Senior Information Security Governance, Risk & Compliance Analyst
$121k - $205kMiniMed
At MiniMed, you can begin a lifelong career of exploration and innovation, while helping make a difference in the lives of people living with diabetes around the globe. You'll lead with purpose, breaking down barriers to innovation for a more connected, compassionate world.
About the Role
The Senior Information Security Governance, Risk & Compliance Analyst is a seasoned individual contributor responsible for supporting enterprise governance, risk, compliance, access governance, SAP GRC, SOX ITGC, and assurance activities. This second-line role provides independent oversight, monitoring, reporting, and control assurance to strengthen information security, technology compliance, and risk management capabilities. The role partners across Information Security, IT, IAM, Finance, Internal Audit, Privacy, Legal, and business stakeholders to assess risks, support regulatory obligations, improve control effectiveness, and mature governance practices across a global public medical technology environment.Responsibilities may include the following and other duties may be assigned.
Access Governance & Segregation of Dutie s
Coordinate and support enterprise Segregation of Duties governance across SAP and other key enterprise platforms.
Administer SAP GRC Access Control capabilities, including Access Risk Analysis, Access Request Management, Emergency Access Management, and Business Role Management.
Maintain SoD rulesets, risk functions, mitigating controls, access governance documentation, and related control evidence.
Assess access risks, including SoD conflicts, excessive entitlements, privileged access exposure, and control effectiveness concerns.
Monitor access-related exceptions, remediation plans, compensating controls, metrics, and trends to support risk reduction and compliance obligations.
Partner with application owners, IAM, SAP Security, and business stakeholders to evaluate and address identified access governance risks
User Access Review & Privileged Access Governance
Coordinate and manage periodic User Access Reviews and access certification activities.
Monitor completion rates, overdue certifications, and non-compliance issues in accordance with governance requirements.
Support oversight of privileged access, emergency access, Firefighter governance, and related monitoring activities.
Review privileged access activity and maintain evidence supporting user access governance controls.
SOX ITGC Compliance & Control Monitoring
Administer and support SAP GRC Process Control activities used to monitor, assess, and validate SOX IT General Controls and security compliance requirements.
Support SOX ITGC compliance execution, control monitoring, audit evidence collection, validation, retention, and reporting.
Assist control owners and stakeholders with control procedures, evidence requirements, deficiencies, findings, remediation tracking, and closure activities.
Develop dashboards, metrics, and reporting to support management self-assessment, continuous control monitoring, and control effectiveness improvements.
Audit & Assurance Support
Support internal audits, external audits, and regulatory assessments by coordinating evidence, documentation, walkthroughs, and audit responses.
Maintain audit-ready documentation repositories and supporting records.
Monitor remediation activities and validate completion of corrective actions.
Perform control assurance activities by reviewing evidence completeness, control execution, and remediation effectiveness.
Governance & Compliance Operations
Support the development, implementation, and maintenance of information security policies, standards, procedures, governance processes, and control frameworks.
Support control inventory management, exception management, compliance reporting, GRC tool administration, workflows, dashboards, and reporting capabilities.
Develop compliance and risk metrics to monitor program effectiveness and identify opportunities for process improvement, automation, and control optimization.
Contribute to scalable governance standards, operational procedures, and compliance monitoring practices that strengthen enterprise security governance.
Risk Management Support
Assess cybersecurity, technology, artificial intelligence, data protection, and operational risks through structured risk assessment and governance processes.
Facilitate information security risk assessments supporting governance, compliance, and enterprise risk management activities.
Maintain risk registers, treatment plans, issue logs, action tracking, KRIs, risk dashboards, and management reporting.
Evaluate mitigation strategies and control implementation activities to support informed business and technology decision-making.
Stakeholder Collaboration & Advisory Support
Partner with Information Security, Information Technology, Finance, Privacy, Internal Audit, Legal, Enterprise Risk Management, and business stakeholders.
Translate technical risks, access governance issues, and compliance requirements into clear, business-focused recommendations.
Facilitate assessments, workshops, compliance reviews, and cross-functional discussions to promote risk-informed decision-making.
Provide subject matter guidance on governance, compliance, access governance, risk management, and security control requirements.
Second-Line Independence & Governance Boundaries
This role provides oversight, monitoring, reporting, governance, compliance, risk management, and assurance activities while maintaining appropriate second-line independence. The role partners with first-line teams to evaluate control design, monitor execution, assess risk, validate evidence, and support remediation governance while preserving independent oversight responsibilities.
Required Qualifications
Bachelor’s degree in Information Security, Cybersecurity, Information Systems, Risk Management, Business Administration, Accounting, Finance, Audit, or a related discipline, or equivalent combination of education and experience.
Minimum 7 years of experience in Information Security GRC, Information Security Risk Management, SOX ITGC Compliance, Internal Audit, External Audit, Access Governance, Identity Governance, SAP Security Governance, Compliance Management, or Internal Controls Management.
Requires advanced knowledge of Information Security GRC, access governance, regulatory compliance, risk management, and internal controls.
Requires strong understanding of SAP GRC Access Control and SAP GRC Process Control administration. Typically obtained through advanced education combined with significant professional experience in information security, compliance, governance, risk management, audit, or internal controls.
Current SAP Certified Application Associate, SAP Access Control certification required.
Current SAP GRC Process Control certification required.
Preferred Qualifications
Hands-on experience administering SAP GRC capabilities supporting SoD, UAR, EAM, SOX ITGC, continuous control monitoring, compliance reporting, and audit evidence management.
Experience administering SAP GRC Access Risk Analysis, Access Request Management, Emergency Access Management, Business Role Management, and SAP GRC Process Control.
Experience maintaining SoD rulesets, mitigating controls, access-risk libraries, access review campaigns, compliance dashboards, and audit evidence repositories.
Experience supporting SOX ITGC testing, walkthroughs, evidence requests, remediation tracking, and audit readiness activities.
Working knowledge of SAP authorization concepts, including roles, profiles, transaction codes, and role-based access controls.
Strong analytical, documentation, reporting, stakeholder management, and business communication skills.
SAP GRC Risk Management Certification or experience administering SAP GRC Risk Management solutions.
Professional certifications such as CISA, CRISC, CIA, CISM, CISSP, GRCP, or CPA.
Experience supporting public-company SOX 404 compliance programs.
Experience in medical device, healthcare, life sciences, pharmaceutical, manufacturing, or other highly regulated industries.
Experience supporting enterprise access governance platforms beyond SAP, including Oracle, Workday, ServiceNow, SailPoint, Entra ID, or comparable platforms.
Experience developing compliance dashboards, risk reporting, and executive-facing control metrics.
Experience supporting enterprise information security risk management programs.
Framework Knowledge
Knowledge of one or more of the following frameworks and standards is preferred:
NIST Cybersecurity Framework
NIST Risk Management Framework
NIST AI Risk Management Framework
ISO 27001
ISO 31000
ISO 42001
COBIT
COSO Internal Control Framework
SOX 404 IT General Controls
HIPAA Security and Privacy Requirements
Data Protection and Privacy Regulations
Physical Job Requirements
The above statements are intended to describe the general nature and level of work being performed by employees assigned to this position, but they are not an exhaustive list of all the required responsibilities and skills of this position.
The physical demands described within the Responsibilities section of this job description are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. For Office Roles: While performing the duties of this job, the employee is regularly required to be independently mobile. The employee is also required to interact with a computer and communicate with peers and co-workers. Contact your manager or local HR to understand the Work Conditions and Physical requirements that may be specific to each role.
Benefits & Compensation
MiniMed offers a competitive salary and flexible benefits package
At MiniMed, we put people first. A commitment to our employees lives at the core of our values: We recognize their contributions. They share in the success they help create. We offer a wide range of benefits, resources, and competitive compensation plans designed to support you at every stage of your career and life.
Salary ranges for U.S (excl. PR) locations (USD):$128,800.00 - $193,200.00For roles located in California, Seattle WA, Washington DC, Boston MA, and New York City, the salary range is $121,000.00- $205,000.00 USD.
Actual compensation may vary based on factors including experience, education, certifications, skills, market conditions, internal equity, and geographic location. Compensation and benefits information pertains solely to candidates hired within the United States (local market compensation and benefits will apply for others).
This position is eligible for a short-term incentive called the Short Term Incentive (STI).At MiniMed, we are committed to supporting the well-being and financial security of our employees. Regular employees working 20 or more hours per week are eligible for a robust benefits package, including health, dental, and vision insurance, as well as access to a Health Savings Account, Healthcare Flexible Spending Account, life insurance, long-term disability leave, and a dependent daycare spending account. In addition, all regular employees enjoy incentive plans, a 401(k) plan with company match, short-term disability coverage, paid time off and holidays, participation in our Employee Stock Purchase Plan, and access to our Employee Assistance Program. Eligible employees may also benefit from our Non-qualified Retirement Plan Supplement and Capital Accumulation Plan, subject to IRS minimum earnings requirements. Please note that “regular employees” refers to those who are not temporary staff, such as interns, and some benefits may not apply to employees in Puerto Rico.
For further details about our comprehensive benefits, we encourage you to visit the link below.
MiniMed Benefits Overview
About MiniMed
MiniMed is a full-stack insulin delivery company dedicated to supporting people living with diabetes through every step of their journey — when and how they need it. For more than 40 years, we’ve been committed to redefining what’s possible: intelligent dosing systems designed for real life, predictive insights that stay a step ahead, and always on support when it’s needed most. At the heart of everything we do is a simple Mission: to make every day a better day for people with diabetes.
Learn more about our business, and our mission here .
It is the policy of MiniMed to provide equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, sexual orientation, gender identity and/or expression, genetic information, marital status, familial status, membership or activity in a local human rights commission, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state, or local law. In addition, MiniMed will provide reasonable accommodations for qualified individuals with disabilities.
If you are applying to perform work for MiniMed in any position which will involve performing at least two (2) hours of work on average each week within the unincorporated areas of Los Angeles County, you can find here a list of all material job duties of the specific job position which MiniMed reasonably believes that criminal history may have a direct, adverse and negative relationship potentially resulting in the withdrawal of a conditional offer of employment. MiniMed will consider for employment qualified job applicants with arrest or conviction records in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act.
- ...community. Description JOB DESCRIPTION: The Senior IT GRC (Governance, Risk, and Compliance) Analyst oversees technical design, implementation, maintenance, and responsibilities for multiple information security disciplines such as security policy, awareness and...SeniorWork experience placementRemote workWork from homeFlexible hours
$138k - $173k
...name on itFanDuel is seeking a Senior Technology Governance, Risk & Compliance (GRC) Analyst to join its Technology GRC team... ...ensuring alignment with FanDuel's security frameworks, industry best... ...technical field (e.g., Cybersecurity, Information Technology) or equivalent...SeniorTemporary workWork at officeLocal areaWorldwideShift work- Yamaha Motor Corporation, USA is seeking a Governance and Risk Compliance Analyst in Marietta, GA to partner with privacy and website teams. You... ...broader Cyber GRC initiatives while contributing to information security infrastructure and incident response. The role...Suggested
- Yamaha is seeking to fill a Governance and Risk Compliance Analyst role for our facility in... ...member of the cyber security team and involvement in other... ...security areas like Information security infrastructure,... ...Yamaha product Reports to: Senior Manager Cyber Security Yamaha...SuggestedHourly payContract workTemporary workWork experience placementLocal area
- A leading financial services firm located in Atlanta is seeking a Compliance Manager. This role involves overseeing compliance training, advising on regulations, and supporting audits. The ideal candidate will have at least 6 years of experience in financial services,...Senior
- The Senior Technical Compliance Analyst is an integral team member of the QTS Security Risk & Compliance Team and reports to the Manager, Information Security Compliance & Risk. QTS has adopted a risk-based... ...into a cohesive governance structure that supports operational...SeniorFull time
- ...Job Purpose: Our Senior Cyber Defense & Risk Analyst is responsible for strengthening Veritiv’s security posture through both cybersecurity... ...operations and governance, risk, and compliance. This position... ...Preferred ● Certified Information Systems Security Professional...SeniorWork experience placementWork at office
- Governance, Risk, & Framework Analyst (Finance) Job ID: 525936 CRH is a leading global diversified building... ...Job Summary As part of the Group Information Security team and reporting to the... ...Divisional teams-including Legal, Compliance, Finance, Risk, IT, and Internal...Work at officeLocal area
- DMI is seeking a Senior Information Security Analyst, SME to provide expert guidance on cybersecurity operations, risk management, and regulatory compliance for a CDC program. The role entails partnering across infrastructure, identity management, and program leadership...Senior
- COUNTRY Financial is seeking a security consultant/advisor focused on risk to join our team in the United States. The role involves researching... ...candidate has 7+ years of experience in information security risk, strong governance knowledge, and the ability to translate...Senior
$102.83k - $190.97k
...schedule (3 days onsite) out of our DC office. THE JOB The Senior Information Security Risk Analyst will support the assessment of information security... ...page for instructions to submit your request. In compliance with local law, we are disclosing the compensation, or...SeniorContract workTemporary workWork at officeLocal area- ...leaders face constantly shifting risks. Riveron helps organizations implement leading governance, risk and compliance practices by combining deep... ...risk assessment. The Senior Associate level position... ...humans. If you would like more information about how your data is...SeniorFull timeContract workWork at officeShift work
- OverviewJob PurposeThe Senior Engineer, Information Security, GRC is part of a team responsible for the global Information Security program... ...and physical security policies and controls.Governance, Risk, and Compliance maintain said policies, ensure controls are operating...Senior
- HD Supply seeks a Senior Information Security Analyst in Atlanta, GA to monitor, analyze, and safeguard internal information systems, networks, databases, and web security. You will partner with technology and business teams to enhance security software solutions and maintain...Senior
- ...across operations, technology, risk, finance, marketing, and... ...We are looking for a Senior Security Risk & Compliance Analyst to support and strengthen APCO’s security governance, risk, and compliance (GRC... ...Qualifications Bachelor’s degree in Information Security, Information...SeniorTemporary work
$73.36k - $118.77k
MorganFranklin Consulting LLC is seeking a qualified professional to join their Risk & Regulatory team in Atlanta, GA. This role involves assisting clients with Sarbanes-Oxley compliance, conducting risk assessments, and supporting internal audit initiatives. The ideal...Senior$73.36k - $118.77k
...MorganFranklin Consulting) in Atlanta, GA is seeking a professional with experience in risk management and internal audits. The role involves assisting companies with Sarbanes-Oxley compliance, executing audits, and providing best practices on risk and control. A Bachelor's...Senior$133.2k - $199.8k
...operations design and material and information flow. We deliver exceptional... ...are seeking an experienced Senior Manager, Cybersecurity & Governance, Risk & Compliance (GRC) to lead and mature our enterprise... ...management, compliance, and security assurance programs. This role...SeniorFull timeLocal area- Illumia is seeking an experienced Business Risk Analyst to support information security compliance, GRC workflow, and risk management initiatives. The role involves risk assessments, business continuity planning, and coordinating audits with external auditors and internal...SeniorRemote job
- ...makes a lasting impactJob Summary:The Senior Risk Management Analyst is responsible for collecting,... ...benefit analyses. Assist in ensuring compliance with internal controls, financial procedures... ..., billing issues, and underwriting information. Prepare and analyze underwriting...SeniorFull time
- ...we move money and information in a way that... ...quickly, reliably, and securely. Any time you... ...Fiserv.Job TitleCyber Risk AnalystAbout your... ...:As a Cyber Risk Analyst, you will support... ...to strengthen governance processes,... ...governance, risk, and compliance, software engineering...Full timeTemporary workH1bWork at officeMonday to Friday
- ...worldwide.Position Summary The Senior Trade Compliance Analyst supports NCR Voyix’s... ...compliance controls and supporting government inquiries and audit... ...from regulatory risk, managing tariff exposure,... ...military service, genetic information, or any other characteristic...SeniorFull timeWorldwideFlexible hours
- Senior IT Risk & Security Compliance Officer Emory University is hiring for the role of Senior IT Risk & Security Compliance Officer, Atlanta, GA (Hybrid). This is a Cybersecurity role in the governance, risk, and compliance field. Review the full details below and apply...SeniorWork at officeLocal areaRelocation package
- ...technology. Our approach unites operations, compliance, and technology experts, enabling us... ...build sustainable and scalable risk programs. At Myna, we are building a dynamic... ...and enhancing documentation around information security, risk, and compliance practices to ensure...Full timeWork at officeRemote work
$65.11k - $85k
A leading educational institution in Atlanta is seeking an Enterprise Risk Associate Senior to enhance the Enterprise Risk Management (ERM) program. This role involves aiding in governance, risk identification, assessment and ensuring proper alignment of risk practices...SeniorFull time- WestRock Company in the United States seeks a Senior Risk Analyst to support the ERM program by identifying, assessing, monitoring, and reporting... ...with cross-functional leaders to align risks with strategic initiatives and governance #J-18808-Ljbffr WestRock CompanySenior
- ...Risk Consulting - Risk Technology - Sap Grc & Security - Senior Consultant Location: New York Other locations: Anywhere... ...growth across SAP and Governance, Risk, and Compliance (GRC), EY is seeking SAP... ...degree in computer science, information systems, information...SeniorShift work
- The Federal Home Loan Bank of Atlanta is seeking a qualified individual to conduct collateral verification reviews and analyze pledges to support lending. This role includes preparing evaluations of mortgage loans, interacting with member institutions, and offering guidance...SeniorRemote workFlexible hours
- The Fayette Chamber of Commerce is seeking an Enterprise Risk Testing Analyst. This role ensures a strong risk culture by managing programs that monitor compliance with laws and regulations, testing activities, and collaborating with stakeholders. The ideal candidate has...Full timeFlexible hours
- The Opportunity The Senior Risk Analyst will support the execution and continuous... ..., reporting, and compliance risks. The position plays a... ...risk management process that informs decision-making and supports... ...methodologies, tools, and governance processes to enhance consistency...Senior
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Information Security Governance, Risk & Compliance Analyst. Be the first to apply!
- senior technology project manager Georgia
- remote senior business analyst Georgia
- senior leadership Georgia
- senior grant accountant Georgia
- senior storage engineer Georgia
- senior manager automotive Georgia
- senior magento developer Georgia
- senior application administrator Georgia
- senior java full-stack developer Georgia
- senior accountant work from home Georgia


