Sr. Director, Infrastructure Automation & Compliance
Listed on 2026-10-03
-
IT/Tech
Cybersecurity, Information Security & Data Protection
McKesson is an impact-driven, Fortune 10 company that touches virtually every aspect of healthcare. We are known for delivering insights, products, and services that make quality care more accessible and affordable. Here, we focus on the health, happiness, and well-being of you and those we serve – we care. What you do at McKesson matters. We foster a culture where you can grow, make an impact, and are empowered to bring new ideas.
Together, we thrive as we shape the future of health for patients, our communities, and our people. If you want to be part of tomorrow’s health today, we want to hear from you.
The Senior Director of Audit, Compliance & Automation (M5) is a senior enterprise leader responsible for driving end-to-end audit readiness, compliance execution, and large-scale automation of control processes across infrastructure platforms and services. This role provides strategic direction, governance, and operational leadership to ensure regulatory adherence, audit excellence, and continuous control optimization. It integrates audit, GRC frameworks, and automation engineering to transform compliance from a reactive process into a proactive, scalable, and technology-enabled capability.
Operating at the intersection of compliance, infrastructure operations, and automation, the role partners with executive leadership, audit committees, and platform teams to ensure enterprise-wide control effectiveness, risk transparency, and measurable improvements in audit outcomes.
Lead enterprise-wide audit readiness strategy across data center, infrastructure, and platform environments. Own relationship with internal audit, external auditors, and regulatory bodies. Oversee audit lifecycle (planning, walkthroughs, evidence collection, remediation tracking). Ensure consistent execution of control frameworks (e.g., SOX ITGC, security, operational controls). Drive closure of audit findings, ensuring sustainable remediation and root-cause elimination.
Define and execute a strategy to automate audit evidence collection, control monitoring, and certification workflows. Partner with engineering and platform teams to embed automated controls into infrastructure systems. Lead adoption of tools (e.g., Service Now GRC, workflow platforms) to digitize compliance processes. Drive continuous control monitoring (CCM) and real-time risk visibility. Eliminate manual audit processes through intelligent automation and integration.
Design and implement enterprise GRC frameworks integrated with infrastructure transformation initiatives (DDC exit, cloud migration, colo consolidation). Establish standardized control libraries, policies, and governance models across platforms. Lead risk identification, assessment, and mitigation strategies for infrastructure services. Provide executive dashboards and reporting on compliance posture, risk exposure, and audit health.
Embed compliance and audit requirements into run and build operating models. Ensure controls are integrated into day-2 operations, provisioning workflows, and platform engineering standards. Partner with infrastructure leaders to align audit compliance with transformation initiatives (cloud, EUC, data center exits). Drive accountability for control ownership across engineering and operations teams.
Serve as a trusted advisor to EITP Infrastructure VP and senior leadership on audit risk, compliance posture, and regulatory exposure. Prepare executive briefings for audit committees and Steer Cos. Represent…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).