🌎
이 채용 공고를 일부 웹사이트 언어에서는 사용할 수 없습니다.

Senior Product Security Engineer - ISO27k1

📁
Engineering
📅
2400043W 충원요청 번호

Career That Changes Lives

The Principal Cyber Info Assurance Analyst will join the Business Information Security team within the Business Partner Services (BPS) group and partner closely with the Global Security Office (GSO).  You will serve as a champion of the GSO, focusing on enhancing user experience with our business partners.  You’ll serve as a cybersecurity and compliance subject matter expert (SME) to the intelligent Data Solutions business. The cybersecurity SME will focus on identifying, prioritizing and driving remediation of all security risks owned by the business 

The primary focus of the role will be on supporting implementation of achieving and/or maintaining HIPAA, GDPR and other regulatory compliance, and achieving and maintaining the ISO27011 and HITRUST certifications.  You will facilitate and assist the business by interpreting the requirements and driving technical remediations.   Communicate, escalate, and track progress on assessment remediation activities. Understand information security risks that are inherent to a business and articulate those risks in business terms. Support Commercial activities including contracting and IT/security questionnaires.  Maintain current knowledge on data privacy and information security topics and their applicable program requirements.  Provide concierge service to our business stakeholders when interacting with the GSO.

We believe that when people from different cultures, genders, and points of view come together, innovation is the result —and everyone wins. Medtronic walks the walk, creating an inclusive culture where you can thrive.

Bring your talents to an industry leader in medical technology and healthcare solutions – we’re a market leader and growing every day. You can be proud to be a part of technologies that are rooted in our long history of mission-driven innovation. You will be empowered to shape your own career. We support your growth with the training, mentorship, and guidance you need to own your future success. Together, we can transform healthcare.

Join us for a career in IT that changes lives.

Medtronic is committed to fostering a diverse and inclusive culture.  Check out the accomplishments of our Women in IT group!  http://bit.ly/MedtronicWomeninIT. 

A Day in the Life

  • Maintain relationships within Operating Unit proactively share business' upcoming projects to the GSO
  • Engage with cross functional teams to drive complex data security issues to resolution
  • Contribute continuous improvement to the methodologies and practices of the Business Information Security to attain higher capability maturity levels
  • Track status of open requests/tasks and drive accountability of requestors to ensure timely submitting
  • Partner with the GSO and Privacy to perform deep dives over high risk processes and systems to identify and remediate gaps in data security
  • Support implementing monitoring Security compliance activities related to HITRUST, ISO27001, SOC2, etc.
  • Help facilitate and/or respond to Customer Inquiries
  • Streamline processes and use of tools across Global IT to ensure data flow and security is maintained in the most efficient way possible
  • Provide insight and business background to include data security, encryption, authorization, authentication, and access controls to the GSO process teams, when needed
  • Prepare status reports on data security and privacy matters to educate the Business Relationship Managers (BRM) and business leadership about business owned IT security risks
  • Compile and communicate security/privacy risk to Business IT Leadership, BRMs and business leadership as appropriate
  • Establish a forum for outreach to the broader organization you represent to educate business requestors, business leaders, and IT leadership on the GSO Engagement processes
  • Demonstrate strong knowledge of IT security controls, security risk and threats
  • Regularly meet with the GSO to discuss issues, concerns, complex or high visibility projects, process improvement areas, and review SLA goals and actual results – leverage these relationships and information to ensure business readiness, engagement, and alignment with security programs and initiatives.
  • Act as a resource for security compliance questions, risks, and concerns for the bisomess
  • Perform other security-related duties as and when directed by the Business Information Security management
  • Engage in stakeholder management in their respective business
  • Reach out and meet with stakeholders, educate them about the GSO and Global IT 
  • Serve business stakeholders and requesters as "Customers" with a focus on service and support
  • Advise business / R&D teams on attaining security reviews earlier in their projects
  • Hold yourself and your business accountable for committed deliverables and deadlines
  • Ensure timely response to requests for security support from the business.

Basic Qualifications

Must Have (Minimum Qualifications)

•    High school diploma (or equivalent) and 12+ years of experience
OR
•    Bachelor’s degree and 7+ years of experience or advanced degree and 5+ years of experience

Desired / Preferred Qualifications

Nice To Have (Preferred Qualifications)

  • Previous Medtronic experience
  • Preference given to current Medtronic employees
  • Strongly preferred:
  • Experience in audit, risk management, vulnerability management, governance, IT security and/or compliance functions
  • Experience with cloud storage systems/PaaS/SaaS
  • Experience with AWS highly regarded
  • Clear understanding of product architecture, data, data flows, and usage
  • Experience working across business units and geographical boundaries to engage IT, business counterparts, and team members
  • Ability to understand, question, and interpret internal and external security environments
  • 3+ years working in IT GRC or controls function
  • Proven experience dealing with ambiguous situations, and producing a consistent result with varied input
  • Working knowledge of IT and security control frameworks (NIST, CobiT, ITIL, CyberEssentials, HDH), as well as regulatory requirements (PCI, HIPAA, GDPR, CCPA)
  • Knowledge of information risk concepts and practices required
  • Knowledge of controls manifestation in large global corporations with regional and local presence is required
  • Experience communicating conceptual and technical information
  • Experience translating technical data into business impact information
  • Experience working with ServiceNow GRC (Governance, Risk, and Compliance)
  • Knowledge of Frameworks, including PCI, SOX and ISO 27001 is a plus
  • Detailed knowledge of ITGRC, Auditing principles / practices is desired
  • Good understanding of Vendor management desired
  • Good understanding of security frameworks desired, included but not limited to NIST, HISTRUST, OWASP, etc.
  • Good project management skills desired
  • Experience in examining reports on security controls (SSAE-16, PCI-ROC, Application Security Assessments)


About Medtronic

Together, we can change healthcare worldwide. At Medtronic, we push the limits of what technology, therapies and services can do to help alleviate pain, restore health and extend life.  We challenge ourselves and each other to make tomorrow better than yesterday. It is what makes this an exciting and rewarding place to be.

We want to accelerate and advance our ability to create meaningful innovations - but we will only succeed with the right people on our team. Let’s work together to address universal healthcare needs and improve patients’ lives. Help us shape the future.

Physical Job Requirements

The physical demands described within the Responsibilities section of this job description are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. For Office Roles: While performing the duties of this job, the employee is regularly required to be independently mobile. The employee is also required to interact with a computer, and communicate with peers and co-workers. Contact your manager, recruiter or local HR to understand the Work Conditions and Physical requirements that may be specific to each role. (ADA-United States of America)

내 프로파일

미래의 기회를 위해 프로파일을 생성 및 관리하십시오.

프로파일로 이동

내 지원서

귀하의 기회들을 추적하십시오.

내 지원서

유사 목록

Nanakramguda, Hyderabad, India

📁 Engineering

충원요청 번호: 24000099

Nanakramguda, Hyderabad, India

📁 Engineering

충원요청 번호: 2400056S

Nanakramguda, Hyderabad, India

📁 Engineering

충원요청 번호: 240005NW

변화는 여러분과 함께 시작됩니다

우리는 대담한 아이디어와 신선한 통찰력을 찾고 있습니다. 그것이 바로 혁신의 원동력입니다. 함께 의료 업계의 미래를 열어 나갑시다.

엔지니어링

발명 기회. 리더와 함께할 수 있는 혜택. 삶을 향상시키는 힘. 이곳에서 이 모든 것과 그 이상을 찾으실 수 있습니다.

자세히 알아보기

영업

인생을 변화시킬 해법이 필요한 사람들에게 이를 제공합니다. 보람된 업무를 수행하고 보상을 받으세요.

자세히 알아보기

규제

전 세계 사람들이 좀 더 쉽고 저렴하게 의료 혜택을 받을 수 있도록 하려는 우리의 도전에 동참하십시오. 여러분의 통찰과 관리감독은 우리가 세계를 변화시키는 해법을 마련하는 데 도움이 됩니다.

자세히 알아보기

Medtronic 미션에 대해 읽어 보세요.

“통증 완화, 건강 회복, 수명 연장”이라는 우리의 미션은 표현된 것 그 이상을 의미합니다. 그것은 우리 직원들이 매일을 살아가는 신념입니다.

자세히 알아보기

직원 스토리:
엔지니어링

Alyse는 미네소타 주 미네아폴리스에서 신경조절 분야의 엔지니어링 프로그램 매니저로 일하고 있습니다.

자세히 알아보기

MEDTRONIC? 에서 일하는 것에 대해 궁금하십니까?

우리 직원들은 다양한 배경을 갖고 있으며, 삶의 변화라는 공동의 목표를 가지고 있습니다.

자세히 알아보기

우리는 여러분을특별하게 만드는것을 소중하게 여깁니다.

동참하세요. 여러분만의 특별한 관점은 우리 회사의 협력 및 혁신 문화에 큰 힘이 될 수 있습니다.

자세히 알아보기
전 세계의 의료 접근성 향상이라는 우리의 미션은 우리 모두가 커다란 긍지를 가지고 달성을 위해 열심히 노력하는 사명과도 같은 것입니다. 좋은 사람들, 즐거운 분위기, 대도시 수준의 봉급. CEO는 우리에게 미션을 매우 분명하게 전달할 뿐 아니라 미션 달성을 위해 헌신하고 있습니다. 정말 멋진 분입니다.
스마트하고 최선을 다하는 동료 직원들. 미션 추구. 좋은 복리후생. 훌륭한 장기 경력 기회. 여러분이 항상 흥미로운 프로젝트를 찾아 일할 수 있을 만큼 큰 회사입니다.
내가 매일 하는 일이 생명을 구하는 데 도움이 된다는 사실을 알고 나면 이곳은 정말 일하고 싶은 곳이 됩니다. 군더더기 없는 실무, 품질 등에 대한 교육. 훌륭한 동료들.

MEDTRONIC에서일하기

세계 일류의 의료 기술 및 솔루션 기업 중 한 곳의 일원이 되어 보세요.