At MiniMed, you can begin a lifelong career of exploration and innovation, while helping make a difference in the lives of people living with diabetes around the globe. You'll lead with purpose, breaking down barriers to innovation for a more connected, compassionate world.
About the Role
A Day in the Life
Our Global Diabetes Capability Center in Pune is expanding to serve more people living with diabetes globally. Our state-of-the-art facility is dedicated to transforming diabetes management through innovative solutions and Technologies that reduce the burden of living with diabetes.
This position is an exciting opportunity to work with Minimed’s Diabetes business. Medtronic has announced its intention to separate the Diabetes division to promote future growth and innovation within the business and reallocate investments and resources across Medtronic, subject to applicable information and consultation requirements. This separation provides our team with a bold prospect to unleash our potential, enabling us to operate with greater speed and agility. As a separate entity, we anticipate leveraging increased investments to drive meaningful innovation and enhance our impact on patient care.
#BetterDaysStartNow
Information Assurance & Control Effectiveness
- Conduct independent assurance reviews to evaluate the design and operating effectiveness of information security, governance, compliance, and technology controls.
- Assess control performance, monitoring activities, and governance processes to identify weaknesses, gaps, and improvement opportunities.
- Validate implementation of security, compliance, and regulatory requirements across business and technology environments.
Governance & Compliance Assurance
- Assess adherence to information security policies, standards, governance requirements, and regulatory obligations.
- Evaluate access governance, SOX IT General Controls (ITGC), compliance monitoring, and related governance controls.
- Validate alignment of controls and processes with applicable cybersecurity, privacy, and regulatory frameworks, including NIST CSF, ISO 27001, HIPAA, SOX, NIS2, BSI C5, ENS, and other applicable requirements.
Control Testing & Risk Analysis
- Perform risk-based control testing and assurance activities across cybersecurity, technology, and governance domains.
- Analyze control deficiencies, audit observations, incidents, and compliance findings to identify trends and improvement opportunities.
- Assess the effectiveness of remediation activities and corrective actions designed to address identified control weaknesses.
Findings Management & Reporting
- Document assurance observations, control deficiencies, compliance findings, and recommendations for improvement.
- Track remediation activities and report on the status of corrective actions and issue resolution efforts.
- Develop assurance metrics, dashboards, and reporting to support governance oversight and informed decision-making.
Stakeholder Engagement & Advisory
- Partner with Information Security, Technology, Compliance, Privacy, Internal Audit, Risk Management, Legal, Finance, and business stakeholders to support assurance objectives.
- Communicate assurance results, observations, and recommendations to technical and non-technical audiences.
- Provide independent challenge and subject matter expertise regarding information assurance, security governance, compliance monitoring, and control effectiveness.
Independence & Scope
This role operates as an independent second-line assurance function within the Information Security Governance, Risk & Compliance (InfoSec GRC) organization. The position provides objective assessment, validation, and oversight of information security governance, compliance, and control effectiveness activities while maintaining appropriate independence from operational control ownership, control execution, remediation activities, and internal audit responsibilities.
Specialist Career Stream
Typically an individual contributor with responsibility in a professional discipline or specialty. Delivers and manages assurance reviews, information assurance activities, control assessments, compliance validation activities, and governance evaluations while working with stakeholders throughout the organization. May provide guidance, coaching, and mentoring to less experienced professionals. The majority of time is spent delivering and overseeing assurance activities while utilizing specialized cybersecurity, compliance, governance, and information assurance knowledge.
Differentiating Factors
Autonomy
- Seasoned individual contributor working independently under limited supervision.
- Determines and develops approaches to assurance, validation, and control effectiveness activities.
- Exercises judgment in applying information assurance principles, governance standards, and compliance requirements to complex cybersecurity scenarios.
Organizational Impact
- Contributes directly to improving security governance, compliance readiness, control effectiveness, and protection of organizational assets.
- Builds relationships and consensus across the organization to achieve control improvement and assurance objectives.
Innovation & Complexity
- Evaluates difficult and complex cybersecurity, governance, compliance, and control effectiveness issues.
- Performs detailed analysis and develops recommendations that improve processes, controls, and security capabilities.
Communication & Influence
- Communicates with senior internal stakeholders, business leaders, auditors, regulators, and external partners.
- Exchanges information regarding control effectiveness, risk exposure, compliance obligations, and governance expectations while influencing decision-making.
Leadership & Talent Management
- May provide guidance, coaching, and training to other employees within the Information Security organization.
- May lead projects and assurance initiatives requiring coordination of cross-functional participation.
Required Knowledge & Experience
- Bachelor's degree in Information Security, Cybersecurity, Information Systems, Computer Science, Accounting, Audit, Business Administration, or related discipline; or equivalent combination of education and experience.
- Minimum 7 years of relevant experience,
or an advanced degree with a minimum of 5 years of relevant experience.
- Experience in information assurance, cybersecurity governance, information security compliance, risk management, IT audit, access governance, SOX IT compliance, or related disciplines.
- Experience assessing and evaluating information security controls, governance processes, compliance activities, and technology risks.
- Strong understanding of cybersecurity principles, information assurance practices, security controls, governance processes, and regulatory compliance requirements.
- Experience analyzing control effectiveness, developing recommendations, and supporting remediation activities.
- Strong analytical, communication, documentation, facilitation, and stakeholder management skills.
- Knowledge of information security governance, control validation, and assurance methodologies.
Preferred Qualifications
- Experience supporting SOX-regulated public companies.
- Experience evaluating SAP GRC Access Control, SAP GRC Process Control, User Access Reviews (UAR), Segregation of Duties (SoD), Emergency Access Management (EAM), and access governance controls.
- Experience supporting cybersecurity governance, information assurance, compliance assurance, or control validation programs.
- Experience within healthcare, medical device, pharmaceutical, manufacturing, or other highly regulated industries.
- Experience supporting NIST CSF, ISO 27001, HIPAA, SOX, NIS2, BSI C5, ENS, ACN, or similar regulatory frameworks.
- Experience working with Governance, Risk & Compliance (GRC) platforms including SAP GRC, ServiceNow IRM, RSA Archer, AuditBoard, MetricStream, or similar solutions.
- Experience assessing cybersecurity, privacy, operational, and technology risks.
Preferred Certifications
- Certified Information Systems Auditor (CISA)
- Certified Information Systems Security Professional (CISSP)
- Certified Information Security Manager (CISM)
- Certified in Risk and Information Systems Control (CRISC)
- Certified Governance, Risk and Compliance Professional (CGRC)
- Certified Internal Auditor (CIA)
- Certified Public Accountant (CPA)
Physical Job Requirements
The above statements are intended to describe the general nature and level of work being performed by employees assigned to this position, but they are not an exhaustive list of all the required responsibilities and skills of this position.
Benefits & Compensation
MiniMed offers a competitive salary and flexible benefits package
At MiniMed, we put people first. A commitment to our employees lives at the core of our values: We recognize their contributions. They share in the success they help create. We offer a wide range of benefits, resources, and competitive compensation plans designed to support you at every stage of your career and life.
About MiniMed
We want to make every day a better day for people living with diabetes. Our team of creative innovators around the globe share a passion for finding the simplest solutions to the problems that people with diabetes face on a daily basis. For more than 40 years, we've been redefining what's possible, from intelligent dosing systems designed for real life to predictive insights that stay a step ahead, and we're dedicated to continuing to support our customers through every step of their journey — meeting them where and how they need it.
📌 Senior Information Security Assurance Analyst (India)
🏢 MiniMed
📍 India