Chase

    Columbus, OH
    3 days ago
  •  ...with your knowledge and mentorship of security engineers. Lead teams to excellence in...  ...Engineering at JPMorganChase within the Cybersecurity Technology and Controls, you serve in a...  ...understanding of agile methodologies, CI/CD, Application Resiliency, Security, Service Ownership... 
    Application

    Aumni

    Columbus, OH
    2 days ago
  • $99k - $232k

     ...Specialty/Competency: Cybersecurity & Privacy Industry/Sector: Not Applicable Time Type: Full time Travel Requirements: Up to 40% At PwC, our people...  .... They work to identify vulnerabilities, develop secure systems, and provide proactive solutions to... 
    Application
    Full time
    H1b

    PwC

    Columbus, OH
    11 days ago
  •  ...with your knowledge and mentorship of security engineers. Lead teams to excellence in...  ...Engineering at JPMorganChase within the Cybersecurity Technology and Controls, you serve in a...  ...understanding of agile methodologies, CI/CD, Application Resiliency, Security, Service Ownership... 
    Application

    JPMorgan Chase & Co.

    Columbus, OH
    1 day ago
  •  ...operations, IT, and vendors to design scalable, secure, and standards-compliant solutions that...  ...Define target state architectures (application, integration, data, infrastructure) for...  ...requirements and incorporate cybersecurity controls and standards. As an Application... 
    Application

    CBASE

    Columbus, OH
    2 days ago
  •  ...Consulting is a mission-focused technology and cybersecurity services firm supporting Federal agencies across defense, logistics, and national security sectors. The company specializes in...  ...supporting cybersecurity tools and applications. Conduct configuration management,... 
    Application
    Full time
    Contract work

    Kinsley Power Systems

    Columbus, OH
    3 days ago
  •  ...ideas into reality. We Are Accenture Security helps organizations prepare, protect,...  ...all points of the security lifecycle. Cybersecurity challenges are different for every...  ...risk strategy, digital identity, cyber defense, application security and managed service solutions... 
    Application
    Full time
    Work experience placement
    Live in
    Work at office
    Local area

    Accenture

    Columbus, OH
    5 days ago
  • $152.7k - $294k

     .... As part of EY Information Security, this role is focused on ensuring...  ...facing services, platforms, applications, and technology capabilities...  ..., digital identity, cyber defense, application security,...  ...outcomes. As an Associate Director within the TARP BCCM team... 
    Application
    Summer holiday
    Local area
    Flexible hours

    EY

    Columbus, OH
    7 days ago
  •  ...Expert with SAP S/4HANA: Deep expertise in SAP S/4HANA and its application in client environments.Leadership & Project Management Skills...  ...on time, within budget, and required quality standards.AI & Cybersecurity Knowledge: Familiarity with Artificial Intelligence models,... 
    Application

    IBM

    Columbus, OH
    3 days ago
  • $83k - $93k

     ...the Position Cologix is seeking a Security Manager to lead physical security operations...  ...requirements Ensure consistent application of post orders, procedures, and security...  ...Cologix's information security, cybersecurity, privacy, and environmental management... 
    Application
    Full time
    Contract work
    Temporary work
    Local area
    Work visa
    Flexible hours

    Cologix

    Columbus, OH
    4 days ago
  • 2 days ago Be among the first 25 applicants Get AI-powered advice on this job and more exclusive features. Brooksource is looking for...  ...proven expertise translating IT concepts (e.g., networking, cybersecurity, software development) into user-friendly, accessible learning... 
    Application
    Permanent employment
    Full time
    Contract work
    Local area
    Remote work

    Brooksource

    Columbus, OH
    1 day ago
  • $99k - $225k

     ...innovative solutions to enable secure and reliable operations of...  ...enterprise network cyber defense capabilities to prevent sophisticated...  ...across the globe through cybersecurity. Join us. The world can't...  ...operating systems and applications Experience working with STIGs... 
    Application
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Phase2 Technology

    Columbus, OH
    1 day ago
  •  ...Enterprise and Cloud IT services, Cybersecurity, Special Operations Forces (...  ...the US Government Defense, Intelligence and Aerospace...  ...in accordance with the PWS, applicable UFC/NFPA/OSHA standards, cybersecurity...  ...OSHA 30 Certification. Security Requirement : ~ Must... 
    Application
    Contract work
    For contractors
    For subcontractor
    Local area

    Nemean Solutions, LLC

    Columbus, OH
    5 days ago
  •  ...Summary We are seeking a Senior Cloud Security Architect to support and contribute to...  ...remediation activities with cloud, DevOps, and application teams Support prioritization of...  ...considered Advanced degree (Master’s in Cybersecurity or Information Assurance) is a plus 8–1... 
    Application
    Temporary work

    Vertiv

    Westerville, OH
    3 days ago
  • $170.6k - $390k

     ...working world. Join EY’s Cybersecurity consulting practice – the best...  ...your career in information security! The opportunity The...  ...with infrastructure, cloud, application, and security operations teams...  ...zero trust principles, defense‑in‑depth, and least privilege... 
    Application
    Summer holiday
    Remote work
    Flexible hours

    EY

    Columbus, OH
    5 days ago
  • $77.6k - $176k

     ...and enable the Department of Defense (DoD) to achieve their...  ...infrastructures, and increase security, reliability, and availability...  ...architecting enterprise network and cybersecurity solutions within DoD hybrid...  ...Certification Clearance Applicants selected will be subject to... 
    Casual work
    Work at office
    Local area
    Remote work

    Phase2 Technology

    Columbus, OH
    2 days ago
  •  ...Description We are looking for an Application Security Engineer to work for our client. The...  ...and strengthen application defenses across critical platforms, including...  ...experience in application security or cybersecurity engineering ~ Hands-on experience with... 
    Application

    Ringside Talent Acquisition Partners

    Worthington, OH
    1 day ago
  •  ...Phoenix Cyberis looking for security focused Python programmers to help develop custom...  ...integrations for a commercial-off-the-shelf cybersecurity software product. The work involves...  ...update data across multiple third-party applications Experience with Git, CI/CD and other... 
    Application
    Remote work
    Work from home

    Phoenix Cyber

    Columbus, OH
    2 days ago
  • $99.3k - $158.69k

     ...remote endpoints in a highly regulated, defense-focused environment. This role defines...  ..., aligning remediation activities with security policies, regulatory requirements, and...  ...vulnerability management into broader cybersecurity and IT governance frameworks. Compensation... 
    Contract work
    Work at office
    Remote work

    ASM Research, An Accenture Federal Services Company

    Columbus, OH
    7 days ago
  •  ...tools (Wireshark, command line) Cybersecurity concepts such as vulnerability and risk assessment, security controls, confidentiality and...  ...System Administrator(Epic Application Analyst) - Hybrid, OH Columbus...  ...Operations Support Director, System Engineer and Administration... 
    Application
    Full time
    Work at office
    Remote work
    Relocation
    Visa sponsorship
    Relocation package

    Epic

    Columbus, OH
    3 days ago
  • $87.7k - $164k

     ...Within Information Security we blend risk strategy, digital identity, cyber defense, application security and technology solutions as we consider the entire security lifecycle. You will join a team of hardworking, security-focused individuals dedicated to supporting, protecting... 
    Application
    Summer holiday
    Local area
    Flexible hours

    Ernst & Young Oman

    Columbus, OH
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Director, Application Security (Cybersecurity Defense). Be the first to apply!