Sr. Privacy and Data Protection Engineer (On-Site), Mounds View, MN
MedtronicAbout the role
At Medtronic you can begin a life-long career of exploration and innovation, while helping champion healthcare access and equity for all. You’ll lead with purpose, breaking down barriers to innovation in a more connected, compassionate world.
A Day in the Life
The Cardiac Rhythm Management Group brings all of our cardiac businesses together into one cross-functional, collaborative operating unit to employ the full breadth of our talent, technologies, products, services, and solutions to address the needs of customers and patients across the globe. Cardiac Rhythm Management offers devices and therapies to treat abnormal heart rhythms, as well as cardiac diagnostic and monitoring solutions.Be on the frontlines of the emerging area of medical device data protection and privacy as an integral member and technical leader within a team responsible for creating, deploying, and monitoring cybersecurity and privacy solutions for Medtronic’s medical devices and supporting IT infrastructure.
Work directly with R&D teams to ensure all relevant data protection and privacy risks are identified and evaluated, and appropriate and well-balanced solutions are implemented.
Develop project privacy management deliverables for regulatory bodies to comply with standards / guidance documents, and successfully communicate data protection policies, processes and solutions to customers, regulatory bodies, and other stakeholders.
Responsibilities may include the following and other duties may be assigned.
Lead and perform product data privacy activities ranging from in from data protection impact assessments to mitigation implementation.
Develop and perform product privacy consultations, product specific privacy policies and procedures.
Leads product through Privacy by Design process in conjunction with product R&D teams and develop and recommend specific privacy controls for product/system wide privacy needs.
Conducts and participates in product specific Data Privacy investigations and leads appropriate corrective action, remediation and mitigation efforts.
Manage privacy related deliverables for regulatory bodies, ensuring compliance with key standards / guidance documents.
Responds and assists as appropriate with the Privacy & Security customer question response process.
Consults with and educates regional business and legal partners on product specific privacy.
Enforces privacy awareness and measures compliance through training and consultation.
Other duties as assigned.
Must Have: Minimum Requirements- To be considered for this role, please ensure the minimum requirements are evident in your applicant profile.
Bachelor’s degree.
4+ years of relevant experience (2+ years in Privacy Compliance related roles) OR advanced degree with a minimum of 2 years relevant experience.
Nice to Have:
CIPP-US, CIPP-E or similar certification, or sufficient demonstrated experience and/or formal education in Privacy and Compliance
Strong decision-making capabilities, with a proven ability to weigh the relative costs and benefits of potential actions and identify the most appropriate solution.
High attention to detail in completing tasks with complete facts.
An ability to communicate complex and technical information in a creative and engaging way to diverse audiences, orally and in writing, in an easily understood and actionable manner.
An ability to effectively coach, influence and convince others to make appropriate changes in their priorities and behaviors for the benefit of the organization.
An ability to communicate to employees outside legal and privacy in a way that consistently drives objective decisions about privacy risk to optimize the trade-off between risk mitigation and business performance.
An understanding of business needs and commitment to delivering high-quality, prompt, and efficient service to the business.
Excellent prioritization capabilities, with an aptitude for breaking down work into manageable parts, effectively assessing the priority and time required to complete each part.
Privacy and Security incident management experience.
Demonstrated understanding of data protection practices, risk management processes, cybersecurity principles, and incident response methodologies.
Expertise in Global Privacy laws including HIPAA and GDPR.
Demonstrated ability to develop and grow productive, trusting, and open relationship
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s