Security Portfolio Manager Principal

USA - PA - Remote, United States

⚠️ We'll shut down after Aug 1st - try foo🦍 for all jobs in tech ⚠️

AmerisourceBergen

AmerisourceBergen fosters a positive impact on healthcare around the world by advancing the development and delivery of pharmaceuticals and healthcare products.

View all jobs at AmerisourceBergen

Apply now Apply later

Our team members are at the heart of everything we do. At Cencora, we are united in our responsibility to create healthier futures, and every person here is essential to us being able to deliver on that purpose. If you want to make a difference at the center of health, come join our innovative company and help us improve the lives of people and animals everywhere. Apply today!

Job Details

Summary:

The Security Portfolio Manager Principal is responsible for leading and overseeing the planning, execution, and management of the holistic Information Security portfolio ensuring alignment of all portfolio resources (financials, labor, services, tools, etc.) with organizational goals. Principal Security Portfolio Managers develop, review, and analyze portfolio performance data to measure portfolio effectiveness, identify risks and opportunities, and use data-driven insights to inform decision making. They lead the design, development, and execution of portfolio management practices and guardrails for Security including resource prioritization and allocation, portfolio risk assessment, and stakeholder engagement. They collaborate closely with multiple internal and external stakeholders including Information Security leadership, operations, Finance, Procurement, and Project Management Office (PPMO) to ensure appropriate financial and organizational support is allocated to address organizational goals, providing robust protection while maintaining fiscal responsibility. They are expected to have a deep understanding of the Information Security domains in which they are aligned. They play a key expert role in defining Information Security portfolio principles and best practices. They act as a subject matter expert for Information Security portfolio management and participate in senior leadership meetings to bring Information Security perspective to company-wide practices.

Responsibilities:

  • Provides leadership of one or more security domain portfolios involving large-scale, complex and highly analytical tasks.

  • Manages and leads oversight of all portfolio resources (Run and investment financials, labor, tools, services, etc.) for one or more security domains to ensure that the portfolio is prioritized and aligned optimally for the protection of information systems and networks. 

  • Formulates methodologies to monitor and assess portfolio performance against organizational benchmarks and key performance indicators (KPIs) to evaluate effectiveness, provide actionable insights, identify risk, and drive continuous optimization of our resources.

  • Delivers clear and comprehensive reporting that summarizes full portfolio performance, outcomes, risks, and strategic insights to Security leadership to ensure transparent communications and drive proactive, informed decision making.

  • Analyzes trends, news, and changes in threat and business environment with respect to organizational portfolio risk; advises organizational management and develops and executes plans for mitigation of portfolio risk.

  • Continuously analyzes and recommends opportunities for cost, resource, service, operational efficiencies, and portfolio process improvements.

  • Provides technical guidance, coaching, and mentorship to other Security Portfolio Managers in executing their tasks and responsibilities.

  • Develops and implements strategies to drive on-going prioritization and align Information Security budget and resources with business objectives and goals, maximize control effectiveness, and ensure operational efficiency.

  • Guides, coaches, and mentors Information Security team and key stakeholders  to drive awareness and adoption of consistent Information Security portfolio policies, processes, and guardrails.

  • Leads comprehensive security planning, forecasting, and analysis activities in partnership with Security leadership and partners (Finance, Procurement, PMO, etc.) to provide strategic and tactical direction and align to organizational objectives.

Education:

  • Bachelor’s Degree in Computer Science, Information Technology or any other related discipline or equivalent related experience.

Preferred Certifications:

  • Industry Agile certification (e.g., SAFe Agilist, SAFe LPM, etc.)

  • Industry project management certification (e.g., PMP)

  • Certified Cloud Security Professional (CCSP)

  • Certification in Information Security Strategy Management (CISM)

  • Certified Information Systems Security Professional (CISSP)

  • CompTIA Security + Certification

  • Systems Security Certified Practitioner (SSCP)

  • TS-SCI Security Clearance Certification

Work Experience:

  • 8+ years of directly-related or relevant experience, preferably in information security.

Behavioral Skills:

  • Analytical Skills: Strong analytical and problem-solving skills with a focus on data-driven decision making.

  • Change Leadership: demonstrated success promoting change by helping others to change and remove barriers.

  • Consulting and Influencing: strong ability to assess customer needs, provide expert advice, and develop solutions that enhance portfolio performance and alignment with organizational objectives.

  • Strategic Communication: able to simplify the complex with proven experience presenting to top level leaders.

  • Adaptability: Ability to adjust approach in response to changing or evolving organizational conditions or priorities.

  • Collaboration: strong inclination to work effectively with different teams, foster a spirit of cooperation, and break down silos.

Technical Skills:

  • Cybersecurity:  strong knowledge of cyber principles, frameworks, technologies, and standards (SOX, ISO 27001/27002, COBIT, ITIL, NIST, PCI, etc.).

  • Financial Acumen: knowledge of budgeting, financial analysis, and cost management concepts to optimize management of cyber-related financial, technology, and labor resources.

  • Vendor management acumen: knowledge of third-party vendor and service provider management and processes for cybersecurity solutions and suppliers.

  • Data management and reporting: proficiency in collecting, analyzing, and interpreting data to generate insightful reports that inform decision-making, track portfolio performance, and support effective prioritization and allocation of budget and resources.

  • Demand and capacity planning: proficiency in forecasting and aligning capacity allocations with organizational demands to optimize portfolio performance and meet strategic objectives.

Tools Knowledge:

  • Microsoft Office Suite

  • Reporting Tools (e.g., PowerBI)

  • Portfolio Management Tools (e.g., Clarity, ServiceNow, Apptio, etc.)

What Cencora offers

We provide compensation, benefits, and resources that enable a highly inclusive culture and support our team members’ ability to live with purpose every day. In addition to traditional offerings like medical, dental, and vision care, we also provide a comprehensive suite of benefits that focus on the physical, emotional, financial, and social aspects of wellness. This encompasses support for working families, which may include backup dependent care, adoption assistance, infertility coverage, family building support, behavioral health solutions, paid parental leave, and paid caregiver leave. To encourage your personal growth, we also offer a variety of training programs, professional development resources, and opportunities to participate in mentorship programs, employee resource groups, volunteer activities, and much more. For details, visit https://www.virtualfairhub.com/cencora

Full time

Equal Employment Opportunity

Cencora is committed to providing equal employment opportunity without regard to race, color, religion, sex, sexual orientation, gender identity, genetic information, national origin, age, disability, veteran status or membership in any other class protected by federal, state or local law.

The company’s continued success depends on the full and effective utilization of qualified individuals. Therefore, harassment is prohibited and all matters related to recruiting, training, compensation, benefits, promotions and transfers comply with equal opportunity principles and are non-discriminatory.

Cencora is committed to providing reasonable accommodations to individuals with disabilities during the employment process which are consistent with legal requirements. If you wish to request an accommodation while seeking employment, please call 888.692.2272 or email hrsc@cencora.com. We will make accommodation determinations on a request-by-request basis. Messages and emails regarding anything other than accommodations requests will not be returned

Affiliated CompaniesAffiliated Companies: AmerisourceBergen Services Corporation
Apply now Apply later

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Job stats:  2  0  0
Category: Leadership Jobs

Tags: Agile CCSP CISM CISSP Clearance Cloud COBIT CompTIA Computer Science Finance ISO 27001 ITIL KPIs NIST Risk assessment Security Clearance Security strategy SOX SSCP Strategy Vendor management

Perks/benefits: Career development Health care Medical leave Parental leave Team events Wellness

Regions: Remote/Anywhere North America
Country: United States

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.