McKesson

Principal M&A Analyst Cyber

McKesson • $149K — $199K *
Healthcare
11 - 15 years of experience
Job Overview by Ladders

Qualifications

  • 13+ years of professional experience, with 8+ years in cybersecurity or related disciplines.
  • Bachelor's degree or equivalent combination of education and experience.
  • Experience leading cybersecurity due diligence or risk assessments for complex transactions.
  • Knowledge of frameworks such as NIST CSF, ISO 27001, HIPAA, and GDPR.
  • Strong stakeholder management and cross-functional collaboration skills.

Responsibilities

  • Lead cybersecurity due diligence assessments for mergers and acquisitions.
  • Evaluate target company security controls and governance practices.
  • Document cybersecurity findings and remediation requirements for stakeholders.
  • Coordinate with security and compliance teams for integration risk assessments.
  • Translate complex cybersecurity findings into actionable business insights.

Benefits

  • Comprehensive benefits package including health and wellness programs.
  • Opportunities for professional development and career advancement.
  • Flexible work environment fostering work-life balance.
  • Employee assistance and mental health support services.
  • Retirement savings plan with company match.
Full Job Description
McKesson is seeking a Principal M&A Analyst Cyber to support cybersecurity due diligence and risk assessment activities across mergers, acquisitions, divestitures, and strategic investments. This role serves as a trusted advisor to business and technology stakeholders, helping evaluate target-company cybersecurity programs, identify risks, document findings, and support integration planning.

The successful candidate will partner with cybersecurity, legal, compliance, technology, and business teams to assess security posture, recommend remediation strategies, and help protect enterprise value throughout the transaction lifecycle. This role is ideal for a cybersecurity professional who combines strong analytical skills, risk management expertise, and collaborative leadership.

What You'll Do
Enterprise Cybersecurity Due Diligence Leadership
  • Lead cybersecurity due diligence assessments for mergers, acquisitions, and strategic transactions.
  • Evaluate target company security controls, governance practices, regulatory compliance, and cyber risks.
  • Document cybersecurity findings, risk ratings, and remediation requirements for stakeholders and executive audiences.
  • Coordinate with security, infrastructure, application, privacy, and compliance teams on integration risk assessments.
  • Assess third-party, cloud, identity, vulnerability, and data protection risks associated with acquisition targets.
  • Provide actionable recommendations that help inform transaction decisions and post-close integration planning.
  • Collaborate with cross-functional stakeholders to ensure cybersecurity risks are tracked, mitigated, and communicated effectively.
Financial and Integration Planning Inputs
  • Own the cybersecurity contribution to the transaction cost model, including preliminary one-time and recurring cost estimates, assumptions, contingencies, and key estimation risks.
  • Identify potential Day 1, initial hardening, Employee Day 1, and longer-term integration requirements to inform transaction decisions and subsequent planning.
  • Define the recommended cybersecurity integration principles, priorities, planning guardrails, and critical dependencies arising from due diligence.
  • Partner with Finance, Cybersecurity Service Areas, Infrastructure, Enterprise Applications, Enterprise Architecture, and MT M&A leadership to ensure cybersecurity risk and cost implications are reflected consistently in deal materials.
Strategic Deal Advisory and Executive Influence
  • Translate complex cybersecurity findings into clear business implications, including potential deal impact, risk acceptance requirements, cost exposure, timing constraints, and integration complexity.
  • Identify, prioritize, and escalate material or potentially deal-altering cybersecurity risks, with practical recommendations and clearly articulated trade-offs.
  • Advise transaction leaders on cybersecurity considerations affecting valuation, deal structure, contractual protections, closing conditions, transition services, and investment requirements.
  • Deliver concise, decision-oriented cybersecurity recommendations to executive leadership.
  • Serve as the senior cybersecurity diligence advisor in high-ambiguity situations where evidence is incomplete, timelines are compressed, and decisions carry significant enterprise consequence.
Governance, Standards, and Capability Building
  • Establish and maintain enterprise standards, playbooks, templates, quality criteria, and escalation thresholds for M&A cybersecurity due diligence.
  • Provide portfolio-level visibility into cybersecurity diligence status, material risk themes, cost exposure, and recurring integration complexity across concurrent transactions.
  • Drive consistency and quality across internal subject matter experts and external advisors supporting diligence activities.
  • Incorporate lessons learned and evolving threat, regulatory, and technology considerations into the cybersecurity M&A diligence methodology.


Basic Requirements
  • 13+ years of professional experience with 8+ years of direct experience in cybersecurity, information security, cyber risk, security consulting, or related disciplines.
  • Bachelor's degree or equivalent combination of education and experience.
  • Significant experience leading cybersecurity due diligence or cyber risk assessment for mergers, acquisitions, divestitures, strategic investments, or similarly complex enterprise transactions.
  • Knowledge of NIST CSF, ISO 27001, HITRUST, SOC 2, HIPAA, PCI DSS, GDPR, and other relevant security or privacy frameworks.
  • Experience evaluating security controls across cloud, infrastructure, applications, identity, and data protection domains.
  • Strong stakeholder management and cross-functional collaboration skills.
  • Proven written and verbal communication skills with the ability to present risk information clearly.
  • Recognized expertise in enterprise cybersecurity risk, control environments, security architecture, regulatory considerations, and integration complexity.
  • Demonstrated ability to shape executive decisions through clear risk, financial, and strategic recommendations.
  • Experience directing cross-functional work through influence in highly matrixed, time-sensitive, and confidential environments.
  • Strong financial acumen, including cost estimation, assumption development, scenario analysis, and communication of uncertainty.

Preferred Skills/Experience
  • Experience assessing regulatory and compliance considerations, including privacy and data protection requirements.
  • Familiarity with cyber threat management, vulnerability management, incident response, or security operations.
  • Experience developing cybersecurity governance processes, assessment methodologies, or due diligence frameworks.
  • Professional certifications such as CISSP, CISM, CRISC, CCSP, GIAC, or relevant cloud security certifications.
  • Experience supporting post-acquisition integration planning and risk remediation programs.
  • Advanced analytical, risk prioritization, and executive presentation skills.
  • Master's degree in Cybersecurity, Information Technology, Business, or a related field.


We are proud to offer a competitive compensation package at McKesson as part of our Total Rewards. This is determined by several factors, including performance, experience and skills, equity, regular job market evaluations, and geographical markets. The pay range shown below is aligned with McKesson's pay philosophy, and pay will always be compliant with any applicable regulations. In addition to base pay, other compensation, such as an annual bonus or long-term incentive opportunities may be offered. For more information regarding benefits at McKesson, please click here.

Our Base Pay Range for this position

$149,600 - $199,500

McKesson has become aware of online recruiting-related scams in which individuals who are not affiliated with or authorized by McKesson are using McKesson's (or affiliated entities, like CoverMyMeds or RxCrossroads) name in fraudulent emails, job postings or social media messages. In light of these scams, please bear the following in mind:

McKesson Talent Advisors will never solicit money or credit card information in connection with a McKesson job application.

McKesson Talent Advisors do not communicate with candidates via online chatrooms or using email accounts such as Gmail or Hotmail. Note that McKesson does rely on a virtual assistant (Gia) for certain recruiting-related communications with candidates.

McKesson job postings are posted on our career site: careers.mckesson.com.

About McKesson

McKesson Corporation provides medicines, pharmaceutical supplies, information and care management products and services across the healthcare industry. The Company operates in two segments. The McKesson Distribution Solutions segment delivers ethical drugs, medical-surgical supplies and equipment and health and beauty care products throughout North America. This segment also provides specialty pharmaceutical solutions for biotech and pharmaceutical manufacturers, sells financial, operational and clinical solutions for pharmacies (retail, hospital, long-term care) and provides consulting, outsourcing and other services. The McKesson Technology Solutions segment delivers enterprise-wide clinical, patient care, financial, supply chain, strategic management and software solutions. In July 2011, the Company acquired Portico Systems from Safeguard Scientifics, Inc. On March 25, 2012, it acquired the independent banner and franchise businesses of Katz Group Canada Inc. McKesson Distribution Solutions delivers pharmaceuticals to retail pharmacies and institutional providers like hospitals and health systems. They operate pharmaceutical distribution centers across the country, serving customers in all 50 states. They also deliver a comprehensive offering of health care products, technology, equipment and related services to the alternate site market, including physician offices, surgery centers, long-term care facilities and home care businesses across the country. McKesson is currently the largest pharmaceutical distributor in North America. McKesson also operates McKesson Canada and has an equity holding in Nadro, a leading distributor in Mexico.

McKesson Careers

Join McKesson, a leading global healthcare company, and be part of a team that is redefining the future of healthcare. With a variety of job opportunities available, McKesson is the perfect place to advance your career, whether you're a seasoned professional or just starting out. Work You’ll Do At McKesson, we are committed to improving care in every setting—one product, one partner, one patient at a time. We’re seeking talented professionals to join our team and contribute to a culture of innovation, diversity, and leadership. Our employees are driven by a deep sense of purpose and a desire for continuous growth and improvement. Empower Your Future in Healthcare With positions ranging from internships to leadership roles, McKesson offers unparalleled employment opportunities to develop your skills and advance your career. Our commitment to diversity training ensures that all team members have the opportunity to thrive. Join a team where your skills will be honed, your professional growth will be supported, and where you can genuinely see the difference you make in the lives of patients around the world. Innovative Work Environment McKesson is at the forefront of healthcare innovation. Our team is constantly exploring new ways to improve patient outcomes and streamline care processes. This commitment to innovation is what sets us apart and what makes McKesson an exciting place to work. Career Development and Benefits McKesson believes in nurturing the potential of its employees through robust career development programs and comprehensive benefits designed to support your life and well-being. From leadership training to health and wellness benefits, we ensure our team members are equipped to meet their professional and personal goals. Explore Job Opportunities Whether you’re looking for an internship to kickstart your career, or a senior position to utilize your extensive experience, McKesson offers a range of opportunities. Explore our open positions and find where you can make a difference at McKesson. Stay Connected Join Our Team Search for open positions that match your skills and interests. We are looking for passionate, curious, and solution-driven team players who are ready to take the next step in their careers. Keep Up to Date Stay ahead with career tips, insider perspectives, and industry-leading insights you can put to use today—all from the people who work here. Networking and Professional Growth At McKesson, networking and professional growth are part of our everyday environment. We encourage our employees to connect, share, and learn from each other to foster personal and professional development. Job Alert Emails Personalize your subscription to receive job alerts, latest news, and insider tips tailored to your preferences. Discover the exciting and rewarding career opportunities that await you at McKesson. Join McKesson today and be part of a team that is dedicated to shaping the future of healthcare.
Learn more about McKesson
Size
58,000 employees
Market Cap
$53.7 billion
Industry
Net Income
-$4.1 billion
Founded
1833
5 Year Trend
+5.9%
Revenue
$237.6 billion
NASDAQ

Similar Jobs

More Jobs at McKesson

More Healthcare Jobs

Find similar Principal M&A Analyst Cyber jobs: