About this role
Our team members are at the heart of everything we do. At Cencora, we are united in our responsibility to create healthier futures, and every person here is essential to us being able to deliver on that purpose. If you want to make a difference at the center of health, come join our innovative company and help us improve the lives of people and animals everywhere. Apply today!
Job Details
Position Overview:
The Lead Engineer – IAM will deliver and manage large and complex Identity and Access Management initiatives across the business with the goals of improving efficiency, increasing security posture, and supporting aggressive growth. The Lead Engineer will be expected to work in the Non-Human Identity Management space.
Key Responsibilities:
• Drive the design, implementation and management of Privileged Access Management Services which includes management of privileged accounts, secure access to Cencora resources (on premise and in the cloud), secure management of credentials, session management, zero standing privilege model, just-in-time privilege access and Identity & Access Analytics.
• Drive and manage Non-Human Identity Management (NHIM).
• Understand a variety of IAM-related product suites and tools to make critical operational and strategic decisions with a focus on NHI discovery, ownership attestation and risk reduction.
• Lead the development and implementation of prudent enterprise security standards, guidelines and procedures to protect the integrity, availability and privacy of all corporate information assets.
• Ensure Identity and Access Management Services follow appropriate policies, procedures, operational considerations, IT change control, and IT risk and compliance management programs.
• Directly partner with the enterprise Finance, Legal, Audit and Compliance executives to support Internal and External Audits relating to IAM (SOX, COBIT, IT Controls)
• Working with ISO Risk Organization, supporting the Business Unit and IT executives through the process of prioritizing security initiatives and spending based on relevant business risk and regulatory compliance issues, financial implications, and alignment with the corporate strategic plan.
• Support strategic and tactical security, risk mitigation and regulatory compliance guidance for all IT projects, including the evaluation of enterprise policies, processes, operating procedures and governance controls
This job profile description is a standardized, non-contractual reference description and global reference tool provided for organizational consistency and talent architecture purposes across Cencora. It does not alter actual job duties, responsibilities, reporting lines, working conditions, grading, compensation, or other essential terms and conditions of employment. Actual duties and responsibilities may vary based on business needs, local requirements, and operational practices. Where a team member's role is governed by an employment agreement, local terms and conditions, prior job description or collective bargaining agreement, those documents shall prevail in case of any inconsistency. Mandatory local laws shall also prevail.
.
Required Qualifications:
• Bachelor's degree in computer science, information technology, cybersecurity, software engineering, or a related field, or equivalent experience.
• Typically requires 10+ years of combined IT and security work experience with a broad range of exposure to Identity and Access Management functions with a focus on Privileged Access Management and over 5 years’ experience designing and deploying Identity and Access Management solutions at the enterprise level.
• Experience managing NHIs in a large and complex enterprise.
• Experience designing, managing and supporting IAM and PAM products: BeyondTrust Password Safe, BeyondTrust Endpoint Privilege Management (EPM), BeyondTrust Privileged Remote Access, SSH Key Management, MFA, SIEM, Azure Entra, Active Directory, Linux, PowerShell scripts, etc.
• Experience leading technical teams in a large and complex environment to deliver related capabilities and services.
• Demonstrated successful implementation of security control frameworks and standards such as ISO 27001, ISO 17799, COBIT, ITIL, NIST and PCI.
• Certification in Information Security relevant areas such as Audit (CISA), Security Management (CISM), Security Professional (CISSP) and/or equivalent business experience in a matrix Organization required.
What Cencora offers
Benefit offerings outside the US may vary by country and will be aligned to local market practice. The eligibility and effective date may differ for some benefits and for team members covered under collective bargaining agreements.
Full time
Affiliated Companies Affiliated Companies: CENCORA BUSINESS SERVICES INDIA PRIVATE LIMITED
Equal Employment Opportunity
Cencora is committed to providing equal employment opportunity without regard to race, color, religion, sex, sexual orientation, gender identity, genetic information, national origin, age, disability, veteran status or membership in any other class protected by federal, state or local law.
The company’s continued success depends on the full and effective utilization of qualified individuals. Therefore, harassment is prohibited and all matters related to recruiting, training, compensation, benefits, promotions and transfers comply with equal opportunity principles and are non-discriminatory.
Cencora is committed to providing reasonable accommodations to individuals with disabilities during the employment process which are consistent with legal requirements. If you wish to request an accommodation while seeking employment, please call 888.692.2272 or email hrsc@cencora.com. We will make accommodation determinations on a request-by-request basis. Messages and emails regarding anything other than accommodations requests will not be returned