Senior Principal Information Security Risk Specialist

MiniMed

Maharashtra

On-site

INR 300,000 - 600,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Flexible benefits package
Competitive salary

Job summary

MiniMed, a global leader in diabetes care, is expanding its Global Information Security Risk Management practice in Pune. The role focuses on leading risk assessments across cybersecurity, cloud, data, and AI, partnering with stakeholders to drive risk-informed decision making.

It requires a strong background in GRC, risk quantification, and regulatory compliance. You will contribute to risk governance, reporting, and program administration while mentoring junior staff in a fast-paced, globally

Qualifications

  • Bachelor's degree in information security, risk management, or related field and 10+ years of relevant experience.
  • Expertise in information security risk management, cybersecurity governance, and GRC frameworks.
  • Experience facilitating risk workshops and communicating findings to executives.
  • Knowledge of NIST CSF/RMF, ISO 27001, HIPAA, and related privacy and regulatory requirements.

Responsibilities

  • Lead enterprise cybersecurity, technology, cloud, data, and AI risk assessments to identify, evaluate, prioritize, and monitor information security risks.
  • Maintain risk methodologies, scoring models, risk taxonomies, and the enterprise information security risk register.
  • Partner with risk owners to evaluate risk exposure, develop treatment strategies, document mitigation activities, and monitor remediation efforts.
  • Provide independent challenge and oversight of risk assessments, treatment plans, mitigation strategies, and risk acceptance recommendations.
  • Support governance processes and program maturity through continuous improvement of risk management practices.

Skills

Information Security Risk Management
Cybersecurity Governance
Stakeholder Management
Analytical Thinking
Communication Skills

Education

Bachelor's degree in related field

Tools

ServiceNow IRM
SAP GRC
AuditBoard
Risk Dashboards

Job description

At MiniMed, you can begin a lifelong career of exploration and innovation, while helping make a difference in the lives of people living with diabetes around the globe. You'll lead with purpose, breaking down barriers to innovation for a more connected, compassionate world.

About The Role
A Day in the Life

Our Global Diabetes Capability Center in Pune is expanding to serve more people living with diabetes globally. Our state-of-the-art facility is dedicated to transforming diabetes management through innovative solutions and Technologies that reduce the burden of living with diabetes.

This position is an exciting opportunity to work with Minimed’s Diabetes business. Medtronic has announced its intention to separate the Diabetes division to promote future growth and innovation within the business and reallocate investments and resources across Medtronic, subject to applicable information and consultation requirements. This separation provides our team with a bold opportunity to unleash our potential, enabling us to operate with greater speed and agility. As a separate entity, we anticipate leveraging increased investments to drive meaningful innovation and enhance our impact on patient care.

#BetterDaysStartNow

Responsibilities may include the following and other duties may be assigned.

Information Security Risk Management
  • Lead enterprise cybersecurity, technology, cloud, data, and AI risk assessments to identify, evaluate, prioritize, and monitor information security risks.
  • Maintain risk methodologies, scoring models, risk taxonomies, and the enterprise information security risk register.
  • Partner with risk owners to evaluate risk exposure, develop treatment strategies, document mitigation activities, and monitor remediation efforts.
  • Provide independent challenge and oversight of risk assessments, treatment plans, mitigation strategies, and risk acceptance recommendations.
  • Support continuous improvement of enterprise information security risk management processes, governance standards, and program maturity.
Cyber, Data & AI Risk Governance
  • Assess risks associated with cybersecurity, information protection, privacy, data governance, cloud services, emerging technologies, and artificial intelligence initiatives.
  • Support implementation of AI governance and risk management practices aligned to NIST AI RMF, ISO/IEC 42001, and organizational requirements.
  • Evaluate emerging threats, incidents, audit results, assessments, and control deficiencies to identify risk trends and opportunities for improvement.
  • Support secure adoption of technology and digital initiatives through risk-informed governance and advisory services.
Risk Reporting & Program Administration
  • Develop and maintain risk metrics, key risk indicators (KRIs), key performance indicators (KPIs), dashboards, governance reports, and program documentation.
  • Support administration, optimization, and continuous improvement of Governance, Risk & Compliance (GRC) technologies and risk management processes.
  • Provide risk reporting and analysis to support leadership decision-making, governance activities, and program effectiveness measurement.
Stakeholder Advisory & Collaboration
  • Partner with Information Security, Information Technology, Privacy, Compliance, Internal Audit, Legal, Enterprise Risk Management, and business stakeholders to support risk-informed decision-making.
  • Facilitate risk workshops, risk reviews, governance discussions, and remediation planning activities.
  • Serve as a trusted advisor and subject matter expert regarding information security risk management, cybersecurity governance, and emerging technology risk.
  • Communicate complex technical risks and recommendations to business, technical, and executive audiences.
Independence & Scope

This role operates as an independent second-line risk oversight function within the Information Security Governance, Risk & Compliance (InfoSec GRC) organization. The position is responsible for facilitating, assessing, monitoring, and reporting information security risks while providing objective challenge and oversight of risk management activities across the enterprise. The role maintains appropriate independence from operational control ownership, control execution, technology implementation, security operations, engineering activities, remediation ownership, and internal audit responsibilities.

Specialist Career Stream

Typically an individual contributor recognized as a subject matter expert within Information Security Risk Management. Leads complex initiatives, influences risk management practices, and provides guidance to less experienced professionals while driving continuous improvement of enterprise risk management capabilities.

Differentiating Factors
Autonomy
  • Recognized subject matter expert operating with significant independence.
  • Applies advanced judgment to complex cybersecurity, technology, data, and artificial intelligence risk scenarios.
Organizational Impact
  • Influences enterprise risk management practices, governance processes, and leadership decision-making.
  • Contributes directly to organizational risk transparency, governance effectiveness, and program maturity.
Innovation & Complexity
  • Evaluates complex cyber, technology, cloud, data, and AI risks requiring analysis of technical, operational, regulatory, and business considerations.
  • Develops practical risk management solutions, governance improvements, and strategic recommendations.
Communication & Leadership
  • Communicates effectively with technical, business, and executive stakeholders.
  • Leads cross-functional risk initiatives and mentors less experienced professionals.
Required Knowledge & Experience
  • Bachelor's degree and a minimum of 10 years of relevant experience, an advanced degree with a minimum of 8 years of relevant experience, or an equivalent combination of education and experience.
  • Expertise in Information Security Risk Management, cybersecurity governance, technology risk management, Governance, Risk & Compliance (GRC), information assurance, enterprise risk management, audit, or related disciplines.
  • Experience executing risk assessments, maintaining risk registers, administering risk methodologies, evaluating mitigation effectiveness, and supporting governance processes.
  • Strong understanding of cybersecurity, cloud computing, artificial intelligence, privacy, data governance, regulatory compliance, and emerging technology risks.
  • Experience facilitating risk workshops and translating complex technical findings into business-focused risk recommendations.
  • Experience supporting risk quantification, business impact analysis, and risk treatment decision-making processes.
  • Strong analytical, communication, facilitation, and stakeholder management skills.
Preferred Qualifications
  • Experience supporting enterprise Information Security Risk Management Programs within large, complex, or global organizations.
  • Experience developing risk dashboards, KRIs, KPIs, executive reporting, governance metrics, and risk heat maps.
  • Experience supporting cyber risk quantification programs utilizing FAIR methodologies or similar quantitative risk models.
  • Experience facilitating cyber, cloud, data, artificial intelligence, and technology risk assessments.
  • Experience supporting AI governance initiatives and implementation of NIST AI RMF and ISO/IEC 42001.
  • Experience integrating cybersecurity, privacy, AI governance, data governance, and risk management practices into enterprise governance frameworks.
  • Experience within healthcare, medical technology, life sciences, manufacturing, or other highly regulated industries.
  • Experience working with ServiceNow IRM, SAP GRC, AuditBoard, or similar GRC technologies.
  • Knowledge of NIST CSF, RMF, ISO/IEC 27001, ISO/IEC 31000, ISO/IEC 42001, HIPAA, NIS2, and related privacy and regulatory frameworks.
Preferred Certifications
  • CRISC
  • CISSP
  • CISM
  • CISA
  • CGRC
  • Open FAIR Foundation or Open FAIR Practitioner
  • ISO/IEC 27001 Lead Implementer or Lead Auditor
  • ISO/IEC 42001 Artificial Intelligence Management Systems Certification
  • AI Governance, AI Assurance, Responsible AI, or Emerging Technology Risk Certifications
Physical Job Requirements

The above statements are intended to describe the general nature and level of work being performed by employees assigned to this position, but they are not an exhaustive list of all the required responsibilities and skills of this position.

Benefits & Compensation

MiniMed offers a competitive salary and flexible benefits package

At MiniMed, we put people first. A commitment to our employees lives at the core of our values: We recognize their contributions. They share in the success they help create. We offer a wide range of benefits, resources, and competitive compensation plans designed to support you at every stage of your career and life.

About MiniMed

We want to make every day a better day for people living with diabetes. Our team of creative innovators around the globe share a passion for finding the simplest solutions to the problems that people with diabetes face on a daily basis. For more than 40 years, we've been redefining what's possible, from intelligent dosing systems designed for real life to predictive insights that stay a step ahead, and we're dedicated to continuing to support our customers through every step of their journey — meeting them where and how they need it.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Principal Information Security Risk Specialist
Senior Principal Information Security Risk Specialist

MiniMed Group • Pune District

On-site
INR 2,200,000 - 3,500,000
Flexible benefits
Sr Prin IT Technologist - Network Security Engineer
Sr Prin IT Technologist - Network Security Engineer

MiniMed • Maharashtra

On-site
INR 1,500,000 - 2,500,000
Competitive salary
Flexible benefits package
Team Leader
Team Leader

MiniMed • Maharashtra

On-site
INR 1,200,000 - 2,000,000
Competitive salary
Flexible benefits
Team Leader
Team Leader

MiniMed Group • Pune District

On-site
INR 1,600,000 - 2,200,000
Insurance Collection Sr. Executive
Insurance Collection Sr. Executive

MiniMed • Maharashtra

On-site
INR 279,000 - 469,000
Competitive salary
Flexible benefits
Prin IT Technologist - Clinical Research Technology Specialist (EDC, eCOA & eConsent)
Prin IT Technologist - Clinical Research Technology Specialist (EDC, eCOA & eConsent)

IND-Medtronic MiniMed India Private Limited • Pune District

On-site
INR 2,200,000 - 3,800,000
Team Lead - Collections
Team Lead - Collections

MiniMed • Maharashtra

On-site
INR 1,500,000 - 2,500,000
Flexible benefits package
Competitive salary
Software Engineer II - Mobile App Development , Devops Engineer
Software Engineer II - Mobile App Development , Devops Engineer

MiniMed • Maharashtra

On-site
INR 1,200,000 - 2,400,000
Sr Prin IT Technologist - Network Security Engineer
Sr Prin IT Technologist - Network Security Engineer

MiniMed Group • Pune District

On-site
INR 3,800,000 - 6,000,000
Insurance Collection Sr. Executive
Insurance Collection Sr. Executive

MiniMed Group • Pune District

On-site
INR 450,000 - 650,000