Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior Principal Information Security Governance, Risk & Compliance Analyst

$150k - $256k

Jobleads-US

We anticipate the application window for this opening will close on - 5 Oct 2026At MiniMed, you can begin a lifelong career of exploration and innovation, while helping make a difference in the lives of people living with diabetes around the globe. You'll lead with purpose, breaking down barriers to innovation for a more connected, compassionate world.About the RoleThe Senior Principal Information Security Governance, Risk & Compliance Analyst is a recognized subject matter expert responsible for advancing enterprise IT SOX governance, risk management, compliance, and assurance capabilities by establishing oversight practices, influencing governance strategy, and providing expert guidance to senior leaders and cross-functional stakeholders.Operating within the second line of defense, this role is responsible for independently developing and enhancing risk-based oversight, compliance monitoring, internal control governance, and assurance practices that strengthen the organization's IT control environment and support regulatory and financial reporting objectives.The position serves as a senior advisor for IT SOX, technology risk, and internal control matters, partnering closely with Information Technology, Finance, Internal Audit, Enterprise Risk Management, and Information Security stakeholders to evaluate control effectiveness, identify emerging risks, monitor compliance obligations, and support continuous improvement of governance and assurance processes. The role leads complex cross-functional initiatives that improve control maturity, compliance readiness, risk transparency, and sustainable governance practices across the enterprise.While primarily focused on IT SOX governance, risk oversight, and internal controls, the role contributes to broader information security, regulatory compliance, and enterprise risk management objectives by providing subject matter expertise, independent challenge, and control assurance across key business and technology processes.Responsibilities may include the following and other duties may be assigned.Access Governance & Segregation of DutiesCoordinate and support enterprise Segregation of Duties governance across SAP and other key enterprise platforms.Administer SAP GRC Access Control capabilities, including Access Risk Analysis, Access Request Management, Emergency Access Management, and Business Role Management.Maintain SoD rulesets, risk functions, mitigating controls, access governance documentation, and related control evidence.Assess access risks, including SoD conflicts, excessive entitlements, privileged access exposure, and control effectiveness concerns.Monitor access-related exceptions, remediation plans, compensating controls, metrics, and trends to support risk reduction and compliance obligations.Partner with application owners, IAM, SAP Security, and business stakeholders to evaluate and address identified access governance risks.User Access Review & Privileged Access GovernanceCoordinate and manage periodic User Access Reviews and access certification activities.Monitor completion rates, overdue certifications, and non-compliance issues in accordance with governance requirements.Support oversight of privileged access, emergency access, Firefighter governance, and related monitoring activities.Review privileged access activity and maintain evidence supporting user access governance controls.SOX ITGC Compliance & Control MonitoringAdminister and support SAP GRC Process Control activities used to monitor, assess, and validate SOX IT General Controls and security compliance requirements.Support SOX ITGC compliance execution, control monitoring, audit evidence collection, validation, retention, and reporting.Assist control owners and stakeholders with control procedures, evidence requirements, deficiencies, findings, remediation tracking, and closure activities.Develop dashboards, metrics, and reporting to support management self-assessment, continuous control monitoring, and control effectiveness improvements.Audit & Assurance SupportSupport internal audits, external audits, and regulatory assessments by coordinating evidence, documentation, walkthroughs, and audit responses.Maintain audit-ready documentation repositories and supporting records.Monitor remediation activities and validate completion of corrective actions.Perform control assurance activities by reviewing evidence completeness, control execution, and remediation effectiveness.Governance & Compliance OperationsSupport the development, implementation, and maintenance of information security policies, standards, procedures, governance processes, and control frameworks.Support control inventory management, exception management, compliance reporting, GRC tool administration, workflows, dashboards, and reporting capabilities.Develop compliance and risk metrics to monitor program effectiveness and identify opportunities for process improvement, automation, and control optimization.Contribute to scalable governance standards, operational procedures, and compliance monitoring practices that strengthen enterprise security governance.Risk Management SupportAssess cybersecurity, technology, artificial intelligence, data protection, and operational risks through structured risk assessment and governance processes.Facilitate information security risk assessments supporting governance, compliance, and enterprise risk management activities.Maintain risk registers, treatment plans, issue logs, action tracking, KRIs, risk dashboards, and management reporting.Evaluate mitigation strategies and control implementation activities to support informed business and technology decision-making.Stakeholder Collaboration & Advisory SupportPartner with Information Security, Information Technology, Finance, Privacy, Internal Audit, Legal, Enterprise Risk Management, and business stakeholders.Translate technical risks, access governance issues, and compliance requirements into clear, business-focused recommendations.Facilitate assessments, workshops, compliance reviews, and cross-functional discussions to promote risk-informed decision-making.Provide subject matter guidance on governance, compliance, access governance, risk management, and security control requirements.Second-Line Independence & Governance BoundariesThis role provides oversight, monitoring, reporting, governance, compliance, risk management, and assurance activities while maintaining appropriate second-line independence. The role partners with first-line teams to evaluate control design, monitor execution, assess risk, validate evidence, and support remediation governance while preserving independent oversight responsibilities.Required QualificationsBachelor’s degree in Information Security, Cybersecurity, Information Systems, Risk Management, Business Administration, Accounting, Finance, Audit, or a related discipline, or equivalent combination of education and experience.Minimum 10 years of experience in Information Security GRC, Information Security Risk Management, SOX ITGC Compliance, Internal Audit, External Audit, Access Governance, Identity Governance, SAP Security Governance, Compliance Management, or Internal Controls Management.Requires advanced knowledge of Information Security GRC, access governance, regulatory compliance, risk management, and internal controls.Requires strong understanding of SAP GRC Access Control and SAP GRC Process Control administration. Typically obtained through advanced education combined with significant professional experience in information security, compliance, governance, risk management, audit, or internal controls.Current SAP Certified Application Associate, SAP Access Control certification required.Current SAP GRC Process Control certification required.Preferred QualificationsHands-on experience administering SAP GRC capabilities supporting SoD, UAR, EAM, SOX ITGC, continuous control monitoring, compliance reporting, and audit evidence management.Experience administering SAP GRC Access Risk Analysis, Access Request Management, Emergency Access Management, Business Role Management, and SAP GRC Process Control.Experience maintaining SoD rulesets, mitigating controls, access-risk libraries, access review campaigns, compliance dashboards, and audit evidence repositories.Experience supporting SOX ITGC testing, walkthroughs, evidence requests, remediation tracking, and audit readiness activities.Working knowledge of SAP authorization concepts, including roles, profiles, transaction codes, and role-based access controls.Strong analytical, documentation, reporting, stakeholder management, and business communication skills.SAP GRC Risk Management Certification or experience administering SAP GRC Risk Management solutions.Professional certifications such as CISA, CRISC, CIA, CISM, CISSP, GRCP, or CPA.Experience supporting public-company SOX 404 compliance programs.Experience in medical device, healthcare, life sciences, pharmaceutical, manufacturing, or other highly regulated industries.Experience supporting enterprise access governance platforms beyond SAP, including Oracle, Workday, ServiceNow, SailPoint, Entra ID, or comparable platforms.Framework KnowledgeKnowledge of one or more of the following frameworks and standards is preferred:NIST Cybersecurity FrameworkNIST Risk Management FrameworkNIST AI Risk Management FrameworkISO 27001ISO 31000ISO 42001COBITCOSO Internal Control FrameworkSOX 404 IT General ControlsHIPAA Security and Privacy RequirementsData Protection and Privacy RegulationsPhysical Job RequirementsThe above statements are intended to describe the general nature and level of work being performed by employees assigned to this position, but they are not an exhaustive list of all the required responsibilities and skills of this position.The physical demands described within the Responsibilities section of this job description are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. For Office Roles: While performing the duties of this job, the employee is regularly required to be independently mobile. The employee is also required to interact with a computer and communicate with peers and co-workers. Contact your manager or local HR to understand the Work Conditions and Physical requirements that may be specific to each role.Benefits & CompensationMiniMed offers a competitive salary and flexible benefits packageAt MiniMed, we put people first. A commitment to our employees lives at the core of our values: We recognize their contributions. They share in the success they help create. We offer a wide range of benefits, resources, and competitive compensation plans designed to support you at every stage of your career and life.Salary ranges for U.S (excl. PR) locations (USD):150,000.00 - $256,000.00For roles located in California, Seattle WA, Washington DC, Boston MA, and New York City, the salary range is $150,000.00 - $256,000.00 USD.Actual compensation may vary based on factors including experience, education, certifications, skills, market conditions, internal equity, and geographic location. Compensation and benefits information pertains solely to candidates hired within the United States (local market compensation and benefits will apply for others).At MiniMed, we are committed to supporting the well-being and financial security of our employees. Regular employees working 20 or more hours per week are eligible for a robust benefits package, including health, dental, and vision insurance, as well as access to a Health Savings Account, Healthcare Flexible Spending Account, life insurance, long-term disability leave, and a dependent daycare spending account. In addition, all regular employees enjoy incentive plans, a 401(k) plan with company match, short-term disability coverage, paid time off and holidays, participation in our Employee Stock Purchase Plan, and access to our Employee Assistance Program. Eligible employees may also benefit from our Non-qualified Retirement Plan Supplement and Capital Accumulation Plan, subject to IRS minimum earnings requirements. Please note that “regular employees” refers to those who are not temporary staff, such as interns, and some benefits may not apply to employees in Puerto Rico.For further details about our comprehensive benefits, we encourage you to visit the link below.MiniMed Benefits OverviewAbout MiniMedMiniMed is a full-stack insulin delivery company dedicated to supporting people living with diabetes through every step of their journey — when and how they need it. For more than 40 years, we’ve been committed to redefining what’s possible: intelligent dosing systems designed for real life, predictive insights that stay a step ahead, and always on support when it’s needed most. At the heart of everything we do is a simple Mission: to make every day a better day for people with diabetes.Learn more about our business, and our mission here .It is the policy of MiniMed to provide equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, sexual orientation, gender identity and/or expression, genetic information, marital status, familial status, membership or activity in a local human rights commission, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state, or local law. In addition, MiniMed will provide reasonable accommodations for qualified individuals with disabilities.If you are applying to perform work for MiniMed in any position which will involve performing at least two (2) hours of work on average each week within the unincorporated areas of Los Angeles County, you can find here a list of all material job duties of the specific job position which MiniMed reasonably believes that criminal history may have a direct, adverse and negative relationship potentially resulting in the withdrawal of a conditional offer of employment. MiniMed will consider for employment qualified job applicants with arrest or conviction records in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act. #J-18808-Ljbffr Jobleads-US

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Senior Principal Information Security Governance, Risk & Compliance Analyst in Los Angeles, CA vacancy
  •  ...MiniMed seeks a Senior Principal Information Security Governance, Risk & Compliance Analyst to lead IT SOX governance, risk management, and assurance initiatives. You will partner with IT, Finance, Internal Audit, and Enterprise Risk Management to strengthen control effectiveness... 
    Principal
    Senior

    Jobleads-US

    Los Angeles, CA
    1 day ago
  •  ...Cybersecurity Engineering, Risk & Governance Senior Advisor at Southern...  ..., customer information, and business operations...  ..., OT/ICS, compliance, risk, audit, operations...  ...reporting. Advising on secure architecture patterns...  ...solution provider and analysts to enhance security... 
    Senior
    Local area
    Remote work
    Relocation

    Edison International

    Rosemead, CA
    2 days ago
  • $105.4k - $207.8k

    Position Summary Cyber Security & Risk Strategy Senior Consultant Our Deloitte...  ...client cyber and information technology environments,...  ...organizational structure, governance, roles and responsibilities...  ...with governance, risk, and compliance tools, identity and access... 
    Senior
    Local area
    Visa sponsorship

    Deloitte

    Los Angeles, CA
    1 day ago
  • $24 - $28 per hour

     ...commitment to absolute integrity. East West Bank gives people the confidence to reach further. Overview The primary role of Senior FX Risk Analyst is to support daily Risk management function of FX Business. This position will be required to have FX industry knowledge,... 
    Senior
    Full time

    East West Bank

    Pasadena, CA
    4 days ago
  •  ...Risk Consulting - Risk Technology - Sap Grc & Security - Senior ConsultantLocation: New York Other locations: Anywhere...  ...growth across SAP and Governance, Risk, and Compliance (GRC), EY is seeking SAP Security...  ...in computer science, information systems, information security... 
    Senior
    Shift work

    EY

    Los Angeles, CA
    4 days ago
  • $61k - $102k

     ...SUMMARY The Senior Risk Analyst will facilitate the execution of the Bank’s Enterprise Risk...  ...Vendor Management Program. Ensures compliance with established Company policies and...  ..., Anti-Money Laundering and Customer Information Program, Right to Financial Privacy Act... 
    Senior
    Full time

    Hanmi Bank

    Los Angeles, CA
    1 day ago
  • $120k - $140k

    Job TitleThird-Party Risk AnalystCompany OverviewA leading...  ...a Third-Party Risk Analyst to join its growing IT Security team. The organization is...  ...services while ensuring compliance with industry standards and...  ...with direct exposure to senior leadership and security stakeholders
    Work at office
    Remote work

    Robert Half

    Los Angeles, CA
    4 days ago
  • $100k - $160k

     ...bring the opportunity.Zions Bancorporation is seeking a Senior Risk Officer and Subject Matter Expert (SME) in Supply Chain...  ...bank-specific requirements.Strong proficiency required in Governance, Risk, and Compliance (GRC) tools (experience managing data integrity in... 
    Senior
    Work at office
    Local area
    Flexible hours

    Zions Bancorporation

    Los Angeles, CA
    1 day ago
  • $127k - $197k

     ...fire science and risk management, with a...  ...making our world safe, secure and resilient....  ...more.We are hiring a Senior Wildfire Risk...  ...utility clients and government agencies. The candidate...  ...to ensure compliance and best practices...  ...and may not use the information for any unauthorized... 
    Senior
    Temporary work
    Remote work
    Relocation package
    Flexible hours

    Jensen Hughes

    Los Angeles, CA
    2 days ago
  •  ...Job Description Job Description NETWORK SECURITY RISK AND COMPLIANCE ANALYST II   Location; Newport Beach, CA   JOB DESCRIPTION...  ...in this position requires experience with cybersecurity governance, control assurance, risk management, vulnerability remediation... 
    Contract work
    Interim role
    Remote work

    Platinum Resource Group

    Los Angeles, CA
    12 days ago
  • $101.2k - $140.76k

    As a Healthcare Process Risk Senior Associate, you will have the opportunity...  ...management, and regulatory compliance within hospitals, academic...  ..., automation, and Governance, Risk, and Compliance (GRC)...  ...degree in Accounting, Finance, Information Technology, Management Information... 
    Senior
    Internship
    Seasonal work
    Work at office
    Local area
    Flexible hours
    3 days per week

    Grant Thornton

    Los Angeles, CA
    3 days ago
  • Join the Clean Energy RevolutionBecome a Operational Risk Management Senior Advisor at Southern California Edison (SCE) and build a better tomorrow...  ...your analytical skills to help the company make risk-informed decisions. You will regularly interact with senior leadership... 
    Senior
    Remote work
    Relocation

    Edison International

    Rosemead, CA
    3 days ago
  • Apple Inc. in Culver City, CA seeks a Business Assurance & Compliance staff member to audit and review business processes,...  ...across the company. Responsibilities include audits, risk assessment, reporting to senior management, and collaboration with multiple business groups... 

    Apple

    Culver City, CA
    1 day ago
  • Posted 4 weeks agoSenior P&C Consulting Actuary opening in Atlanta, Boston, Charlotte, Chicago, Dallas, Houston, Los Angeles, Montreal, New York, or Philadelphia. Manage client projects involving your choice of Reserving, Pricing, and/or Capital Modeling. Consult to (re...
    Senior

    Pryor Associates Executive Search

    Los Angeles, CA
    2 days ago
  • Starr Insurance seeks an Environmental Loss Control Consultant to evaluate and advise on environmental risks, minimize losses, and support underwriting decisions. You will perform site inspections, risk assessments, and technical reviews, delivering actionable recommendations... 
    Senior

    Starr Insurance

    Los Angeles, CA
    5 days ago
  • $180.2k - $355.1k

     ...Capital practice is adding an Actuarial Senior Manager to our Insights, Innovation & Operate...  ..., predictive modeling, underwriting, and risk analysis methodologies to support client...  ...incentive program, subject to the rules governing the program, whereby an award, if any,... 
    Senior
    Local area
    Visa sponsorship

    Deloitte

    Los Angeles, CA
    4 days ago
  •  ...Commonwealth Business Bank is seeking an Information Security Officer in Los Angeles to lead the bank's information security program. This role drives strategy, governance, and risk management to protect information assets and technology infrastructure. The candidate... 
    Senior

    Jobleads-US

    Los Angeles, CA
    3 days ago
  • $85k - $145k

    COMPLIANCE SPECIALIST SENIOR WEALTH MANAGEMENTWHAT IS THE OPPORTUNITY?The Compliance Specialist establishes and implements an effective compliance...  ...or compliance operationsMinimum 5 years of experience with risk management and/or Compliance policies and proceduresAdditional... 
    Senior
    Remote work

    City National Bank

    Los Angeles, CA
    4 days ago
  • $77k - $202k

     ...Consultant- Payer/Provider- Senior Associate you will...  ...interpret market changes and inform solutions- Supporting...  .../Quantitative Finance, Government/Public Policy, Health...  ...Management/Behavior, Risk Management/Insurance, Science...  ...to establish a secure and trusted workplace for... 
    Senior
    Full time
    H1b

    PwC

    Los Angeles, CA
    4 days ago
  •  ...Senior Associate Credit Officer Bring your...  ...JPMorgan Chase. As part of Risk Management and Compliance, you are at the...  ...management in making well-informed credit decisions on...  ...analysis on loans secured by multifamily and...  ..., institutional and government clients under the J.... 
    Senior

    JPMorgan Chase

    Pasadena, CA
    1 day ago
  • $100.2k - $164.1k

    Senior Construction Specialties Risk Engineering Consultant: Arizona or California. Zurich is currently looking for a Senior Construction Specialties...  ...for fee Comfortable with technology, building information modeling, and standard computer software programs and communication... 
    Senior
    Full time
    Temporary work
    Apprenticeship
    Work at office
    Local area
    Remote work
    Work from home
    Visa sponsorship

    Zurich North America

    Pasadena, CA
    3 days ago
  • Jacobs in the United States seeks a Major Crossings Design-Build Principal to lead pursuit, planning, and execution of major bridge projects. You will guide multidisciplinary teams across locations, driving design-build delivery and client relationships. The role emphasizes... 
    Principal
    Senior

    Jacobs

    Los Angeles, CA
    5 days ago
  •  ...TYLin is seeking a Principal Engineer to accelerate growth in Southern California's Transportation practice, leading client relationships and major roadway pursuits while delivering high-quality projects. The role includes collaboration with Irvine office leadership and... 
    Principal
    Senior
    Work at office

    Jobleads-US

    Santa Monica, CA
    1 day ago
  •  ...certificates of insurance; Monitor and analyze insured and uninsured risks making recommendations on appropriate types and levels of...  ...reports; assist in the preparation of budget documents by providing information relative to claims; may be required to represent the department... 
    Contract work
    Work at office

    Professional Risk Managers' International Association

    Gardena, CA
    13 hours ago
  •  ...We are seeking a Risk Management Analyst to join our Global Risk Management team...  ..., and Ireland. For further information on Kennedy Wilson, please...  ...concerns/inconsistencies for senior risk management review In...  ...insurance programs for loan compliance Assist in preparing risk... 
    Internship
    Summer internship
    Work at office

    Kennedy Wilson

    Beverly Hills, CA
    2 days ago
  • $139.8k - $164.5k

     ...?West Monroe is seeking a Senior ServiceNow Developer - IRM...  ...to help clients modernize governance, risk, and compliance capabilities on the ServiceNow...  ...risk, compliance, audit, security, and technology...  ...offices (see table below). Information on our competitive total rewards... 
    Senior
    Local area
    Immediate start
    Flexible hours

    West Monroe Partners

    Los Angeles, CA
    4 days ago
  • Samson Rose seeks a Principal/Senior Principal Mechanical Engineer to lead mechanical design and integration for advanced aerospace and defense systems. You will own architecture, interfaces, and detailed designs across hardware and electronics for deployable platforms... 
    Principal
    Senior

    Samson Rose

    Los Angeles, CA
    3 days ago
  •  ...Office of Integrated Risk Management...  ...Summary The Risk Analyst, Culture of Safety...  ...managing sensitive information, developing reports...  ..., and security of program-related...  ...quality improvement, compliance, risk management,...  ...supporting committees, governance groups, or... 
    Work at office
    Monday to Friday

    Tucker Parker Smith Group (TPS Group)

    Los Angeles, CA
    4 days ago
  • $74k - $86k

     ...Job Description Job Description Senior Insider Risk Analyst Our client is looking for a...  ...opportunity to join a collaborative Information Security team where you'll investigate insider...  ...with applicable state and local laws governing non-discrimination in employment in... 
    Senior
    Local area
    Remote work
    Visa sponsorship

    Irvine Technology Corporation

    El Monte, CA
    26 days ago
  • $100k - $135k

     ...solvers to help us create it. Who you are Metropolis is seeking a Governance, Risk, and Compliance (GRC) Analyst to join our expanding Security team. Reporting to the Senior Manager, GRC, you will mature information security policies, drive employee security awareness, and... 
    Contract work
    Temporary work
    For contractors
    For subcontractor
    Work at office
    Local area

    Metropolis

    Los Angeles, CA
    19 hours ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior Principal Information Security Governance, Risk & Compliance Analyst. Be the first to apply!