Cardinal Health

Senior Engineer - Information Security & Risk

Cardinal Health United States · $125K–$179K/yr

Hospitals and Health Care · 10,001+ employees

Yesterday
Senior (5-10 yrs) Full-time United States
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The Senior Engineer is responsible for defining, implementing, and evaluating IT SOX controls to ensure organizational compliance and risk mitigation. This role also involves managing junior staff, conducting risk assessments, and collaborating with IT stakeholders to improve control processes.

What they look for

IT SOX control Audit methodology Risk assessment Compliance Root cause analysis Problem-solving IT governance Flowcharting Network security Database security SAP Archer AuditBoard ServiceNow GRC Incident response Threat management

Requirements

Candidates must have a bachelor's degree and at least 6 years of experience in IT audit or compliance. Strong knowledge of SOX, risk-based judgment, and proficiency in IT technologies like databases and networks are required.

Benefits

Medical coverage Dental coverage Vision coverage Paid time off Health savings account 401k savings plan Access to wages before pay day Flexible spending accounts Short-term disability coverage Long-term disability coverage Work-life resources Paid parental leave Healthy lifestyle programs

Full description

What Information Security and Risk contributes to Cardinal Health

Information Technology oversees the effective development, delivery, and operation of computing and information services. This function anticipates, plans, and delivers Information Technology solutions and strategies that enable operations and drive business value.

Information Security and Risk develops, implements, and enforces security controls to protect the organization's technology assets from intentional or inadvertent modification, disclosure or destruction. This job family develops system back-up and disaster recovery plans. Information Technology also conducts incident response, threat management, vulnerability scanning, virus management and intrusion detection and completes risk assessments.

Job Overview:

The Senior Engineer, Information Security & Risk is a second line of defense role responsible for defining, implementing, and evaluating the effectiveness of IT SOX controls. Reporting to the Manager, Information Security & Risk , this role drives the detail design and implementation of IT SOX controls based on relevant risks. Furthermore, the position will work closely with Manager, Information Security & Risk to support business and IT leaders for ongoing risk management process and continuous control/process improvement.

Responsibilities:

  • Control design and remediation consulting –
  • Perform IT risk assessment for pilot areas, identify control gap, and provide guidance for gap remediation
  • Work with IT stakeholders to design effective IT controls to help the IT org achieve SOX compliance goals
  • Process improvement of IT controls that increases operational efficiency and reduces the likelihood of control failure
  • Evaluate/monitor the execution of IT controls to ensure they are operating effectively
  • Support due diligence phase of company's M&A activities   
  • Provide support for third party certifications (such as SOC1/2) review and issuance
  • Align with internal and external audit to understand SOX scope and audit strategy
  • Track and drive remediation of IT control issues within our IT risk governance process
  • Manage assigned junior staff(s) and contractors to ensure the quality of the work
  • Support budgeting of compliance workstream and responsible for proactively communicate budget overruns to key stakeholders
  • Support the manager in compliance posture reporting

Qualifications:

  • Bachelor’s degree in related field or equivalent work experience
  • Deep knowledge of IT SOX control and audit methodology - 6 + years of experience in related field preferred, such as IT audit and/or IT compliance function preferred
  • Strong understanding and experience with SOX is a must and knowledge on other compliance requirements/frameworks, such as HIPAA, GDPR, PCI, is a plus
  • Strong in educating/influencing of IT stakeholders to raise their awareness/mindset of IT control compliance
  • Strong root cause analysis and problem-solving skill is a must
  • Pro-level of risk-based judgement in addressing control issues and juggling competing priorities
  • Self-motivated to learn new technologies and achieve objectives
  • Ability to multi-task with organization, efficiency, accountability, and attention to detail
  •  Strong knowledge in IT technologies and concepts including networks, databases, middleware, interfaces, and applications. Knowledge/experience of IT controls for mainstream ERP, such as SAP, is a plus
  • Strong flowcharting skill is preferred
  • Experience with IT risk governance software (i.e., Archer, AuditBoard, ServiceNow GRC) is a plus
  • Professional certification preferred: CISA, CPA, CISM, CISSP, CRISC

Anticipated salary range: $125,300 - $178,900

Bonus eligible: yes

Benefits: Cardinal Health offers a wide variety of benefits and programs to support health and well-being.

  • Medical, dental and vision coverage
  • Paid time off plan
  • Health savings account (HSA)
  • 401k savings plan
  • Access to wages before pay day with myFlexPay
  • Flexible spending accounts (FSAs)
  • Short- and long-term disability coverage
  • Work-Life resources
  • Paid parental leave
  • Healthy lifestyle programs

Application window anticipated to close: 10/15/2026 *if interested in opportunity, please submit application as soon as possible.

The salary range listed is an estimate. Pay at Cardinal Health is determined by multiple factors including, but not limited to, a candidate’s geographical location, relevant education, experience and skills and an evaluation of internal pay equity.

Candidates who are back-to-work, people with disabilities, without a college degree, and Veterans are encouraged to apply.

Cardinal Health supports an inclusive workplace that values diversity of thought, experience and background. We celebrate the power of our differences to create better solutions for our customers by ensuring employees can be their authentic selves each day. Cardinal Health is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, ancestry, age, physical or mental disability, sex, sexual orientation, gender identity/expression, pregnancy, veteran status, marital status, creed, status with regard to public assistance, genetic status or any other status protected by federal, state or local law.

To read and review this privacy notice click here