Senior Principal Information Security Risk Specialist

MiniMed Group

Pune District

On-site

INR 2,200,000 - 3,500,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Flexible benefits

Job summary

MiniMed is seeking an experienced Information Security Risk Management Leader in Pune to oversee enterprise cybersecurity risk assessments, governance, and risk reporting. You will collaborate with IT, Privacy, Compliance, and Audit teams to ensure robust risk controls and effective remediation.

The role emphasizes leadership in risk management, alignment with regulatory requirements, and the integration of AI and emerging tech risk into governance frameworks.

Qualifications

  • Bachelor's degree in a related field; advanced degree preferred.
  • Minimum 10 years of relevant experience in information security risk management.
  • Expertise in cybersecurity governance, GRC, and regulatory requirements.

Responsibilities

  • Lead enterprise information security risk assessments and risk governance activities.
  • Develop and maintain risk metrics, KRIs, KPIs, and risk dashboards.
  • Collaborate with cross-functional stakeholders to guide risk-informed decision making.
  • Translate complex risk findings into business-focused recommendations.

Skills

Information Security Risk Management
Cybersecurity governance
GRC
Risk assessments
Risk registers
Risk treatment
Cloud computing
Privacy
Regulatory compliance
Audits

Education

Bachelor's degree
Advanced degree (preferred)

Tools

ServiceNow IRM
SAP GRC
AuditBoard

Job description

About the Role

A Day in the Life Our Global Diabetes Capability Center in Pune is expanding to serve more people living with diabetes globally. Our state-of-the-art facility is dedicated to transforming diabetes management through innovative solutions and Technologies that reduce the burden of living with diabetes. This position is an exciting opportunity to work with Minimed’s Diabetes business. Medtronic has announced its intention to separate the Diabetes division to promote future growth and innovation within the business and reallocate investments and resources across Medtronic, subject to applicable information and consultation requirements. This separation provides our team with a bold opportunity to unleash our potential, enabling us to operate with greater speed and agility. As a separate entity, we anticipate leveraging increased investments to drive meaningful innovation and enhance our impact on patient care. #BetterDaysStartNow

Responsibilities
  • Information Security Risk Management Lead enterprise cybersecurity, technology, cloud, data, and AI risk assessments to identify, evaluate, prioritize, and monitor information security risks. Maintain risk methodologies, scoring models, risk taxonomies, and the enterprise information security risk register. Partner with risk owners to evaluate risk exposure, develop treatment strategies, document mitigation activities, and monitor remediation efforts. Provide independent challenge and oversight of risk assessments, treatment plans, mitigation strategies, and risk acceptance recommendations. Support continuous improvement of enterprise information security risk management processes, governance standards, and program maturity.
  • Cyber, Data & AI Risk Governance Assess risks associated with cybersecurity, information protection, privacy, data governance, cloud services, emerging technologies, and artificial intelligence initiatives. Support implementation of AI governance and risk management practices aligned to NIST AI RMF, ISO/IEC 42001, and organizational requirements. Evaluate emerging threats, incidents, audit results, assessments, and control deficiencies to identify risk trends and opportunities for improvement. Support secure adoption of technology and digital initiatives through risk-informed governance and advisory services.
  • Risk Reporting & Program Administration Develop and maintain risk metrics, key risk indicators (KRIs), key performance indicators (KPIs), dashboards, governance reports, and program documentation. Support administration, optimization, and continuous improvement of Governance, Risk & Compliance (GRC) technologies and risk management processes. Provide risk reporting and analysis to support leadership decision-making, governance activities, and program effectiveness measurement.
  • Stakeholder Advisory & Collaboration Partner with Information Security, Information Technology, Privacy, Compliance, Internal Audit, Legal, Enterprise Risk Management, and business stakeholders to support risk-informed decision-making. Facilitate risk workshops, risk reviews, governance discussions, and remediation planning activities. Serve as a trusted advisor and subject matter expert regarding information security risk management, cybersecurity governance, and emerging technology risk. Communicate complex technical risks and recommendations to business, technical, and executive audiences.
Independence & Scope

This role operates as an independent second-line risk oversight function within the Information Security Governance, Risk & Compliance (InfoSec GRC) organization. The position is responsible for facilitating, assessing, monitoring, and reporting information security risks while providing objective challenge and oversight of risk management activities across the enterprise. The role maintains appropriate independence from operational control ownership, control execution, technology implementation, security operations, engineering activities, remediation ownership, and internal audit responsibilities.

Specialist Career Stream

Typically an individual contributor recognized as a subject matter expert within Information Security Risk Management. Leads complex initiatives, influences risk management practices, and provides guidance to less experienced professionals while driving continuous improvement of enterprise risk management capabilities.

Differentiating Factors

Autonomy Recognized subject matter expert operating with significant independence. Applies advanced judgment to complex cybersecurity, technology, data, and artificial intelligence risk scenarios.

Organizational Impact Influences enterprise risk management practices, governance processes, and leadership decision-making. Contributes directly to organizational risk transparency, governance effectiveness, and program maturity.

Innovation & Complexity Evaluates complex cyber, technology, cloud, data, and AI risks requiring analysis of technical, operational, regulatory, and business considerations. Develops practical risk management solutions, governance improvements, and strategic recommendations.

Communication & Leadership Communicates effectively with technical, business, and executive stakeholders. Leads cross-functional risk initiatives and mentors less experienced professionals.

Required Knowledge & Experience
  • Bachelor's degree and a minimum of 10 years of relevant experience, an advanced degree with a minimum of 8 years of relevant experience, or an equivalent combination of education and experience.
  • Expertise in Information Security Risk Management, cybersecurity governance, technology risk management, Governance, Risk & Compliance (GRC), information assurance, enterprise risk management, audit, or related disciplines.
  • Experience executing risk assessments, maintaining risk registers, administering risk methodologies, evaluating mitigation effectiveness, and supporting governance processes.
  • Strong understanding of cybersecurity, cloud computing, artificial intelligence, privacy, data governance, regulatory compliance, and emerging technology risks.
  • Experience facilitating risk workshops and translating complex technical findings into business-focused risk recommendations.
  • Experience supporting risk quantification, business impact analysis, and risk treatment decision-making processes.
  • Strong analytical, communication, facilitation, and stakeholder management skills.
Preferred Qualifications
  • Experience supporting enterprise Information Security Risk Management Programs within large, complex, or global organizations.
  • Experience developing risk dashboards, KRIs, KPIs, executive reporting, governance metrics, and risk heat maps.
  • Experience supporting cyber risk quantification programs utilizing FAIR methodologies or similar quantitative risk models.
  • Experience facilitating cyber, cloud, data, artificial intelligence, and technology risk assessments.
  • Experience supporting AI governance initiatives and implementation of NIST AI RMF and ISO/IEC 42001.
  • Experience integrating cybersecurity, privacy, AI governance, data governance, and risk management practices into enterprise governance frameworks.
  • Experience within healthcare, medical technology, life sciences, manufacturing, or other highly regulated industries.
  • Experience working with ServiceNow IRM, SAP GRC, AuditBoard, or similar GRC technologies.
  • Knowledge of NIST CSF, RMF, ISO/IEC 27001, ISO/IEC 31000, ISO/IEC 42001, HIPAA, NIS2, and related privacy and regulatory frameworks.
Preferred Certifications
  • CRISC CISSP CISM CISA CGRC Open FAIR Foundation or Open FAIR Practitioner ISO/IEC 27001 Lead Implementer or Lead Auditor ISO/IEC 42001 Artificial Intelligence Management Systems Certification AI Governance, AI Assurance, Responsible AI, or Emerging Technology Risk Certifications
Physical Job Requirements

The above statements are intended to describe the general nature and level of work being performed by employees assigned to this position, but they are not an exhaustive list of all the required responsibilities and skills of this position.

Benefits & Compensation

MiniMed offers a competitive salary and flexible benefits package

About MiniMed

We want to make every day a better day for people living with diabetes. Our team of creative innovators around the globe share a passion for finding the simplest solutions to the problems that people with diabetes face on a daily basis. For more than 40 years, we've been redefining what's possible, from intelligent dosing systems designed for real life to predictive insights that stay a step ahead, and we're dedicated to continuing to support our customers through every step of their journey — meeting them where and how they need it.

MiniMed is a full-stack insulin delivery company dedicated to supporting people living with diabetes through every step of their journey — when and how they need it. With a heritage rooted in technology, empathy, and a relentless pursuit of innovation, we’re focused on one thing: making every day a better day for people with diabetes. From our intelligent dosing systems that stay one step ahead to our always-on support when it’s needed most, we’re committed to building a connected system of care that works together and fits into everyday life, so people with diabetes can move through the day with fewer interruptions. Fewer second guesses. And more freedom to live in the moment. We’re here to make better days possible for people with diabetes. Joyful, messy, fully lived days. Days where things feel lighter, easier. For more than four decades, we’ve been driven by this mission, delivering groundbreaking advancements in technology to help people live more fully, freely, and with greater confidence.

At MiniMed, diabetes care is personal for us. Many of our employees have a connection to diabetes, whether they're living with it themselves or through family members and friends, and we all show up each day to help make the lives of our coworkers and loved ones easier. Our people-first priority. At MiniMed, we put our customers at the forefront of all we do, and that focus extends to our team as well. We're dedicated to creating a culture of belonging and providing our people with all the career-building resources you might need. Our life-transforming technologies. No matter what your role at our company, you're making a difference in the lives of people with diabetes. Our innovative inventions improve their day-to-day by helping lift the mental load and allowing diabetes to fade into the background, empowering them to live life on their own terms. Our focus on the future. We're chasing the dream of a world where people with diabetes can be free of that never-ending battle of balancing blood sugar. A world where better days are the norm, not the exception. Fresh faces and new viewpoints will help create our cutting-edge solutions and define the next generation of breakthroughs in care, so that a better day can start today.

It is the policy of MiniMed to provide equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, sexual orientation, gender identity and/or expression, genetic information, marital status, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state or local law. In addition, MiniMed will provide reasonable accommodations for qualified individuals with disabilities. For sales reps and other patient facing field employees, going into a healthcare setting is considered an essential function of the job and we expect our employees to comply with all credentialing requirements at the hospitals or clinics they support. This employer participates in the federal E-Verify program to confirm the identity and employment authorization of all newly hired employees.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Team Leader
Team Leader

MiniMed Group • Pune District

On-site
INR 1,600,000 - 2,200,000
Insurance Collection Sr. Executive
Insurance Collection Sr. Executive

MiniMed Group • Pune District

On-site
INR 450,000 - 650,000
Insurance Verification Sr. Executive
Insurance Verification Sr. Executive

MiniMed Group • Pune District

On-site
INR 350,000 - 550,000
Senior Principal Information Security Risk Specialist
Senior Principal Information Security Risk Specialist

MiniMed • Maharashtra

On-site
INR 300,000 - 600,000
Flexible benefits package
Competitive salary
Insurance Verification Sr. Executive
Insurance Verification Sr. Executive

IND-Medtronic MiniMed India Private Limited • Pune District

On-site
INR 520,000 - 750,000
Prin Graphic Designer
Prin Graphic Designer

IND-Medtronic MiniMed India Private Limited • Pune District

On-site
INR 600,000 - 1,200,000
Executive - Insurance Collection
Executive - Insurance Collection

MiniMed Group • Pune District

On-site
INR 300,000 - 540,000
Senior Information Security Assurance Analyst
Senior Information Security Assurance Analyst

MiniMed • Maharashtra

On-site
INR 2,500,000 - 4,000,000
Competitive salary and benefits
Flexible benefits package
Prin Graphic Designer
Prin Graphic Designer

MiniMed Group • Pune District

On-site
INR 500,000 - 900,000
Sr Prin IT Technologist - Security Engineering
Sr Prin IT Technologist - Security Engineering

MiniMed Group • Pune District

On-site
INR 1,500,000 - 2,500,000
Competitive salary
Flexible benefits package