Secure MA&D Lead
Job in
Conshohocken, Montgomery County, Pennsylvania, 19428, USA
Listed on 2026-08-31
Listing for:
Cencora
Full Time
position Listed on 2026-08-31
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below
Secure Ma&D Lead
The Secure MA&D Lead is responsible for cybersecurity due diligence for mergers, acquisitions, divestitures, and other strategic transactions. This role identifies cyber risks, estimates remediation and integration costs, manages third-party diligence partners, transfers findings to security capability owners, and supports Day-1 readiness planning.
Key Responsibilities:
- Lead pre-close cybersecurity due diligence for assigned MA&D transactions.
- Review target-company security posture, documentation, interviews, and assessment results.
- Identify key cyber risks, control gaps, compliance concerns, and Day 1 readiness issues.
- Translate technical findings into clear business, operational, and financial impacts.
- Manage third-party cybersecurity diligence providers, including scope, timelines, deliverables, and quality of findings.
- Develop preliminary cost estimates for remediation, integration, tooling, licensing, labor, and ongoing run support.
- Partner with Finance, Corporate Development, Legal, IT, and Information Security teams to validate risks, assumptions, and costs.
- Transfer diligence findings, risks, and open items to security capability owners before close.
- Support Day 1 readiness planning by identifying minimum required controls, dependencies, and immediate post-close actions.
- Maintain clear documentation of risks, decisions, assumptions, action items, and handoffs.
- Improve Secure MA&D diligence templates, playbooks, cost models, and reporting materials.
Qualifications:
- Bachelor's degree in cybersecurity, computer science, information systems, information technology, or a related field, or equivalent experience required.
- 6+ years of experience in information security analysis, cybersecurity engineering, incident response, vulnerability management, M&A due diligence, or security program leadership.
- Experience leading cybersecurity assessments, risk reviews, diligence activities, or integration planning.
- Strong understanding of core security domains, including IAM, endpoint security, vulnerability management, cloud security, data protection, security operations, GRC, and third-party risk.
- Ability to explain cyber risks in business terms and connect findings to cost, timing, compliance, and operational impact.
- Experience developing high-level remediation, integration, and run-cost estimates.
- Strong vendor-management and stakeholder-management skills.
- Excellent written and verbal communication skills, including executive-level summaries and decision materials.
- Ability to manage multiple confidential transactions and competing priorities.
- Relevant certifications such as CISSP, CISM, CRISC, CISA, or CCSP are a plus.
- Ability to travel as needed (5% - 10%)
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×