Logo
Medtronic

Medtronic is hiring: Principal Cybersecurity Specialist - Governance & Complianc

Medtronic, Greendale, WI, United States, 53129


Principal Cybersecurity Specialist - Governance & Compliance We anticipate the application window for this opening will close on 11 Nov 2024. At Medtronic, you can begin a life-long career of exploration and innovation, while helping champion healthcare access and equity for all. You’ll lead with purpose, breaking down barriers to innovation in a more connected, compassionate world. A Day in the Life The person in this role may work remotely within the US or onsite at a US-based Medtronic facility. In this role, you will serve as a central point of contact across multiple internal Medtronic teams (i.e., Global Cybersecurity Information Security Office (GCISO), various operating units (OUs), IT, Legal, Privacy, Product Security, Procurement, etc.) to help facilitate the execution of various compliance audits and initiatives. This work is incredibly important as we strive to achieve global cybersecurity certifications for systems and products, which allows us to successfully market and sell medical devices across global markets. This role will also coordinate with Medtronic internal teams to ensure appropriate cybersecurity language and protections are included within vendor contracts. Lastly, this role will have a significant impact in the GCISO Governance, Risk, & Compliance program, and may perform additional activities to support the mission and vision of that team. This individual accepting this role is expected to have very strong leadership skills, internal and external communication skills, and a deep understanding of cybersecurity controls. We believe that when people from different cultures, genders, and points of view come together, innovation is the result — and everyone wins. Medtronic walks the walk, creating an inclusive culture where you can thrive. Our unwavering commitment to inclusion, diversity, and equity (ID&E) means zero barriers to opportunity within Medtronic and a culture where all employees belong, are respected, and feel valued for who they are and the life experiences they contribute. Responsibilities ISO 27001 CONTROLS TESTING & MAINTENANCE Will work to successfully scope and complete ISO 27001 compliance gap assessments / internal audits. Will work to identify key gaps and areas of risk, log / track / monitor those areas and convey their criticality, importance, and priority to the business and other key stakeholders. Plan, schedule, and execute internal ISO 27001 audits to evaluate the effectiveness of the ISMS. Assess the organization's existing information security policies, procedures, and controls against ISO 27001 standards and control objectives. Compare current practices with ISO 27001 requirements to identify areas where the organization is non-compliant or could improve its security posture. Suggest remediation actions or enhancements to align with ISO 27001 standards. Where applicable, ensure that the organization's ISO 27001 efforts are aligned with other relevant standards and regulations (e.g., GDPR, HIPAA). Ensure all necessary documentation, including policies, risk assessments, control descriptions, and incident logs, are up-to-date and in line with ISO 27001 standards. Respond to questions and requests from external auditors during the certification process. GOVERNANCE DOCUMENTATION Ensure that all security controls and related activities are documented, providing evidence of compliance. Develop and maintain comprehensive information security policies that govern the protection of data and systems. Ensure that security policies and procedures are regularly reviewed and updated to reflect changes in the threat landscape, business processes, or regulatory requirements. Align governance documentation with relevant industry standards (e.g., ISO 27001, NIST CSF, CIS Controls) and regulatory requirements (e.g., GDPR, HIPAA, PCI-DSS). Clearly document roles and responsibilities within the cybersecurity governance framework, including data owners, custodians, and security team roles. Ensure that governance documentation is stored in a centralized, secure location with appropriate access controls to prevent unauthorized modifications. IDENTIFICATION AND TRIAGE OF CYBERSECURITY GAPS & RISKS Collaborate with other teams both within and outside of GCISO to identify and quantify cybersecurity gaps & risks. Assist with the creation of risk mitigation plans and remediation schedules, tracking, etc. Work with MDT teams to confirm cybersecurity gaps and risks have been appropriately mitigated completely per pre-defined plans and regulatory / industry standard requirements. CYBERSECURITY COMPLIANCE, AUDIT, CERTIFICATION SUPPORT Serve as central point of contact (POC) across multiple groups (Various Operating Units, GCISO, IT, Legal, Privacy, Product Security, Procurement, etc.) to remove roadblocks and barriers, enhance audit / assessment / certification efficiency and effectiveness. Assist with the planning, execution, and follow-ups around ISO 27001 certification and maintenance. Partner with Operating Units (OU’s) to identify gaps within Global IT and ensure proper follow up is completed and tracked to resolution. Work with Global IT pre and post audit to address issues, identify opportunities for improvement and ensure consistency of evidence collection. Identify potential solutions if there are challenges from a technical standpoint to reduce risk to the company. Maintain Medtronic (MDT) relevant documents (policies, procedures, SOP’s, etc.) for OU’s and provide feedback on when to share documents. Represent MDT evidence to Healthcare Delivery Organizations (HDOs) as part of the sales process where appropriate. Stay up to date with MDT products and network across the OUs to represent Medtronic and/or OU when necessary, with HDO’s during Third Party Risk meetings as part of the Request for Proposal process. Coordinate assessments with HDO’s and identify/work with OUs to answer questions and/or provide support for escalation when needed. Consult with, analyze, escalate and coordinate with privacy, regulatory, reimbursement, legal, contracting, sales, etc. and other areas of MDT on Bid requirements, security language, regulatory requirements and other country specific requirements as needed. Maintain annual self-certification/evaluation of NHS Data Protection Toolkit. Address the challenges of interpreting questions and managing long and inconsistent customer inquiries. Coordinate knowledge spread across multiple teams (R&D, Privacy, Contracts, Corporate vs. Product specific) and ensure the availability of necessary information to respond effectively to customer inquiries. Enhance communication across different teams. Improve the tracking of inquiries to ensure timely and consistent responses and enhance visibility over the entire process and approval needs. Consult and work with OUs on programs/requirements for compliance for sales at country level such as: ISO 27001 certifications UK NHS UK Cyber Essentials Israel Clalit Japan 2G3M JAHIS Etc. VENDOR CONTRACT REVIEWS Work with Legal counsel to perform reviews of MDT contract security language (i.e., Data Protection Exhibits or DPE) to ensure Medtronic is represented appropriately in contracts with potential suppliers, partners, and vendors. Continuously partner with Legal on new challenges that overlap with regards to cybersecurity and make continuous updates to legal-owned DPE playbook to ensure consistency. Provide consistent, objective, and detailed feedback on Medtronic DPE’s. Work with Third-Party Risk Management (TPRM) office to point out issues with Vendor Risk Assessments (VRA’s), escalate actions when needed and/or be point of contact to share “critical” suppliers. Participate in discussions with potential suppliers alongside legal for contract review. Identify solutions related to challenges with contracts from a technical standpoint to reduce risk to the company. Assist with education and awareness related to cybersecurity requirements in partnership with Legal and Procurement. All other duties as assigned by management. MUST HAVE (Minimum Qualifications) High school diploma (or equivalent) and 12+ years of experience. OR Bachelor’s degree and 7+ years of experience or advanced degree and 5+ years of experience. NICE TO HAVE (Preferred Qualifications) Strongly Preferred: Previous Medtronic experience. Extremely strong leadership & communication skills. Extremely robust knowledge and experience of cybersecurity control design, implementation, and maintenance. Previous experience within IT Audit, Compliance, and/or Cybersecurity. Previous experience with ISO 27001/2 gap assessments, certifications, audits, etc. (trained ISO 27001 Auditor). Previous experience planning, executing, and following up on cybersecurity / regulatory audits. Key Cybersecurity and/or IT Audit certifications (i.e., CISSP, CISA, CRISC, HCISPP, etc.). Experience using artificial intelligence (AI) at an enterprise level to increase efficiency within processes. Experience within process improvement initiatives. Understanding of use cases and general risk assessment methodologies and goals from Healthcare Delivery Organizations (HDOs). Strong analytical and problem-solving skills. Excellent communication and coordination abilities. Proven experience in process improvement or a related field. Experience with training and knowledge management. Ability to manage multiple tasks and prioritize effectively. Physical Job Requirements The above statements are intended to describe the general nature and level of work being performed by employees assigned to this position, but they are not an exhaustive list of all the required responsibilities and skills of this position. The physical demands described within the Responsibilities section of this job description are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. For Office Roles: While performing the duties of this job, the employee is regularly required to be independently mobile. The employee is also required to interact with a computer, and communicate with peers and co-workers. Contact your manager or local HR to understand the Work Conditions and Physical requirements that may be specific to each role. Benefits & Compensation Medtronic offers a competitive salary and flexible benefits package. A commitment to our employees' lives is at the core of our values. We recognize their contributions. They share in the success they help to create. We offer a wide range of benefits, resources, and competitive compensation plans designed to support you at every career and life stage. Salary ranges for U.S (excl. PR) locations (USD): $133,600.00 - $200,400.00. This position is eligible for a short-term incentive called the Medtronic Incentive Plan (MIP). The base salary range is applicable across the United States, excluding Puerto Rico and specific locations in California. The offered rate complies with federal and local regulations and may vary based on factors such as experience, certification/education, market conditions, and location. Compensation and benefits information pertains solely to candidates hired within the United States (local market compensation and benefits will apply for others). About Medtronic We lead global healthcare technology and boldly attack the most challenging health problems facing humanity by searching out and finding solutions. Our Mission — to alleviate pain, restore health, and extend life — unites a global team of 90,000+ passionate people. We are engineers at heart— putting ambitious ideas to work to generate real solutions for real people. From the R&D lab, to the factory floor, to the conference room, every one of us experiments, creates, builds, improves, and solves. We have the talent, diverse perspectives, and guts to engineer the extraordinary. It is the policy of Medtronic to provide equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, sexual orientation, gender identity and/or expression, genetic information, marital status, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state or local law. In addition, Medtronic will provide reasonable accommodations for qualified individuals with disabilities. #J-18808-Ljbffr