Leads cybersecurity due diligence for mergers, acquisitions, divestitures, and strategic transactions. The role assesses target-company security posture, identifies cyber risks and control gaps, estimates remediation and integration costs, manages third-party diligence providers, and supports Day 1 readiness. It partners with Finance, Legal, Corporate Development, IT, and Information Security teams while maintaining transaction documentation and improving diligence playbooks, cost models, templates, and reporting.
Our team members are at the heart of everything we do. At Cencora, we are united in our responsibility to create healthier futures, and every person here is essential to us being able to deliver on that purpose. If you want to make a difference at the center of health, come join our innovative company and help us improve the lives of people and animals everywhere. Apply today!
Job Details
Position Summary
The Secure MA&D (Mergers, Acquisitions & Divestitures) Principal leads and is responsible for pre-close cybersecurity due diligence for mergers, acquisitions, divestitures, and other strategic transactions. This role identifies cyber risks, estimates remediation and integration costs, manages third-party diligence partners, transfers findings to security capability owners, and supports Day 1 readiness planning.
Key Responsibilities
Candidate Requirements
What Cencora offers
Benefit offerings outside the US may vary by country and will be aligned to local market practice. The eligibility and effective date may differ for some benefits and for team members covered under collective bargaining agreements.
Full time
Affiliated Companies
Affiliated Companies: AmerisourceBergen Services Corporation
Equal Employment Opportunity
Cencora is committed to providing equal employment opportunity without regard to race, color, religion, sex, sexual orientation, gender identity, genetic information, national origin, age, disability, veteran status or membership in any other class protected by federal, state or local law.
The company's continued success depends on the full and effective utilization of qualified individuals. Therefore, harassment is prohibited and all matters related to recruiting, training, compensation, benefits, promotions and transfers comply with equal opportunity principles and are non-discriminatory.
Cencora is committed to providing reasonable accommodations to individuals with disabilities during the employment process which are consistent with legal requirements. If you wish to request an accommodation while seeking employment, please call 888.692.2272 or email [email protected]. We will make accommodation determinations on a request-by-request basis. Messages and emails regarding anything other than accommodations requests will not be returned
Job Details
Position Summary
The Secure MA&D (Mergers, Acquisitions & Divestitures) Principal leads and is responsible for pre-close cybersecurity due diligence for mergers, acquisitions, divestitures, and other strategic transactions. This role identifies cyber risks, estimates remediation and integration costs, manages third-party diligence partners, transfers findings to security capability owners, and supports Day 1 readiness planning.
Key Responsibilities
- Lead pre-close cybersecurity due diligence for assigned MA&D transactions.
- Review target-company security posture, documentation, interviews, and assessment results.
- Identify key cyber risks, control gaps, compliance concerns, and Day 1 readiness issues.
- Translate technical findings into clear business, operational, and financial impacts.
- Manage third-party cybersecurity diligence providers, including scope, timelines, deliverables, and quality of findings.
- Develop preliminary cost estimates for remediation, integration, tooling, licensing, labor, and ongoing run support.
- Partner with Finance, Corporate Development, Legal, IT, and Information Security teams to validate risks, assumptions, and costs.
- Transfer diligence findings, risks, and open items to security capability owners before close.
- Support Day 1 readiness planning by identifying minimum required controls, dependencies, and immediate post-close actions.
- Maintain clear documentation of risks, decisions, assumptions, action items, and handoffs.
- Improve Secure MA&D diligence templates, playbooks, cost models, and reporting materials.
Candidate Requirements
- 10+ years of experience in cybersecurity, information risk, security consulting, M&A due diligence, or security program leadership.
- Experience leading cybersecurity assessments, risk reviews, diligence activities, or integration planning.
- Strong understanding of core security domains, including IAM, endpoint security, vulnerability management, cloud security, data protection, security operations, GRC, and third-party risk.
- Ability to explain cyber risks in business terms and connect findings to cost, timing, compliance, and operational impact.
- Experience developing high-level remediation, integration, and run-cost estimates.
- Strong vendor-management and stakeholder-management skills.
- Excellent written and verbal communication skills, including executive-level summaries and decision materials.
- Ability to manage multiple confidential transactions and competing priorities.
- Bachelor's degree preferred; PMP (or equivalent formal project management certification) and CRISC strongly preferred
- Additional relevant certifications such as CISSP, CISM, CISA, or CCSP are a plus.
What Cencora offers
Benefit offerings outside the US may vary by country and will be aligned to local market practice. The eligibility and effective date may differ for some benefits and for team members covered under collective bargaining agreements.
Full time
Affiliated Companies
Affiliated Companies: AmerisourceBergen Services Corporation
Equal Employment Opportunity
Cencora is committed to providing equal employment opportunity without regard to race, color, religion, sex, sexual orientation, gender identity, genetic information, national origin, age, disability, veteran status or membership in any other class protected by federal, state or local law.
The company's continued success depends on the full and effective utilization of qualified individuals. Therefore, harassment is prohibited and all matters related to recruiting, training, compensation, benefits, promotions and transfers comply with equal opportunity principles and are non-discriminatory.
Cencora is committed to providing reasonable accommodations to individuals with disabilities during the employment process which are consistent with legal requirements. If you wish to request an accommodation while seeking employment, please call 888.692.2272 or email [email protected]. We will make accommodation determinations on a request-by-request basis. Messages and emails regarding anything other than accommodations requests will not be returned
Cencora Chessington, England Office
Our major business support centre is based in Chessington, Surrey. It can be accessed easily by car with proximity to the M25 and the A3 or with good public transport links. This office features large garden area, well-being room and a multi-faith room.
Cencora Feltham, England Office
Situated adjacent to Heathrow airport, Feltham is a major operational hub in the UK with excellent transport links to London and internationally.
Cencora Woking, England Office
In 2024 we opened our brand-new state-of-the-art offices in Woking’s town centre. A few minutes walk from the main train station, these offices offer a light, modern space to work from just 20 minutes from central London.
Similar Jobs at Cencora
Healthtech • Logistics • Pharmaceutical
Leads cybersecurity due diligence for mergers, acquisitions, divestitures, and strategic transactions. Evaluates target security postures, identifies risks and control gaps, estimates remediation and integration costs, manages third-party diligence providers, and supports Day 1 readiness planning. Partners with Finance, Legal, Corporate Development, IT, and Information Security teams to translate technical findings into business and financial impacts. Maintains transaction documentation and improves diligence templates, playbooks, cost models, and reporting.
Top Skills:
Cloud SecurityData ProtectionEndpoint SecurityGrcIamSecurity OperationsThird-Party Risk ManagementVulnerability Management
Healthtech • Logistics • Pharmaceutical
Leads cybersecurity due diligence for mergers, acquisitions, divestitures, and strategic transactions. Evaluates target security postures, identifies risks and control gaps, estimates remediation and integration costs, manages third-party diligence providers, and supports Day 1 readiness planning. Partners with Finance, Legal, Corporate Development, IT, and Information Security teams to translate technical findings into business and financial impacts. Maintains transaction documentation and improves diligence templates, playbooks, cost models, and reporting.
Top Skills:
Cloud SecurityData ProtectionEndpoint SecurityGrcIamSecurity OperationsThird-Party Risk ManagementVulnerability Management
Healthtech • Logistics • Pharmaceutical
Lead master data and entity governance for a pan-European ERP/WMS transformation. Define critical entities, establish federated ownership, ensure golden record strategy, align data standards across markets, and provide decision-quality guidance to Architecture and SteerCo to prevent fragmented local models.
Top Skills:
AnalyticsAxwayClient PortalCRMD365ErpIntegration MiddlewareO2CSAPWms
What you need to know about the London Tech Scene
London isn't just a hub for established businesses; it's also a nursery for innovation. Boasting one of the most recognized fintech ecosystems in Europe, attracting billions in investments each year, London's success has made it a go-to destination for startups looking to make their mark. Top U.K. companies like Hoptin, Moneybox and Marshmallow have already made the city their base — yet fintech is just the beginning. From healthtech to renewable energy to cybersecurity and beyond, the city's startups are breaking new ground across a range of industries.

