Profil recherché
Qu’est-ce qui définit Principal M&A Analyst Cyber couronné de succès? Voici les qualités principales de cette personne :
- Conceptualisation
- Proactivité
- Résolution de problèmes
- Stratégie
- Fine pointe de la technologie
- Pensée visuelle
La Culture
Accomplissement
Mettre à profit vos aptitudes dans la résolution de problèmes pour maximiser le temps disponible de nos produits et assurer une expérience agréable à notre clientèle, tout en maintenant un équilibre travail-vie personnelle sain.
Innovation
à l’aide de nos données en évolution et de nos outils technologiques, surveiller et analyser l’information et les tendances pour définir les prochaines étapes de notre mission d’améliorer les soins de santé.
Grandir
Intégrez un environnement bienveillant où vous pourrez faire progresser votre carrière tout en vous développant sur le plan personnel et professionnel.
Avantages sociaux
-
Une couverture sur laquelle vous pouvez compter :
- Soins médicaux, dentaires et de la vue
- Compte de frais médicaux
- Compte de frais variables
-
Des avantages sociaux qui surpassent votre salaire de base :
- 401(k) (États-Unis)
- Régime de retraite (Canada)
- Régime d’actionnariat privilégié pour le personnel
-
Soutien au bien-être global :
- Programmes de santé mentale
- Horaires de travail flexibles
- Congés payés
- Programme de mieux-être
- Remboursement des droits de scolarité
- Occasions de bénévolat
- Environnement de travail flexible
-
Une culture propulsée par le sentiment d’appartenance :
En favorisant une culture d’appartenance, nous avançons vers notre objectif d’être le meilleur endroit où travailler dans le secteur de la santé — en reliant les bons talents aux bons rôles afin de relever nos défis les plus critiques.
Responsabilité
McKesson is an impact-driven, Fortune 10 company that touches virtually every aspect of healthcare. We are known for delivering insights, products, and services that make quality care more accessible and affordable. Here, we focus on the health, happiness, and well-being of you and those we serve – we care.
What you do at McKesson matters. We foster a culture where you can grow, make an impact, and are empowered to bring new ideas. Together, we thrive as we shape the future of health for patients, our communities, and our people. If you want to be part of tomorrow’s health today, we want to hear from you.
McKesson is seeking a Principal M&A Analyst Cyber to support cybersecurity due diligence and risk assessment activities across mergers, acquisitions, divestitures, and strategic investments. This role serves as a trusted advisor to business and technology stakeholders, helping evaluate target-company cybersecurity programs, identify risks, document findings, and support integration planning.
The successful candidate will partner with cybersecurity, legal, compliance, technology, and business teams to assess security posture, recommend remediation strategies, and help protect enterprise value throughout the transaction lifecycle. This role is ideal for a cybersecurity professional who combines strong analytical skills, risk management expertise, and collaborative leadership.
What You'll Do
Enterprise Cybersecurity Due Diligence Leadership
- Lead cybersecurity due diligence assessments for mergers, acquisitions, and strategic transactions.
- Evaluate target company security controls, governance practices, regulatory compliance, and cyber risks.
- Document cybersecurity findings, risk ratings, and remediation requirements for stakeholders and executive audiences.
- Coordinate with security, infrastructure, application, privacy, and compliance teams on integration risk assessments.
- Assess third-party, cloud, identity, vulnerability, and data protection risks associated with acquisition targets.
- Provide actionable recommendations that help inform transaction decisions and post-close integration planning.
- Collaborate with cross-functional stakeholders to ensure cybersecurity risks are tracked, mitigated, and communicated effectively.
Financial and Integration Planning Inputs
- Own the cybersecurity contribution to the transaction cost model, including preliminary one-time and recurring cost estimates, assumptions, contingencies, and key estimation risks.
- Identify potential Day 1, initial hardening, Employee Day 1, and longer-term integration requirements to inform transaction decisions and subsequent planning.
- Define the recommended cybersecurity integration principles, priorities, planning guardrails, and critical dependencies arising from due diligence.
- Partner with Finance, Cybersecurity Service Areas, Infrastructure, Enterprise Applications, Enterprise Architecture, and MT M&A leadership to ensure cybersecurity risk and cost implications are reflected consistently in deal materials.
Strategic Deal Advisory and Executive Influence
- Translate complex cybersecurity findings into clear business implications, including potential deal impact, risk acceptance requirements, cost exposure, timing constraints, and integration complexity.
- Identify, prioritize, and escalate material or potentially deal-altering cybersecurity risks, with practical recommendations and clearly articulated trade-offs.
- Advise transaction leaders on cybersecurity considerations affecting valuation, deal structure, contractual protections, closing conditions, transition services, and investment requirements.
- Deliver concise, decision-oriented cybersecurity recommendations to executive leadership.
- Serve as the senior cybersecurity diligence advisor in high-ambiguity situations where evidence is incomplete, timelines are compressed, and decisions carry significant enterprise consequence.
Governance, Standards, and Capability Building
- Establish and maintain enterprise standards, playbooks, templates, quality criteria, and escalation thresholds for M&A cybersecurity due diligence.
- Provide portfolio-level visibility into cybersecurity diligence status, material risk themes, cost exposure, and recurring integration complexity across concurrent transactions.
- Drive consistency and quality across internal subject matter experts and external advisors supporting diligence activities.
- Incorporate lessons learned and evolving threat, regulatory, and technology considerations into the cybersecurity M&A diligence methodology.
Basic Requirements
- 13+ years of professional experience with 8+ years of direct experience in cybersecurity, information security, cyber risk, security consulting, or related disciplines.
- Bachelor's degree or equivalent combination of education and experience.
- Significant experience leading cybersecurity due diligence or cyber risk assessment for mergers, acquisitions, divestitures, strategic investments, or similarly complex enterprise transactions.
- Knowledge of NIST CSF, ISO 27001, HITRUST, SOC 2, HIPAA, PCI DSS, GDPR, and other relevant security or privacy frameworks.
- Experience evaluating security controls across cloud, infrastructure, applications, identity, and data protection domains.
- Strong stakeholder management and cross-functional collaboration skills.
- Proven written and verbal communication skills with the ability to present risk information clearly.
- Recognized expertise in enterprise cybersecurity risk, control environments, security architecture, regulatory considerations, and integration complexity.
- Demonstrated ability to shape executive decisions through clear risk, financial, and strategic recommendations.
- Experience directing cross-functional work through influence in highly matrixed, time-sensitive, and confidential environments.
- Strong financial acumen, including cost estimation, assumption development, scenario analysis, and communication of uncertainty.
Preferred Skills/Experience
- Experience assessing regulatory and compliance considerations, including privacy and data protection requirements.
- Familiarity with cyber threat management, vulnerability management, incident response, or security operations.
- Experience developing cybersecurity governance processes, assessment methodologies, or due diligence frameworks.
- Professional certifications such as CISSP, CISM, CRISC, CCSP, GIAC, or relevant cloud security certifications.
- Experience supporting post-acquisition integration planning and risk remediation programs.
- Advanced analytical, risk prioritization, and executive presentation skills.
- Master's degree in Cybersecurity, Information Technology, Business, or a related field.
We are proud to offer a competitive compensation package at McKesson as part of our Total Rewards. This is determined by several factors, including performance, experience and skills, equity, regular job market evaluations, and geographical markets. The pay range shown below is aligned with McKesson's pay philosophy, and pay will always be compliant with any applicable regulations. In addition to base pay, other compensation, such as an annual bonus or long-term incentive opportunities may be offered. For more information regarding benefits at McKesson, please click here.
Our Base Pay Range for this position
$149,600 - $199,500McKesson has become aware of online recruiting-related scams in which individuals who are not affiliated with or authorized by McKesson are using McKesson’s (or affiliated entities, like CoverMyMeds or RxCrossroads) name in fraudulent emails, job postings or social media messages. In light of these scams, please bear the following in mind:
McKesson Talent Advisors will never solicit money or credit card information in connection with a McKesson job application.
McKesson Talent Advisors do not communicate with candidates via online chatrooms or using email accounts such as Gmail or Hotmail. Note that McKesson does rely on a virtual assistant (Gia) for certain recruiting-related communications with candidates.
McKesson job postings are posted on our career site: careers.mckesson.com.
McKesson is an Equal Opportunity Employer
McKesson provides equal employment opportunities to applicants and employees, without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, disability, age, genetic information, or any other legally protected category. For additional information on McKesson’s full Equal Employment Opportunity policies, visit our Equal Employment Opportunity page.
McKesson is committed to being an Equal Employment Opportunity Employer and offers opportunities to all job seekers including job seekers with disabilities. If you need a reasonable accommodation to assist with your job search or application for employment, please contact us by sending an email to (United States) Disability_Accommodation@McKesson.com or (Canada) Accessibility@mckesson.ca. Resumes or CVs submitted to this email box will not be accepted.
Join us at McKesson!
McKesson a pris connaissance d'arnaques en ligne liées au recrutement dans lesquelles des individus non affiliés à McKesson ou autorisés par celle-ci utilisent le nom de McKesson (ou d'entités affiliées, telles que CoverMyMeds ou RxCrossroads) dans des courriels frauduleux, des offres d'emploi ou des messages sur les réseaux sociaux. Compte tenu de ces arnaques, veuillez garder à l'esprit ce qui suit :
- Les conseillers en talent de McKesson ne demanderont jamais d'argent ni d'informations de carte de crédit dans le cadre d'une candidature à un emploi chez McKesson.
- Les conseillers en talent de McKesson ne communiquent pas avec les candidats via des salles de discussion en ligne ou en utilisant des comptes courriels tels que Gmail ou Hotmail. Notez que McKesson s'appuie sur un assistant virtuel (Gia) pour certaines communications liées au recrutement avec les candidats.
- Les offres d'emploi de McKesson sont publiées sur le site de carrières de McKesson: careers.mckesson.com