Cencora
Senior Application Security Analyst
Full details on LinkedIn
The complete job description, requirements, and application details are available on the original posting.
About Cencora
Cencora, Inc. is a global pharmaceutical solutions organization that emerged from AmerisourceBergen. With a history spanning over 150 years, Cencora focuses on pharmaceutical distribution, supply chain management, and contract research services for both human and animal health sectors. The company operates in over 50 countries and employs more than 46,000 people across 1,300 locations. Cencora offers a range of services, including pharmaceutical distribution of generic and over-the-counter products, specialty distribution through its World Courier network, and contract research organization services for clinical trials. The company also provides consulting services for supply chain optimization and supports innovative health businesses through Cencora Ventures. With reported revenues of $294 billion for fiscal year 2024, Cencora is positioned as a leader in the healthcare industry, dedicated to improving patient outcomes and operational efficiencies.
Security at Cencora
Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.
Security Philosophy
- Embed security into the software development lifecycle by integrating security controls and automated scanning throughout the DevOps/CI-CD pipeline.
- Advocate for security earlier in development, empower and educate developers on secure coding, and balance business enablement with enterprise risk and governance responsibilities.
Security Team
- AppSec/DevSecOps engineers and leads focused on application and API security, vulnerability identification and remediation, CI/CD security integration, and developer enablement.
- Enterprise information-security leadership oversees SOC/IR operations (SIEM, SOAR, EDR), incident command, KPIs/budgets, and centers of excellence for information security strategy.
Key Initiatives
1) Application and API security: identify and remediate vulnerabilities before production. 2) Automation & CI/CD integration: integrate automated SAST/DAST/SCA/IaC checks into pipelines. 3) Vulnerability management: track aging vulnerabilities, reduce false positives, and monitor remediation. 4) Secure testing & tooling: adopt SAST, DAST, SCA, IAST, IaC and container security, and perform manual testing/pen testing where needed. 5) Incident response & SOC optimization: operate SIEM/SOAR/EDR, serve as enterprise incident commander for high-severity events. 6) Metrics & governance: set KPIs, report to leadership, and run centers of excellence. 7) Privacy & compliance: maintain global privacy program (HIPAA/GDPR/state laws) and named privacy contacts.
Preparing for an AppSec interview?
Get the weekly briefing 2,000+ security pros trust.