At MiniMed, you can begin a lifelong career of exploration and innovation, while helping make a difference in the lives of people living with diabetes around the globe. You'll lead with purpose, breaking down barriers to innovation for a more connected, compassionate world.
About The Role The Senior Information Security Governance, Risk & Compliance (GRC) Analyst is a seasoned individual contributor responsible for supporting and operating key governance, risk management, compliance, access governance, and assurance activities across the enterprise technology environment. This second-line role provides independent oversight, monitoring, reporting, and control assurance activities designed to strengthen the organization's information security, technology compliance, and risk management capabilities. The role serves as a critical bridge between Information Security, Information Technology, Identity & Access Management, Finance, Internal Audit, Privacy, and business stakeholders.
The Senior Information
Security GRC Analyst supports enterprise-wide governance processes, including Segregation of Duties (SoD) governance, User Access Reviews (UAR), privileged access oversight, SOX IT General Controls (ITGC), audit readiness, compliance monitoring, GRC platform administration, and risk management support activities. While the role supports enterprise-wide governance and compliance activities, the initial primary focus will be administration and oversight of SAP GRC Access Control and SAP GRC Process Control in support of SOX 404 compliance, access governance, and control monitoring activities. This position contributes to the protection of organizational assets, regulatory compliance obligations, and operational resilience within a public, global medical technology organization.
Responsibilities may include the following and other duties may be assigned.
Access
Governance & Segregation of Duties Coordinate and administer enterprise Segregation of Duties (SoD) governance processes across SAP and other enterprise applications and technology platforms.
Administer SAP GRC Access Control, including Access Risk Analysis (ARA), Access Request Management (ARM), Emergency Access Management (EAM), and Business Role Management (BRM). [Global Pri..., and Data | PowerPoint], [HIPAA_Vuln...iveSummary | Word]
Maintain SoD rule libraries, risk functions, mitigating controls, and access governance documentation.
Perform access risk assessments to identify SoD conflicts, excessive entitlements, privileged access risks, and other access-related control concerns.
Monitor and track access-related exceptions, remediation plans, and compensating controls.
Partner with application owners, Identity & Access Management teams, SAP Security, and business stakeholders to evaluate and address identified risks.
Analyze access governance metrics and trends to identify opportunities for control improvements.
User Access
Review & Privileged Access Governance Coordinate and manage periodic User Access Review (UAR) and access certification activities.
Monitor completion rates and escalate non-compliance or overdue certifications in accordance with governance requirements.
Support governance oversight of privileged and emergency access processes.
Review privileged access activity reports and identify unusual or elevated-risk activities for further assessment.
Maintain compliance evidence supporting user access governance controls.
Support Firefighter governance processes and privileged access monitoring activities. [Global Pri..., and Data | PowerPoint], [HIPAA_Vuln...iveSummary | Word] SOX ITGC Compliance & Control Monitoring Administer and support SAP GRC Process Control activities related to SOX IT General Controls (ITGC) compliance.
Support execution and monitoring of SOX ITGC compliance activities.
Coordinate audit-ready evidence collection, validation, retention, and reporting.
Assist control owners and stakeholders in documenting control procedures and evidence requirements.
Track control deficiencies, findings,
observations, and remediation activities through closure.
Support management self-assessment and continuous control monitoring initiatives.
Develop and maintain compliance dashboards, metrics, and reporting capabilities. Audit & Assurance Support Support internal audits, external audits, and regulatory assessments by providing evidence and documentation.
Participate in walkthroughs, control discussions, and audit inquiries.
Coordinate audit requests and maintain audit response documentation.
Monitor remediation activities and validate completion of corrective actions.
Maintain audit-ready documentation repositories and supporting records. Governance & Compliance Operations Support development, implementation, and ongoing maintenance of information security policies, standards, procedures, and control frameworks.
Assist with control inventory management, exception management, and compliance reporting processes.
Support administration and maintenance of GRC tools, workflows, dashboards, and reporting capabilities.
Develop compliance and risk metrics used to monitor program effectiveness.
Identify opportunities for process automation, efficiency improvements, and control optimization.
Risk Management Support
Support cybersecurity, technology, artificial intelligence, data protection, and operational risk assessment activities.
Assist with maintenance of risk registers, treatment plans, issues, and action tracking processes.
Monitor key risk indicators (KRIs) and risk trends.
Support development of risk reporting and management dashboards.
Assist stakeholders in documenting and evaluating risk mitigation activities.
Stakeholder
Collaboration & Advisory Support Partner with Information Security, Information Technology, Finance, Privacy, Internal Audit, Legal, Enterprise Risk Management, and business stakeholders.
Translate technical risks and compliance requirements into business-focused discussions and recommendations.
Facilitate meetings, assessments, workshops, and compliance reviews involving cross-functional teams.
Promote risk-informed decision-making while maintaining independence from operational execution responsibilities.
Provide guidance regarding governance, compliance, access governance, and risk management processes.
What This Role Does Not Do To maintain appropriate Second Line independence, this role does not: Provision user accounts or grant system access.
Configure application security roles or technical authorization structures.
Administer enterprise platforms outside approved governance activities.
Execute first-line control activities on behalf of system or process owners.
Approve business access certifications on behalf of management.
Accept business risk on behalf of control owners or executive management.
Own technical implementation of remediation activities. The role provides oversight, monitoring, reporting, governance, compliance, and assurance activities while remaining independent from operational execution responsibilities.
Required Qualifications Bachelor's degree in Information Security, Cybersecurity, Information Systems, Risk Management, Business Administration, Accounting, Finance, Audit, or a related discipline; or equivalent combination of education and experience.
Minimum 4 years of experience in Information Security GRC, IT Risk Management, SOX ITGC Compliance, Internal Audit, External Audit, Access Governance, Identity Governance, SAP Security Governance, or Internal Controls Management.
Current SAP Certified Application Associate – SAP Access Control certification (required).
Current SAP GRC Process Control certification (required).
Demonstrated hands-on experience administering SAP GRC solutions in support of: Segregation of Duties (SoD) User Access Reviews (UAR) Emergency Access Management (EAM) SOX IT General Controls (ITGC) Control monitoring Compliance reporting Audit evidence management
Hands-on experience administering: SAP GRC Access Risk Analysis (ARA) SAP GRC Access Request Management (ARM) SAP GRC Emergency Access Management (EAM) SAP GRC Business Role Management (BRM) SAP GRC Process Control
Experience maintaining SoD rulesets, mitigating controls, access-risk libraries, user access review campaigns, compliance dashboards, and audit evidence repositories.
Experience supporting SOX ITGC testing, walkthroughs, evidence requests, and remediation tracking.
Working knowledge of SAP authorization concepts, including roles, profiles, transaction codes, and role-based access controls.
Strong analytical, documentation, reporting, and stakeholder management skills.
Demonstrated ability to communicate technical control concepts and risk findings to business stakeholders and management.
Preferred Qualifications SAP GRC Risk Management Certification.
Experience administering SAP GRC Risk Management solutions.
Certified Information Systems Auditor (CISA).
Certified in Risk and Information Systems Control (CRISC).
Certified Internal Auditor (CIA).
Certified Information Systems Security Professional (CISSP).
Governance, Risk and Compliance Professional (GRCP).
Certified Public Accountant (CPA).
Experience supporting public-company SOX 404 compliance programs.
Experience within medical device, healthcare, life sciences, pharmaceutical, manufacturing, or other highly regulated industries.
Experience supporting enterprise access governance platforms beyond SAP, including Oracle, Workday, ServiceNow, SailPoint, Entra ID, or comparable platforms.
Experience developing compliance dashboards, risk reporting, and executive-facing control metrics. FRAMEWORK KNOWLEDGE Knowledge of one or more of the following frameworks and standards is preferred: NIST Cybersecurity Framework (CSF)
NIST Risk Management Framework (RMF)
NIST AI Risk Management Framework (AI RMF)
ISO 27001
ISO 31000
ISO 42001
COBIT
COSO Internal Control Framework
SOX 404 IT General Controls CAREER STREAM Typically an individual contributor with responsibility in a professional discipline or specialty. Delivers and/or manages projects assigned and works with stakeholders across the enterprise to achieve desired results. May provide guidance, coaching, and mentorship to less experienced personnel.
The majority of time is spent executing governance, risk management, compliance, access governance, and assurance activities while applying specialized knowledge and skills.
Physical Job Requirements The above statements are intended to describe the general nature and level of work being performed by employees assigned to this position, but they are not an exhaustive list of all the required responsibilities and skills of this position.
Benefits & Compensation MiniMed offers a competitive salary and versatile benefits package At MiniMed, we put people first. A commitment to our employees lives at the core of our values: We recognize their contributions. They share in the success they help create.
We offer a wide range of benefits, resources, and competitive compensation plans designed to support you at every stage of your career and life.
About
MiniMed We want to make every day a better day for people living with diabetes. Our team of creative innovators around the globe share a passion for finding the simplest solutions to the problems that people with diabetes face on a daily basis. For more than 40 years, we've been redefining what's possible, from intelligent dosing systems designed for real life to predictive insights that stay a step ahead, and we're dedicated to continuing to support our customers through every step of their journey — meeting them where and how they need it.
📌 Sr IT Technologist (Pune)
🏢 MiniMed
📍 Pune