About this role
McKesson is an impact-driven, Fortune 10 company that touches virtually every aspect of healthcare. We are known for delivering insights, products, and services that make quality care more accessible and affordable. Here, we focus on the health, happiness, and well-being of you and those we serve – we care.
What you do at McKesson matters. We foster a culture where you can grow, make an impact, and are empowered to bring new ideas. Together, we thrive as we shape the future of health for patients, our communities, and our people. If you want to be part of tomorrow’s health today, we want to hear from you.
About the Role
McKesson is seeking a highly skilled Lead Information Security Analyst to strengthen our cyber threat intelligence capabilities. This role serves as a senior intelligence leader responsible for identifying, analyzing, and communicating cyber threats that may affect the enterprise, its business operations, and the healthcare sector.
As a lead analyst, you will partner with cybersecurity, technology, risk, legal, and business teams to define intelligence needs, assess emerging threats, translate complex findings into relevant business insights, and guide risk-informed decisions. You will also mentor analysts, strengthen analytic tradecraft, and improve how intelligence is collected, produced, and shared.
What You'll Do
- Identify and track emerging threats by discovering untracked adversary activity, developing new threat clusters into tracked actor groups across McKesson telemetry
- Deliver time-sensitive behavioral attack chains supporting active incident response and threat hunting operations to drive cross-team detection and protection actions.
- Lead attribution and threat actor analysis by collecting, modeling, attributing, and documenting intelligence gathered during investigations. Serve as the primary owner for attribution efforts while partnering with incident response teams.
- Author actor profiles for the CIRT, Red Team, Threat Hunt, and Detection Engineering-- leveraging internal signals, open-source, vendor research, and sharing community reporting
- Leverage AI to guide investigations and automation (e.g., intel-to-detection pipelines, infrastructure clustering, cross-actor TTP analysis) to scale production beyond manual analysis
- Provide technical mentorship to mid-level analysts on tradecraft, source evaluation, and production standards
- Represent the intelligence function in cross-functional planning with SOC, threat hunting, red team, and incident response
- Contribute to strategic planning on how internal telemetry investments map to intelligence production goals
Basic Requirements
- 10+ years of cybersecurity, information security, cyber threat intelligence, threat research, or related experience.
- Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Systems, or related field; equivalent experience will be considered.
- Experience developing a telemetry-to-intelligence model that reduces reliance on third-party feeds and vendors—shifting teams from intel consumers to intel producers
- Experience with open source research tools, including Virus Total, Domain Tools, Censys, Grey Noise, and other similar tools.
- Experience in tactical threat intelligence, specifically identifying IOCs, tools, and behavioral fingerprints left by adversaries across our telemetry (endpoint, network, cloud, and identity)
- Mine SIEM, EDR, NDR, firewall, DNS, proxy, and cloud logging data to identify adversary tradecraft, infrastructure, and behavioral patterns unique McKesson
- Experience using MITRE ATT&CK, Cyber Kill Chain, or similar frameworks to structure and communicate threat analysis.
- Experience with threat intelligence platforms, link analysis, data enrichment, or scripting and automation that support intelligence workflows.
Preferred Skills/Experience
- Advanced cyber threat intelligence experience using TIPs, commercial reporting, OSINT, information-sharing communities, and dark web intelligence sources.
- Experience building or maturing a cyber threat intelligence program, operating model, or intelligence lifecycle.
- Knowledge of intelligence collection management, source validation, confidence assessments, and structured analytic techniques. Experience with design, build, and optimize intelligence systems for structured storage, correlation, and analytics of large-scale threat intelligence data sets.
- Experience supporting regulatory, audit, compliance, or healthcare security environments.
- Relevant certifications such as CISSP, GCTI, OSCP, GREM, or equivalent intelligence, cybersecurity, or analytic credentials.
- Experience coaching technical teams and leading cross-functional security initiatives.
Travel / Work Environment / Physical Requirements
- May require occasional travel (up to 10%) based on business needs.
- Hybrid or remote work arrangements may be available based on location and business requirements.
- Ability to work extended hours during critical security incidents when necessary.
Ability to operate standard computer equipment and collaborate in virtual and in-person environments.
We are proud to offer a competitive compensation package at McKesson as part of our Total Rewards. This is determined by several factors, including performance, experience and skills, equity, regular job market evaluations, and geographical markets. The pay range shown below is aligned with McKesson's pay philosophy, and pay will always be compliant with any applicable regulations. In addition to base pay, other compensation, such as an annual bonus or long-term incentive opportunities may be offered. For more information regarding benefits at McKesson, please click here.
Our Base Pay Range for this position
$151,600 - $252,600
McKesson has become aware of online recruiting-related scams in which individuals who are not affiliated with or authorized by McKesson are using McKesson’s (or affiliated entities, like CoverMyMeds or RxCrossroads) name in fraudulent emails, job postings or social media messages. In light of these scams, please bear the following in mind:
McKesson Talent Advisors will never solicit money or credit card information in connection with a McKesson job application.
McKesson Talent Advisors do not communicate with candidates via online chatrooms or using email accounts such as Gmail or Hotmail. Note that McKesson does rely on a virtual assistant (Gia) for certain recruiting-related communications with candidates.
McKesson job postings are posted on our career site: careers.mckesson.com .
McKesson is an Equal Opportunity Employer
McKesson provides equal employment opportunities to applicants and employees, without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, disability, age, genetic information, or any other legally protected category. For additional information on McKesson’s full Equal Employment Opportunity policies, visit our Equal Employment Opportunity page.
McKesson is committed to being an Equal Employment Opportunity Employer and offers opportunities to all job seekers including job seekers with disabilities. If you need a reasonable accommodation to assist with your job search or application for employment, please contact us by sending an email to (United States) [email protected] or (Canada) [email protected] . Resumes or CVs submitted to this email box will not be accepted.
Join us at McKesson!