ForgeApply
Try it free

ForgeApply · Job listing

Lead Cyber Security Architect

McKesson

Richmond, VA, US$143k – $238konsite

Tailor your resume for this McKesson job in about a minute.

ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for McKesson's site. Free trial, no card required.

About this role

McKesson is an impact-driven, Fortune 10 company that touches virtually every aspect of healthcare. We are known for delivering insights, products, and services that make quality care more accessible and affordable. Here, we focus on the health, happiness, and well-being of you and those we serve – we care.

What you do at McKesson matters. We foster a culture where you can grow, make an impact, and are empowered to bring new ideas. Together, we thrive as we shape the future of health for patients, our communities, and our people. If you want to be part of tomorrow’s health today, we want to hear from you.

Lead Cyber Security Architect Location: Richmond, VA, USA - 9954 Mayland Drive (on-site)

The Opportunity

The Lead Cyber Security Architect is a senior, advanced-skill role responsible for establishing and evolving MMS security architecture, patterns, and guardrails that protect the business while enabling speed and innovation. This role partners with the Chief Information Security Officer (CISO), Technology Senior Leadership, audit/compliance, product and application owners, infrastructure, and security engineering/operations teams to drive consistent security outcomes across the enterprise. 

This role provides expert guidance on current security issues while anticipating where threats and technology are heading to proactively shape MMS security strategy. The Lead Cyber Security Architect is expected to think like an adversary, translate business objectives into security architecture decisions, and define target-state architectures and roadmaps. As a Lead (P5), this role sets standards and raises the bar through mentoring and coaching, critical review of deliverables, and driving measurable improvements in risk reduction and control effectiveness. The architect leads through influence (often without direct people-management authority) and ensures security architecture decisions are documented, communicated, and adopted across delivery teams. 

Key Responsibilities 

• Own and evolve MMS security architecture reference patterns and guardrails across cloud, network, identity, endpoint, application, and data protection; ensure designs are secure-by-design and compliant-by-design. 

• Lead architecture reviews for key initiatives (new platforms, major applications, third-party integrations, and B2B/B2C capabilities); document decisions, risks, exceptions, and required compensating controls. 

• Translate security policy, risk, and regulatory obligations into practical engineering requirements, reusable design standards, and implementation guidance (e.g., templates, runbooks, and secure reference implementations). 

• Define target-state security architecture and roadmaps; drive organizational alignment and prioritization with security, technology, and business stakeholders. 

• Embed security in delivery through DevSecOps: advise on CI/CD controls, infrastructure-as-code, policy-as-code, secrets management, and secure SDLC practices; partner with engineering teams to increase automation and reduce friction. 

• Establish measurable security architecture outcomes (e.g., coverage of guardrails, reduction in high-risk exceptions, control adoption, improved detection/response maturity) and use metrics to guide continuous improvement. 

• Mentor and coach architects and engineers; perform critical self-review and peer review of deliverables to ensure high quality, accuracy, and alignment to enterprise security standards. 

• Design and maintain cloud security architecture patterns and guardrails (e.g., IAM and privileged access, organization policies, network segmentation, encryption and key management, logging/monitoring, vulnerability management, and posture management) with clear implementation guidance for delivery teams. 

• Perform other duties as assigned. 

Minimum Requirements

• Degree or equivalent and typically requires 10+ years of relevant experience. Less years required if has relevant Master’s or Doctorate qualifications

Skills and Qualifications

• 10+ years in cybersecurity with 5+ years in security architecture, including risk management and compliance.

• Demonstrated ability to lead complex initiatives, drive alignment, and coach others while delivering measurable security outcomes. 

• Hands-on security architecture experience, including designing guardrails/reference architectures and driving adoption across multiple teams. 

• Demonstrated experience designing security controls for sensitive data (PII/PHI) and supporting audits and compliance efforts through strong documentation and evidence-based controls. 

• Zero Trust and IAM/PAM (workforce and customer identity) design at scale; demonstrated ability to define and implement enterprise guardrails, including policy-as-code and standardized identity/network patterns. 

• Proven stakeholder leadership able to lead planning and architecture discussions, incorporate reviewer feedback, and obtain alignment and approvals for secure solutions. 

• Experience with modern security platforms and automation (e.g., SIEM, EDR/XDR, SOAR, secrets management, and data protection) plus scripting/automation to scale controls. 

• Strong background in technology design, implementation, and delivery (cloud, networking, identity, endpoint, and application platforms), with the ability to translate business requirements into secure reference architectures and pragmatic implementation plans. 

• Deep expertise in security controls and architecture domains: IAM (including privileged access), network security, encryption/key management, secrets management, application security, vulnerability management, logging/monitoring, and security posture management across public cloud and hybrid environments. 

• Ability to communicate technical risk and tradeoffs in business terms, influence decisions at multiple levels, and facilitate productive outcomes across security, engineering, and business stakeholders. 

• Experience improving detection and

Salary insight

The midpoint of this range ($191k) is about 57% above the median disclosed salary for Richmond roles listed on ForgeApply ($121k across 66 jobs).

Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.

Tailor your resume for this McKesson role before you apply.

Tailor my resume for this job

Similar jobs

More like this: More jobs at McKesson · Browse all jobs

Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)