Manager, Infrastructure Governance

🏢 Cardinal Health · all 71 jobs
📍 United States
💰 USD 125,300 - 178,900 / annual
📅 Posted Sep 13, 2026 · via Himalayas
🏷 Infrastructure Governance, Cloud Security Management, It Compliance, Security Operations Manager, Risk Management, Infrastructure Engineering Manager +7 more
Apply on original site ↗

What Infrastructure Governance contributes to Cardinal Health

Information Technology oversees the effective development, delivery, and operation of computing and information services. This function anticipates, plans, and delivers Information Technology solutions and strategies that enable operations and drive business value.

Infrastructure Governance enforces Cardinal Health ’s risk and security policies to ensure compliance with internal and external regulations, and to maintain a secure infrastructure environment.
Responsibilities

- Lead and mentor a high-performing team of Cloud Engineers, fostering professional growth and establishing a culture of proactive exposure management.

- Drive team evolution by expanding the governance scope beyond Cloud Security Posture Management (CSPM) and firewall rule monitoring into comprehensive security policy enforcement, vulnerability, data, and application security management.

- Champion Automation & AI to deliver real-time compliance results, reduce manual verification cycles, and accelerate auto-remediation of cloud risks.

Governance, Risk, & Compliance (GRC) Execution

- Govern Firewall Rule Policies to guarantee alignment with network standards, and direct the rule certification program for all in-scope firewalls.

- Oversee CSPM & Cloud-Native Security Solutions to ensure robust, continuous alerting, monitoring, and audit reporting across GCP, Azure, and AWS.

- Orchestrate remediation campaigns for non-compliant issues, leveraging ServiceNow and GRC platforms to assign, track, and verify resolution by solution owners.

- Manage critical certifications to ensure Sarbanes-Oxley (SOX) server quarterly certifications are executed on time, addressing any findings with urgency.

- Analyze and address non-compliance proactively, including deprecated network protocols, violations of least privilege, or any configurations drifting from internal Information Security policies.

- Ensure compliance with exception management policies and standards by maintaining accountability for approved exceptions and their timely remediation, renewal, or closure.

Audit, Reporting, & Mergers & Acquisitions (M&A)

- Formulate governance metrics, providing monthly Key Performance Indicator (KPI) and Key Risk Indicator (KRI) reports for internal operations, and quarterly Reports of Compliance (ROC) for executive leadership.

- Support regulatory audits, serving as a key stakeholder and evidence provider for FDA audits and HITRUST certifications (monthly, quarterly, and annual reporting).

- Drive M&A security onboarding, collaborating with Enterprise Technology Platform and InfoSec Operations teams to seamlessly integrate newly acquired entities onto the Infrastructure Governance platforms.

- Align with Cyber Operations strategies, ensuring direct support of foundational programs such as Unified Vulnerability Management (UVM).

Qualifications:

- Experience: 4 to 6 years of progressive experience in security compliance governance, cloud security engineering, or an equivalent technical risk management role preferred.

- Leadership: Demonstrated experience leading, mentoring, or technically directing a team of engineering professionals.

- Cloud Expertise: Extensive, hands-on knowledge of multi-cloud environments, specifically Google Cloud Platform (GCP), Microsoft Azure, and Amazon Web Services (AWS).

- Framework Proficiency: Working knowledge of security frameworks, particularly NIST CSF (Cybersecurity Framework).

- Regulatory & Compliance Acumen: Solid understanding of industry regulations and compliance standards, including HIPAA, HITRUST, SOX, and GDPR.

- Systems Familiarity: Experience using and integrating GRC platforms, ServiceNow, and cloud-native security tools (e.g., Prisma, Wiz, Sentinel, or cloud-native CSPMs).

What is expected of you and others at this level

- Manages department operations and supervises professional employees, front line supervisors and/or business support

← All remote jobs

Get remote jobs like this by email

10 hand-picked jobs, one email a day. No spam, unsubscribe anytime.

Similar for you