Live opening · Posted 7 hours ago

Senior Principal Information Security Governance, Risk & Compliance Analyst

MiniMed · 4 Locations
Workday
You are 7 hours behind. JobBeeper subscribers saw this role while it was still new.

At a glance

The key details from the original listing.

Posted 7 hours ago
CompanyMiniMed
Location4 Locations
SourceWorkday
Listed7 hours ago

Your early-applicant advantage

Live timing from JobBeeper.

Live data
12 min from Workday publishing this role to us finding it
10 min median time from a role going live to a subscriber being told
6 hours subscribers had this role before this page existed
71,368 roles found in the last 24 hours — the newest are not on this site yet
Start your free trial →

About the role

Description supplied by the original job listing.

We anticipate the application window for this opening will close on - 5 Oct 2026
At MiniMed, you can begin a lifelong career of exploration and innovation, while helping make a difference in the lives of people living with diabetes around the globe. You'll lead with purpose, breaking down barriers to innovation for a more connected, compassionate world.
About the Role
The Senior Principal Information Security Governance, Risk & Compliance Analyst is a recognized subject matter expert responsible for advancing enterprise IT SOX governance, risk management, compliance, and assurance capabilities by establishing oversight practices, influencing governance strategy, and providing expert guidance to senior leaders and cross-functional stakeholders.
Operating within the second line of defense, this role is responsible for independently developing and enhancing risk-based oversight, compliance monitoring, internal control governance, and assurance practices that strengthen the organization's IT control environment and support regulatory and financial reporting objectives.
The position serves as a senior advisor for IT SOX, technology risk, and internal control matters, partnering closely with Information Technology, Finance, Internal Audit, Enterprise Risk Management, and Information Security stakeholders to evaluate control effectiveness, identify emerging risks, monitor compliance obligations, and support continuous improvement of governance and assurance processes. The role leads complex cross-functional initiatives that improve control maturity, compliance readiness, risk transparency, and sustainable governance practices across the enterprise.
While primarily focused on IT SOX governance, risk oversight, and internal controls, the role contributes to broader information security, regulatory compliance, and enterprise risk management objectives by providing subject matter expertise, independent challenge, and control assurance across key business and technology processes.
Responsibilities may include the following and other duties may be assigned.
Access Governance & Segregation of Duties
Coordinate and support enterprise Segregation of Duties governance across SAP and other key enterprise platforms.
Administer SAP GRC Access Control capabilities, including Access Risk Analysis, Access Request Management, Emergency Access Management, and Business Role Management.
Maintain SoD rulesets, risk functions, mitigating controls, access governance documentation, and related control evidence.
Assess access risks, including SoD conflicts, excessive entitlements, privileged access exposure, and control effectiveness concerns.
Monitor access-related exceptions, remediation plans, compensating controls, metrics, and trends to support risk reduction and compliance obligations.
Partner with application owners, IAM, SAP Security, and business stakeholders to evaluate and address identified access governance risks.
User Access Review & Privileged Access Governance
Coordinate and manage periodic User Access Reviews and access certification activities.
Monitor completion rates, overdue certifications, and non-compliance issues in accordance with governance requirements.
Support oversight of privileged access, emergency access, Firefighter governance, and related monitoring activities.
Review privileged access activity and maintain evidence supporting user access governance controls.
SOX ITGC Compliance & Control Monitoring
Administer and support SAP GRC Process Control activities used to monitor, assess, and validate SOX IT General Controls and security compliance requirements.
Support SOX ITGC compliance execution, control monitoring, audit evidence collection, validation, retention, and reporting.
Assist control owners and stakeholders with control procedures, evidence requirements, deficiencies, findings, remediation tracking, and closure activities.
Develop dashboards, metrics, and reporting to support management self-assessment, continuous control monitoring, and control effectiveness improvements.
Audit & Assurance Support
Support internal audits, external audits, and regulatory assessments by coordinating evidence, documentation, walkthroughs, and audit responses.
Maintain audit-ready documentation repositories and supporting records.
Monitor remediation activities and validate completion of corrective actions.
Perform control assurance activities by reviewing evidence completeness, control execution, and remediation effectiveness.
Governance & Compliance Operations
Support the development, implementation, and maintenance of information security policies, standards, procedures, governance processes, and control frameworks.
Support control inventory management, exception management, compliance reporting, GRC tool administration, workflows, dashboards, and reporting capabilities.
Develop compliance and risk metrics to monitor program effectiveness and identify opportunities for process improvement, automation, and control optimization.
Contribute to scalable governance standards, operational procedures, and compliance monitoring practices that strengthen enterprise security governance.
Risk Management Support
Assess cybersecurity, technology, artificial intelligence, data protection, and operational risks through structured risk assessment and governance processes.
Facilitate information security risk assessments supporting governance, compliance, and enterprise risk management activities.
Maintain risk registers, treatment plans, issue logs, action tracking, KRIs, risk dashboards, and management reporting.
Evaluate mitigation strategies and control implementation activities to support informed business and technology decision-making.
Stakeholder Collaboration & Advisory Support
Partner with Information Security, Information Technology, Finance, Privacy, Internal Audit, Legal, Enterprise Risk Management, and business stakeholders.
Translate technical risks, access governance issues, and compliance requirements into clear, business-focused recommendations.
Facilitate assessments, workshops, compliance reviews, and cross-functional discussions to promote risk-informed decision-making.
Provide subject matter guidance on governance, compliance, access governance, risk management, and security control requirements.
Second-Line Independence & Governance Boundaries
This role provides oversight, monitoring, reporting, governance, compliance, risk management, and assurance activities while maintaining appropriate second-line independence. The role partners with first-line teams to evaluate control design, monitor execution, assess risk, validate evidence, and support remediation governance while preserving independent oversight responsibilities.
Required Qualifications
Bachelor’s degree in Information Security, Cybersecurity, Information Systems, Risk Management, Business Administration, Accounting, Finance, Audit, or a related discipline, or equivalent combination of education and experience.
Minimum 10 years of experience in Information Security GRC, Information Security Risk Management, SOX ITGC Compliance, Internal Audit, External Audit, Access Governance, Identity Governance, SAP Security Governance, Compliance Management, or Internal Controls Management.
Requires advanced knowledge of Information Security GRC, access governance, regulatory compliance, risk management, and internal controls.
Requires strong understanding of SAP GRC Access Control and SAP GRC Process Control administration. Typically obtained through advanced education combined with significant professional experience in information security, compliance, governance, risk management, audit, or internal controls.
Current SAP Certified Application Associate, SAP Access Control certification required.
Current SAP GRC Process Control certification required.
Preferred Qualifications
Hands-on experience administering SAP GRC capabilities supporting SoD, UAR, EAM, SOX ITGC, continuous control monitoring, compliance reporting, and audit evidence management.
Experience administering SAP GRC Access Risk Analysis, Access Request Management, Emergency Access Management, Business Role Management, and SAP GRC Process Control.
Experience maintaining SoD rulesets, mitigating controls, access-risk libraries, access review campaigns, compliance dashboards, and audit evidence repositories.
Experience supporting SOX ITGC testing, walkthroughs, evidence requests, remediation tracking, and audit readiness activities.
Working knowledge of SAP authorization concepts, including roles, profiles, transaction codes, and role-based access controls.
Strong analytical, documentation, reporting, stakeholder management, and business communication skills.
SAP GRC Risk Management Certification or experience administering SAP GRC Risk Management solutions.
Professional certifications such as CISA, CRISC, CIA, CISM, CISSP, GRCP, or CPA.
Experience supporting public-company SOX 404 compliance programs.
Experience in medical device, healthcare, life sciences, pharmaceutical, manufactu

Get JobBeeper Mobile App

Never miss a job opening! Get instant job alerts on your phone.

Subscribers see fresh openings within minutes. Download the JobBeeper App on Google Play to get real-time push notifications and apply before anyone else.

⚡ Instant Push Alerts 🎯 Tailored Filters 🚀 Direct Employer Links
GET IT ON Google Play

More openings worth a look

Recently tracked roles with full details and direct application links.

6 roles
Good roles move before most people even see them. Tell JobBeeper what you want and get fresh matches delivered in minutes.
Start your free trial →
⚡ Get fresh job alerts 📱 Get App