Principal Security Analyst, Governance Risk, and Compliance
HistoSonics, Inc.
HistoSonics is a commercial-stage medtech company advancing the Edison® System, a novel non-invasive sonic beam therapy based on histotripsy. Since receiving FDA De Novo grant for the non-invasive destruction of liver tumors in 2023, the company has progressed beyond initial market entry into commercial expansion, reimbursement momentum, and ongoing clinical and pipeline development. In addition to its current liver tumor indication, HistoSonics is pursuing future indications across multiple applications including kidney, pancreas, prostate, neuro, women’s health, and other significant underserved human health areas, to realize the broader potential histotripsy across multiple disease states and medical specialties. Location: Plymouth, MN Position Summary (Why This Role Matters) The Principal Security Analyst, Governance Risk and Compliance is the senior-most individual contributor within the HistoSonics governance, risk, and compliance function and is a member of a larger, multi-site Information Systems and Security team that supports HistoSonics as a whole. This is a hybrid position based out of the Plymouth, MN office. The role owns the organization’s information security policy portfolio and Information Security Management System documentation, the mapping of internal ISO 27001 controls to the NIST Cybersecurity Framework, the resulting security maturity baseline and roadmap, third-party risk management, and security training and awareness. The Principal Security Analyst provides the primary execution behind the Information Systems partnership with Legal on privacy policy and data protection matters, a partnership owned by the Senior Director, Information Systems and Security. The role serves as the highest level of escalation for security governance, risk, and compliance matters and sets standards and practices for the function. Key Responsibilities (What You’ll Do) Security Governance and Policy Own the organization’s information security policy portfolio and Information Security Management System documentation, including authorship, periodic review, approval routing, version control, and retirement of policies, standards, and procedures. Lead the transition of Information Security Management System ownership and administration into the Information Systems and Security organization, and administer the policy exception and risk acceptance process, including analysis, compensating control review, documented approval by the appropriate authority, expiration tracking, and reporting. Framework Alignment and Security Maturity Maintain authoritative control mappings between the organization’s ISO 27001 control set, the NIST Cybersecurity Framework, and other standards or customer and regulatory requirements adopted by the organization, keeping mappings current as controls, systems, and standards change. Conduct recurring security maturity assessments using the mapped framework, produce the maturity baseline, and maintain a prioritized multi-year improvement roadmap with defined target states, owners, and measures of completion. Coordinate internal and external audits and certification activities, including scoping, evidence collection standards, auditor engagement, and tracking of findings and corrective actions through closure, and maintain the control inventory and control owner assignments, verifying that assigned controls operate and are evidenced as designed. Risk Management and Third-Party Risk Own the enterprise information security risk register, including risk identification, analysis, scoring methodology, treatment planning, ownership assignment, and periodic reporting to leadership. Design, implement, and administer the third-party risk management program, including vendor intake and tiering, security questionnaires, review of attestations such as SOC 2 reports and ISO 27001 certificates, remediation tracking, periodic reassessment, and offboarding. Partner with Legal, Procurement, Quality, and business stakeholders on security and data protection terms in vendor agreements, and provide risk input to purchasing, renewal, and contract review decisions. Security Training and Awareness Design, implement, and administer the enterprise security training and awareness program, including the awareness platform (KnowBe4 or comparable), annual and role-based training content, onboarding training, completion tracking, and audit evidence. Plan and execute the phishing simulation program, including campaign design, difficulty progression, and targeted follow-up training, own the user-facing suspicious message reporting workflow in coordination with security operations, and report program metrics and trends to leadership. Privacy and Legal Partnership Serve as the primary Information Systems and Security resource to Legal on privacy matters, including privacy policy and notice development, data protection and business associate agreements, data inventory and mapping, data retention standards, and individual rights requests. In partnership with Legal, assess the privacy and regulatory implications of new systems, integrations, data flows, and vendor relationships, translate requirements including HIPAA and GDPR into implementable technical and administrative controls, and support security and privacy incident response from a governance perspective, including documentation, notification analysis with Legal, and corrective action tracking. Leadership and Collaboration Serve as the final internal escalation point for security governance, risk, and compliance matters, and provide mentorship, work review, and knowledge transfer to current and future governance, risk, and compliance staff. Represent security governance and compliance in architecture reviews, change control, and project intake, provide requirements and risk input to Information Systems, Security, Quality, Regulatory, and the CTO organization, and support validation in alignment with the HistoSonics Quality Management System. Escalate cross-organizational governance conflicts, scope disputes, and resourcing trade-offs to the Senior Director, Information Systems and Security, and evaluate, recommend, and implement governance, risk, and compliance tooling, including assessment of functionality, security posture, integration requirements, and licensing costs. Required Qualifications and Skills Bachelor’s degree in Information Technology, Information Security, Computer Science, or a related field. 10+ years of progressive experience in information security governance, risk, and compliance, security audit, or a closely related discipline, including experience above senior level. Expert-level working knowledge of ISO 27001 and the NIST Cybersecurity Framework, including experience building and maintaining control mappings across frameworks, using them to produce defensible maturity assessments, and supporting internal and external audits and certification activities through evidence collection, auditor engagement, and closure of findings. Demonstrated experience owning an information security policy portfolio or Information Security Management System, including policy authorship, review cycles, exception handling, and control ownership. Demonstrated experience designing and running a third-party risk management program end to end, including vendor tiering, security assessment, attestation review, remediation tracking, and reassessment. Demonstrated experience owning a security training and awareness program, including administration of an awareness platform and design and execution of phishing simulation campaigns. Working knowledge of privacy requirements and their operational application, including HIPAA and GDPR, and experience partnering with Legal on privacy policy, contractual, and data protection matters. Sufficient technical depth across cloud platforms, enterprise identity and access management, endpoint management, and network and application security to assess control design and implementation and hold credible technical discussions with engineering staff. Preferred Experience in a regulated industry such as medical device, healthcare, or manufacturing, including familiarity with quality management system processes and validation. Experience administering a governance, risk, and compliance or compliance automation platform, responding to customer and partner security assessments, and supporting business continuity and disaster recovery governance. Relevant industry certifications are a plus. Key Competencies Strong analytical and problem-solving skills, with sound judgment in balancing risk, business objectives, and operational reality, and a bias toward durable documentation, repeatable process, and evidence-backed conclusions. Excellent communication and interpersonal skills, with the ability to explain security and privacy risk and trade-offs to technical and non-technical audiences, and to prioritize tasks and manage time effectively while working independently and as part of a team. Ability to set direction and influence outcomes across teams and departments without direct reporting authority. Benefits We offer a comprehensive benefits package for full-time employees. This includes health, dental, and vision insurance, life, short-term and long-term disability insurance, 401(k), paid time off, and more. We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. U.S. Work Authorization & Sponsorship: Employer will not sponsor visas for position. #J-18808-Ljbffr HistoSonics, Inc.
- Ovative Group is seeking a Lead Security Analyst to join our Information Security team in Minneapolis. You will own governance, risk, and compliance programs, including client security questionnaires, vendor assessments, and SOC 2 operations, with a focus on AI governance...Suggested
- VITS Consulting Corp is seeking a Senior GRC Information Security Systems Analyst to join our Information Security team in a direct hire role. The position supports governance, risk, and compliance initiatives, with emphasis on ISMS, audits, and security governance across...SuggestedWork at office
- Ovative Group, LLC is seeking a Security Analyst to advance our governance, risk, and compliance program. You’ll own client security questionnaires end to end, build a reusable answers library, and conduct vendor security assessments. The role includes SOC 2 operations...Suggested
$155k - $165k
Branch is seeking an experienced Security Governance, Risk, and Compliance professional to manage their Information Security Program and ensure compliance with major regulatory frameworks. This remote role requires 5-7 years in a similar position and proven experience in...SuggestedRemote jobFlexible hours- ...Solutions is seeking a Senior Security Policy Analyst to develop, implement, and... ...policy management, compliance tracking, and reporting, while... ...while applying NIST CSF and AI governance principles. You will mentor... ..., and collaborate with IT, Risk, and Compliance teams to...Suggested
- Senior GRC Information Security Systems Analyst Location: Minneapolis, MN (Preferred) or one of the following office locations: Anchorage... ...Security team. This role is responsible for leading Governance, Risk, and Compliance (GRC) initiatives while strengthening the...Contract workWork at office
- ...scalable HR service delivery.The Principal Analyst, HR Technology Risk and Access Governance will lead access governance,... ...Internal Audit, Privacy, Legal, Compliance and HR leadership to build effective... ...audit findings and enterprise security standards into clear HR...PrincipalHourly payWork at officeLocal areaRelocation packageShift work3 days per week
$72.6k - $135.7k
...working world. The opportunity The Threat & Risk Analyst leads strategic and tactical threat... ...efforts in partnership with Global Security and Regional Security teams, with a focus... ...relationships with other corporate and government intelligence teams to share methodologies...Summer holidayLocal areaFlexible hours$85.1k - $154.42k
...Job Duties What you'll do at Jamf: The Security Risk & Compliance Analyst (Analyst) is responsible for ensuring that Jamf ‘s security controls... ...year of relevant experience (e.g. security operations, governance, risk management, compliance) (Required) • Familiarity...Full timeWork at officeRemote workWorldwideShift work$85k - $95k
...The University of Minnesota's University Information Security seeks an Information Security Risk Analyst who will improve the information security of the... ...and procedures, based on industry best practices and compliance requirements. Maintain a strong working knowledge...Full timeWork experience placementH1bLocal areaImmediate startRelocationFlexible hours$90k - $132k
...Search Engine Land.About the RoleOvative Group is seeking a Security Analyst to join our growing Information Security team.... ...and Privacy, this roleowns the operational core of our governance, risk, and compliance program — client security questionnaires, vendor assessments...Full timeWork at office- Prime Therapeutics is seeking a Principal Actuary to support actuarial concepts, lead strategic pricing, and provide pricing support across... ...to executives, mentoring actuarial staff, and ensuring compliance with regulations and standards. #J-18808-Ljbffr Prime TherapeuticsPrincipalRemote job
$112k - $134k
Join our newly established reinsurance function and make a difference in Actuarial, Finance, and Operations—Drive Innovation, Shape Strategies, and Contribute to Our Success in a Dynamic and Collaborative Environment! Explore opportunities at all levels across Actuarial...PrincipalH1bLocal areaRelocation packageFlexible hours$60k - $80k
...IT Security Analyst The IT Security Analyst role will assess information risk, track vulnerabilities, and facilitate remediation of... ...assessments and regulatory compliance activities Facilitates and... ...with this position will be the principal, major or most important...Daily paidTemporary workSummer workWork at office$92.82k - $109.2k
...Business Risk ProfessionalThe organization's risk management structure... ...to promote effective governance and risk management that is systematic... .../or activities that ensure compliance with applicable federal,... ..., protect your financial security and give you peace of mind. Our...Work at officeLocal areaRemote workFlexible hours3 days per week$185k - $237.5k
...management and operation of Circle’s Product Risk Management function. The goal of this... ...to business activities, including compliance, legal, security, finance and 3rd parties. Self-... ...across teams.What you'll bring to Circle:Principal Product Operations and Risk Analyst10...PrincipalFlexible hours$65k - $115k
...Description What is the opportunity? The Senior Analyst, Disclosures Management and Risk Governance is responsible for executing duties by working... ...and services), business support units (e.g., Legal, Compliance, Operations, Business Administration, Technology),...Full timeWork at officeLocal areaFlexible hours$81.9k - $139.7k
...configuration, and maintenance of Workday security, ensuring secure, compliant, and... ...individual partners with HR, Technology, Risk, and Compliance stakeholders to execute security... ...security configurations through well-governed and effective design.ResponsibilitiesSupport...Full timeWork experience placementInternshipLocal area$108.2k - $140k
...collaborate closely across exposure management, security engineering, and cloud security.This role... ..., surfacing coverage gaps and emerging risk before they become incidents.Work AI and... ...provide coaching and feedback that helps analysts grow.Participate in the team's on-call...Full timeWork at officeLocal areaRemote work$220k
Apply your project leadership experience here! Growing Life company is seeking an ASA or FSA with 11+ years of experience to join the team as a Senior Actuary (Reinsurance). This role will lead various projects, design new reinsurance structures, and negotiate reinsurance...- RBC Capital Markets, LLC in Minneapolis seeks a Senior Analyst to help build and drive the WM-US Risk Transformation program, identifying and leading high-impact projects across governance, analytics and reporting. You will partner with senior leaders to innovate with risk...
$93.4k - $128.4k
About Our CompanyWe’re a diversified financial services leader with more than $1.5 trillion in assets under management, administration and advisement as of year-end 2024. Our team of 22,000 people across 19 countries, serves more than 3.5 million individual, small business...Full timeH1bWork at officeWork from homeVisa sponsorship1 day per week- ...tax and assurance firm, is seeking an IT Audit, Cybersecurity & Risk Senior Consultant (SOC focus) to join its Risk Advisory... ...technology risks, design controls, and support SOC reporting and IT governance initiatives. Ideal candidates have 3+ years in IT audit or cybersecurity...
$100.4k - $197.9k
...better at work. Work you'll do As an Actuarial Consultant on the Government & Public Services team, you will: Provide strategic and... ..., Medicaid policy, budget forecasting and fiscal analyses, and risk adjustmentSupport business development efforts for Federal and...Local area$180.2k - $355.1k
...apply trend forecasting, predictive modeling, underwriting, and risk analysis methodologies to support client decision-making Advise... ...a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various...Local areaVisa sponsorship$128k - $252.5k
...is $128,000 - $252,500. You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance...Local areaVisa sponsorship$148.2k - $292.3k
...apply trend forecasting, predictive modeling, underwriting, and risk analysis methodologies to support client decision-making Advise... ...a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various...Local areaVisa sponsorship$94.4k - $129.8k
...roleParticipates in projects and assessments as a security consultant or advisor on risk. Researches general and industry specific... ...environments.Working knowledge of cybersecurity governance, risk, and compliance practices, including the development or maintenance...Ongoing contractFull timeTemporary work$66.7k - $91.7k
...Actuarial AnalystAmeriprise Financial is looking to add an Actuarial Analyst to the team! The individual in this role will perform actuarial tasks with manager assistance or supervision. Provide technical analysis and support by modifying, maintaining, operating and documenting...Full timeInternshipH1bWork at officeWork from homeVisa sponsorship1 day per week$70k - $130k
...DescriptionWhat is the opportunity?The Senior Analyst, Risk Transformation is a newly created role... ...partner closely with the Head, Risk Governance and Transformation to build out the WM-... ...posted : 2026-08-10Profession: Audit | Compliance | Legal | RiskEmployment type: Full...Full timeWork at officeFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Principal Security Analyst, Governance Risk, and Compliance. Be the first to apply!
- senior information security analyst Minneapolis, MN
- cloud security analyst Minneapolis, MN
- entry level security analyst Minneapolis, MN
- security analyst remote Minneapolis, MN
- security analyst intern Minneapolis, MN
- IT security analyst Minneapolis, MN
- security analyst Minneapolis, MN
- security operations analyst Minneapolis, MN
- bond analyst Minneapolis, MN
- junior security analyst Minneapolis, MN


