This role has closed. Myhrabc has taken the posting down.
hirly last saw it live on 29 September 2026. See similar open roles below, or browse the live board.
Myhrabc
Senior Director, Secure MA&D
USA > PA > Conshohocken > West First · USA > IN > Remote · Remote, MI · USA > OH > Remote · Remote, TX
Similar open jobs
- Channel Sr Account DirectorZayo · 5 LocationsFirst seen today
- Sr. Director, Legal CorporateDigital Realty · TX, United States; Phoenix, AZ, United StatesFirst seen today
- Director of Revenue Cycle ManagementCareers at Lympha Press · Chadds Ford, PAFirst seen today
- Associate Program Director - Internal Med ResidencyMulticareFirst seen today
- Physician - Co-Medical Director Adult HospitalistMulticareFirst seen today
- Director, Technical SolutionerKyndryl · Durham, NC, USAFirst seen today
- Senior Director of Engineering – Horizon Catalog, Collaboration & MarketplaceSnowflake · US-CA-Menlo ParkFirst seen today
- Director/Senior Director, Preclinical Pharmacology/ToxicologyVIKING THERAPEUTICS INC · San Diego, CAFirst seen today
- Director of OperationsCOLOURS INC · Des Moines, IAFirst seen today
- Director of Spa & Wellness ServicesAll Jobs · Blowing Rock, NCFirst seen today
- Assistant Director of Nursing ADONCavalier Healthcare of Trussville LLC · Trussville, ALFirst seen today
- Director of Clinical Services – Private Duty Home CareComplete Home Care · Naples, FLFirst seen today
- Director of Operations (Electronic Security Systems)Active Security Consulting LLC · Sterling, VAFirst seen today
- Director, Long Haul OSP Deployment (East)Zayo · United StatesFirst seen today
- Senior Associate Director, Prospect Management - University AdvancementWustl · Washington University (West Campus), Clayton, MissouriFirst seen today
hirly's read of this role
- Seniority
- Director
- Country
- US
- Work mode
- On-site / unstated
- First seen by hirly
- 27 Sept 2026
Derived automatically from the posting.
the posting
Our team members are at the heart of everything we do. At Cencora, we are united in our responsibility to create healthier futures, and every person here is essential to us being able to deliver on that purpose. If you want to make a difference at the center of health, come join our innovative company and help us improve the lives of people and animals everywhere. Apply today!
Job Details
Job Summary:
The Senior Director, Secure MA&D owns the enterprise strategy, governance, and delivery of cybersecurity across the full transaction lifecycle - pre-close due diligence, Day 1 readiness, post-close integration, and divestiture separation. This role is the single accountable security leader to Corporate Development, Finance, and Legal for cyber risk that affects valuation, deal structure, closing conditions, and integration cost. The Senior Director leads a global team of principals and analysts and a bench of third-party diligence partners; sets the risk thresholds and decision rights that determine when a cyber finding is deal-impacting; advises executive leadership and the Board on aggregate transaction risk; and drives the organizational change required to bring acquired entities onto enterprise security standards.
Key Responsibilities:
Strategic Leadership and Program Ownership
Own and evolve the enterprise Secure MA&D strategy, operating model, and capability roadmap covering acquisitions, divestitures, carve-outs, joint ventures, and minority investments.
Establish the governance framework, decision rights, risk thresholds, and escalation criteria that determine when a cyber finding is deal-impacting versus a post-close remediation item.
Set the standard for diligence playbooks, cost models, integration blueprints, Day 1 control baselines, and executive reporting used across the transaction portfolio.
Own the function's annual plan, budget, tooling, and third-party bench, sized to support an unpredictable and confidential deal pipeline.
Define and report the metrics that demonstrate program effectiveness, including diligence cycle time, cost-estimate accuracy, Day 1 control coverage, and time to remediate inherited risk.
Position Secure MA&D as an enabler of inorganic growth by balancing speed of deal execution against defensible risk coverage.
People and Vendor Leadership
Lead, coach, and develop a global team of Secure MA&D principals and analysts; set performance standards, career paths, and succession plans.
Allocate scarce specialist capacity across concurrent transactions and adjust staffing as deals accelerate, pause, or collapse.
Direct third-party diligence and integration partners end to end, including selection, scoping, commercial terms, quality assurance, and performance management.
Build a team culture of disciplined judgment, documentation, and absolute confidentiality consistent with material non-public information obligations.
Serve as player-coach on the largest, most sensitive, or most contested transactions.
MA&D Lifecycle Execution
Direct pre-close cybersecurity due diligence under compressed timelines, restricted target access, staged data-room release, and clean-team constraints, drawing defensible conclusions from incomplete evidence.
Calibrate diligence depth and approach to deal type, size, and thesis, recognizing the differences between a negotiated acquisition, a competitive auction, an asset versus stock purchase, and a carve-out from a larger parent.
Quantify and defend remediation, integration, tooling, licensing, labor, and run-rate cost estimates within the deal model, including capital versus operating treatment and dis-synergy impacts.
Ensure cyber findings are reflected in deal documents and protections, including representations and warranties, purchase price adjustments, escrow and indemnity, disclosure schedules, and closing conditions.
Define security requirements and exit criteria for Transition Service Agreements and reverse TSAs; direct separation planning for divestitures, including data segregation, entitlement removal, and protection of retained intellectual property.
Direct Day 1 readiness, including minimum viable controls, identity and network interconnection decisions, endpoint and email protections, logging and monitoring onboarding, and incident response coverage for the acquired entity.
Own the handoff from diligence to delivery, transferring risks, named owners, and funded remediation plans to security capability owners with accountability tracked through TSA exit and integration close.
Lead the security response when a target is found to have an active or historical compromise, coordinating pre-close containment, valuation impact, and disclosure implications with Legal and Corporate Development.
Risk Management and Compliance
Establish the risk-acceptance and exception framework for inherited risks that cannot be remediated by Day 1, ensuring documented ownership, funding, and time-bound closure.
Ensure diligence and integration address the regulatory exposure relevant to the enterprise, including HIPAA and protected health information, GxP and validated systems, DSCSA, PCI DSS, SOX IT general controls, GDPR, and cross-border data transfer requirements.
Aggregate inherited cyber risk across the transaction portfolio into the enterprise risk register and report exposure trends to executive risk committees.
Oversee the third-party and fourth-party risk introduced through acquired vendor ecosystems, contracts, and data-sharing arrangements.
Align Secure MA&D practices to recognized frameworks such as NIST CSF, NIST SP 800-53, ISO 27001, CIS Controls, and HITRUST, and support internal audit and regulatory inquiry into transaction risk.
Communications and Executive Engagement
Serve as the security voice in deal committee, investment committee, and Board-level materials, presenting a clear position, a risk-adjusted cost range, and an explicit confidence level.
Translate technical findings into valuation, timing, compliance, and operational impact for non-technical executives across Finance, Legal, Corporate Development, and Technology.
Produce concise, decision-grade deliverables for audiences that will not read a technical report, while retaining the underlying evidence for audit and integration use.
Brief and align security capability owners, business unit leaders, and acquired-company executives on findings, obligations, and sequencing.
Represent the enterprise credibly while protecting confidentiality and negotiating position.
Deliver difficult messages to deal sponsors and target leadership without stalling the transaction, and escalate with evidence when risk exceeds tolerance.
Change Management and Integration Enablement
Lead the organizational change required to bring acquired entities onto enterprise security standards, including policy adoption, control uplift sequencing, and tooling migration.
Build stakeholder engagement, training, and communication plans that reduce resistance, shadow IT, and control drift during integration.
Assess acquired security talent and define retention, onboarding, and organizational design recommendations in partnership with Human Resources and security leadership.
Manage the cultural transition from a smaller or less mature security environment to enterprise expectations, sequencing change to preserve business continuity and acquired-team morale.
Institutionalize lessons learned after each close, feeding improvements back into playbooks, cost models, and Day 1 baselines.
Qualifications:
Bachelor's degree required; advanced degree in business or a technical discipline preferred.
15+ years of progressive experience in cybersecurity, technology risk, or security consulting, including 5+ years leading teams and enterprise-scale programs.
Demonstrated experience leading cybersecurity due diligence and integration across multiple co
Listed on hirly, a job board. hirly is not the employer: Myhrabc is hiring for this role.