Talent.com
Senior Engineer, IT Governance and Compliance
Senior Engineer, IT Governance and ComplianceCardinal Health • Boston, MA, United States
Senior Engineer, IT Governance and Compliance

Senior Engineer, IT Governance and Compliance

Cardinal Health • Boston, MA, United States
3 days ago
Job type
  • Full-time
Job description

Company Overview :

Cardinal Health, Inc. (NYSE : CAH) is a global healthcare services and products company. We provide customized solutions for hospitals, healthcare systems, pharmacies, ambulatory surgery centers, clinical laboratories, physician offices and patients in the home. We are a distributor of pharmaceuticals and specialty products; a global manufacturer and distributor of medical and laboratory products; an operator of nuclear pharmacies and manufacturing facilities; and a provider of performance and data solutions. Working to be healthcare’s most trusted partner, our customer‑centric focus drives continuous improvement and leads to innovative solutions that improve the lives of people every day. With approximately 50,000 employees worldwide, Cardinal Health ranks among the top fifteen in the Fortune 500.

Department Overview :

Information Technology oversees the effective development, delivery, and operation of computing and information services. This function anticipates, plans, and delivers Information Technology solutions and strategies that enable operations and drive business value.

Information Security and Risk develops, implements, and enforces security controls to protect the organization's technology assets from intentional or inadvertent modification, disclosure, or destruction. This job family develops system back‑up and disaster recovery plans, conducts incident responses, threat management, vulnerability scanning, virus management and intrusion detection as well as completes risk assessments.

IT Governance and Compliance function within the organization develops, enhances, and maintains security policies and IT compliance programs in alignment with regulatory, legal, and contractual requirements, while collaborating closely with key stakeholders to maintain a security and compliant technology environment.

We are committed to building a resilient, secure, and compliant digital ecosystem, and you will play a critical role in safeguarding our information and supporting our mission to improve the lives of people every day.

Job Overview :

We are seeking a strategic and experienced Senior Engineer for IT Governance and Compliance , who will be responsible for the design, implementation and continuous improvements of IT governance frameworks, controls, and compliance processes across the organization. This role will also serve as a senior technical and strategic resource ensuring IT operations, projects, and M&A activities are aligned with enterprise standards, regulatory requirements and industry’s best practices. In this role, you will have the opportunity to lead meaningful work, collaborate across functions, and help shape the future of our IT Governance and Compliance strategy.

This role is a leader position within the IT Governance and Compliance team and requires having an in-depth understanding of key privacy and security regulations within healthcare industry such as PCI DSS (Payment Card Industry Data Security Standard), HIPAA (Health Insurance Portability and Accountability Act), GDPR (General Data Protection Regulation), CCPA (California Consumer Privacy Act), FDA (Food and Drug Administration) / GxP / CSV (Computer System Validation), DSCSA (Drug Supply Chain Security Act), as well as relevant governance frameworks to drive compliance to those regulatory requirements such as NIST, HITRUST, SOC 2, ISO, COBIT, ITIL, etc., while working with members of the Information Security and Risk Management team as well as stakeholders from Finance, Legal, Ethics & Compliance, Internal Audit and our various business segment leadership teams throughout the Cardinal Health enterprise.

Responsibilities :

  • Lead the development, implementation and maintenance of the IT governance framework in alignment with industry standards.
  • Partner with IT and business leaders to embed governance principles across IT eco‑system.
  • Define and monitor key risk and performance indicators to ensure continuous compliance and operational excellence.
  • Conduct periodic control assessments to confirm IT regulatory / compliance requirements are met (e.g., PCI‑DSS, HIPAA, DFARS / CMMC).
  • Collaborate with solution owners and key stakeholders to identify and understand control gaps and vulnerabilities, prioritize based on risk, and recommend action plans that will address root causes. Monitor and manage open issues through closure to improve the IT compliance posture.
  • Act as an "IT Compliance Lead" on programs / projects including M&A initiatives to direct processes and people through influence to confirm key IT compliance requirements are identified and met through cross‑functional collaboration across key stakeholders (e.g., Cybersecurity, Finance, Internal Audit, Legal and Compliance, IT / Business Leadership team).
  • Conduct discovery / impact assessments of target organizations through M&A and / or future‑state IT environment to identify regulatory / compliance requirements and controls required to meet the requirements.
  • Develop and track remediation roadmaps to improve compliance posture of the future state IT environment.
  • Provide oversight to confirm compliance requirements are being designed and implemented and risks / issues are reported to the leadership timely.
  • Act as a trusted advisor to IT and business leadership as well as key stakeholders on IT compliance and governance processes.
  • Support internal and external audit processes to confirm timely responses and evidence collection.
  • Mentor team members and promote a culture of accountability and continuous improvement.
  • Effectively manage and implement changes throughout the organization.
  • Be a thought‑leader and implementer of optimizing and automating GRC processes.
  • Shape the evolution of our GRC management program, helping build and refine processes that scale with our growing organization.

Qualifications :

  • Bachelor’s Degree in related field or equivalent work experience.
  • 10+ years’ experience in IT Governance, Risk and Compliance (GRC) functional roles such as IT Compliance, IT Risk Management, IT Audit, Enterprise Risk Management, etc preferred.
  • Demonstrated leadership in driving cross‑functional governance initiatives.
  • Proven experience with implementing and leveraging IT governance frameworks (e.g., ITIL, COBIT, NIST).
  • Deep understanding of healthcare industry regulations and standards (e.g., PCI DSS, HIPAA, GDPR, NIST, HITRUST, SOC 2).
  • Proven experience supporting IT due‑diligence and integration during M&A initiatives.
  • Experience building or significantly improving GRC programs within high‑growth technology organizations, particularly those dealing with emerging technologies.
  • Experience gathering and analyzing business requirements, translating them into actionable plans and technical specifications.
  • Strong technical knowledge of enterprise IT environments (cloud, network, infrastructure, applications, data lake / data warehouse) and ability to design and implement control framework across it.
  • Hands‑on experience with GRC platforms, project management tools, and service management systems, with a focus on scaling and automating GRC processes.
  • Experience in analyzing data and creating reports / dashboards / views to provide visibility into risk and control landscape.
  • Excellent analytical and problem‑solving skills – able to translate technical concepts into business outcomes.
  • Excellent communication skills (both verbal and written) – able to facilitate discussions with leaders at all levels within the organization, work in a matrixed environment to drive results, and clearly define and execute repeatable processes.
  • Excellent time management, active listening, meeting facilitation, and influencing skills.
  • Professional certifications preferred : CGEIT (Certified in the Governance of Enterprise IT), CISA (Certified Information Systems Auditor), CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager), CRISC (Certified in Risk and Information Systems Control).
  • Anticipated salary range :

    $123,400 - $176,300

    Bonus eligible : Yes

    Benefits :

  • Medical, dental and vision coverage
  • Paid time off plan
  • Health savings account (HSA)
  • 401k savings plan
  • Access to wages before pay day with myFlexPay
  • Flexible spending accounts (FSAs)
  • Short- and long‑term disability coverage
  • Work‑life resources
  • Paid parental leave

  • Healthy lifestyle programs
  • Application window anticipated to close :

    12 / 28 / 2025

  • if interested in opportunity, please submit application as soon as possible.
  • Salary disclaimer :

    The salary range listed is an estimate. Pay at Cardinal Health is determined by multiple factors including, but not limited to, a candidate’s geographical location, relevant education, experience and skills and an evaluation of internal pay equity.

    EEO Statement :

    Candidates who are back‑to‑work, people with disabilities, without a college degree, and Veterans are encouraged to apply.

    Cardinal Health supports an inclusive workplace that values diversity of thought, experience and background. We celebrate the power of our differences to create better solutions for our customers by ensuring employees can be their authentic selves each day. Cardinal Health is an Equal Opportunity / Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, ancestry, age, physical or mental disability, sex, sexual orientation, gender identity / expression, pregnancy, veteran status, marital status, creed, status with regard to public assistance, genetic status or any other status protected by federal, state or local law.

    Privacy Notice :

    To read and review this privacy notice click here https : / / www.cardinalhealth.com / content / dam / corp / email / documents / corp / cardinal-health-online-application-privacy-policy.pdf

    #J-18808-Ljbffr

    Create a job alert for this search

    Senior It Compliance • Boston, MA, United States

    Related jobs
    Senior Information Security Engineer

    Senior Information Security Engineer

    Analysis Group • Boston, MA, United States
    Full-time
    Senior Information Security Engineer.Location : Boston, MA (US-MA-Boston).Analysis Group is one of the largest international economics consulting firms, with more than 1,500 professionals across 15 ...Show more
    Last updated: 30+ days ago • Promoted
    IT Audit, Cybersecurity & Risk Advisory Senior

    IT Audit, Cybersecurity & Risk Advisory Senior

    Baker Tilly Advisory Group, LP • USA, Massachusetts, Tewksbury
    Full-time
    Baker Tilly is a leading advisory, tax and assurance firm, providing clients with a genuine coast-to-coast and global advantage in major regions of the U. New York, London, San Francisco, Los Angele...Show more
    Last updated: 30+ days ago
    Senior Banker I

    Senior Banker I

    BankTalent HQ • Walpole, MA, United States
    Full-time
    It is the responsibility of the Senior Banker I to represent Middlesex Savings Bank to the public and to their colleagues, and to promote the Bank's core values and mission.They accomplish this by ...Show more
    Last updated: 30+ days ago • Promoted
    Senior Information Security Engineer

    Senior Information Security Engineer

    WHOOP • Boston, MA, United States
    Full-time
    At WHOOP, we're on a mission to unlock human performance.WHOOP empowers members to perform at a higher level through a deeper understanding of their bodies and daily lives.WHOOP is seeking a Senior...Show more
    Last updated: 30+ days ago • Promoted
    IT Manger

    IT Manger

    TradeJobsWorkforce • 02474 Arlington, MA, US
    Full-time
    IT Manager Job Duties : Maintains information technology strategies.Researches and im...Show more
    Last updated: 30+ days ago • Promoted
    Compliance, Fraud, Waste and Abuse Supervisor

    Compliance, Fraud, Waste and Abuse Supervisor

    Tempus Unlimited Inc. • Stoughton, MA, US
    Full-time
    Compliance, Fraud, Waste and Abuse Supervisor.Tempus Corporate Headquarters, 600 Technology Center Drive, Stoughton, Massachusetts, United States of America. The agency, through its programs and ser...Show more
    Last updated: 1 day ago • Promoted
    Server

    Server

    Texas Roadhouse • East Walpole, MA, US
    Full-time
    At Texas Roadhouse, we are a people-first company that just happens to serve steaks.Legendary Food and Legendary Service is who we are. We’re about loving what you’re doing today and pre...Show more
    Last updated: 30+ days ago • Promoted
    Information System Security Engineer, Senior

    Information System Security Engineer, Senior

    BOOZ, ALLEN & HAMILTON, INC. • Lexington, MA, US
    Full-time +1
    Information System Security Engineer, Senior.Maintain responsibility for all Information Systems Security Engineer ( ISSE ) duties in support of Department of Defense ( DoD ) Risk Management Framew...Show more
    Last updated: 30+ days ago • Promoted
    Senior Manager, IT Audit

    Senior Manager, IT Audit

    SharkNinja • Needham, MA, United States
    Full-time
    SharkNinja is a global product design and technology company with a diversified portfolio of 5-star rated lifestyle solutions that positively impact people’s lives in homes around the world.Powered...Show more
    Last updated: 4 days ago • Promoted
    Senior IT & Cloud Infrastructure Engineer

    Senior IT & Cloud Infrastructure Engineer

    Drawbridge • Boston, MA, United States
    Full-time
    Senior IT & Cloud Infrastructure Engineer.At Drawbridge, we are committed to attracting and retaining the best individuals who enjoy working in a dynamic environment. You will be joining an agile te...Show more
    Last updated: 3 hours ago • Promoted • New!
    Sr. Director - IT Risk & Governance

    Sr. Director - IT Risk & Governance

    MFS Investment Management • Boston, MA, United States
    Full-time
    At MFS, you will find a culture that supports you in doing what you do best.Our employees work together to reach better outcomes, favoring the strongest idea over the strongest individual.We put pe...Show more
    Last updated: 4 days ago • Promoted
    Senior Manager, Strategic Sourcing IT and Telecom

    Senior Manager, Strategic Sourcing IT and Telecom

    Vertex • Boston, MA, US
    Full-time
    Senior Manager, Strategic Sourcing IT & Telecom.The Senior Manager, Strategic Sourcing IT & Telecom will lead category management activities, including the development and execution of sourcing str...Show more
    Last updated: 17 hours ago • Promoted • New!
    Senior Global Category Manager IT

    Senior Global Category Manager IT

    Fresenius Medical Care • Waltham, MA, US
    Full-time
    Senior Global Category Manager.The Senior Global Category Manager is responsible for developing and executing procurement strategies with third-party suppliers in support of Fresenius Medical Care'...Show more
    Last updated: 5 hours ago • Promoted • New!
    Senior IT Engineer

    Senior IT Engineer

    Elucid • Boston, MA, US
    Full-time
    Quick Apply
    We are a rapidly growing, Boston-based medical technology company using AI to enable clinicians to make informed decisions on cardiovascular care - leading to better patient outcomes, improved qual...Show more
    Last updated: 29 days ago
    Digital & IT Senior Analyst

    Digital & IT Senior Analyst

    Jobright.ai • Boston, MA, United States
    Full-time +1
    Be among the first 25 applicants.Get AI-powered advice on this job and more exclusive features.Jobright is an AI-powered career platform that helps job seekers discover the top opportunities in the...Show more
    Last updated: 1 day ago • Promoted
    Senior Manager, IT Audit

    Senior Manager, IT Audit

    Ninjakitchen • Needham, MA, United States
    Full-time
    SharkNinja is a global product design and technology company, with a diversified portfolio of 5-star rated lifestyle solutions that positively impact people’s lives in homes around the world.Powere...Show more
    Last updated: 30+ days ago • Promoted
    Senior Information Security Engineer

    Senior Information Security Engineer

    Analysis Group, Inc. • Boston, MA, United States
    Full-time
    Analysis Group is one of the largest international economics consulting firms, with more than 1,500 professionals across 15 offices in North America, Europe, and Asia. Since 1981, we have provided e...Show more
    Last updated: 30+ days ago • Promoted
    System Support Associate

    System Support Associate

    Kelmar • Wakefield, MA, United States
    Full-time
    The System Support Associate is a client-facing position whose primary responsibility is to support clients using Kelmar's KAPS unclaimed property management system. The System Support Associate wil...Show more
    Last updated: 28 days ago • Promoted