Lead Cyber Security Architect
Listed on 2026-09-08
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Systems Engineer, Security Management & Operations
McKesson is an impact-driven, Fortune 10 company that touches virtually every aspect of healthcare. We are known for delivering insights, products, and services that make quality care more accessible and affordable. Here, we focus on the health, happiness, and well-being of you and those we serve – we care.
Lead Cyber Security Architect LocationRichmond, VA, USA - 9954 Mayland Drive (on-site)
The OpportunityThe Lead Cyber Security Architect is a senior, advanced-skill role responsible for establishing and evolving MMS security architecture, patterns, and guardrails that protect the business while enabling speed and innovation. This role partners with the Chief Information Security Officer (CISO), Technology Senior Leadership, audit/compliance, product and application owners, infrastructure, and security engineering/operations teams to drive consistent security outcomes across the enterprise.
This role provides expert guidance on current security issues while anticipating where threats and technology are heading to proactively shape MMS security strategy. The Lead Cyber Security Architect is expected to think like an adversary, translate business objectives into security architecture decisions, and define target-state architectures and roadmaps. As a Lead (P5), this role sets standards and raises the bar through mentoring and coaching, critical review of deliverables, and driving measurable improvements in risk reduction and control effectiveness.
The architect leads through influence (often without direct people-management authority) and ensures security architecture decisions are documented, communicated, and adopted across delivery teams.
- Own and evolve MMS security architecture reference patterns and guardrails across cloud, network, identity, endpoint, application, and data protection; ensure designs are secure-by-design and compliant-by-design.
- Lead architecture reviews for key initiatives (new platforms, major applications, third-party integrations, and B2B/B2C capabilities); document decisions, risks, exceptions, and required compensating controls.
- Translate security policy, risk, and regulatory obligations into practical engineering requirements, reusable design standards, and implementation guidance (e.g., templates, runbooks, and secure reference implementations).
- Define target-state security architecture and roadmaps; drive organizational alignment and prioritization with security, technology, and business stakeholders.
- Embed security in delivery through Dev Sec Ops : advise on CI/CD controls, infrastructure-as-code, policy-as-code, secrets management, and secure SDLC practices; partner with engineering teams to increase automation and reduce friction.
- Establish measurable security architecture outcomes (e.g., coverage of guardrails, reduction in high-risk exceptions, control adoption, improved detection/response maturity) and use metrics to guide continuous improvement.
- Mentor and coach architects and engineers; perform critical self-review and peer review of deliverables to ensure high quality, accuracy, and alignment to enterprise security standards.
- Design and maintain cloud security architecture patterns and guardrails (e.g., IAM and privileged access, organization policies, network segmentation, encryption and key management, logging/monitoring, vulnerability management, and posture management) with clear implementation guidance for delivery teams.
- Perform other duties as assigned.
- Degree or equivalent and typically requires 10+ years of relevant experience. Less years required if has relevant Master’s or Doctorate qualifications
- 10+ years in cybersecurity with 5+ years in security architecture, including risk management and compliance.
- Demonstrated ability to lead complex initiatives, drive alignment, and coach others while delivering measurable security outcomes.
- Hands‑on security architecture experience, including designing guardrails/reference architectures and driving adoption across multiple teams.
- Demonstrated experience designing security controls for sensitive data (PII/PHI) and supporting audits and compliance…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).