Senior Manager, Cybersecurity and Cloud Security
Listed on 2026-05-22
-
IT/Tech
Cybersecurity, IT Project Manager, Cloud Computing, Systems Engineer
We anticipate the application window for this opening will close on – 23 Apr 2026.
At Medtronic you can begin a life-long career of exploration and innovation, while helping champion healthcare access and equity for all. You’ll lead with purpose, breaking down barriers to innovation in a more connected, compassionate world.
A Day in the LifeAt Medtronic, we bring bold ideas forward with speed and decisiveness to put patients first in everything we do. In-person exchanges are invaluable to our work. We’re working onsite 4 days a week as part of our commitment to fostering a culture of professional growth and cross‑functional collaboration. In your role, you may work from the following Medtronic sites:
- Mounds View, Minnesota
- Boston, Massachusetts
- Lafayette, Colorado
- Irvine, California (UCI)
- Jacksonville, Florida
- Fort Worth, Texas
- Memphis, Tennessee
- North Haven, Connecticut
This role will require 5% travel to enhance collaboration and ensure successful completion of projects.
Key Responsibilities Leadership & Strategy- Lead and mentor the application security team and a group of senior cloud security engineers.
- Define and execute the organization’s application and cloud security strategy.
- Partner with engineering, Dev Ops, and architecture teams to embed security into all stages of development.
- Establish security KPIs, metrics, and reporting for executive leadership.
- Provide leadership for the development, design, and optimization of information technology and systems functions supporting company business processes and technical information systems platforms.
- Drive secure SDLC practices including threat modeling, code reviews, and security testing.
- Oversee implementation of SAST, DAST, SCA, and API security tools.
- Develop and maintain secure coding standards and developer training programs.
- Lead vulnerability management and remediation efforts for applications.
- Responsibilities include, but are not limited to, analysis, selection and modification of enterprise systems; application software; installation of network hardware/software; and database management.
- Design and enforce security controls across cloud platforms (AWS, Azure, GCP).
- Ensure secure configuration and governance of cloud environments (IAM, networking, storage, containers).
- Implement and manage CSPM, CWPP, and CIEM solutions.
- Oversee container and Kubernetes security practices.
- Assign project work to cloud team to support organizational needs.
- Align security practices with frameworks such as NIST, ISO 27001, SOC 2, and CIS benchmarks.
- Conduct risk assessments and support audits and regulatory requirements.
- Collaborate with GRC teams to maintain compliance posture.
- Support incident response related to application and cloud threats.
- Drive root cause analysis and continuous improvement efforts.
- Stay ahead of emerging threats, vulnerabilities, and industry trends.
- Provide direction for the effort required to protect the company’s data, tools, and information systems.
- Ensure infrastructure architecture standards maximize efficiency and support platform compatibility.
- Coordinate delivery of services to user groups and ensure IT service is uninterrupted.
- Select, develop, and evaluate personnel to ensure the efficient operation of the function.
- 7+ years of experience with a bachelor’s degree or 5+ years of experience with an advanced degree.
- 5+ years of managerial experience.
- Bachelor’s degree in Computer Science, Cybersecurity, or related field (Master’s preferred).
- 8–12+ years of experience in cybersecurity, with a focus on application and cloud security.
- 3–5+ years in a leadership or management role.
- Strong expertise in cloud platforms (AWS, Azure, or GCP).
- Deep understanding of secure software development and Dev Sec Ops practices.
- Experience with security tools (e.g., SAST, DAST, SIEM, CSPM, container security).
- Knowledge of modern architectures (microservices, APIs, serverless).
- Industry certifications such as CISSP, CCSP, CISM, or GIAC.
- Experience with Infrastructure as Code (Terraform, Cloud…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).