Information Assurance Analyst jobs at Leidos - 1092 jobs
Senior Environmental Information Systems & Security Engineer
Leidos 4.7
Information assurance analyst job at Leidos
At Leidos, we deliver innovative solutions through the efforts of our diverse and talented people who are dedicated to our customers' success. We empower our teams, contribute to our communities, and operate sustainably. Everything we do is built on a commitment to do the right thing for our customers, our people, and our community. Our Mission, Vision, and Values guide the way we do business. Your greatest work is ahead!
Due to contract requirements; U.S. Citizenship or U.S. Permanent Residency is required.
The Civil Environmental & Infrastructure Portfolio at Leidos currently has an opening for a Senior Environmental Information Systems & Security Engineer.
The successful candidate will:
• Manage a technical systems integration team (system administrators, software developers, database administrators, data managers, GIS operators) in the development, testing, and maintenance of new .NET, JavaScript, T-SQL applications, and extending the functionality of SaaS applications.
• Support multiple projects related to environmental data management, logistics management, document management and search capabilities, mobile data collection, modeling, and workflow automation under contracts with the Army Corps of Engineers.
• Drive collaboration and innovation across office locations and technical skill areas, ensuring performance excellence and professional growth for the information technology section.
• Perform information security officer duties and be responsible for guiding the systems through the Risk Management Framework to obtain an Authorization to Operate (ATO). This responsibility includes overseeing, implementing, and validating IT security controls to ensure compliance with NIST policy and organizational mandated security requirements, ensuring the confidentiality, integrity, and availability for each assigned system, and will guide systems through re-authorization audits and continuous monitoring compliance requirements.
• Develop and maintain system requirements documents, system design documents and diagrams, system hardware and software inventories, system security plans, contingency plans, incident response plans, interconnection agreements, and system-specific standard operating procedures.
• Enforce SecDevOps change management lifecycle procedures, including dynamic testing, static code analysis, and peer reviews to ensure code quality across all managed systems.
• Provide technology guidance to program managers and develop basis of estimates (BOEs) in support of new work opportunities.
• Prepare resource estimates used in the development of proposals, ensuring BOE rationale is documented to support the resource estimates for environmental data management, geospatial data management, system development/maintenance, hosting, and software licensing support for environmental investigations and/or support activities.
Responsibilities:
• Manage environmental data lifecycle across projects with stakeholders, data managers, project chemists.
• Manage system development lifecycle across projects with stakeholders, system developers and administrators.
• Maintain security compliance status and documentation of system environments.
• Perform security reviews of new or changed code objects and system posture.
• Perform audit log reviews to identify suspect activity, application errors, incidents.
• Ensure systems availability, reviewing hardware resources, system backup performance, patch status.
• Conduct break/fix analysis for hosted systems.
• Manage team assignments and workloads, tracking tasks and deliverable progress.
• Lead technology initiatives across organization contracts.
Required Education & Experience:
• Bachelors Science degree and 12+ years of prior relevant experience in Environmental Science, Software Development, Software Engineering, Computer Science, Cybersecurity Compliance, or related discipline; a Master's degree with 10+ years of experience will also be considered.
• Demonstrate excellent written and verbal communication skills, leadership skills, and attention to detail. Strong organizational skills are essential.
• Significant staff and team management experience.
• Significant RCRA and CERCLA environmental investigation experience.
• Proficient in .NET application development in Microsoft Visual Studio.
• Proficient in developing T-SQL statements and stored procedures in Microsoft SQL Server.
• Significant NIST security compliance experience.
• The position requires the ability to communicate technical information orally and in writing.
• Must possess excellent organization skills and attention to detail.
• Due to contract requirements; U.S. Citizenship or U.S. Permanent Residency is required.
• Ability to obtain and maintain a Public Trust security clearance (which includes three years immediate residency in the US).
Preferred Qualifications:
Experience with:
• ArcGIS Online administration, ESRI mobile data collection, and Trimble mobile apps.
• Using Earthsoft, EQuIS suite of products, and extending its functionality.
• Secure coding principles and adherence to DISA STIGs.
• Developing security compliance documentation and guiding systems through the ATO process.
• Integrating identify federation and multi-factor authentication into applications.
• Using AFCEC ERPIMS, FUDSChem, ADR.NET data management software packages.
Salary Range for this position: $145K to $150K
At Leidos, we don't want someone who "fits the mold"-we want someone who melts it down and builds something better. This is a role for the restless, the over-caffeinated, the ones who ask, “what's next?” before the dust settles on “what's now.”
If you're already scheming step 20 while everyone else is still debating step 2… good. You'll fit right in.
Original Posting:December 22, 2025
For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.
Pay Range:Pay Range $116,350.00 - $210,325.00
The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.
A prominent financial institution in Denver seeks a cybersecurity expert to join their Malware Defense Team. The role involves analyzing malware, tracking campaigns, and creating tools to assist in analysis. Ideal candidates will have strong experience in malware analysis, threat detection tools, and team collaboration. This position offers a competitive salary range of $95,700 to $144,900 annually, with industry-leading benefits and a commitment to professional growth.
#J-18808-Ljbffr
$95.7k-144.9k yearly 2d ago
Malware Defense Malware Analyst
Stryker Corporation 4.7
Denver, CO jobs
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day. Being a Great Place to Work is core to how we drive Responsible Growth. This includes our commitment to being an inclusive workplace, attracting and developing exceptional talent, supporting our teammates' physical, emotional, and financial wellness, recognizing and rewarding performance, and how we make an impact in the communities we serve. Bank of America is committed to an in-office culture with specific requirements for office-based attendance and which allows for an appropriate level of flexibility for our teammates and businesses based on role-specific considerations. At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us! Bank of America is one of the world's leading financial institutions, serving over 66 million consumers and small businesses. Company success is only possible with a strong cyber defense, which enables Bank of America to safely conduct global operations across the United States and in approximately 35 countries. Our primary goal is to safeguard not only the company, but our clients and their trust. The Malware Defense Team is looking for top talent who would like to join one of the most advanced cybersecurity teams in the world.
Responsibilities
In-depth analysis of malware, including authoring analysis reports.
Tracking malware campaigns, malicious actors, and related infrastructure.
Creation of tools and scripts to assist in the analysis of malware analysis.
Field escalations of potentially malicious files and websites from teams within Malware Defense.
Required Qualifications
Strong direct experience of analyzing malware.
Intermediate to advanced malware analysis skills.
Experience creating innovative ways to track progression of malware families, infrastructure, and campaigns conducted by e-crime, and cyber espionage actors.
Experience creating tools and scripts to accelerate malware and threat analysis.
Background in network traffic analysis - WireShark, Fiddler, proxy logs, etc.
Experience analyzing malicious web content such as ClickFix, ClearFake, SocGholish, etc.
Experience authoring YARA, Suricata, and EKFiddle detection rules.
Experience with penetration testing and/or adversary emulation is a plus.
Able to work independently on tasks, but also work well within a team environment.
Desired Qualifications
Experience analyzing malware targeting Linux, Android, and IOT platforms.
Skills
Cyber Security
Data Privacy and Protection
Problem Solving
Process Management
Threat Analysis
Business Acumen
Data and Trend Analysis
Interpret Relevant Laws, Rules, and Regulations
Risk Analytics
Stakeholder Management
Access and Identity Management
Data Governance
Encryption
Information Systems Management
Technology System Assessment
Shift
1st shift (United States of America)
Hours Per Week
40
Pay Transparency details
US - CO - Denver - 1144 15th St - Denver Gis (CO9926), US - DC - Washington - 1800 K St NW - 1800 K Street NW (DC1842), US - IL - Chicago - 540 W Madison St - Bank Of America Plaza (IL4540)
Pay and benefits information
Pay range: $95,700.00 - $144,900.00 annualized salary, offers to be determined based on experience, education and skill set.
Discretionary incentive eligible: This role is eligible to participate in the annual discretionary plan. Employees are eligible for an annual discretionary award based on their overall individual performance results and behaviors, the performance and contributions of their line of business and/or group; and the overall success of the Company.
Benefits
This role is currently benefits eligible. We provide industry-leading benefits, access to paid time off, resources and support to our employees so they can make a genuine impact and contribute to the sustainable growth of our business and the communities we serve.
#J-18808-Ljbffr
$95.7k-144.9k yearly 2d ago
Senior Security Engineer, Apps
Hinge-Health 4.4
San Francisco, CA jobs
About the role
We're looking for a detail oriented, technically skilled engineer to join our Application Security team. This role offers opportunities to influence the group's growth and direction while integrating security within the entire Software Development Life Cycle (SDLC).
Security Engineers will collaborate with Product and Engineering teams to embed security into all phases of the SDLC from feature design and implementation to deployment. They also establish and evaluate authentication, authorization, and privacy controls for B2C, B2B and M2M entity types and use cases.
They will identify, prioritize, and remediate vulnerabilities identified via internal and third party penetration testing, Software Composition Analysis (SCA), Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST). They will also deploy, maintain and tune the tools used to perform this testing.
Security Engineers serve as subject matter experts on authentication and authorization security, partnering with product and engineering teams to implement security and privacy best practices for healthcare applications.
The ideal candidate will have experience securing, hardening, and identifying vulnerabilities in web applications, RESTful and GraphQL APIs, and mobile applications (iOS and Android) in a cloud hosted microservice environment.
The ideal candidate will also have experience risk assessing the results of automated SCA, SAST and DAST to validate severity before assigning to engineers for remediation.
They may also have experience in securing Generative AI LLM services, including, but not limited to security guardrails to prevent jailbreaks, sensitive information disclosure, data/model poisoning, and safety guardrail verification and testing.
What You'll Accomplish
Implement and maintain automated security scanning tools (SCA, SAST, DAST) and perform manual and AI assisted security assessments including source code review to identify and remediate vulnerabilities in Hinge Health web applications, mobile applications and API endpoints.
Enable the product teams to create secure by design product features and services by working alongside product managers and engineers during the design phase of projects including Generative AI projects.
Assist with third party security assessments and penetration tests of Hinge Health web applications, API endpoints, and mobile applications, including interpretation of results and verification of remediations.
Contribute to the improvement of Software Development Life Cycle management policies, procedures, and standards.
Basic Qualifications
3+ years of experience in application security, product security, or related security engineering roles
Experience securing web applications, mobile applications (iOS/Android), or API endpoints
Experience with automated security testing, including configuring and automating security scans as part of the CI/CD process, and interpreting the results and working directly with engineers on prioritization and remediation.
Experience in examining source code in multiple languages to evaluate security controls and identifying common coding and design vulnerabilities. Experience with OWASP Top 10 and other common security flaw patterns.
Demonstrated ability to collaborate with engineering and product teams to address security concerns.
Preferred Qualifications
Experience securing applications in Health Care, securing ePHI and HIPAA/HITECH regulations.
Experience with modern authentication and authorization technologies including OAuth 2.0, OIDC, SAML, JWT validation, SSO integrations, MFA/OTP implementations, API tokens, and identity platforms such as Auth0 or Okta. Understanding of session management, refresh tokens, and secure authentication flows for B2C, B2B, and M2M use cases.
Experience assessing the security and safety of Generative AI LLM solutions and in evaluating and implementing solutions for their continuous monitoring
Familiarity with HITRUST CSF and NIST control frameworks.
Experience in Threat Modeling
Experience performing security assessments and secure design of hardware and firmware of medical devices communicating over Bluetooth
Experience with any of the following, deploying web based services on AWS infrastructure, Kubernetes, Typescript, ReactNative, Python, Go, Ruby on Rails, GraphQL, IaC using Terraform.
Incident Handling: Be able to work as a subject matter expert in the security controls, internal communications, and infrastructure of Hinge Health applications during security incidents.
Hinge Health Hybrid Model
We believe that remote work and in-person work have their own advantages and disadvantages, and we want to be able to leverage the best of both worlds. Employees in hybrid roles are required to be in the office 3 days/week. The San Francisco office has a dog-friendly workplace program.
Compensation
This position will have an annual salary, plus equity and benefits. Please note the annual salary range is a guideline, and individual total compensation will vary based on factors such as qualifications, skill level, competencies, and work location. The annual salary range for this position is $192,000 - $230,400.
About Hinge Health
Hinge Health leverages software, including AI, to largely automate care for joint and muscle health, delivering an outstanding member experience, improved member outcomes, and cost reductions for its clients. The company has designed its platform to address a broad spectrum of MSK care-from acute injury, to chronic pain, to post-surgical rehabilitation-and the platform can help to ease members' pain, improve their function, and reduce their need for surgeries, all while driving health equity by allowing members to engage in their exercise therapy sessions from anywhere. The company is headquartered in San Francisco, California.
Learn more at **************************
What You'll Love About Us
Inclusive healthcare and benefits: On top of comprehensive medical, dental, and vision coverage, we offer employees and their family members help with gender-affirming care, tools for family and fertility planning, and travel reimbursements if healthcare isn't available where you live.
Planning for the future: Start saving for the future with our traditional or Roth 401k retirement plan options which include a 2% company match.
Modern life stipends: Manage your own learning and development
Culture & Engagement
Hinge Health is an equal opportunity employer and prohibits discrimination and harassment of any kind. We make employment decisions without regards to race, color, religion, sex, sexual orientation, gender identity, national origin, age, veteran status, disability status, pregnancy, or any other basis protected by federal, state or local law. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. We provide reasonable accommodations for candidates with disabilities. If you feel you need assistance or an accommodation due to a disability, let us know by reaching out to your recruiter.
By submitting your application you are acknowledging we are using your personal data as outlined in personnel and candidate privacy policy.
#J-18808-Ljbffr
$192k-230.4k yearly 4d ago
Senior Security Engineer II (DevSecOps)
Aledade, Inc. 4.1
Bethesda, MD jobs
As a Senior Security Engineer II at Aledade, we play a central role in helping secure our enterprise, cloud native environments, and applications. We're looking for security engineers that understand data and automation are important ingredients to our mission and know how to actively employ these ingredients at scale. Beyond the technical expertise, we value individuals who can partner cross-functionally across various teams, driving impactful outcomes and further securing our digital landscape.
Primary Duties
Working cross functionally to design, build, and operate solutions that continuously improve and automate our security capabilities
Leveraging data to understand trends, metrics, and opportunities to improve our security posture and then helping execute on those opportunities with stakeholders
Leading and enhancing incident response efforts, spearheading analysis, containment, and mitigation strategies in a cross-functional environment to ensure effective resolution and remediation of security incidents
Helping craft and refine security documentation pertinent to our Security Program, such as policies, standards, baselines, and standard operating procedures
Mentoring and coaching more junior engineers or analysts
Minimum Qualifications
BS / BTech (or higher) in Computer Science, Information Technology, Cybersecurity or a related field, 8 years security domain experience without degree
4+ years of experience acting as a trusted advisor in a team setting, solving for short-term and long-term business value
4+ years of experience coaching other engineers or analysts
Domain Specific
6+ years of experience in securing and deploying applications within Cloud Native environments
5+ years of experience in a dedicated DevOps/DevSecOps/SRE role with focus on establishing secure SDLC and DevSecOps processes.
Experience in scripting languages such as Python and Bash.
Experience with Cloud Native Software Development environments and practices with a focus on multi-cloud deployments in AWS, Azure and/or GCP.
Preferred KSA's
Prior experience working in the healthcare industry with health-tech systems, like Electronic Health Records, Clinical data, etc.
Prior experience with a focus on tooling, automation, and distributed systems development is preferred.
Experience generating automated metrics to measure service and program effectiveness and consistency
Strong communication skills, both written and verbal, with the capability to articulate complex technical issues to a diverse audience
Domain Specific
Experience with continuous integration tools (e.g. Cloud formation, Code deploy, Jenkins, CircleCI, Codefresh, Github Actions etc.).
Experience with configuration management platforms (e.g. Ansible, Chef, Salt).
Hands-on experience using Terraform, Python and/or other orchestration platforms at scale.
Familiarity with Agile and waterfall development methodologies.
Familiarity with automated testing methodologies, and continuous integration concepts.
Experience in creating, deploying, maintaining, and troubleshooting Docker images.
Experience in scoping, deploying, maintaining and troubleshooting Kubernetes clusters.
Experience with deploying policies with AWS Control tower, Azure Security hub, Google Resource Manager etc.
Physical Requirements
Sitting for prolonged periods of time. Extensive use of computers and keyboard. Occasional walking and lifting may be required.
Who We Are
Aledade, a public benefit corporation, exists to empower the most transformational part of our health care landscape - independent primary care. We were founded in 2014, and since then, we've become the largest network of independent primary care in the country - helping practices, health centers and clinics deliver better care to their patients and thrive in value-based care. Additionally, by creating value-based contracts across a wide variety of health plans, we aim to flip the script on the traditional fee-for-service model. Our work strengthens continuity of care, aligns incentives and ensures primary care physicians are paid for what they do best - keeping patients healthy. If you want to help create a health care system that is good for patients, good for practices and good for society - and if you're eager to join a collaborative, inclusive and remote-first culture - you've come to the right place.
What Does This Mean for You?
At Aledade, you will be part of a creative culture that is driven by a passion for tackling complex issues with respect, open-mindedness and a desire to learn. You will collaborate with team members who bring a wide range of experiences, interests, backgrounds, beliefs and achievements to their work - and who are all united by a shared passion for public health and a commitment to the Aledade mission.
In addition to time off to support work-life balance and enjoyment, we offer the following comprehensive benefits package designed for the overall well-being of our team members:
Flexible work schedules and the ability to work remotely are available for many roles
Health, dental and vision insurance paid up to 80% for employees, dependents and domestic partners
Robust time-off plan (21 days of PTO in your first year)
Two paid volunteer days and 11 paid holidays
12 weeks paid parental leave for all new parents
Six weeks paid sabbatical after six years of service
Educational Assistant Program and Clinical Employee Reimbursement Program
401(k) with up to 4% match
Stock options
And much more!
At Aledade, we don't just accept differences, we celebrate them! We strive to attract, develop and retain highly qualified individuals representing the diverse communities where we live and work. Aledade is committed to creating a diverse environment and is proud to be an equal opportunity employer. Employment policies and decisions at Aledade are based on merit, qualifications, performance and business needs. All qualified candidates will receive consideration for employment without regard to age, race, color, national origin, gender (including pregnancy, childbirth or medical conditions related to pregnancy or childbirth), gender identity or expression, religion, physical or mental disability, medical condition, legally protected genetic information, marital status, veteran status, or sexual orientation.
Privacy Policy: By applying for this job, you agree to Aledade's Applicant Privacy Policy available at *************************************************
#J-18808-Ljbffr
$102k-141k yearly est. 4d ago
Senior Security Engineer I
Aledade 4.1
Bethesda, MD jobs
As a Senior Security Engineer I at Aledade, you will play a central role in enhancing the security posture of our enterprise, cloud-native environments, and applications. We are seeking a dedicated professional with in-depth knowledge of security principles, standards, and best practices to help safeguard our systems and support our security compliance initiatives.
In this role, you will work to design, implement, and maintain robust security solutions across diverse platforms and technologies. You will collaborate closely with various teams to ensure alignment between security solutions and organizational requirements, enabling secure operations across the enterprise. Your ability to partner cross-functionally will be key to driving impactful security outcomes and strengthening our digital landscape.
Your expertise will be crucial as we continue to mature our security capabilities and maintain our commitment to protecting critical systems and data.
Primary Duties
Working cross-functionally to design, build, and operate solutions that improve and mature our security capabilities
Leveraging data to understand trends, metrics, and opportunities to improve our security posture, researching options, and then making recommendations as options to secure those opportunities with stakeholders
Leading and enhancing incident / issues response efforts, spearheading analysis, containment, and mitigation strategies in a cross-functional environment to ensure effective resolution and remediation of security incidents / issues
Helping craft and refine security documentation pertinent to our Security Program, such as policies, standards, baselines, and standard operating procedures
Minimum Qualifications
BS / BTech (or higher) in Computer Science, Information Technology, Cybersecurity or a related field, 6 years security domain experience without degree.
4+ years combined experience as a security engineer in an enterprise environment (preferably cloud) across multiple disciplines.
3+ years of relevant work experience in security posture management.
2+ years of experience acting as a trusted technical decision-maker in a team setting, solving for short-term and long term business value.
Preferred KSA's
Prior experience working in the healthcare industry with health-tech systems, like Electronic Health Records, Clinical data, etc.
Experience in scripting languages such as Python and Bash is required.
Experience with Cloud Native Software Development environments and practices with a focus on multi-cloud deployments in AWS, Azure and/or GCP is required.
Prior experience with a focus on tooling, automation, and distributed systems development is preferred.
Experience with continuous integration tools (e.g. Cloud formation, Code deploy, Jenkins, CircleCI, Codefresh, Github Actions etc.).
Experience with configuration management platforms (e.g. Ansible, Chef, Salt).
Hands-on experience using Terraform, Python and/or other orchestration platforms at scale.
Familiarity with Agile and waterfall development methodologies.
Familiarity with automated testing methodologies, and continuous integration concepts.
Experience in creating, deploying, maintaining, and troubleshooting Docker images.
Experience in scoping, deploying, maintaining and troubleshooting Kubernetes clusters.
Experience with deploying policies with AWS Control tower, Azure Security hub, Google Resource Manager etc.
Experience generating automated metrics to measure service and program effectiveness and consistency
Strong communication skills, both written and verbal, with the capability to articulate complex technical issues to a diverse audience
Physical Requirements
Sitting for prolonged periods of time. Extensive use of computers and keyboard. Occasional walking and lifting may be required.
Who We Are:
Aledade, a public benefit corporation, exists to empower the most transformational part of our health care landscape - independent primary care. We were founded in 2014, and since then, we've become the largest network of independent primary care in the country - helping practices, health centers and clinics deliver better care to their patients and thrive in value-based care. Additionally, by creating value-based contracts across a wide variety of health plans, we aim to flip the script on the traditional fee-for-service model. Our work strengthens continuity of care, aligns incentives and ensures primary care physicians are paid for what they do best - keeping patients healthy. If you want to help create a health care system that is good for patients, good for practices and good for society - and if you're eager to join a collaborative, inclusive and remote-first culture - you've come to the right place.
What Does This Mean for You?
At Aledade, you will be part of a creative culture that is driven by a passion for tackling complex issues with respect, open-mindedness and a desire to learn. You will collaborate with team members who bring a wide range of experiences, interests, backgrounds, beliefs and achievements to their work - and who are all united by a shared passion for public health and a commitment to the Aledade mission.
In addition to time off to support work-life balance and enjoyment, we offer the following comprehensive benefits package designed for the overall well-being of our team members:
Flexible work schedules and the ability to work remotely are available for many roles
Health, dental and vision insurance paid up to 80% for employees, dependents and domestic partners
Robust time-off plan (21 days of PTO in your first year)
Two paid volunteer days and 11 paid holidays
12 weeks paid parental leave for all new parents
Six weeks paid sabbatical after six years of service
Educational Assistant Program and Clinical Employee Reimbursement Program
401(k) with up to 4% match
Stock options
And much more!
At Aledade, we don't just accept differences, we celebrate them! We strive to attract, develop and retain highly qualified individuals representing the diverse communities where we live and work. Aledade is committed to creating a diverse environment and is proud to be an equal opportunity employer. Employment policies and decisions at Aledade are based on merit, qualifications, performance and business needs. All qualified candidates will receive consideration for employment without regard to age, race, color, national origin, gender (including pregnancy, childbirth or medical conditions related to pregnancy or childbirth), gender identity or expression, religion, physical or mental disability, medical condition, legally protected genetic information, marital status, veteran status, or sexual orientation.
Privacy Policy: By applying for this job, you agree to Aledade's Applicant Privacy Policy available at *************************************************
#J-18808-Ljbffr
$102k-141k yearly est. 3d ago
Hybrid Senior Security Engineer: Corporate Security Lead
Persona 4.3
San Francisco, CA jobs
A leading identity platform company in San Francisco is seeking a Corporate Security Lead to fortify defenses against evolving threats. This full-time role involves developing endpoint security solutions and collaborating with cross-functional teams. The ideal candidate has over 3 years of IT security experience, including endpoint hardening and scripting skills. Enjoy competitive benefits like unlimited PTO, mental health days, and professional development stipends in a vibrant work culture.
#J-18808-Ljbffr
$135k-181k yearly est. 3d ago
Senior Enterprise Security Engineer - Hybrid SF
Persona 4.3
San Francisco, CA jobs
An innovative technology company in San Francisco seeks a Security Lead to fortify their defenses against evolving threats. In this role, you'll develop and implement security tools, collaborate across teams on best practices, and manage insider threat programs. Candidates should have 3+ years in IT security, experience with endpoint hardening, and strong coding skills in Ruby or Python. The company offers a competitive benefits package, promoting a supportive work culture.
#J-18808-Ljbffr
$135k-181k yearly est. 2d ago
Senior Cloud Security Engineer: Incident Response & IAM
Aledade 4.1
Bethesda, MD jobs
A healthcare technology firm located in Maryland is seeking a Senior Security Engineer I to enhance security capabilities within cloud-native environments. The candidate will design and implement security solutions, lead incident response efforts, and collaborate with various teams to strengthen security posture. Applicants should have a degree in Computer Science or related field, extensive experience in security engineering, and proficiency in scripting languages like Python and Bash. This role offers a supportive workplace that values diversity and innovation.
#J-18808-Ljbffr
$102k-141k yearly est. 3d ago
Senior Security Engineer, Enterprise
Persona 4.3
San Francisco, CA jobs
Persona is the configurable identity platform built for businesses in a digital-first world. Verifying individuals and organizations is harder - but more important - than ever, with AI enabling fraudsters to launch sophisticated accounts at scale and regulations evolving rapidly.
We've built Persona to support practically every use case and industry - that's why we're able to serve a wide range of leading companies. For example, Instacart relies on Persona to verify shoppers who onboard onto their platform before delivering groceries to your doorstep. Meanwhile, OpenAI relies on Persona to keep bad actors out, protecting one of the world's most powerful AI platforms from large-scale abuse in a time when AI is reshaping the way we work and live.
We're growing rapidly and looking for exceptional people to join us!
About the Role
Persona's Security Team is looking for someone to lead our corporate security efforts. You'll play a pivotal role in fortifying our defenses against evolving threats. Your mission is to protect fellow Personerds and the systems we use to do our work. You'll have the opportunity to employ cutting‑edge technologies, innovative strategies, and your expertise to thwart potential attacks before they disrupt our operations.
This is a full-time position based in our headquarters in downtown San Francisco. Our in-office days are Tuesday - Thursday, with the option to work from home on Monday and Friday.
What you'll do at Persona
Develop, enhance, and implement endpoint detection and response rules and tooling for endpoint devices
Collaborate cross-functionally with our TechOps Team in implementing security best practices for SaaS and endpoint environments and support security initiatives like 2-factor authentication, automated encryption of client devices, DLP, etc.
Build tools and processes for automating security controls and monitoring at scale
Support security initiatives across the organization and harden our corporate infrastructure against attack
Recommend endpoint and SaaS mitigations and controls based on generated telemetry
Provide recommendations and support for insider threat programs
Participate in the on‑call rotation for the Security Team
What you'll bring to Persona
3+ years of experience in IT security or building endpoint security solutions, including experience supporting mac OS devices
Experience with planning and executing endpoint hardening initiatives
Experience with mobile device management (MDM) and endpoint detection and response (EDR) tools and technologies
Experience with data loss prevention (DLP) and insider threat concepts and mitigations
Experience with email security concepts and protecting a workforce against phishing
Ability to explain security topics clearly to non-technical business representatives
Ability to write code in Ruby, Python, or similar scripting languages, as well as SQL queries
Full-time Employee Benefits and Perks
For full-time employees (excluding internship and contractor opportunities), Persona offers a wide range of benefits, including medical, dental, and vision, 3% 401(k) contribution, unlimited PTO, quarterly mental health days, family planning benefits, professional development stipend, wellness benefits, among others. While we believe competitive compensation and benefits are a critical aspect of you deciding to join us, we do hope you consider why our core values and culture are right for you. If you'd like to better understand what it's like working at Persona, feel free to check out our reviews on Glassdoor.
#J-18808-Ljbffr
$135k-181k yearly est. 2d ago
Senior Security Engineer, Product San Francisco
Persona 4.3
San Francisco, CA jobs
Persona is the configurable identity platform built for businesses in a digital-first world.
Verifying individuals and organizations is harder - but more important - than ever, with AI enabling fraudsters to launch sophisticated accounts at scale and regulations evolving rapidly.
We've built Persona to support practically every use case and industry - that's why we're able to serve a wide range of leading companies. For example, Instacart relies on Persona to verify shoppers who onboard onto their platform before delivering groceries to your doorstep. Meanwhile, OpenAI relies on Persona to keep bad actors out, protecting one of the world's most powerful AI platforms from large-scale abuse in a time when AI is reshaping the way we work and live.
We're growing rapidly and looking for exceptional people to join us!
About the Role
We're building something special here at Persona, and our Security Team is a big part of that. Our team is made up of veterans from industry leaders like Square and Dropbox, and we're looking for someone to join us in shipping innovative products quickly and securely.
Your job? Work with our engineering teams to make sure we're delivering rock-solid security for our customers and users. As we grow fast (and we mean fast), you'll be key in managing the risks that come with that speed. We're not just looking for someone to play defense - we want you to think ahead and outsmart the bad guys before they even know what hit them. You'll get to work with the latest tech and come up with clever ways to keep our systems locked down tight.
What you'll do at Persona
Collaborate cross-functionally with our product teams to understand, manage, and mitigate the security risks associated with their work, while supporting their ability to ship quickly
Build tools and processes for automating product security controls and monitoring at scale
Support product security initiatives across our fast-growing engineering team
Participate in the on-call rotation for the Security Team
What you'll bring to Persona
Communication and Collaboration skills. Ability to explain security topics clearly to non-technical business representatives. Drive to enable other engineers to ship securely.
Bias toward shipping. Improving our product quickly and continually is one of Persona's greatest strengths. You should be excited about finding ways to integrate security into our product delivery processes without slowing things down.
Proactive approach to solving problems. We're looking for someone that can tell us how to solve our problems, not someone who waits to be told how to solve problems.
Passion for security. You should be excited about keeping your skills and knowledge sharp, and sharing that with your peers and the rest of the company.
Experience. 2+ years of software engineering, 2+ years of product security at a fast-moving technology company.
Nice to have
Experience securing a large Ruby on Rails application.
Full-time Employee Benefits and Perks
For full-time employees (excluding internship and contractor opportunities), Persona offers a wide range of benefits, including medical, dental, and vision, 3% 401(k) contribution, unlimited PTO, quarterly mental health days, family planning benefits, professional development stipend, wellness benefits, among others. While we believe competitive compensation and benefits is a critical aspect of you deciding to join us, we do hope you consider why our core values and culture are right for you. If you'd like to better understand what it's like working at Persona, feel free to check out our reviews on Glassdoor.
#J-18808-Ljbffr
$135k-181k yearly est. 1d ago
Senior Security Engineer - Ship Securely at Speed
Persona 4.3
San Francisco, CA jobs
A leading identity platform in San Francisco seeks a Security Engineer to enhance product security while supporting the fast-paced delivery processes of engineering teams. The candidate will collaborate cross-functionally to manage risks, build security automation tools, and participate in on-call rotations. Required skills include communication, collaboration, and a passion for security, with 2+ years in software engineering and product security at a tech company. This full-time role offers competitive benefits and emphasizes a culture of proactive problem-solving.
#J-18808-Ljbffr
$135k-181k yearly est. 1d ago
Senior Security Engineer - Endpoint Defense
Persona 4.3
San Francisco, CA jobs
A forward-thinking technology company in San Francisco seeks a skilled individual to lead their corporate security efforts. In this full-time role, you'll enhance security practices, develop innovative defense strategies, and protect the organization's operations from evolving threats. The ideal candidate has over 3 years of experience in IT security, particularly in endpoint security solutions. The company offers competitive medical, dental, and mental health benefits along with an engaging workplace culture.
#J-18808-Ljbffr
$135k-181k yearly est. 1d ago
Senior Security Analyst
Independent Living Systems, LLC 4.4
Miami, FL jobs
We are seeking a Senior Security Analyst to join our team at Independent Living Systems (ILS). ILS, along with its affiliated health plans known as Florida Community Care and Florida Complete Care, is committed to promoting a higher quality of life and maximizing independence for all vulnerable populations.
About the Role:
The Senior Security Analyst plays a critical role in safeguarding the organization's information systems and digital assets by proactively identifying, analyzing, and mitigating security threats. This position is responsible for leading advanced security investigations, managing incident response activities, and ensuring compliance with industry standards and regulatory requirements. The role requires collaboration with cross-functional teams to design and implement robust security controls and to continuously improve the organization's security posture. The Senior Security Analyst will also mentor junior team members and contribute to the development of security policies and procedures. Ultimately, this role ensures the confidentiality, integrity, and availability of sensitive data while supporting business objectives through effective risk management.
Minimum Qualifications:
Bachelor's degree in Computer Science, Information Security, or a related field.
5+ years of experience in information security or cybersecurity roles.
Strong knowledge of security frameworks such as NIST, ISO 27001, or CIS Controls.
Experience with security monitoring tools such as SIEM, IDS/IPS, and endpoint protection platforms.
Proven ability to conduct incident response and forensic investigations.
Relevant experience may substitute for the educational requirement on a year-for-year basis.
Preferred Qualifications:
Master's degree in computer science, Information Security, or a related field.
Professional certifications such as CISSP, CISM, GIAC, CISA, CRISC
Knowledge of regulatory requirements such as GDPR, HIPAA, or PCI-DSS.
Framework & compliance expertise in SOC 2 / SSAE 18, evidence collection, testing, control mapping
Audit / GRC tooling, Evidence workflows, issue tracking, remediation validation
Responsibilities:
Monitor security alerts and analyze potential threats using advanced security tools and techniques.
Lead incident response efforts, including investigation, containment, eradication, and recovery from security breaches.
Conduct vulnerability assessments and penetration testing to identify and remediate security weaknesses.
Develop and maintain security documentation, including policies, procedures, and incident reports.
Collaborate with IT, compliance, and business units to implement security best practices and ensure regulatory compliance.
Provide mentorship and guidance to junior security analysts and other team members.
Stay current with emerging security threats, technologies, and industry trends to proactively enhance security measures.
$88k-113k yearly est. 4d ago
Entry Level Healthcare IT Analyst
Optimum Healthcare It 4.3
Cleveland, OH jobs
Start Your Career in Healthcare Information Technology Today!
Getting your first job can be difficult when employers want experience, but to gain that experience, you need your first job. We bridge the gap between your education and professional career by helping you gain the experience and training you need within the Healthcare Information Technology Industry.
Optimum Healthcare IT is looking for recent college graduates with an interest in moving into the Healthcare IT Industry. Our Optimum CareerPath training program will equip you with the tools needed for your success as a Healthcare IT Analyst.
Healthcare IT Analyst Job Responsibilities:
· The Healthcare IT Analyst will have primary responsibility for the design, build/configuration, testing, validation, documentation, and ongoing support for the Healthcare applications.
· This position will implement, administer, and support assigned systems under the guidance of senior members of the team.
· The position will have a good understanding of healthcare organizations, ancillary systems, and health system operations.
· Analyze and document user requirements, procedures, and problems to automate or improve existing systems. Review system capabilities, workflow, and scheduling limitations.
· Document workflows, configure and/or build activities, change management adherence, end-user notifications, training information, and status reporting in the appropriate system.
· Develop, document, and revise system design procedures, test procedures, and quality standards.
· Expand or modify the system to serve new purposes or improve workflows.
· Review and analyze the system and performance indicators to locate problems and correct errors. Escalate problems and issues to the appropriate staff to ensure timely resolution.
· Coordinate projects, schedule, and facilitate meetings as necessary to complete assignments.
· Technical and functional analyst support of systems that may include Electronic Health Records platforms (Epic, Cerner), IT Project Management, ERP Systems (Workday, Oracle, PeopleSoft, UKG), ITSM applications (ServiceNow), data and analytics applications (Tableau, PowerBI), cloud deployments (GCP, Azure, AWS), and other digital platforms and services.
Requirements:
· Bachelor's Degree
· US work authorization (This position is not open to any H1B /F1/ H-4 EAD OPT/STEM degrees)
· Excellent communication skills (verbal and written)
· Ability to exercise tact and good interpersonal skills
· Superb analytical and time management skills required
· Self-starter, self-motivated, high level of initiative
· Result-focused, ability to solve complex problems and resolve conflicts in a timely manner
· Internships or research project work are highly desired in a healthcare setting
· Understanding of how data works and looks, coming from different formats, is preferred
· Ability to travel during the training program if necessary
$65k-88k yearly est. 1d ago
Entry Level Healthcare IT Analyst
Optimum Healthcare It 4.3
Charleston, SC jobs
Start Your Career in Healthcare Information Technology Today!
Getting your first job can be difficult when employers want experience, but to gain that experience, you need your first job. We bridge the gap between your education and professional career by helping you gain the experience and training you need within the Healthcare Information Technology Industry.
Optimum Healthcare IT is looking for recent college graduates with an interest in moving into the Healthcare IT Industry. Our Optimum CareerPath training program will equip you with the tools needed for your success as a Healthcare IT Analyst.
Healthcare IT Analyst Job Responsibilities:
· The Healthcare IT Analyst will have primary responsibility for the design, build/configuration, testing, validation, documentation, and ongoing support for the Healthcare applications.
· This position will implement, administer, and support assigned systems under the guidance of senior members of the team.
· The position will have a good understanding of healthcare organizations, ancillary systems, and health system operations.
· Analyze and document user requirements, procedures, and problems to automate or improve existing systems. Review system capabilities, workflow, and scheduling limitations.
· Document workflows, configure and/or build activities, change management adherence, end-user notifications, training information, and status reporting in the appropriate system.
· Develop, document, and revise system design procedures, test procedures, and quality standards.
· Expand or modify the system to serve new purposes or improve workflows.
· Review and analyze the system and performance indicators to locate problems and correct errors. Escalate problems and issues to the appropriate staff to ensure timely resolution.
· Coordinate projects, schedule, and facilitate meetings as necessary to complete assignments.
· Technical and functional analyst support of systems that may include Electronic Health Records platforms (Epic, Cerner), IT Project Management, ERP Systems (Workday, Oracle, PeopleSoft, UKG), ITSM applications (ServiceNow), data and analytics applications (Tableau, PowerBI), cloud deployments (GCP, Azure, AWS), and other digital platforms and services.
Requirements:
· Bachelor's Degree
· US work authorization (This position is not open to any H1B /F1/ H-4 EAD OPT/STEM degrees)
· Excellent communication skills (verbal and written)
· Ability to exercise tact and good interpersonal skills
· Superb analytical and time management skills required
· Self-starter, self-motivated, high level of initiative
· Result-focused, ability to solve complex problems and resolve conflicts in a timely manner
· Internships or research project work are highly desired in a healthcare setting
· Understanding of how data works and looks, coming from different formats, is preferred
· Ability to travel during the training program if necessary
$57k-78k yearly est. 1d ago
Senior Cyber Information Assurance Analyst
Medtronic Inc. 4.7
Irvine, CA jobs
We anticipate the application window for this opening will close on - 23 Jan 2026 At Medtronic you can begin a life-long career of exploration and innovation, while helping champion healthcare access and equity for all. You'll lead with purpose, breaking down barriers to innovation in a more connected, compassionate world.
A Day in the Life
At Medtronic, we bring bold ideas forward with speed and decisiveness to put patients first in everything we do. In-person exchanges are invaluable to our work. We're working onsite 4 days a week as part of our commitment to fostering a culture of professional growth and cross-functional collaboration as we work together to engineer the extraordinary. In your role, you may work from the following Medtronic sites:
* Mounds View, Minnesota • Boston, Massachusetts
* Fridley, Minnesota (OHQ) • Lafayette, Colorado
* Irvine, California (UCI) • Jacksonville, Florida
* Rice Creek, Minnesota
The Medtronic Global Cyber and Information Security Office (GCISO) is seeking a highly skilled and experienced Senior Cybersecurity InformationAssuranceAnalyst to join our cybersecurity team. In this role, you will be responsible for leading the identification, assessment, and mitigation of cybersecurity risks across the organization. As a senior member of the team, you will provide expertise in risk management, compliance, and security strategy, while also playing a key role in driving initiatives to ensure the protection of sensitive data, particularly in a highly regulated healthcare environment. You will collaborate with cross-functional teams to evaluate and enhance our cybersecurity posture, ensuring adherence to relevant regulations such as HIPAA, GDPR, and other industry standards.
We believe that when people from different cultures, genders, and points of view come together, innovation is the result -and everyone wins. Medtronic walks the walk, creating an inclusive culture where you can thrive. Our unwavering commitment to inclusion, diversity, and equity (ID&E) means zero barriers to opportunity within Medtronic and a culture where all employees belong, are respected, and feel valued for who they are and the life experiences they contribute. We know equity starts beyond our workplace, and we must play a role in addressing systemic inequities in our communications to achieve long-term sustainable impact. Anchored in our Mission, we continue to drive ID&E forward both to enhance the well-being of Medtronic employees and to accelerate innovation that brings our lifesaving technologies to more people in more places around the world.
Bring your talents to an industry leader in medical technology and healthcare solutions - we're a market leader and growing every day. You can be proud to be a part of technologies that are rooted in our long history of mission-driven innovation. You will be empowered to shape your own career. We encourage and support your growth with the training, mentorship, and guidance you need to own your future success. Together, we can transform healthcare. Join us for a career in IT that changes lives. Medtronic is committed to fostering a diverse and inclusive culture. Check out the accomplishments of our Women in IT group! ********************************
At Medtronic, we bring bold ideas forward with speed and decisiveness to put patients first in everything we do. In-person exchanges are invaluable to our work. We're working a minimum of 4 days a week onsite as part of our commitment to fostering a culture of professional growth and cross-functional collaboration as we work together to engineer the extraordinary.
Responsibilities may include the following and other duties may be assigned.
* Defines requirements for business continuity, operations security, cryptography, forensics, regulatory compliance, internal counter-espionage (insider threat detection and mitigation), physical security analysis (including facilities analysis, and security management) to best protect company assets.
* Assesses and mitigates system security threats and risks throughout the program life cycle.
* Validates system security requirements definition and analysis.
* Implements and validates security designs in hardware, software, data, and procedures.
* Verifies security requirements; performs system certification and accreditation planning and testing and liaison activities.
* Understanding of Identity, Lifecycle and Governance capabilities, intersection with other cyber security domains, products and industry practices.
* Identify and assess cybersecurity risks through business analysis and propose solutions to mitigate those risks, contributing to overall business continuity and security resilience.
* Demonstrated expertise in GRC frameworks and processes, including system selection, system administration, and supporting core GRC functions. Lead the design and implementation of process flows, ensuring alignment with business objectives.
* Collaborate with teams across various departments, including IT, legal, compliance, and product security, to identify, assess, and mitigate cybersecurity risks across a broad range of products and services, ensuring security is integrated throughout the entire product lifecycle and operational processes.
* Maintain up-to-date knowledge of cybersecurity regulations and standards specific to the medical device industry (FDA, HIPAA, IEC 62443, NIST, NIS 2, etc.).
* Drive improvements in the GRC platform by automating workflows, integrating new tools, and optimizing risk management processes to increase operational efficiency and reduce manual effort.
Minimum Requirements
4+ years of experience with a with a high school diploma or equivalent.
NICE TO HAVE (Preferred Qualifications)
* Previous Medtronic experience
* 7+ years of experience in cybersecurity GRC (Governance, Risk, & Compliance), or external/internal audit, preferably within the medical device or healthcare industry.
* Strong understanding of cybersecurity frameworks, regulatory requirements, risk management, and industry best practices (e.g., HIPAA, NIST, ISO 27001, GDPR, etc.).
SKILLS & COMPETENCIES
* Excellent communication and interpersonal skills, with the ability to interact effectively with both technical and non-technical stakeholders.
* Ability to think critically and strategically about risk management and how technology, process improvements, and automation can help the organization proactively address cybersecurity risks.
* Excellent presentation skills with the ability to communicate complex risk management concepts clearly to executive-level audiences, translating technical details into actionable insights for senior leadership.
RISK MANAGEMENT EXPERIENCE
* Minimum 5 years of experience executing key risk management activities, including conducting risk assessments using various quantitative and qualitative methodologies, such as the FAIR model (Factor Analysis of Information Risk), ensuring a deep understanding of risk analysis methodologies.
* At least 3 years of active participation in the design and implementation of at least 2 comprehensive risk management programs (e.g., risk assessments, regulatory assessments) within a large, complex organization, including hands-on experience with program execution and improvement.
* Proven expertise in process design and improvement related to risk management frameworks and methodologies, ensuring effective risk mitigation strategies are incorporated into operational processes.
* Experience conducting NIST risk assessments (e.g., NIST CSF, NIST 800-53) and applying their standards and recommendations to improve organizational cybersecurity postures.
* Strong knowledge of regulatory changes and trends impacting IT risk assessments, including compliance requirements such as GDPR, HIPAA, and others, ensuring risk management strategies align with the latest regulatory standards.
* Knowledge of Operational Technology (OT) risk management is a plus, with the ability to assess risks related to OT environments and integrate them into overall IT risk strategies.
* Minimum 3 years of experience evaluating technical design documents for systems or environments to assess associated risks, including reviewing architectural, infrastructure, and application designs for security and operational risk vulnerabilities.
TECHNICAL EXPERTISE
* Familiarity with GRC tools such as ServiceNow, LogicGate, or OneTrust
* Strong understanding of technical infrastructure, including networks, cloud environments, endpoints, and medical device systems.
* Experience with system integration and data flow analysis within GRC tools, ideally leveraging APIs and other automation technologies to improve operational efficiencies.
CERTIFICATIONS
* Certified Information Systems Security Professional (CISSP).
* Certified in Risk and Information Systems Control (CRISC).
* Certified Information Security Auditor (CISA).
Physical Job Requirements
The above statements are intended to describe the general nature and level of work being performed by employees assigned to this position, but they are not an exhaustive list of all the required responsibilities and skills of this position.
The physical demands described within the Responsibilities section of this job description are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. For Office Roles: While performing the duties of this job, the employee is regularly required to be independently mobile. The employee is also required to interact with a computer, and communicate with peers and co-workers. Contact your manager or local HR to understand the Work Conditions and Physical requirements that may be specific to each role.
Benefits & Compensation
Medtronic offers a competitive Salary and flexible Benefits Package
A commitment to our employees lives at the core of our values. We recognize their contributions. They share in the success they help to create. We offer a wide range of benefits, resources, and competitive compensation plans designed to support you at every career and life stage.
Salary ranges for U.S (excl. PR) locations (USD):$104,000.00 - $156,000.00
This position is eligible for a short-term incentive called the Medtronic Incentive Plan (MIP).
The base salary range is applicable across the United States, excluding Puerto Rico and specific locations in California. The offered rate complies with federal and local regulations and may vary based on factors such as experience, certification/education, market conditions, and location. Compensation and benefits information pertains solely to candidates hired within the United States (local market compensation and benefits will apply for others).
The following benefits and additional compensation are available to those regular employees who work 20+ hours per week: Health, Dental and vision insurance, Health Savings Account, Healthcare Flexible Spending Account, Life insurance, Long-term disability leave, Dependent daycare spending account, Tuition assistance/reimbursement, and Simple Steps (global well-being program).
The following benefits and additional compensation are available to all regular employees: Incentive plans, 401(k) plan plus employer contribution and match, Short-term disability, Paid time off, Paid holidays, Employee Stock Purchase Plan, Employee Assistance Program, Non-qualified Retirement Plan Supplement (subject to IRS earning minimums), and Capital Accumulation Plan (available to Vice Presidents and above, or subject to IRS earning minimums).
Regular employees are those who are not temporary, such as interns. Temporary employees are eligible for paid sick time, as required under applicable state law, and the Employee Stock Purchase Plan. Please note some of the above benefits may not apply to workers in Puerto Rico.
Further details are available at the link below:
Medtronic benefits and compensation plans
About Medtronic
We lead global healthcare technology and boldly attack the most challenging health problems facing humanity by searching out and finding solutions.
Our Mission - to alleviate pain, restore health, and extend life - unites a global team of 95,000+ passionate people.
We are engineers at heart- putting ambitious ideas to work to generate real solutions for real people. From the R&D lab, to the factory floor, to the conference room, every one of us experiments, creates, builds, improves and solves. We have the talent, diverse perspectives, and guts to engineer the extraordinary.
Learn more about our business, mission, and our commitment to diversity here.
It is the policy of Medtronic to provide equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, sexual orientation, gender identity and/or expression, genetic information, marital status, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state or local law. In addition, Medtronic will provide reasonable accommodations for qualified individuals with disabilities.
If you are applying to perform work for Medtronic, Inc. ("Medtronic") in any position which will involve performing at least two (2) hours of work on average each week within the unincorporated areas of Los Angeles County, you can find here a list of all material job duties of the specific job position which Medtronic reasonably believes that criminal history may have a direct, adverse and negative relationship potentially resulting in the withdrawal of a conditional offer of employment. Medtronic will consider for employment qualified job applicants with arrest or conviction records in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act.
$104k-156k yearly Auto-Apply 4d ago
Senior Cyber Information Assurance Analyst
Medtronic 4.7
Jacksonville, FL jobs
We anticipate the application window for this opening will close on - 23 Jan 2026 At Medtronic you can begin a life-long career of exploration and innovation, while helping champion healthcare access and equity for all. You'll lead with purpose, breaking down barriers to innovation in a more connected, compassionate world.
**A Day in the Life**
At Medtronic, we bring bold ideas forward with speed and decisiveness to put patients first in everything we do. In-person exchanges are invaluable to our work. We're working onsite 4 days a week as part of our commitment to fostering a culture of professional growth and cross-functional collaboration as we work together to engineer the extraordinary. In your role, you may work from the following Medtronic sites:
- Mounds View, Minnesota - Boston, Massachusetts
- Fridley, Minnesota (OHQ) - Lafayette, Colorado
- Irvine, California (UCI) - Jacksonville, Florida
- Rice Creek, Minnesota
The Medtronic Global Cyber and Information Security Office (GCISO) is seeking a highly skilled and experienced Senior Cybersecurity InformationAssuranceAnalyst to join our cybersecurity team. In this role, you will be responsible for leading the identification, assessment, and mitigation of cybersecurity risks across the organization. As a senior member of the team, you will provide expertise in risk management, compliance, and security strategy, while also playing a key role in driving initiatives to ensure the protection of sensitive data, particularly in a highly regulated healthcare environment. You will collaborate with cross-functional teams to evaluate and enhance our cybersecurity posture, ensuring adherence to relevant regulations such as HIPAA, GDPR, and other industry standards.
We believe that when people from different cultures, genders, and points of view come together, innovation is the result -and everyone wins. Medtronic walks the walk, creating an inclusive culture where you can thrive. Our unwavering commitment to inclusion, diversity, and equity (ID&E) means zero barriers to opportunity within Medtronic and a culture where all employees belong, are respected, and feel valued for who they are and the life experiences they contribute. We know equity starts beyond our workplace, and we must play a role in addressing systemic inequities in our communications to achieve long-term sustainable impact. Anchored in our Mission, we continue to drive ID&E forward both to enhance the well-being of Medtronic employees and to accelerate innovation that brings our lifesaving technologies to more people in more places around the world.
Bring your talents to an industry leader in medical technology and healthcare solutions - we're a market leader and growing every day. You can be proud to be a part of technologies that are rooted in our long history of mission-driven innovation. You will be empowered to shape your own career. We encourage and support your growth with the training, mentorship, and guidance you need to own your future success. Together, we can transform healthcare. Join us for a career in IT that changes lives. Medtronic is committed to fostering a diverse and inclusive culture. Check out the accomplishments of our Women in IT group! ********************************
At Medtronic, we bring bold ideas forward with speed and decisiveness to put patients first in everything we do. In-person exchanges are invaluable to our work. We're working a minimum of 4 days a week onsite as part of our commitment to fostering a culture of professional growth and cross-functional collaboration as we work together to engineer the extraordinary.
Responsibilities may include the following and other duties may be assigned.
+ Defines requirements for business continuity, operations security, cryptography, forensics, regulatory compliance, internal counter-espionage (insider threat detection and mitigation), physical security analysis (including facilities analysis, and security management) to best protect company assets.
+ Assesses and mitigates system security threats and risks throughout the program life cycle.
+ Validates system security requirements definition and analysis.
+ Implements and validates security designs in hardware, software, data, and procedures.
+ Verifies security requirements; performs system certification and accreditation planning and testing and liaison activities.
+ Understanding of Identity, Lifecycle and Governance capabilities, intersection with other cyber security domains, products and industry practices.
+ Identify and assess cybersecurity risks through business analysis and propose solutions to mitigate those risks, contributing to overall business continuity and security resilience.
+ Demonstrated expertise in GRC frameworks and processes, including system selection, system administration, and supporting core GRC functions. Lead the design and implementation of process flows, ensuring alignment with business objectives.
+ Collaborate with teams across various departments, including IT, legal, compliance, and product security, to identify, assess, and mitigate cybersecurity risks across a broad range of products and services, ensuring security is integrated throughout the entire product lifecycle and operational processes.
+ Maintain up-to-date knowledge of cybersecurity regulations and standards specific to the medical device industry (FDA, HIPAA, IEC 62443, NIST, NIS 2, etc.).
+ Drive improvements in the GRC platform by automating workflows, integrating new tools, and optimizing risk management processes to increase operational efficiency and reduce manual effort.
**Minimum Requirements**
**4+ years of experience with a with a high school diploma or equivalent.**
**NICE TO HAVE** (Preferred Qualifications)
+ Previous Medtronic experience
+ 7+ years of experience in cybersecurity GRC (Governance, Risk, & Compliance), or external/internal audit, preferably within the medical device or healthcare industry.
+ Strong understanding of cybersecurity frameworks, regulatory requirements, risk management, and industry best practices (e.g., HIPAA, NIST, ISO 27001, GDPR, etc.).
SKILLS & COMPETENCIES
+ Excellent communication and interpersonal skills, with the ability to interact effectively with both technical and non-technical stakeholders.
+ Ability to think critically and strategically about risk management and how technology, process improvements, and automation can help the organization proactively address cybersecurity risks.
+ Excellent presentation skills with the ability to communicate complex risk management concepts clearly to executive-level audiences, translating technical details into actionable insights for senior leadership.
RISK MANAGEMENT EXPERIENCE
+ Minimum 5 years of experience executing key risk management activities, including conducting risk assessments using various quantitative and qualitative methodologies, such as the FAIR model (Factor Analysis of Information Risk), ensuring a deep understanding of risk analysis methodologies.
+ At least 3 years of active participation in the design and implementation of at least 2 comprehensive risk management programs (e.g., risk assessments, regulatory assessments) within a large, complex organization, including hands-on experience with program execution and improvement.
+ Proven expertise in process design and improvement related to risk management frameworks and methodologies, ensuring effective risk mitigation strategies are incorporated into operational processes.
+ Experience conducting NIST risk assessments (e.g., NIST CSF, NIST 800-53) and applying their standards and recommendations to improve organizational cybersecurity postures.
+ Strong knowledge of regulatory changes and trends impacting IT risk assessments, including compliance requirements such as GDPR, HIPAA, and others, ensuring risk management strategies align with the latest regulatory standards.
+ Knowledge of Operational Technology (OT) risk management is a plus, with the ability to assess risks related to OT environments and integrate them into overall IT risk strategies.
+ Minimum 3 years of experience evaluating technical design documents for systems or environments to assess associated risks, including reviewing architectural, infrastructure, and application designs for security and operational risk vulnerabilities.
TECHNICAL EXPERTISE
+ Familiarity with GRC tools such as ServiceNow, LogicGate, or OneTrust
+ Strong understanding of technical infrastructure, including networks, cloud environments, endpoints, and medical device systems.
+ Experience with system integration and data flow analysis within GRC tools, ideally leveraging APIs and other automation technologies to improve operational efficiencies.
CERTIFICATIONS
+ Certified Information Systems Security Professional (CISSP).
+ Certified in Risk and Information Systems Control (CRISC).
+ Certified Information Security Auditor (CISA).
**Physical Job Requirements**
The above statements are intended to describe the general nature and level of work being performed by employees assigned to this position, but they are not an exhaustive list of all the required responsibilities and skills of this position.
The physical demands described within the Responsibilities section of this job description are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. For Office Roles: While performing the duties of this job, the employee is regularly required to be independently mobile. The employee is also required to interact with a computer, and communicate with peers and co-workers. Contact your manager or local HR to understand the Work Conditions and Physical requirements that may be specific to each role.
**Benefits & Compensation**
**Medtronic offers a competitive Salary and flexible Benefits Package**
A commitment to our employees lives at the core of our values. We recognize their contributions. They share in the success they help to create. We offer a wide range of benefits, resources, and competitive compensation plans designed to support you at every career and life stage.
Salary ranges for U.S (excl. PR) locations (USD):$104,000.00 - $156,000.00
This position is eligible for a short-term incentive called the Medtronic Incentive Plan (MIP).
The base salary range is applicable across the United States, excluding Puerto Rico and specific locations in California. The offered rate complies with federal and local regulations and may vary based on factors such as experience, certification/education, market conditions, and location. Compensation and benefits information pertains solely to candidates hired within the United States (local market compensation and benefits will apply for others).
The following benefits and additional compensation are available to those regular employees who work 20+ hours per week: Health, Dental and vision insurance, Health Savings Account, Healthcare Flexible Spending Account, Life insurance, Long-term disability leave, Dependent daycare spending account, Tuition assistance/reimbursement, and Simple Steps (global well-being program).
The following benefits and additional compensation are available to all regular employees: Incentive plans, 401(k) plan plus employer contribution and match, Short-term disability, Paid time off, Paid holidays, Employee Stock Purchase Plan, Employee Assistance Program, Non-qualified Retirement Plan Supplement (subject to IRS earning minimums), and Capital Accumulation Plan (available to Vice Presidents and above, or subject to IRS earning minimums).
Regular employees are those who are not temporary, such as interns. Temporary employees are eligible for paid sick time, as required under applicable state law, and the Employee Stock Purchase Plan. Please note some of the above benefits may not apply to workers in Puerto Rico.
Further details are available at the link below:
Medtronic benefits and compensation plans (**************************************************************************************************************
**About Medtronic**
We lead global healthcare technology and boldly attack the most challenging health problems facing humanity by searching out and finding solutions.
Our Mission - to alleviate pain, restore health, and extend life - unites a global team of 95,000+ passionate people.
We are engineers at heart- putting ambitious ideas to work to generate real solutions for real people. From the R&D lab, to the factory floor, to the conference room, every one of us experiments, creates, builds, improves and solves. We have the talent, diverse perspectives, and guts to engineer the extraordinary.
Learn more about our business, mission, and our commitment to diversity here (************************* .
It is the policy of Medtronic to provide equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, sexual orientation, gender identity and/or expression, genetic information, marital status, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state or local law. In addition, Medtronic will provide reasonable accommodations for qualified individuals with disabilities.
If you are applying to perform work for Medtronic, Inc. ("Medtronic") in any position which will involve performing at least two (2) hours of work on average each week within the unincorporated areas of Los Angeles County, you can find here (*************************************************************************************************************************************** a list of all material job duties of the specific job position which Medtronic reasonably believes that criminal history may have a direct, adverse and negative relationship potentially resulting in the withdrawal of a conditional offer of employment. Medtronic will consider for employment qualified job applicants with arrest or conviction records in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act.
We lead global healthcare technology and boldly attack the most challenging health problems facing humanity by searching out and finding solutions.
Our Mission - to alleviate pain, restore health, and extend life - unites a global team of 95,000+ passionate people.
We are engineers at heart- putting ambitious ideas to work to generate real solutions for real people. From the R&D lab, to the factory floor, to the conference room, every one of us experiments, creates, builds, improves and solves. We have the talent, diverse perspectives, and guts to engineer the extraordinary.
**We change lives** . Each team member, each day, helps to improve and redefine how the world treats the most pressing health conditions, from heart disease to diabetes. Our industry leadership comes from the passion and ingenuity of our people. That's who we are. Working alongside one another, we use science, medicine, and a profound understanding of the human body to build extraordinary technologies that can transform lives.
**We build extraordinary solutions as one team** . With one Medtronic Mindset defining how we work. Speed and decisiveness run through our DNA. Diverse perspectives inspire our bold answers to any challenge that comes our way. And we deliver results the right way, breakthrough after patient breakthrough.
**This life-changing career is yours to engineer** . By bringing your ambitious ideas, unique perspective and contributions, you will...
+ **Build** a better future, amplifying your impact on the causes that matter to you and the world
+ **Grow** a career reflective of your passion and abilities
+ **Connect** to a dynamic and inclusive culture that welcomes the challenge of life-long learning
These commitments set our team apart from the rest:
**Experiences that put people first** . Respect for people is the hallmark of our humanity. It fuels our team to positively impact even a single life. And it means we put our people first at Medtronic as well, creating a culture of belonging and always pushing to get you the career-building resources you need.
**Life-transforming technologies** . No matter your role, you contribute to technologies that transform lives. What we build empowers patients to live life on their terms.
**Better outcomes for our world** . Here, it's about more than the bottom line. Our Mission to improve human welfare drives us. We advance healthcare, society, and equity with every design, inside and outside our walls.
**Insight-driven care** . Fresh viewpoints. Cutting-edge AI, data, and automation. You're shaping the future of healthcare technology and defining the next generation of breakthroughs in care
It is the policy of Medtronic to provide equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, sexual orientation, gender identity and/or expression, genetic information, marital status, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state or local law. In addition, Medtronic will provide reasonable accommodations for qualified individuals with disabilities.
For sales reps and other patient facing field employees, going into a healthcare setting is considered an essential function of the job and we expect our employees to comply with all credentialing requirements at the hospitals or clinics they support.
This employer participates in the federal E-Verify program to confirm the identity and employment authorization of all newly hired employees. For further information about the E-Verify program, please click here (*********************************** .
For updates on job applications, please go to the candidate login page and sign in to check your application status.
If you need assistance completing your application please email *******************
To request removal of your personal information from our systems please email *****************************
$104k-156k yearly 60d+ ago
Senior Cyber Information Assurance Analyst
Medtronic Inc. 4.7
Lafayette, CO jobs
We anticipate the application window for this opening will close on - 23 Jan 2026 At Medtronic you can begin a life-long career of exploration and innovation, while helping champion healthcare access and equity for all. You'll lead with purpose, breaking down barriers to innovation in a more connected, compassionate world.
A Day in the Life
At Medtronic, we bring bold ideas forward with speed and decisiveness to put patients first in everything we do. In-person exchanges are invaluable to our work. We're working onsite 4 days a week as part of our commitment to fostering a culture of professional growth and cross-functional collaboration as we work together to engineer the extraordinary. In your role, you may work from the following Medtronic sites:
* Mounds View, Minnesota • Boston, Massachusetts
* Fridley, Minnesota (OHQ) • Lafayette, Colorado
* Irvine, California (UCI) • Jacksonville, Florida
* Rice Creek, Minnesota
The Medtronic Global Cyber and Information Security Office (GCISO) is seeking a highly skilled and experienced Senior Cybersecurity InformationAssuranceAnalyst to join our cybersecurity team. In this role, you will be responsible for leading the identification, assessment, and mitigation of cybersecurity risks across the organization. As a senior member of the team, you will provide expertise in risk management, compliance, and security strategy, while also playing a key role in driving initiatives to ensure the protection of sensitive data, particularly in a highly regulated healthcare environment. You will collaborate with cross-functional teams to evaluate and enhance our cybersecurity posture, ensuring adherence to relevant regulations such as HIPAA, GDPR, and other industry standards.
We believe that when people from different cultures, genders, and points of view come together, innovation is the result -and everyone wins. Medtronic walks the walk, creating an inclusive culture where you can thrive. Our unwavering commitment to inclusion, diversity, and equity (ID&E) means zero barriers to opportunity within Medtronic and a culture where all employees belong, are respected, and feel valued for who they are and the life experiences they contribute. We know equity starts beyond our workplace, and we must play a role in addressing systemic inequities in our communications to achieve long-term sustainable impact. Anchored in our Mission, we continue to drive ID&E forward both to enhance the well-being of Medtronic employees and to accelerate innovation that brings our lifesaving technologies to more people in more places around the world.
Bring your talents to an industry leader in medical technology and healthcare solutions - we're a market leader and growing every day. You can be proud to be a part of technologies that are rooted in our long history of mission-driven innovation. You will be empowered to shape your own career. We encourage and support your growth with the training, mentorship, and guidance you need to own your future success. Together, we can transform healthcare. Join us for a career in IT that changes lives. Medtronic is committed to fostering a diverse and inclusive culture. Check out the accomplishments of our Women in IT group! ********************************
At Medtronic, we bring bold ideas forward with speed and decisiveness to put patients first in everything we do. In-person exchanges are invaluable to our work. We're working a minimum of 4 days a week onsite as part of our commitment to fostering a culture of professional growth and cross-functional collaboration as we work together to engineer the extraordinary.
Responsibilities may include the following and other duties may be assigned.
* Defines requirements for business continuity, operations security, cryptography, forensics, regulatory compliance, internal counter-espionage (insider threat detection and mitigation), physical security analysis (including facilities analysis, and security management) to best protect company assets.
* Assesses and mitigates system security threats and risks throughout the program life cycle.
* Validates system security requirements definition and analysis.
* Implements and validates security designs in hardware, software, data, and procedures.
* Verifies security requirements; performs system certification and accreditation planning and testing and liaison activities.
* Understanding of Identity, Lifecycle and Governance capabilities, intersection with other cyber security domains, products and industry practices.
* Identify and assess cybersecurity risks through business analysis and propose solutions to mitigate those risks, contributing to overall business continuity and security resilience.
* Demonstrated expertise in GRC frameworks and processes, including system selection, system administration, and supporting core GRC functions. Lead the design and implementation of process flows, ensuring alignment with business objectives.
* Collaborate with teams across various departments, including IT, legal, compliance, and product security, to identify, assess, and mitigate cybersecurity risks across a broad range of products and services, ensuring security is integrated throughout the entire product lifecycle and operational processes.
* Maintain up-to-date knowledge of cybersecurity regulations and standards specific to the medical device industry (FDA, HIPAA, IEC 62443, NIST, NIS 2, etc.).
* Drive improvements in the GRC platform by automating workflows, integrating new tools, and optimizing risk management processes to increase operational efficiency and reduce manual effort.
Minimum Requirements
4+ years of experience with a with a high school diploma or equivalent.
NICE TO HAVE (Preferred Qualifications)
* Previous Medtronic experience
* 7+ years of experience in cybersecurity GRC (Governance, Risk, & Compliance), or external/internal audit, preferably within the medical device or healthcare industry.
* Strong understanding of cybersecurity frameworks, regulatory requirements, risk management, and industry best practices (e.g., HIPAA, NIST, ISO 27001, GDPR, etc.).
SKILLS & COMPETENCIES
* Excellent communication and interpersonal skills, with the ability to interact effectively with both technical and non-technical stakeholders.
* Ability to think critically and strategically about risk management and how technology, process improvements, and automation can help the organization proactively address cybersecurity risks.
* Excellent presentation skills with the ability to communicate complex risk management concepts clearly to executive-level audiences, translating technical details into actionable insights for senior leadership.
RISK MANAGEMENT EXPERIENCE
* Minimum 5 years of experience executing key risk management activities, including conducting risk assessments using various quantitative and qualitative methodologies, such as the FAIR model (Factor Analysis of Information Risk), ensuring a deep understanding of risk analysis methodologies.
* At least 3 years of active participation in the design and implementation of at least 2 comprehensive risk management programs (e.g., risk assessments, regulatory assessments) within a large, complex organization, including hands-on experience with program execution and improvement.
* Proven expertise in process design and improvement related to risk management frameworks and methodologies, ensuring effective risk mitigation strategies are incorporated into operational processes.
* Experience conducting NIST risk assessments (e.g., NIST CSF, NIST 800-53) and applying their standards and recommendations to improve organizational cybersecurity postures.
* Strong knowledge of regulatory changes and trends impacting IT risk assessments, including compliance requirements such as GDPR, HIPAA, and others, ensuring risk management strategies align with the latest regulatory standards.
* Knowledge of Operational Technology (OT) risk management is a plus, with the ability to assess risks related to OT environments and integrate them into overall IT risk strategies.
* Minimum 3 years of experience evaluating technical design documents for systems or environments to assess associated risks, including reviewing architectural, infrastructure, and application designs for security and operational risk vulnerabilities.
TECHNICAL EXPERTISE
* Familiarity with GRC tools such as ServiceNow, LogicGate, or OneTrust
* Strong understanding of technical infrastructure, including networks, cloud environments, endpoints, and medical device systems.
* Experience with system integration and data flow analysis within GRC tools, ideally leveraging APIs and other automation technologies to improve operational efficiencies.
CERTIFICATIONS
* Certified Information Systems Security Professional (CISSP).
* Certified in Risk and Information Systems Control (CRISC).
* Certified Information Security Auditor (CISA).
Physical Job Requirements
The above statements are intended to describe the general nature and level of work being performed by employees assigned to this position, but they are not an exhaustive list of all the required responsibilities and skills of this position.
The physical demands described within the Responsibilities section of this job description are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. For Office Roles: While performing the duties of this job, the employee is regularly required to be independently mobile. The employee is also required to interact with a computer, and communicate with peers and co-workers. Contact your manager or local HR to understand the Work Conditions and Physical requirements that may be specific to each role.
Benefits & Compensation
Medtronic offers a competitive Salary and flexible Benefits Package
A commitment to our employees lives at the core of our values. We recognize their contributions. They share in the success they help to create. We offer a wide range of benefits, resources, and competitive compensation plans designed to support you at every career and life stage.
Salary ranges for U.S (excl. PR) locations (USD):$104,000.00 - $156,000.00
This position is eligible for a short-term incentive called the Medtronic Incentive Plan (MIP).
The base salary range is applicable across the United States, excluding Puerto Rico and specific locations in California. The offered rate complies with federal and local regulations and may vary based on factors such as experience, certification/education, market conditions, and location. Compensation and benefits information pertains solely to candidates hired within the United States (local market compensation and benefits will apply for others).
The following benefits and additional compensation are available to those regular employees who work 20+ hours per week: Health, Dental and vision insurance, Health Savings Account, Healthcare Flexible Spending Account, Life insurance, Long-term disability leave, Dependent daycare spending account, Tuition assistance/reimbursement, and Simple Steps (global well-being program).
The following benefits and additional compensation are available to all regular employees: Incentive plans, 401(k) plan plus employer contribution and match, Short-term disability, Paid time off, Paid holidays, Employee Stock Purchase Plan, Employee Assistance Program, Non-qualified Retirement Plan Supplement (subject to IRS earning minimums), and Capital Accumulation Plan (available to Vice Presidents and above, or subject to IRS earning minimums).
Regular employees are those who are not temporary, such as interns. Temporary employees are eligible for paid sick time, as required under applicable state law, and the Employee Stock Purchase Plan. Please note some of the above benefits may not apply to workers in Puerto Rico.
Further details are available at the link below:
Medtronic benefits and compensation plans
About Medtronic
We lead global healthcare technology and boldly attack the most challenging health problems facing humanity by searching out and finding solutions.
Our Mission - to alleviate pain, restore health, and extend life - unites a global team of 95,000+ passionate people.
We are engineers at heart- putting ambitious ideas to work to generate real solutions for real people. From the R&D lab, to the factory floor, to the conference room, every one of us experiments, creates, builds, improves and solves. We have the talent, diverse perspectives, and guts to engineer the extraordinary.
Learn more about our business, mission, and our commitment to diversity here.
It is the policy of Medtronic to provide equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, sexual orientation, gender identity and/or expression, genetic information, marital status, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state or local law. In addition, Medtronic will provide reasonable accommodations for qualified individuals with disabilities.
If you are applying to perform work for Medtronic, Inc. ("Medtronic") in any position which will involve performing at least two (2) hours of work on average each week within the unincorporated areas of Los Angeles County, you can find here a list of all material job duties of the specific job position which Medtronic reasonably believes that criminal history may have a direct, adverse and negative relationship potentially resulting in the withdrawal of a conditional offer of employment. Medtronic will consider for employment qualified job applicants with arrest or conviction records in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act.
$104k-156k yearly Auto-Apply 4d ago
Senior Cyber Information Assurance Analyst
Medtronic 4.7
Lafayette, CO jobs
We anticipate the application window for this opening will close on - 23 Jan 2026 At Medtronic you can begin a life-long career of exploration and innovation, while helping champion healthcare access and equity for all. You'll lead with purpose, breaking down barriers to innovation in a more connected, compassionate world.
**A Day in the Life**
At Medtronic, we bring bold ideas forward with speed and decisiveness to put patients first in everything we do. In-person exchanges are invaluable to our work. We're working onsite 4 days a week as part of our commitment to fostering a culture of professional growth and cross-functional collaboration as we work together to engineer the extraordinary. In your role, you may work from the following Medtronic sites:
- Mounds View, Minnesota - Boston, Massachusetts
- Fridley, Minnesota (OHQ) - Lafayette, Colorado
- Irvine, California (UCI) - Jacksonville, Florida
- Rice Creek, Minnesota
The Medtronic Global Cyber and Information Security Office (GCISO) is seeking a highly skilled and experienced Senior Cybersecurity InformationAssuranceAnalyst to join our cybersecurity team. In this role, you will be responsible for leading the identification, assessment, and mitigation of cybersecurity risks across the organization. As a senior member of the team, you will provide expertise in risk management, compliance, and security strategy, while also playing a key role in driving initiatives to ensure the protection of sensitive data, particularly in a highly regulated healthcare environment. You will collaborate with cross-functional teams to evaluate and enhance our cybersecurity posture, ensuring adherence to relevant regulations such as HIPAA, GDPR, and other industry standards.
We believe that when people from different cultures, genders, and points of view come together, innovation is the result -and everyone wins. Medtronic walks the walk, creating an inclusive culture where you can thrive. Our unwavering commitment to inclusion, diversity, and equity (ID&E) means zero barriers to opportunity within Medtronic and a culture where all employees belong, are respected, and feel valued for who they are and the life experiences they contribute. We know equity starts beyond our workplace, and we must play a role in addressing systemic inequities in our communications to achieve long-term sustainable impact. Anchored in our Mission, we continue to drive ID&E forward both to enhance the well-being of Medtronic employees and to accelerate innovation that brings our lifesaving technologies to more people in more places around the world.
Bring your talents to an industry leader in medical technology and healthcare solutions - we're a market leader and growing every day. You can be proud to be a part of technologies that are rooted in our long history of mission-driven innovation. You will be empowered to shape your own career. We encourage and support your growth with the training, mentorship, and guidance you need to own your future success. Together, we can transform healthcare. Join us for a career in IT that changes lives. Medtronic is committed to fostering a diverse and inclusive culture. Check out the accomplishments of our Women in IT group! ********************************
At Medtronic, we bring bold ideas forward with speed and decisiveness to put patients first in everything we do. In-person exchanges are invaluable to our work. We're working a minimum of 4 days a week onsite as part of our commitment to fostering a culture of professional growth and cross-functional collaboration as we work together to engineer the extraordinary.
Responsibilities may include the following and other duties may be assigned.
+ Defines requirements for business continuity, operations security, cryptography, forensics, regulatory compliance, internal counter-espionage (insider threat detection and mitigation), physical security analysis (including facilities analysis, and security management) to best protect company assets.
+ Assesses and mitigates system security threats and risks throughout the program life cycle.
+ Validates system security requirements definition and analysis.
+ Implements and validates security designs in hardware, software, data, and procedures.
+ Verifies security requirements; performs system certification and accreditation planning and testing and liaison activities.
+ Understanding of Identity, Lifecycle and Governance capabilities, intersection with other cyber security domains, products and industry practices.
+ Identify and assess cybersecurity risks through business analysis and propose solutions to mitigate those risks, contributing to overall business continuity and security resilience.
+ Demonstrated expertise in GRC frameworks and processes, including system selection, system administration, and supporting core GRC functions. Lead the design and implementation of process flows, ensuring alignment with business objectives.
+ Collaborate with teams across various departments, including IT, legal, compliance, and product security, to identify, assess, and mitigate cybersecurity risks across a broad range of products and services, ensuring security is integrated throughout the entire product lifecycle and operational processes.
+ Maintain up-to-date knowledge of cybersecurity regulations and standards specific to the medical device industry (FDA, HIPAA, IEC 62443, NIST, NIS 2, etc.).
+ Drive improvements in the GRC platform by automating workflows, integrating new tools, and optimizing risk management processes to increase operational efficiency and reduce manual effort.
**Minimum Requirements**
**4+ years of experience with a with a high school diploma or equivalent.**
**NICE TO HAVE** (Preferred Qualifications)
+ Previous Medtronic experience
+ 7+ years of experience in cybersecurity GRC (Governance, Risk, & Compliance), or external/internal audit, preferably within the medical device or healthcare industry.
+ Strong understanding of cybersecurity frameworks, regulatory requirements, risk management, and industry best practices (e.g., HIPAA, NIST, ISO 27001, GDPR, etc.).
SKILLS & COMPETENCIES
+ Excellent communication and interpersonal skills, with the ability to interact effectively with both technical and non-technical stakeholders.
+ Ability to think critically and strategically about risk management and how technology, process improvements, and automation can help the organization proactively address cybersecurity risks.
+ Excellent presentation skills with the ability to communicate complex risk management concepts clearly to executive-level audiences, translating technical details into actionable insights for senior leadership.
RISK MANAGEMENT EXPERIENCE
+ Minimum 5 years of experience executing key risk management activities, including conducting risk assessments using various quantitative and qualitative methodologies, such as the FAIR model (Factor Analysis of Information Risk), ensuring a deep understanding of risk analysis methodologies.
+ At least 3 years of active participation in the design and implementation of at least 2 comprehensive risk management programs (e.g., risk assessments, regulatory assessments) within a large, complex organization, including hands-on experience with program execution and improvement.
+ Proven expertise in process design and improvement related to risk management frameworks and methodologies, ensuring effective risk mitigation strategies are incorporated into operational processes.
+ Experience conducting NIST risk assessments (e.g., NIST CSF, NIST 800-53) and applying their standards and recommendations to improve organizational cybersecurity postures.
+ Strong knowledge of regulatory changes and trends impacting IT risk assessments, including compliance requirements such as GDPR, HIPAA, and others, ensuring risk management strategies align with the latest regulatory standards.
+ Knowledge of Operational Technology (OT) risk management is a plus, with the ability to assess risks related to OT environments and integrate them into overall IT risk strategies.
+ Minimum 3 years of experience evaluating technical design documents for systems or environments to assess associated risks, including reviewing architectural, infrastructure, and application designs for security and operational risk vulnerabilities.
TECHNICAL EXPERTISE
+ Familiarity with GRC tools such as ServiceNow, LogicGate, or OneTrust
+ Strong understanding of technical infrastructure, including networks, cloud environments, endpoints, and medical device systems.
+ Experience with system integration and data flow analysis within GRC tools, ideally leveraging APIs and other automation technologies to improve operational efficiencies.
CERTIFICATIONS
+ Certified Information Systems Security Professional (CISSP).
+ Certified in Risk and Information Systems Control (CRISC).
+ Certified Information Security Auditor (CISA).
**Physical Job Requirements**
The above statements are intended to describe the general nature and level of work being performed by employees assigned to this position, but they are not an exhaustive list of all the required responsibilities and skills of this position.
The physical demands described within the Responsibilities section of this job description are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. For Office Roles: While performing the duties of this job, the employee is regularly required to be independently mobile. The employee is also required to interact with a computer, and communicate with peers and co-workers. Contact your manager or local HR to understand the Work Conditions and Physical requirements that may be specific to each role.
**Benefits & Compensation**
**Medtronic offers a competitive Salary and flexible Benefits Package**
A commitment to our employees lives at the core of our values. We recognize their contributions. They share in the success they help to create. We offer a wide range of benefits, resources, and competitive compensation plans designed to support you at every career and life stage.
Salary ranges for U.S (excl. PR) locations (USD):$104,000.00 - $156,000.00
This position is eligible for a short-term incentive called the Medtronic Incentive Plan (MIP).
The base salary range is applicable across the United States, excluding Puerto Rico and specific locations in California. The offered rate complies with federal and local regulations and may vary based on factors such as experience, certification/education, market conditions, and location. Compensation and benefits information pertains solely to candidates hired within the United States (local market compensation and benefits will apply for others).
The following benefits and additional compensation are available to those regular employees who work 20+ hours per week: Health, Dental and vision insurance, Health Savings Account, Healthcare Flexible Spending Account, Life insurance, Long-term disability leave, Dependent daycare spending account, Tuition assistance/reimbursement, and Simple Steps (global well-being program).
The following benefits and additional compensation are available to all regular employees: Incentive plans, 401(k) plan plus employer contribution and match, Short-term disability, Paid time off, Paid holidays, Employee Stock Purchase Plan, Employee Assistance Program, Non-qualified Retirement Plan Supplement (subject to IRS earning minimums), and Capital Accumulation Plan (available to Vice Presidents and above, or subject to IRS earning minimums).
Regular employees are those who are not temporary, such as interns. Temporary employees are eligible for paid sick time, as required under applicable state law, and the Employee Stock Purchase Plan. Please note some of the above benefits may not apply to workers in Puerto Rico.
Further details are available at the link below:
Medtronic benefits and compensation plans (**************************************************************************************************************
**About Medtronic**
We lead global healthcare technology and boldly attack the most challenging health problems facing humanity by searching out and finding solutions.
Our Mission - to alleviate pain, restore health, and extend life - unites a global team of 95,000+ passionate people.
We are engineers at heart- putting ambitious ideas to work to generate real solutions for real people. From the R&D lab, to the factory floor, to the conference room, every one of us experiments, creates, builds, improves and solves. We have the talent, diverse perspectives, and guts to engineer the extraordinary.
Learn more about our business, mission, and our commitment to diversity here (************************* .
It is the policy of Medtronic to provide equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, sexual orientation, gender identity and/or expression, genetic information, marital status, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state or local law. In addition, Medtronic will provide reasonable accommodations for qualified individuals with disabilities.
If you are applying to perform work for Medtronic, Inc. ("Medtronic") in any position which will involve performing at least two (2) hours of work on average each week within the unincorporated areas of Los Angeles County, you can find here (*************************************************************************************************************************************** a list of all material job duties of the specific job position which Medtronic reasonably believes that criminal history may have a direct, adverse and negative relationship potentially resulting in the withdrawal of a conditional offer of employment. Medtronic will consider for employment qualified job applicants with arrest or conviction records in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act.
We lead global healthcare technology and boldly attack the most challenging health problems facing humanity by searching out and finding solutions.
Our Mission - to alleviate pain, restore health, and extend life - unites a global team of 95,000+ passionate people.
We are engineers at heart- putting ambitious ideas to work to generate real solutions for real people. From the R&D lab, to the factory floor, to the conference room, every one of us experiments, creates, builds, improves and solves. We have the talent, diverse perspectives, and guts to engineer the extraordinary.
**We change lives** . Each team member, each day, helps to improve and redefine how the world treats the most pressing health conditions, from heart disease to diabetes. Our industry leadership comes from the passion and ingenuity of our people. That's who we are. Working alongside one another, we use science, medicine, and a profound understanding of the human body to build extraordinary technologies that can transform lives.
**We build extraordinary solutions as one team** . With one Medtronic Mindset defining how we work. Speed and decisiveness run through our DNA. Diverse perspectives inspire our bold answers to any challenge that comes our way. And we deliver results the right way, breakthrough after patient breakthrough.
**This life-changing career is yours to engineer** . By bringing your ambitious ideas, unique perspective and contributions, you will...
+ **Build** a better future, amplifying your impact on the causes that matter to you and the world
+ **Grow** a career reflective of your passion and abilities
+ **Connect** to a dynamic and inclusive culture that welcomes the challenge of life-long learning
These commitments set our team apart from the rest:
**Experiences that put people first** . Respect for people is the hallmark of our humanity. It fuels our team to positively impact even a single life. And it means we put our people first at Medtronic as well, creating a culture of belonging and always pushing to get you the career-building resources you need.
**Life-transforming technologies** . No matter your role, you contribute to technologies that transform lives. What we build empowers patients to live life on their terms.
**Better outcomes for our world** . Here, it's about more than the bottom line. Our Mission to improve human welfare drives us. We advance healthcare, society, and equity with every design, inside and outside our walls.
**Insight-driven care** . Fresh viewpoints. Cutting-edge AI, data, and automation. You're shaping the future of healthcare technology and defining the next generation of breakthroughs in care
It is the policy of Medtronic to provide equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, sexual orientation, gender identity and/or expression, genetic information, marital status, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state or local law. In addition, Medtronic will provide reasonable accommodations for qualified individuals with disabilities.
For sales reps and other patient facing field employees, going into a healthcare setting is considered an essential function of the job and we expect our employees to comply with all credentialing requirements at the hospitals or clinics they support.
This employer participates in the federal E-Verify program to confirm the identity and employment authorization of all newly hired employees. For further information about the E-Verify program, please click here (*********************************** .
For updates on job applications, please go to the candidate login page and sign in to check your application status.
If you need assistance completing your application please email *******************
To request removal of your personal information from our systems please email *****************************