Senior Cyber Information Assurance Analyst
Listed on 2026-01-16
-
IT/Tech
Cybersecurity, Information Security
We anticipate the application window for this opening will close on - 16 Jan 2026
At Medtronic you can begin a life-long career of exploration and innovation, while helping champion healthcare access and equity for all. You’ll lead with purpose, breaking down barriers to innovation in a more connected, compassionate world.
A Day in the LifeAt Medtronic, we bring bold ideas forward with speed and decisiveness to put patients first in everything we do. In-person exchanges are invaluable to our work. We’re working onsite 4 days a week as part of our commitment to fostering a culture of professional growth and cross‑functional collaboration as we work together to engineer the extraordinary.
- Mounds View, Minnesota
- Boston, Massachusetts
- Fridley, Minnesota (OHQ)
- Lafayette, Colorado
- Irvine, California (UCI)
- Jacksonville, Florida
- Rice Creek, Minnesota
The Medtronic Global Cyber and Information Security Office (GCISO) is seeking a highly skilled and experienced Senior Cybersecurity Information Assurance Analyst to join our cybersecurity team. In this role, you will be responsible for leading the identification, assessment, and mitigation of cybersecurity risks across the organization. As a senior member of the team, you will provide expertise in risk management, compliance, and security strategy, while also playing a key role in driving initiatives to ensure the protection of sensitive data, particularly in a highly regulated healthcare environment.
You will collaborate with cross‑functional teams to evaluate and enhance our cybersecurity posture, ensuring adherence to relevant regulations such as HIPAA, GDPR, and other industry standards.
- Defines requirements for business continuity, operations security, cryptography, forensics, regulatory compliance, internal counter‑espionage (insider threat detection and mitigation), physical security analysis (including facilities analysis, and security management) to best protect company assets.
- Assesses and mitigates system security threats and risks throughout the program life cycle.
- Validates system security requirements definition and analysis.
- Implements and validates security designs in hardware, software, data, and procedures.
- Verifies security requirements; performs system certification and accreditation planning and testing and liaison activities.
- Understanding of Identity, Lifecycle and Governance capabilities, intersection with other cyber security domains, products and industry practices.
- Identify and assess cybersecurity risks through business analysis and propose solutions to mitigate those risks, contributing to overall business continuity and security resilience.
- Demonstrated expertise in GRC frameworks and processes, including system selection, system administration, and supporting core GRC functions. Lead the design and implementation of process flows, ensuring alignment with business objectives.
- Collaborate with teams across various departments, including IT, legal, compliance, and product security, to identify, assess, and mitigate cybersecurity risks across a broad range of products and services, ensuring security is integrated throughout the entire product lifecycle and operational processes.
- Maintain up‑to‑date knowledge of cybersecurity regulations and standards specific to the medical device industry (FDA, HIPAA, IEC 62443, NIST, NIS 2, etc.).
- Drive improvements in the GRC platform by automating workflows, integrating new tools, and optimizing risk management processes to increase operational efficiency and reduce manual effort.
4+ years of experience with a high school diploma or equivalent.
Preferred Qualifications- Previous Medtronic experience
- 7+ years of experience in cybersecurity GRC (Governance, Risk, & Compliance), or external/internal audit, preferably within the medical device or healthcare industry.
- Strong understanding of cybersecurity frameworks, regulatory requirements, risk management, and industry best practices (e.g., HIPAA, NIST, ISO 27001, GDPR, etc.).
- Excellent communication and interpersonal skills, with the ability to…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).