×
Register Here to Apply for Jobs or Post Jobs. X

Senior Principal Information Security Governance, Risk & Compliance Analyst

Job in Los Angeles, Los Angeles County, California, 90079, USA
Listing for: USA-Medtronic MiniMed, Inc 1017
Full Time position
Listed on 2026-10-05
Job specializations:
  • IT/Tech
    Information Security & Data Protection, Cybersecurity
Salary/Wage Range or Industry Benchmark: 150000 - 256000 USD Yearly USD 150000.00 256000.00 YEAR
Job Description & How to Apply Below

We anticipate the application window for this opening will close on - 5 Oct 2026.

About the Role

The Senior Principal Information Security Governance, Risk & Compliance Analyst is a recognized subject matter expert responsible for advancing enterprise IT SOX governance, risk management, compliance, and assurance capabilities by establishing oversight practices, influencing governance strategy, and providing expert guidance to senior leaders and cross-functional stakeholders. Operating within the second line of defense, this role is responsible for independently developing and enhancing risk-based oversight, compliance monitoring, internal control governance, and assurance practices that strengthen the organization’s IT control environment and support regulatory and financial reporting objectives.

The position serves as a senior advisor for IT SOX, technology risk, and internal control matters, partnering closely with Information Technology, Finance, Internal Audit, Enterprise Risk Management, and Information Security stakeholders to evaluate control effectiveness, identify emerging risks, monitor compliance obligations, and support continuous improvement of governance and assurance processes. The role leads complex cross-functional initiatives that improve control maturity, compliance readiness, risk transparency, and sustainable governance practices across the enterprise.

While primarily focused on IT SOX governance, risk oversight, and internal controls, the role contributes to broader information security, regulatory compliance, and enterprise risk management objectives by providing subject matter expertise, independent challenge, and control assurance across key business and technology processes.

Responsibilities may include the following and other duties may be assigned.

Access Governance & Segregation of Duties

Coordinate and support enterprise Segregation of Duties governance across SAP and other key enterprise platforms.

Administer SAP GRC Access Control capabilities, including Access Risk Analysis, Access Request Management, Emergency Access Management, and Business Role Management.

Maintain SoD rulesets, risk functions, mitigating controls, access governance documentation, and related control evidence.

Assess access risks, including SoD conflicts, excessive entitlements, privileged access exposure, and control effectiveness concerns.

Monitor access-related exceptions, remediation plans, compensating controls, metrics, and trends to support risk reduction and compliance obligations.

Partner with application owners, IAM, SAP Security, and business stakeholders to evaluate and address identified access governance risks.

User Access Review & Privileged Access Governance

Coordinate and manage periodic User Access Reviews and access certification activities.

Monitor completion rates, overdue certifications, and non-compliance issues in accordance with governance requirements.

Support oversight of privileged access, emergency access, Firefighter governance, and related monitoring activities.

Review privileged access activity and maintain evidence supporting user access governance controls.

SOX ITGC Compliance & Control Monitoring

Administer and support SAP GRC Process Control activities used to monitor, assess, and validate SOX IT General Controls and security compliance requirements.

Support SOX ITGC compliance execution, control monitoring, audit evidence collection, validation, retention, and reporting.

Assist control owners and stakeholders with control procedures, evidence requirements, deficiencies, findings, remediation tracking, and closure activities.

Develop dashboards, metrics, and reporting to support management self-assessment, continuous control monitoring, and control effectiveness improvements.

Audit & Assurance Support

Support internal audits, external audits, and regulatory assessments by coordinating evidence, documentation, walkthroughs, and audit responses.

Maintain audit-ready documentation repositories and supporting records.

Monitor remediation activities and validate completion of corrective actions.

Perform control assurance activities by reviewing evidence completeness, control execution, and remediation effectiveness.

Governance & Compliance Operations

Support the development, implementation, and maintenance of information security policies, standards, procedures, governance processes, and control frameworks.

Support control inventory management, exception management, compliance reporting, GRC tool…

Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary