Information Security Governance, Risk & Compliance (GRC) Director
MedtronicAbout the role
At Medtronic you can begin a life-long career of exploration and innovation, while helping champion healthcare access and equity for all. You’ll lead with purpose, breaking down barriers to innovation in a more connected, compassionate world.
A Day in the Life
The Information Security Governance, Risk & Compliance (GRC) Director is responsible for leading and maturing the company’s global security governance framework, enterprise cyber risk management program, and compliance activities across IT, OT, cloud, and regulated medical device environments. This leader ensures alignment with cybersecurity expectations, Quality System requirements, and industry best practices. The Director partners closely with IT, R&D, Operations, Legal/Privacy, Quality & Regulatory (QARA), and Internal Audit to strengthen the company’s security posture, reduce enterprise risk, and ensure readiness for audits, inspections, and regulatory submissions.This position is an exciting opportunity to work with Medtronic's Diabetes business. Medtronic has announced its intention to separate the Diabetes division to promote future growth and innovation within the business and reallocate investments and resources across Medtronic, subject to applicable information and consultation requirements. This separation provides our team with a bold opportunity to unleash our potential, enabling us to operate with greater speed and agility. As a separate entity, we anticipate leveraging increased investments to drive meaningful innovation and enhance our impact on patient care.
Responsibilities may include the following and other duties may be assigned.
Governance & Security Program Management
Develop, manage, and continuously improve the Information Security Governance framework based on NIST 800-53, ISO 27001, and corporate risk objectives.
Establish and maintain enterprise security policies, standards, and procedures in coordination with QARA, Legal, and IT.
Lead the security steering committees and reporting for executive leadership and board-level governance.
Enterprise Cyber Risk Management
Own the global cyber risk management strategy, including frameworks, methodologies, risk assessments, and reporting.
Partner with business units, manufacturing sites, and R&D to identify, assess, and mitigate technology and cybersecurity risks.
Maintain the enterprise cyber risk register and report key risks, KRIs, and risk treatment plans to the CISO and leadership.
Lead risk assessments for new products, vendors, technologies, and manufacturing systems.
Regulatory & Compliance Oversight
Ensure ongoing compliance with SOX NIST 800-53, HIPAA, and global data protection laws.
Lead cybersecurity components of internal audits and third-party assessments.
Manage alignment with industry frameworks.
Controls Assurance & Audit Readiness
Build and operate a controls assurance program including internal control testing, continuous monitoring, and audit preparation.
Serve as the primary Information Security liaison to Internal Audit and Quality Audit
Develop and track remediation plans for audit findings, vulnerabilities, and nonconformities.
Vendor & Third-Party Security
Oversee third-party cybersecurity risk assessments, contract security language, and ongoing monitoring of suppliers, including global manufacturing partners.
Work with Procurement and L
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s