Job DetailsSummary:The Secure MA&D Lead is responsible forcybersecurity due diligence for mergers, acquisitions, divestitures, and other strategic transactions. This role identifies cyber risks, estimates remediation and integration costs, manages third-party diligence partners, transfers findings to security capability owners, and supports Day-1 readiness planning.
Key Responsibilities: - Lead pre-close cybersecurity due diligence for assigned MA&D transactions.
- Review target-company security posture, documentation, interviews, and assessment results.
- Identify key cyber risks, control gaps, compliance concerns, and Day 1 readiness issues.
- Translate technical findings into clear business, operational, and financial impacts.
- Manage third-party cybersecurity diligence providers, including scope, timelines, deliverables, and quality of findings.
- Develop preliminary cost estimates for remediation, integration, tooling, licensing, labor, and ongoing run support.
- Partner with Finance, Corporate Development, Legal, IT, and Information Security teams to validate risks, assumptions, and costs.
- Transfer diligence findings, risks, and open items to security capability owners before close.
- Support Day 1 readiness planning by identifying minimum required controls, dependencies, and immediate post-close actions.
- Maintain clear documentation of risks, decisions, assumptions, action items, and handoffs.
- Improve Secure MA&D diligence templates, playbooks, cost models, and reporting materials.
Qualifications:- Bachelor's degree in cybersecurity, computer science, information systems, information technology, or a related field, or equivalent experience required.
- 6+ years of experience in information security analysis, cybersecurity engineering, incident response, vulnerability management, M&A due diligence, or security program leadership.
- Experience leading cybersecurity assessments, risk reviews, diligence activities, or integration planning.
- Strong understanding of core security domains, including IAM, endpoint security, vulnerability management, cloud security, data protection, security operations, GRC, and third-party risk.
- Ability to explain cyber risks in business terms and connect findings to cost, timing, compliance, and operational impact.
- Experience developing high-level remediation, integration, and run-cost estimates.
- Strong vendor-management and stakeholder-management skills.
- Excellent written and verbal communication skills, including executive-level summaries and decision materials.
- Ability to manage multiple confidential transactions and competing priorities.
- Relevant certifications such as CISSP, CISM, CRISC, CISA, or CCSP are a plus.
- Ability to travel as needed (5% - 10%)
What Cencora offersWe provide compensation, benefits, and resources that enable a highly inclusive culture and support our team members' ability to live with purpose every day. In addition to traditional offerings like medical, dental, and vision care, we also provide a comprehensive suite of benefits that focus on the physical, emotional, financial, and social aspects of wellness. This encompasses support for working families, which may include backup dependent care, adoption assistance, infertility coverage, family building support, behavioral health solutions, paid parental leave, and paid caregiver leave. To encourage your personal growth, we also offer a variety of training programs, professional development resources, and opportunities to participate in mentorship programs, employee resource groups, volunteer activities, and much more. For details, visit https://www.virtualfairhub.com/cencora
Full time