🌎
此职位未使用所有网站语言进行发布

Principal Product Security Engineer - ISO2k7

📁
Engineering
📅
240003NS 招聘登记表编号

CAREERS THAT CHANGE LIVES

The Principal Cyber Info Assurance Analyst will join the Business Information Security team within the Business Partner Services (BPS) group and partner closely with the Global Security Office (GSO).  You will serve as a champion of the GSO, focusing on enhancing user experience with our business partners.  You’ll serve as a cybersecurity and compliance subject matter expert (SME) to the intelligent Data Solutions business. The cybersecurity SME will focus on identifying, prioritizing and driving remediation of all security risks owned by the business 

The primary focus of the role will be on achieving and/or maintaining HIPAA, GDPR and other regulatory compliance, and achieving and maintaining the ISO27011 and HITRUST certifications.  You will facilitate and assist the business by interpreting the requirements and driving technical remediations.   Communicate, escalate, and track progress on assessment remediation activities. Understand information security risks that are inherent to a business and articulate those risks in business terms. Support Commercial activities including contracting and IT/security questionnaires.  Maintain current knowledge on data privacy and information security topics and their applicable program requirements.  Provide concierge service to our business stakeholders when interacting with the GSO.

We believe that when people from different cultures, genders, and points of view come together, innovation is the result —and everyone wins. Medtronic walks the walk, creating an inclusive culture where you can thrive.

Bring your talents to an industry leader in medical technology and healthcare solutions – we’re a market leader and growing every day. You can be proud to be a part of technologies that are rooted in our long history of mission-driven innovation. You will be empowered to shape your own career. We support your growth with the training, mentorship, and guidance you need to own your future success. Together, we can transform healthcare.

Join us for a career in IT that changes lives.

Medtronic is committed to fostering a diverse and inclusive culture.  Check out the accomplishments of our Women in IT group!  http://bit.ly/MedtronicWomeninIT 


A DAY IN THE LIFE

  • Maintain relationships within Operating Unit proactively share business' upcoming projects to the GSO
  • Engage with cross functional teams to drive complex data security issues to resolution
  • Contribute continuous improvement to the methodologies and practices of the Business Information Security to attain higher capability maturity levels
  • Track status of open requests/tasks and drive accountability of requestors to ensure timely submitting
  • Partner with the GSO and Privacy to perform deep dives over high risk processes and systems to identify and remediate gaps in data security
  • Drive Security compliance activities related to HITRUST, ISO27001, SOC2, etc.
  • Help facilitate and/or respond to Customer Inquiries
  • Streamline processes and use of tools across Global IT to ensure data flow and security is maintained in the most efficient way possible
  • Provide insight and business background to include data security, encryption, authorization, authentication, and access controls to the GSO process teams, when needed
  • Prepare status reports on data security and privacy matters to educate the Business Relationship Managers (BRM) and business leadership about business owned IT security risks
  • Compile and communicate security/privacy risk to Business IT Leadership, BRMs and business leadership as appropriate
  • Establish a forum for outreach to the broader organization you represent to educate business requestors, business leaders, and IT leadership on the GSO Engagement processes
  • Demonstrate strong knowledge of IT security controls, security risk and threats
  • Regularly meet with the GSO to discuss issues, concerns, complex or high visibility projects, process improvement areas, and review SLA goals and actual results – leverage these relationships and information to ensure business readiness, engagement, and alignment with security programs and initiatives.
  • Act as a resource for security compliance questions, risks, and concerns for the bisomess
  • Perform other security-related duties as and when directed by the Business Information Security management
  • Engage in stakeholder management in their respective business
  • Reach out and meet with stakeholders, educate them about the GSO and Global IT 
  • Serve business stakeholders and requesters as "Customers" with a focus on service and support
  • Advise business / R&D teams on attaining security reviews earlier in their projects
  • Hold yourself and your business accountable for committed deliverables and deadlines
  • Ensure timely response to requests for security support from the business.

BASIC QUALIFICATIONS

MUST HAVE (Minimum Qualifications)


•    High school diploma (or equivalent) and 12+ years of experience
OR
•    Bachelor’s degree and 7+ years of experience or advanced degree and 5+ years of experience

DESIRED/PREFERRED QUALIFICATIONS


NICE TO HAVE (Preferred Qualifications)

  • Previous Medtronic experience
  • Preference given to current Medtronic employees
  • Strongly preferred:
  • Experience in audit, risk management, vulnerability management, governance, IT security and/or compliance functions
  • Experience with cloud storage systems/PaaS/SaaS
  • Experience with AWS highly regarded
  • Clear understanding of product architecture, data, data flows, and usage
  • Experience working across business units and geographical boundaries to engage IT, business counterparts, and team members
  • Ability to understand, question, and interpret internal and external security environments
  • 3+ years working in IT GRC or controls function
  • Proven experience dealing with ambiguous situations, and producing a consistent result with varied input
  • Working knowledge of IT and security control frameworks (NIST, CobiT, ITIL, CyberEssentials, HDH), as well as regulatory requirements (PCI, HIPAA, GDPR, CCPA)
  • Knowledge of information risk concepts and practices required
  • Knowledge of controls manifestation in large global corporations with regional and local presence is required
  • Experience communicating conceptual and technical information
  • Experience translating technical data into business impact information
  • Experience working with ServiceNow GRC (Governance, Risk, and Compliance)
  • Knowledge of Frameworks, including PCI, SOX and ISO 27001 is a plus
  • Detailed knowledge of ITGRC, Auditing principles / practices is desired
  • Good understanding of Vendor management desired
  • Good understanding of security frameworks desired, included but not limited to NIST, HISTRUST, OWASP, etc.
  • Good project management skills desired
  • Experience in examining reports on security controls (SSAE-16, PCI-ROC, Application Security Assessments)
About Medtronic


Together, we can change healthcare worldwide. At Medtronic, we push the limits of what technology, therapies and services can do to help alleviate pain, restore health and extend life.  We challenge ourselves and each other to make tomorrow better than yesterday. It is what makes this an exciting and rewarding place to be.

We want to accelerate and advance our ability to create meaningful innovations - but we will only succeed with the right people on our team. Let’s work together to address universal healthcare needs and improve patients’ lives. Help us shape the future.

Physical Job Requirements

The physical demands described within the Responsibilities section of this job description are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. For Office Roles: While performing the duties of this job, the employee is regularly required to be independently mobile. The employee is also required to interact with a computer, and communicate with peers and co-workers. Contact your manager or local HR to understand the Work Conditions and Physical requirements that may be specific to each role. (ADA-United States of America)

我的概要信息

创建并管理未来工作机会的概要信息。

转至概要信息

我的提交

追踪您的工作机会。

我的提交

类似的列表

Nanakramguda, Hyderabad, India

📁 Engineering

招聘登记表编号: 24000099

Nanakramguda, Hyderabad, India

📁 Engineering

招聘登记表编号: 2400056S

Nanakramguda, Hyderabad, India

📁 Engineering

招聘登记表编号: 240005NW

改变从你开始

我们寻找大胆的想法以及全新的观点,这将引领我们走向创新之路。来与我们一同引领医疗行业的未来。

工程部门

进行发明创造的机会。加入领导团队的益处。提高生活水平的能力。除此之外,在这里你还将有更多发现。

了解更多

销售

为有需求的人们提供改变他们生活的解决方案。从工作中取得应有的回报。

了解更多

监管

接受我们的挑战,让全球医疗服务的价格更加廉宜,让更多的人能够享受医疗服务。你的洞察力和观点将帮助我们创造出能够改变世界的解决方案。

了解更多

了解 MEDTRONIC 的使命。

我们的使命是 “减轻病痛、恢复健康及延长寿命” 这不仅仅是一句口号。这是我们的员工每天赖以生存的信仰。

了解更多

员工故事:
工程部门

Alyse是神经调控部门的工程项目经理,工作地点在明尼苏达州明尼亚波利斯市。

了解更多

想要了解在 MEDTRONIC 的工作是如何的吗?

我们的员工有着不同的背景却有着相同的信念-改变生命。

了解更多

我们重视你所拥有的独一无二 的品质。

欢迎加入我们,将你独到的观点带入到我们共同协作和创新的文化中。

了解更多
我们努力工作,致力于在全球范围内扩大医疗服务的受众群体,对此我们感到十分骄傲。出色的员工、愉悦的氛围、有竞争力的薪资。首席执行官是一位伟大的人物-他明确地践行着这一使命,并且全身心地投入到他的生活和工作中,只为实现这一目标。
聪明又承担义务的同事。使命驱动力。良好的福利。良好的长期职业机会。你始终可以在公司里发现有趣的项目并投身其中。
这里是一个非常好的工作场所,因为你知道自己每天所做的工作都将挽救人们的生命。在精益实践、质量和其他方面的培训。出色的同事。

MEDTRONIC 工作

成为全球领先的医疗技术和解决方案公司的一员。