Jobs and Careers
ME

Information Security Governance, Risk & Compliance (GRC) Director

Medtronic
Northridge, United Statesfull_timeVerifiedPosted 9 Dec 2025
💰 $265,200/yr

About the role

We anticipate the application window for this opening will close on - 23 Dec 2025


 

At Medtronic you can begin a life-long career of exploration and innovation, while helping champion healthcare access and equity for all. You’ll lead with purpose, breaking down barriers to innovation in a more connected, compassionate world.

A Day in the Life

The Information Security Governance, Risk & Compliance (GRC) Director is responsible for leading and maturing the company’s global security governance framework, enterprise cyber risk management program, and compliance activities across IT, OT, cloud, and regulated medical device environments. This leader ensures alignment with cybersecurity expectations, Quality System requirements, and industry best practices. The Director partners closely with IT, R&D, Operations, Legal/Privacy, Quality & Regulatory (QARA), and Internal Audit to strengthen the company’s security posture, reduce enterprise risk, and ensure readiness for audits, inspections, and regulatory submissions.

This position is an exciting opportunity to work with Medtronic's Diabetes business. Medtronic has announced its intention to separate the Diabetes division to promote future growth and innovation within the business and reallocate investments and resources across Medtronic, subject to applicable information and consultation requirements. This separation provides our team with a bold opportunity to unleash our potential, enabling us to operate with greater speed and agility. As a separate entity, we anticipate leveraging increased investments to drive meaningful innovation and enhance our impact on patient care.

Responsibilities may include the following and other duties may be assigned.

Governance & Security Program Management 

  • Develop, manage, and continuously improve the Information Security Governance framework based on NIST 800-53, ISO 27001, and corporate risk objectives. 

  • Establish and maintain enterprise security policies, standards, and procedures in coordination with QARA, Legal, and IT. 

  • Lead the security steering committees and reporting for executive leadership and board-level governance. 

Enterprise Cyber Risk Management 

  • Own the global cyber risk management strategy, including frameworks, methodologies, risk assessments, and reporting. 

  • Partner with business units, manufacturing sites, and R&D to identify, assess, and mitigate technology and cybersecurity risks. 

  • Maintain the enterprise cyber risk register and report key risks, KRIs, and risk treatment plans to the CISO and leadership. 

  • Lead risk assessments for new products, vendors, technologies, and manufacturing systems. 

Regulatory & Compliance Oversight 

  • Ensure ongoing compliance with SOX NIST 800-53, HIPAA, and global data protection laws. 

  • Lead cybersecurity components of internal audits and third-party assessments. 

  • Manage alignment with industry frameworks. 

Controls Assurance & Audit Readiness 

  • Build and operate a controls assurance program including internal control testing, continuous monitoring, and audit preparation. 

  • Serve as the primary Information Security liaison to Internal Audit and Quality Audit 

  • Develop and track remediation plans for audit findings, vulnerabilities, and nonconformities. 

Vendor & Third-Party Security 

  • Oversee third-party cybersecurity risk assessments, contract security language, and ongoing monitoring of suppliers, including global manufacturing partners. 

  • Work with Procurement and L

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Medtronic

View company profile →