Lead Cyber Security Architect
Richmond, VA - USA
Job Summary
McKesson is an impact-driven Fortune 10 company that touches virtually every aspect of healthcare. We are known for delivering insights products and services that make quality care more accessible and affordable. Here we focus on the health happiness and well-being of you and those we serve we care.
What you do at McKesson matters. We foster a culture where you can grow make an impact and are empowered to bring new ideas. Together we thrive as we shape the future of health for patients our communities and our people. If you want to be part of tomorrows health today we want to hear from you.
Lead Cyber Security Architect
Location: Richmond VA USA - 9954 Mayland Drive (on-site)
The Opportunity
The Lead Cyber Security Architect is a senior advanced-skill role responsible forestablishingand evolving MMS security architecture patterns and guardrails that protect the business while enabling speed and innovation. This role partners with the Chief Information Security Officer (CISO) Technology Senior Leadership audit/compliance product and application owners infrastructure and security engineering/operations teams to drive consistent security outcomes across the enterprise.
This roleprovidesexpert guidance on current security issues whileanticipatingwhere threats and technology are heading to proactively shape MMS security strategy. The Lead Cyber Security Architect is expected to think like an adversary translate businessobjectivesinto security architecture decisions and define target-statearchitecturesand roadmaps. Asa Lead(P5) this role sets standards and raises the bar through mentoring and coaching critical review of deliverables and driving measurable improvements in risk reduction and control effectiveness. The architect leads through influence (often without direct people-management authority) and ensures security architecture decisions are documented communicated and adopted across delivery teams.
Key Responsibilities
Own and evolve MMS security architecture reference patterns and guardrails across cloud network identity endpoint application and data protection; ensure designs are secure-by-design and compliant-by-design.
Lead architecture reviews for key initiatives (new platforms major applications third-party integrations and B2B/B2C capabilities); document decisions risks exceptions andrequiredcompensating controls.
Translate security policy risk and regulatory obligations into practical engineering requirements reusable design standards and implementation guidance (e.g. templates runbooks and secure reference implementations).
Define target-state security architecture and roadmaps; drive organizational alignment and prioritization with security technology and business stakeholders.
Embed security in delivery throughDevSecOps: advise on CI/CD controls infrastructure-as-code policy-as-codesecretsmanagement and secure SDLC practices; partner with engineering teams to increase automation and reduce friction.
Establish measurable security architecture outcomes (e.g. coverage of guardrails reduction in high-risk exceptions control adoption improved detection/response maturity) and use metrics to guide continuous improvement.
Mentor and coach architects and engineers; perform critical self-review and peer review of deliverables to ensure high quality accuracy and alignment to enterprise security standards.
Design andmaintaincloud security architecture patterns and guardrails (e.g. IAM and privileged access organization policies network segmentation encryption and key management logging/monitoring vulnerability management and posture management) with clear implementation guidance for delivery teams.
Perform other duties as assigned.
Minimum Requirements
Degree or equivalent andtypically requires 10 years of relevant experience. Less yearsrequired if has relevant Mastersor Doctorate qualifications
Skills and Qualifications
10 years in cybersecurity with 5 years in security architecture including risk management and compliance.
Demonstrated ability to lead complex initiatives drive alignment and coach others while delivering measurable security outcomes.
Hands-on security architecture experience including designing guardrails/reference architectures and driving adoption across multiple teams.
Demonstrated experience designing security controls for sensitive data (PII/PHI) and supporting audits and compliance efforts through strong documentation and evidence-based controls.
Zero Trust and IAM/PAM (workforce and customer identity) design at scale;demonstratedability to define and implement enterprise guardrails including policy-as-code and standardized identity/network patterns.
Proven stakeholder leadershipableto lead planning and architecture discussions incorporate reviewer feedback and obtain alignment and approvals for secure solutions.
Experience with modern security platforms and automation (e.g. SIEM EDR/XDR SOARsecretsmanagement and data protection) plus scripting/automation to scale controls.
Strong background in technology design implementation and delivery (cloud networking identity endpoint and application platforms) with the ability to translate business requirements into secure reference architectures and pragmatic implementation plans.
Deepexpertisein security controls and architecture domains: IAM (including privileged access) network security encryption/key management secrets management application security vulnerability management logging/monitoring and security posture management across public cloud and hybrid environments.
Ability to communicate technicalriskand tradeoffs in business terms influence decisions at multiple levels andfacilitateproductive outcomes across security engineering and business stakeholders.
Experience improving detection and response capabilities at scale (SIEM EDR/XDR SOAR threat intelligence) including driving architectural remediation and hardening based on incidents and post-incident reviews.
Proven ability to define and operationalize security standards patterns and guardrails (includingexceptionprocesses) and to ensure adoption through reviews coaching documentation and automation.
Track recordof acting with integrity taking pride in workseekingto excel being curious and adaptable and holding a high bar for quality through critical self-review and thoughtful peer review.
Hands-on ability to automate and enable teams through scripting and infrastructure-as-code (e.g. Bash Python PowerShell) and policy-as-code approaches.
Experiencedesigning forcyber resilience (disaster recovery business continuity backup/restore security and ransomware recovery considerations).
Working knowledge of common security and risk frameworks and regulations relevant to healthcare and enterprise environments (e.g. NIST ISO 27001 HITRUST HIPAA/HITECH PCI DSS SOX GDPR SOC 2).
Working knowledge of Windows Linux and container platforms (e.g. Kubernetes) and modern application patterns (API-based integrations microservices and serverless)sufficientto guide secure designs.
Strong strategic and tactical decision-making including the ability to assess tradeoffs define compensating controls and drive decisions to closure.
Experience collaborating with offensive/defensive security teams (e.g. purple teaming) tovalidatecontrols and translate findings into architectural improvements.
Highly trustworthy; leads by example and builds credibility through consistent follow-through and high-quality deliverables.
Education Requirements
Bachelors degree in computer science information security/assurance MIS engineering or related field; or equivalent practical experience.
Certification Requirements
CISSP (required). Preferred: CISM GIAC/SANS certifications and/or relevant cloud security certifications (a plus): Google Cloud Professional Cloud Security Engineer and/or Associate Cloud Engineer Google Professional Cloud DevOps Engineer and/or GIAC certifications (e.g. GSEC GCIH) depending on role focus. and/or cloud/security engineering certifications aligned to theteamsplatforms.
About MMS
McKesson Medical-Surgical (MMS) which is expected to become Wellverse in early 2027 is a subsidiary and publicly reported segment of the McKesson Corporation. MMS distributes medical-surgical supplies pharmaceuticals diagnostic equipment and supplies along with other solutions and services to virtually every type of healthcare setting and provider outside of the traditional hospital. These markets often referred to as Alternate Care or Non-Acute Care include physician offices surgery centers long-term care providers laboratories home health and hospice agencies health systems government facilities and online marketplaces and retailers.
Alternate Care markets are growing rapidly and MMS is proud to be a leader in this space. With a team of approximately 8000 employees a network of 15 distribution centers and approximately 900 delivery vehicles we collaborate with more than 2200 leading manufacturers and serve over 200000 customer accounts across the U.S. Our catalog includes more than 270000 SKUs of branded and private-label medical-surgical products from bandages to specialty pharmaceuticals and COVID-19 tests.
Career Level - P5
We are proud to offer a competitive compensation package at McKesson as part of our Total Rewards. This is determined by several factors including performance experience and skills equity regular job market evaluations and geographical markets. The pay range shown below is aligned with McKessons pay philosophy and pay will always be compliant with any applicable regulations. In addition to base pay other compensation such as an annual bonus or long-term incentive opportunities may be offered. For more information regarding benefits at McKesson pleaseclick here.
Our Base Pay Range for this position
$143000 - $238400McKesson has become aware of online recruiting-related scams in which individuals who are not affiliated with or authorized by McKesson are using McKessons (or affiliated entities like CoverMyMeds or RxCrossroads) name in fraudulent emails job postings or social media light of these scams please bear the following in mind:
McKesson Talent Advisors will never solicit money or credit card information in connection with a McKesson job application.
McKesson Talent Advisors do not communicate with candidates via online chatrooms or using email accounts such as Gmail or Hotmail. Note that McKesson does rely on a virtual assistant (Gia) for certain recruiting-related communications with candidates.
McKesson job postings are posted on our career site: .
McKesson is an Equal Opportunity Employer
McKesson provides equal employment opportunities to applicants and employees without regard to race color religion sex sexual orientation gender identity national origin protected veteran status disability age genetic information or any other legally protected category. For additional information on McKessons full Equal Employment Opportunity policies visit our Equal Employment Opportunity page.
McKesson is committed to being an Equal Employment Opportunity Employer and offers opportunities to all job seekers including job seekers with disabilities. If you need a reasonable accommodation to assist with your job search or application for employment please contact us by sending an email to (United States) or (Canada) . Resumes or CVs submitted to this email box will not be accepted.
Join us at McKesson!
Required Experience:
Staff IC
About Company
McKesson is the leading healthcare company for wholesale medical supplies & equipment, pharmaceutical distribution, and healthcare technology solutions. McKesson is the central nervous system of health care. At any given moment, in any given minute, we simultaneously execute thousands ... View more