{"id":1170260,"url":"https://alion.io/job/cencora-senior-director-secure-mad","title":"Senior Director, Secure MA&D","company":{"id":1040788,"name":"Cencora","domain":"cencora.com","url":"https://alion.io/company/cencora","size_band":"5000+","is_staffing_agency":false,"is_intermediary":false,"listed_via":null,"ats_vendor":"Workday","truth_index":null},"role":"Legal","role_family":"Legal","seniority":"head","employment_type":"full_time","work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Conshohocken, United States","United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":154000,"max_usd":295000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":256},"experience_years_min":15,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"GDPR","optional":false},{"name":"HIPAA","optional":false},{"name":"ISO 27001","optional":false},{"name":"NIST CSF","optional":false},{"name":"PCI DSS","optional":false}],"status":"live","first_seen_at":"2026-09-04T00:00:00Z","employer_posted_date":"2026-09-04","last_verified_at":"2026-09-25T01:20:30Z","board_verified":true,"closed_at":null,"days_open":21,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":21},"description":"Our team members are at the heart of everything we do. At Cencora, we are united in our responsibility to create healthier futures, and every person here is essential to us being able to deliver on that purpose. If you want to make a difference at the center of health, come join our innovative company and help us improve the lives of people and animals everywhere. Apply today!\nJob Details\nJob Summary:\nThe Senior Director, Secure MA&D owns the enterprise strategy, governance, and delivery of cybersecurity across the full transaction lifecycle - pre-close due diligence, Day 1 readiness, post-close integration, and divestiture separation. This role is the single accountable security leader to Corporate Development, Finance, and Legal for cyber risk that affects valuation, deal structure, closing conditions, and integration cost. The Senior Director leads a global team of principals and analysts and a bench of third-party diligence partners; sets the risk thresholds and decision rights that determine when a cyber finding is deal-impacting; advises executive leadership and the Board on aggregate transaction risk; and drives the organizational change required to bring acquired entities onto enterprise security standards.\nKey Responsibilities:\nStrategic Leadership and Program Ownership\nOwn and evolve the enterprise Secure MA&D strategy, operating model, and capability roadmap covering acquisitions, divestitures, carve-outs, joint ventures, and minority investments.\n\nEstablish the governance framework, decision rights, risk thresholds, and escalation criteria that determine when a cyber finding is deal-impacting versus a post-close remediation item.\n\nSet the standard for diligence playbooks, cost models, integration blueprints, Day 1 control baselines, and executive reporting used across the transaction portfolio.\n\nOwn the function's annual plan, budget, tooling, and third-party bench, sized to support an unpredictable and confidential deal pipeline.\n\nDefine and report the metrics that demonstrate program effectiveness, including diligence cycle time, cost-estimate accuracy, Day 1 control coverage, and time to remediate inherited risk.\n\nPosition Secure MA&D as an enabler of inorganic growth by balancing speed of deal execution against defensible risk coverage.\n\nPeople and Vendor Leadership\nLead, coach, and develop a global team of Secure MA&D principals and analysts; set performance standards, career paths, and succession plans.\n\nAllocate scarce specialist capacity across concurrent transactions and adjust staffing as deals accelerate, pause, or collapse.\n\nDirect third-party diligence and integration partners end to end, including selection, scoping, commercial terms, quality assurance, and performance management.\n\nBuild a team culture of disciplined judgment, documentation, and absolute confidentiality consistent with material non-public information obligations.\n\nServe as player-coach on the largest, most sensitive, or most contested transactions.\n\nMA&D Lifecycle Execution\nDirect pre-close cybersecurity due diligence under compressed timelines, restricted target access, staged data-room release, and clean-team constraints, drawing defensible conclusions from incomplete evidence.\n\nCalibrate diligence depth and approach to deal type, size, and thesis, recognizing the differences between a negotiated acquisition, a competitive auction, an asset versus stock purchase, and a carve-out from a larger parent.\n\nQuantify and defend remediation, integration, tooling, licensing, labor, and run-rate cost estimates within the deal model, including capital versus operating treatment and dis-synergy impacts.\n\nEnsure cyber findings are reflected in deal documents and protections, including representations and warranties, purchase price adjustments, escrow and indemnity, disclosure schedules, and closing conditions.\n\nDefine security requirements and exit criteria for Transition Service Agreements and reverse TSAs; direct separation planning for divestitures, including data segregation, entitlement removal, and protection of retained intellectual property.\n\nDirect Day 1 readiness, including minimum viable controls, identity and network interconnection decisions, endpoint and email protections, logging and monitoring onboarding, and incident response coverage for the acquired entity.\n\nOwn the handoff from diligence to delivery, transferring risks, named owners, and funded remediation plans to security capability owners with accountability tracked through TSA exit and integration close.\n\nLead the security response when a target is found to have an active or historical compromise, coordinating pre-close containment, valuation impact, and disclosure implications with Legal and Corporate Development.\n\nRisk Management and Compliance\nEstablish the risk-acceptance and exception framework for inherited risks that cannot be remediated by Day 1, ensuring documented ownership, funding, and time-bound closure.\n\nEnsure diligence and integration address the regulatory exposure relevant to the enterprise, including HIPAA and protected health information, GxP and validated systems, DSCSA, PCI DSS, SOX IT general controls, GDPR, and cross-border data transfer requirements.\n\nAggregate inherited cyber risk across the transaction portfolio into the enterprise risk register and report exposure trends to executive risk committees.\n\nOversee the third-party and fourth-party risk introduced through acquired vendor ecosystems, contracts, and data-sharing arrangements.\n\nAlign Secure MA&D practices to recognized frameworks such as NIST CSF, NIST SP 800-53, ISO 27001, CIS Controls, and HITRUST, and support internal audit and regulatory inquiry into transaction risk.\n\nCommunications and Executive Engagement\nServe as the security voice in deal committee, investment committee, and Board-level materials, presenting a clear position, a risk-adjusted cost range, and an explicit confidence level.\n\nTranslate technical findings into valuation, timing, compliance, and operational impact for non-technical executives across Finance, Legal, Corporate Development, and Technology.\n\nProduce concise, decision-grade deliverables for audiences that will not read a technical report, while retaining the underlying evidence for audit and integration use.\n\nBrief and align security capability owners, business unit leaders, and acquired-company executives on findings, obligations, and sequencing.\n\nRepresent the enterprise credibly while protecting confidentiality and negotiating position.\n\nDeliver difficult messages to deal sponsors and target leadership without stalling the transaction, and escalate with evidence when risk exceeds tolerance.\n\nChange Management and Integration Enablement\nLead the organizational change required to bring acquired entities onto enterprise security standards, including policy adoption, control uplift sequencing, and tooling migration.\n\nBuild stakeholder engagement, training, and communication plans that reduce resistance, shadow IT, and control drift during integration.\n\nAssess acquired security talent and define retention, onboarding, and organizational design recommendations in partnership with Human Resources and security leadership.\n\nManage the cultural transition from a smaller or less mature security environment to enterprise expectations, sequencing change to preserve business continuity and acquired-team morale.\n\nInstitutionalize lessons learned after each close, feeding improvements back into playbooks, cost models, and Day 1 baselines.\n\nQualifications:\nBachelor's degree required; advanced degree in business or a technical discipline preferred.\n\n15+ years of progressive experience in cybersecurity, technology risk, or security consulting, including 5+ years leading teams and enterprise-scale programs.\n\nDemonstrated experience leading cybersecurity due diligence and integration across multiple completed transactions, including at least one carve-out, divestiture, or separation.\n\nWorking fluency in deal mechanics and terminology, including letters of intent, data-room and clean-team protocols, SPA and TSA constructs, purchase price adjustments, escrow and indemnity, and representations and warranties insurance.\n\nFinancial acumen sufficient to build, defend, and negotiate multi-year remediation and run-rate cost estimates with Finance and Corporate Development.\n\nBreadth and depth across core security domains, including identity and access management, cloud and network security, endpoint, data protection, application security, security operations and incident response, vulnerability management, GRC, and third-party risk.\n\nExperience in a highly regulated industry; healthcare, pharmaceutical distribution, life sciences, or medical technology strongly preferred, with working knowledge of HIPAA, GxP, DSCSA, SOX, PCI DSS, and GDPR.\n\nFamiliarity with NIST CSF, NIST SP 800-53 and 800-171, ISO 27001, CIS Controls, and HITRUST as diligence and integration baselines.\n\nProven vendor management and budget ownership, including managing external assessment partners against fixed timelines and quality expectations.\n\nDemonstrated ability to influence and align executive stakeholders without direct authority, across global business units and geographies.\n\nExceptional written and verbal communication skills, including Board and deal-committee materials, with a track record of being decisive on incomplete information.\n\nProven discretion in handling material non-public information and simultaneous confidential transactions, with a clear understanding of insider-trading and information-barrier obligations.\n\nRelevant certifications such as CISSP, CISM, CRISC, CISA, CCSP, or PMP preferred.\n\nWillingness to travel and to support compressed transaction timelines, including nonstandard hours and multiple time zones.\n\nWhat Cencora offers\nWe provide compensation, benefits, and resources that enable a highly inclusive culture and support our team members’ ability to live with purpose every day. In addition to traditional offerings like medical, dental, and vision care, we also provide a comprehensive suite of benefits that focus on the physical, emotional, financial, and social aspects of wellness. This encompasses support for working families, which may include backup dependent care, adoption assistance, infertility coverage, family building support, behavioral health solutions, paid parental leave, and paid caregiver leave. To encourage your personal growth, we also offer a variety of training programs, professional development resources, and opportunities to participate in mentorship programs, employee resource groups, volunteer activities, and much more. For details, visit https://www.virtualfairhub.com/cencora\nFull timeEqual Employment Opportunity\nCencora is committed to providing equal employment opportunity without regard to race, color, religion, sex, sexual orientation, gender identity, genetic information, national origin, age, disability, veteran status or membership in any other class protected by federal, state or local law.\nThe company’s continued success depends on the full and effective utilization of qualified individuals. Therefore, harassment is prohibited and all matters related to recruiting, training, compensation, benefits, promotions and transfers comply with equal opportunity principles and are non-discriminatory.\nCencora is committed to providing reasonable accommodations to individuals with disabilities during the employment process which are consistent with legal requirements. If you wish to request an accommodation while seeking employment, please call 888.692.2272 or email . We will make accommodation determinations on a request-by-request basis. Messages and emails regarding anything other than accommodations requests will not be returned\nAffiliated Companies\nAffiliated Companies: AmerisourceBergen Services Corporation","description_format":"text","description_chars":11920,"description_truncated":false,"requirements":{"experience_years_min":15,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":["Parental leave","Professional development"],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Health Care","Pharmaceuticals","Cell & Gene Therapy","Security Compliance"],"lifecycle":[{"event":"open","at":"2026-09-24T06:56:41Z"}],"liveness":{"score":46,"band":"ok","label":"Likely open","p_open":1,"p_active":0.828,"p_room":0.55,"age_days":21,"expected_fill_days":18,"reasons":["conf:0","win:tail","comp:brand"],"computed_at":"2026-09-25T02:13:42Z"},"pay":null,"html_url":"https://alion.io/job/cencora-senior-director-secure-mad","json_url":"https://alion.io/job/cencora-senior-director-secure-mad.json","meta":{"generated_at":"2026-09-25T02:13:42Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":2307,"day_limit":5000,"remaining_today":2693,"minute_limit":60,"resets_at":"2026-09-26T00:00:00Z"}}}