Manager, Cyber Operations
Listed on 2026-05-09
-
IT/Tech
Cybersecurity
The Manager, Information Security & Risk (Purple Team) leads the organization’s adversarial testing, attack simulation, and detection validation capabilities. This role sits at the intersection of offensive and defensive security, partnering closely with Incident Response, Threat Intelligence, Detection Engineering, Platform Engineering, and Application Security to continuously validate and strengthen Cardinal Health’s cyber defenses.
This leader is accountable for building and operating a highly effective Purple Team while guiding the organization through a transformational evolution toward automation-first, detection-as-code, and emerging agentic security capabilities. The role requires deep technical credibility, strong people leadership, and the ability to translate complex security outcomes into actionable improvements aligned to business risk
ResponsibilitiesTechnical & Strategic Leadership
Lead Purple Team operations across adversarial emulation, penetration testing, detection validation, and control assurance, ensuring activities reflect real-world threat actor behavior and enterprise risk priorities.
Define and evolve the Purple Team strategy and roadmap, including scope, cadence, and success metrics for adversarial exercises and detection testing.
Drive the transition toward detection-as-code, automated validation, and agentic security workflows in partnership with SOC and platform teams.
Provide hands-on technical guidance across attack simulation frameworks, detection pipelines, logging validation, and telemetry quality.
Ensure Purple Team findings lead to measurable improvements in detections, response playbooks, logging coverage, and platform resilience.
People Leadership & Team Development
Recruit, develop, and lead a diverse and inclusive Purple Team with a strong focus on mentoring, growth, and sustainable operations.
Foster an environment of psychological safety, collaboration, and continuous learning while maintaining high technical standards.
Balance hands-on technical leadership with effective delegation, prioritization, and long-term capacity planning.
Coach engineers to grow from task execution into systems thinking, automation design, and cross-functional influence.
Cross-Functional Partnership & Influence
Partner with Incident Response, Threat Intelligence, Detection Engineering, Platform Engineering, and Application Security to align adversarial testing with active threats and evolving architectures.
Serve as a trusted advisor to security and technology leaders on adversarial risk, detection gaps, and assurance maturity.
Communicate Purple Team outcomes clearly to technical and non-technical stakeholders, translating findings into risk-informed decisions.
Operational Excellence & Governance
Establish repeatable, well-governed processes for adversarial testing, detection validation, and post-exercise follow-through.
Ensure Purple Team activities support regulatory, audit, cyber insurance, and customer assurance needs where applicable.
Track outcomes, trends, and coverage gaps to inform continuous improvement and executive reporting.
Deep experience in offensive security, detection engineering, Purple Team operations, or related cyber disciplines.
Demonstrated technical leadership across attack simulation, detection validation, and security automation.
Proven experience leading inclusive, high-performing technical teams.
Strong communication and influencing skills across engineering, leadership, and business stakeholders.
Ability to operate effectively in complex, matrixed enterprise environments and through transformation.
Experience implementing detection-as-code, automated validation frameworks, or agentic security capabilities.
Background supporting large-scale enterprise, cloud, or M&A integration environments.
Ability to translate adversarial testing outcomes into measurable risk reduction.
Manages department operations and supervises professional employees, front line supervisors and/or business support staff
Participates in the development of policies and procedures to achieve specific goals
Ensures employees operate within…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).