×
Register Here to Apply for Jobs or Post Jobs. X

Senior Engineer, IT Governance and Compliance – Third Party Certifications

Job in California, Moniteau County, Missouri, 65018, USA
Listing for: Hobbsnews
Full Time position
Listed on 2025-12-08
Job specializations:
  • IT/Tech
    Cybersecurity, IT Consultant
Job Description & How to Apply Below
Location: California

Company Overview:

Cardinal Health, Inc. (NYSE: CAH) is a global healthcare services and products company. We provide customized solutions for hospitals, healthcare systems, pharmacies, ambulatory surgery centers, clinical laboratories, physician offices and patients in the home. We are a distributor of pharmaceuticals and specialty products; a global manufacturer and distributor of medical and laboratory products; an operator of nuclear pharmacies and manufacturing facilities;

and a provider of performance and data solutions. Working to be healthcare’s most trusted partner, our customer‑centric focus drives continuous improvement and leads to innovative solutions that improve the lives of people every day. With approximately 50,000 employees worldwide, Cardinal Health ranks among the top fifteen in the Fortune 500.

Department Overview:

Information Technology oversees the effective development, delivery, and operation of computing and information services. This function anticipates, plans, and delivers Information Technology solutions and strategies that enable operations and drive business value.

Information Security and Risk develops, implements, and enforces security controls to protect the organization’s technology assets from intentional or inadvertent modification, disclosure, or destruction. This job family develops system back‑up and disaster recovery plans, conducts incident responses, threat management, vulnerability scanning, virus management and intrusion detection as well as completes risk assessments.

IT Governance and Compliance function within the organization develops, enhances, and maintains security policies and IT compliance programs in alignment with regulatory, legal, and contractual requirements, while collaborating closely with key stakeholders to maintain a security and compliant technology environment.

We are committed to building a resilient, secure, and compliant digital ecosystem, and you will play a critical role in safeguarding our information and supporting our mission to improve the lives of people every day.

Job Overview:

This role is a leader position within the team and requires having an in‑depth understanding of local, national and international privacy and security regulations such as HIPAA (Health Insurance Portability and Accountability Act), GDPR (General Data Protection Regulation), CCPA (California Consumer Privacy Act), and PCI DSS (Payment Card Industry Data Security Standard) as well as third‑party certifications (e.g., HITRUST, SOC 2, ISO) available that enable in meeting those regulatory requirements.

Senior Engineer will co‑lead third‑party certification (e.g., HITRUST and SOC
2) program to confirm policies, standards, procedures, and audit activities are in alignment with CAH customer, business, IT, and HITRUST and SOC 2 requirements, while working with members of the Information Security and Risk Management team as well as key stakeholders throughout the enterprise such as enterprise architects, IT solution owners, training teams, etc. Success in the role will be measured by the effectiveness of the implementation and operation of HITRUST and SOC 2 program including the ability to retain all current HITRUST and SOC 2 certifications and provide guidance/advice on future certifications from cost models to balancing between compliance, risk, and business benefit.

Daily

Responsibilities:
  • Partner with Sales, Business and IT organizations to determine third‑party certifications needs and recommend best approach on obtaining and maintaining third‑party certifications such as HITRUST and SOC 2 that meet the business needs, while balancing cost of compliance.
  • Develop and implement cost and resource models to help leadership understand funding and resource requirements to obtain and maintain third‑party certifications such as HITRUST and SOC-2
  • Manage third‑party certification Program from both build and run perspective. Some of the key responsibilities include:
    • Partner with HITRUST Alliance and external assessor to identify, understand and incorporate HITRUST and SOC 2 requirements into existing and future CAH certifications.
    • Partner with internal CAH teams to…
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)

Job Posting Language
Employment Category
Education (minimum level)
Filters
Education Level
Experience Level (years)
Posted in last:
Salary