Senior Director, Cyber Resiliency and Business Continuity
Listed on 2026-07-23
-
IT/Tech
Cybersecurity, Disaster Recovery IT, Business Continuity
Overview
McKesson is an impact-driven, Fortune 10 company that touches virtually every aspect of healthcare. We are known for delivering insights, products, and services that make quality care more accessible and affordable. Here, we focus on the health, happiness, and well‑being of you and those we serve – we care.
What you do at McKesson matters. We foster a culture where you can grow, make an impact, and are empowered to bring new ideas. Together, we thrive as we shape the future of health for patients, our communities, and our people. If you want to be part of tomorrow’s health today, we want to hear from you.
Senior Director, Cyber Resiliency and Business ContinuityThis senior leadership role will be responsible for establishing and overseeing the enterprise cybersecurity governance, methodology, and assurance framework for Business Continuity Planning (BCP), cyber incident recovery, and operational resilience. This role ensures the organization can anticipate, withstand, recover from, and adapt to cyber and technology disruptions, while meeting regulatory, audit, and risk management expectations.
Operating within the Cybersecurity organization, this leader provides program ownership and enterprise oversight, partnering closely with Business leaders, IT / Disaster Recovery teams, Enterprise Risk Management, Audit, and Regulatory stakeholders to ensure consistency, effectiveness, and maturity of resiliency capabilities.
This role does not execute business continuity plans or IT recovery directly, but owns the standards, governance, validation, and assurance that ensure those activities are effective, tested, and aligned to enterprise risk tolerance.
Key Responsibilities Cyber Resiliency Governance & StrategyOwn and maintain enterprise BCP and Cyber Resiliency policies, standards, and methodologies in alignment with regulatory expectations and industry frameworks
Define roles, responsibilities, escalation paths, and governance forums for cyber and operational resilience across the enterprise.
Establish and mature a consistent enterprise resiliency operating model, clearly delineating Cyber, Business, and IT / DR accountabilities.
Own the enterprise BIA methodology, including criticality tiers, prioritization criteria, and data quality standards.
Ensure BIAs are consistently executed by the business with appropriate rigor and alignment to policy.
Validate business‑defined recovery objectives (e.g., RTO, MTD, dependencies) for completeness, consistency, and risk‑based justification.
Provide quality assurance and challenge to ensure BIAs reflect real operating realities and cyber threat considerations.
Provide program‑level oversight of enterprise BCP and cyber resiliency activities, focusing on:
Completeness, Consistency, Risk alignment, Maturity progression.Develop and deliver executive reporting on resiliency posture, gaps, trends, and remediation status.
Track findings, gaps, and corrective actions across cyber, business, and IT domains, ensuring accountability and closure.
Measure and report program maturity against recognized frameworks and internal expectations.
Coordinate and govern enterprise resiliency exercises, including tabletop simulations and recovery validation activities.
Ensure testing scenarios incorporate cyber‑driven disruption, realistic failure conditions, and cross‑functional dependencies.
Lead post‑exercise and post‑incident lessons learned processes, driving actionable improvements across policy, plans, and execution.
Validate that testing outcomes result in concrete remediation and capability uplift.
Partner with Crisis Management and Incident Response leaders to ensure clear governance and escalation during major cyber disruptions, alignment between cyber incident response, business continuity, and technology recovery.
Provide oversight assurance that crisis processes, roles, and decision frameworks are defined, tested, and understood.
Influence senior leaders across Business, IT, Risk, and Legal…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).