Senior Information Security Governance, Risk & Compliance Analyst
Listed on 2026-08-19
-
IT/Tech
Information Security & Data Protection, Cybersecurity
We anticipate the application window for this opening will close on - 1 Sep 2026
At Mini Med, you can begin a lifelong career of exploration and innovation, while helping make a difference in the lives of people living with diabetes around the globe. You'll lead with purpose, breaking down barriers to innovation for a more connected, compassionate world.
AboutThe Role
The Senior Information Security Governance, Risk & Compliance Analyst is a seasoned individual contributor responsible for supporting enterprise governance, risk, compliance, access governance, SAP GRC, SOX ITGC, and assurance activities. This second-line role provides independent oversight, monitoring, reporting, and control assurance to strengthen information security, technology compliance, and risk management capabilities. The role partners across Information Security, IT, IAM, Finance, Internal Audit, Privacy, Legal, and business stakeholders to assess risks, support regulatory obligations, improve control effectiveness, and mature governance practices across a global public medical technology environment.
Responsibilities may include the following and other duties may be assigned.
Access Governance & Segregation of Dutie- Coordinate and support enterprise Segregation of Duties governance across SAP and other key enterprise platforms.
- Administer SAP GRC Access Control capabilities, including Access Risk Analysis, Access Request Management, Emergency Access Management, and Business Role Management.
- Maintain SoD rulesets, risk functions, mitigating controls, access governance documentation, and related control evidence.
- Assess access risks, including SoD conflicts, excessive entitlements, privileged access exposure, and control effectiveness concerns.
- Monitor access-related exceptions, remediation plans, compensating controls, metrics, and trends to support risk reduction and compliance obligations.
- Partner with application owners, IAM, SAP Security, and business stakeholders to evaluate and address identified access governance risks
- Coordinate and manage periodic User Access Reviews and access certification activities.
- Monitor completion rates, overdue certifications, and non-compliance issues in accordance with governance requirements.
- Support oversight of privileged access, emergency access, Firefighter governance, and related monitoring activities.
- Review privileged access activity and maintain evidence supporting user access governance controls.
- Administer and support SAP GRC Process Control activities used to monitor, assess, and validate SOX IT General Controls and security compliance requirements.
- Support SOX ITGC compliance execution, control monitoring, audit evidence collection, validation, retention, and reporting.
- Assist control owners and stakeholders with control procedures, evidence requirements, deficiencies, findings, remediation tracking, and closure activities.
- Develop dashboards, metrics, and reporting to support management self-assessment, continuous control monitoring, and control effectiveness improvements.
- Support internal audits, external audits, and regulatory assessments by coordinating evidence, documentation, walkthroughs, and audit responses.
- Maintain audit-ready documentation repositories and supporting records.
- Monitor remediation activities and validate completion of corrective actions.
- Perform control assurance activities by reviewing evidence completeness, control execution, and remediation effectiveness.
- Support the development, implementation, and maintenance of information security policies, standards, procedures, governance processes, and control frameworks.
- Support control inventory management, exception management, compliance reporting, GRC tool administration, workflows, dashboards, and reporting capabilities.
- Develop compliance and risk metrics to monitor program effectiveness and identify opportunities for process improvement, automation, and control optimization.
- Contribute to scalable governance standards, operational procedures, and compliance monitoring practices that strengthen enterprise security governance.
- Assess cybersecurity, technology, artificial intelligence, data protection, and operational risks through structured risk assessment and governance processes.
- Facilitate information security risk assessments supporting governance, compliance, and enterprise risk management activities.
- Maintain risk registers, treatment plans, issue logs, action tracking, KRIs, risk dashboards, and management reporting.
- Evaluate mitigation strategies and control implementation activities to support informed business and technology decision-making.
- Partner with Information Security, Information Technology, Finance, Privacy, Internal Audit, Legal, Enterprise Risk Management, and business stakeholders.
- Translate technical…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).