Job Details
JOB SUMMARY
The Director of Vulnerability Management is the technical leader and owner of Cencora's vulnerability management program. This role sets the strategy, architecture, and operating model for how the organization discovers, prioritizes, and drives remediation of vulnerabilities across cloud, on-premise, endpoint, application, container, and third-party hosted environments. This hands-on technical leadership position leads the design of vulnerability scanning, reviewing detection logic, managing scan data, and defending remediation decisions across engineering teams and executive stakeholders.
RESPONSIBILITIES:
- Own the strategy and continual development of the end-to-end vulnerability management program, including strategy, roadmap, operating model, policy, standards, and success metrics.
- Define and maintain risk-based remediation SLAs by asset criticality, exposure, and severity.
- Mature beyond reactive scanning towards continuous, risk-based exposure management, including attack surface management and validation of remediation effectiveness.
- Establish governance forums to review exposure trends, aging findings, systemic root causes, and escalations.
- Oversee comprehensive and accurate asset coverage by integrating scanning with CMDB, cloud inventories, and other asset discovery sources to reduce unscanned and unknown assets.
- Lead refinement of prioritization models to combine CVSS scoring with threat intelligence and exploitability signals, asset criticality, and compensating controls.
- Partner with penetration testing, red team, threat intelligence, and countermeasures teams to correlate findings and validate control effectiveness.
- Drive measurable reduction in mean time to remediate and aging critical exposures, working with IT operations, infrastructure, application, and cloud engineering teams.
- Lead technical response for zero-day and emerging critical vulnerabilities, including rapid impact assessments, containment guidance, and executive communication.
- Identify and address systemic root causes such as patch tooling gaps, unsupported software, base image drift, and legacy platform debt.
- Define and report KPIs and KRIs to executive leadership, translating technical exposure into business and financial risk.
- Recruit, develop, mentor, and retain a team of vulnerability management analysts, building technical depth and clear career paths.
- Set technical standards, review the team's work product, and cultivate a culture of data quality and continuous improvement.
EDUCATION & QUALIFICATIONS:
- Bachelor's degree in Cybersecurity, Computer Science, Information Systems, or equivalent work experience
- 8+ years of progressive experience in cybersecurity, with at least 5 years in vulnerability management, security engineering, offensive security, or infrastructure security.
- Experience leading technical teams with demonstrated success building or substantially maturing a vulnerability or exposure management program at enterprise scale.
- Hands-on expertise with enterprise vulnerability management tenable (Table, Qualys, Rapid7, Wiz, etc).
- Strong working knowledge of operating system internals, networking, patch and configuration management, and enterprise identity across Windows, Linux, and MacOS.
- Demonstrated Experience security public cloud environments and container technologies, including cloud-native vulnerability and posture management.
- Fluency in vulnerability scoring and prioritization frameworks (CVSS , EPSS, CISA KEV, SSVC).
- Experience with application and software supply chain security concepts, including SAST, DAST, SCA, and SBOM.
- Familiarity with relevant security and risk frameworks (NIST CSF, ISO 27001, MITRE ATT&CK, etc).
- Excellent written and verbal communication skills with proven ability to influence engineering teams without direct authority and to brief executive audiences credibly.
PREFERRED CERTIFICATIONS:
- GIAC GEVA - Enterprise Vulnerability Assessor
- GIAC GPEN - Penetration Tester
- CISSP - Certified Information Systems Security Professional
- CISM - Certified Information Security Manager
Bachelor's degree in cybersecurity, information technology, computer science, information systems, business administration, or a related field, or equivalent experience required. Master's degree in cybersecurity, information technology, computer science, information systems, business administration, or a related field, or equivalent experience preferred. 10+ years of experience in cybersecurity, information security, security operations, IT risk, or a related field required. 5+ years of experience in a managerial capacity required. Certification in cybersecurity, information security, or a related field required. Examples may include Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or equivalent role relevant certification required. Certified Cloud Security Professional (CCSP), Certified Ethical Hacker (CEH), or equivalent certification preferred.
What Cencora offers
We provide compensation, benefits, and resources that enable a highly inclusive culture and support our team members' ability to live with purpose every day. In addition to traditional offerings like medical, dental, and vision care, we also provide a comprehensive suite of benefits that focus on the physical, emotional, financial, and social aspects of wellness. This encompasses support for working families, which may include backup dependent care, adoption assistance, infertility coverage, family building support, behavioral health solutions, paid parental leave, and paid caregiver leave. To encourage your personal growth, we also offer a variety of training programs, professional development resources, and opportunities to participate in mentorship programs, employee resource groups, volunteer activities, and much more. For details, visit https://www.virtualfairhub.com/cencora
Full time
Equal Employment Opportunity
Cencora is committed to providing equal employment opportunity without regard to race, color, religion, sex, sexual orientation, gender identity, genetic information, national origin, age, disability, veteran status or membership in any other class protected by federal, state or local law.
The company's continued success depends on the full and effective utilization of qualified individuals. Therefore, harassment is prohibited and all matters related to recruiting, training, compensation, benefits, promotions and transfers comply with equal opportunity principles and are non-discriminatory.
Cencora is committed to providing reasonable accommodations to individuals with disabilities during the employment process which are consistent with legal requirements. If you wish to request an accommodation while seeking employment, please call 888.692.2272 or email [email protected]. We will make accommodation determinations on a request-by-request basis. Messages and emails regarding anything other than accommodations requests will not be returned
Affiliated Companies
Affiliated Companies: AmerisourceBergen Services Corporation
Skills Required
- Bachelor's degree in cybersecurity, computer science, information systems, information technology, business administration, or a related field, or equivalent experience
- 8+ years of progressive cybersecurity experience, including at least 5 years in vulnerability management, security engineering, offensive security, or infrastructure security
- Enterprise-scale experience building or substantially maturing a vulnerability or exposure management program
- Experience leading technical teams
- Hands-on expertise with enterprise vulnerability management platforms such as Tenable, Qualys, Rapid7, or Wiz
- Working knowledge of operating system internals, networking, patch and configuration management, and enterprise identity across Windows, Linux, and macOS
- Experience securing public cloud environments and container technologies, including cloud-native vulnerability and posture management
- Fluency in CVSS, EPSS, CISA KEV, and SSVC vulnerability scoring and prioritization frameworks
- Experience with application and software supply chain security, including SAST, DAST, SCA, and SBOM
- Familiarity with NIST CSF, ISO 27001, and MITRE ATT&CK
- Excellent written and verbal communication skills, with the ability to influence engineering teams and brief executives
- Cybersecurity, information security, or related professional certification such as CISSP, CISM, or equivalent
- 10+ years of experience in cybersecurity, information security, security operations, IT risk, or a related field
- 5+ years of experience in a managerial capacity
- Master's degree in cybersecurity, information technology, computer science, information systems, business administration, or a related field
- GIAC GEVA, GIAC GPEN, CISSP, or CISM certification
- CCSP, CEH, or equivalent certification
Cencora Compensation & Benefits Highlights
-
Healthcare Strength — Day‑one eligibility for medical, dental, and vision is paired with mental‑health resources, wellness programs that can reduce premiums, and HSA/FSA options. The breadth includes prescription coverage, virtual musculoskeletal physical therapy, and care navigation support.
-
Parental & Family Support — Paid parental leave of 12 weeks for birth, adoption, or surrogacy is offered, plus two weeks of paid caregiver leave. Backup child care and family‑building coverage for fertility, adoption, and surrogacy further bolster support.
-
Retirement Support — A structured 401(k) match of 100% on the first 3% and 50% on the next 2% can also be directed to student‑loan payments. Additional financial programs include a discounted ESPP, tuition reimbursement, and scholarships for dependents.
Cencora Insights
What We Do
Cencora is a leading pharmaceutical solutions organization centered on improving the lives of people and animals everywhere. With 46,000+ global team members, we have the opportunity to make a positive impact on healthcare in communities everywhere. Our team members are empowered to activate their careers through a collective of tools and resources designed to support individual career interests and aspirations. We value our listening culture that actions real outcomes and our team members appreciate and recognize one another for contributions that are making a meaningful global impact. No matter what your role is here, the work we do together has meaning. When you join our team, you become a crucial part of a greater purpose. We’re committed to supporting you personally and professionally, so we can achieve more together at the center of health. Protect yourself from job scams: Recruitment scams are on the rise. To protect yourself, we urge you to be vigilant and follow these guidelines > https://careers.cencora.com/us/en/job-scams
Gallery
Cencora Teams
Cencora Offices
Hybrid Workspace
Employees engage in a combination of remote and on-site work.
















