Senior Information Security GRC Lead (SOX & SAP)

MiniMed

Town of Texas (WI)

On-site

USD 129,000 - 193,000

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Health insurance
401(k) match
Paid time off

Job summary

MiniMed seeks a Senior Information Security Governance, Risk & Compliance Analyst to enhance enterprise governance, risk, and compliance across SAP GRC and SOX ITGC in a global medical technology setting.

The role partners with IT, Privacy, Legal, Finance, Internal Audit, and business stakeholders to assess risks, monitor controls, and mature governance practices with independent second-line oversight.

Qualifications

  • Bachelor’s degree in Information Security, Cybersecurity, Information Systems, Risk Management, or related field.
  • Minimum 7 years of experience in Information Security GRC, Information Security Risk Management, SOX ITGC Compliance, Internal Audit, External Audit, Access Governance, Identity Governance, SAP Security Governance, Compliance Management, or Internal Controls Management.
  • Requires advanced knowledge of Information Security GRC, access governance, regulatory compliance, risk management, and internal controls.
  • Requires strong understanding of SAP GRC Access Control and SAP GRC Process Control administration. Typically obtained through advanced education combined with significant professional experience in information security, compliance, governance, risk management, audit, or internal controls.
  • Current SAP Certified Application Associate, SAP Access Control certification required.
  • Current SAP GRC Process Control certification required.

Responsibilities

  • Coordinate and manage enterprise Segregation of Duties governance across SAP and other key enterprise platforms.
  • Administer SAP GRC Access Control capabilities, including Access Risk Analysis, Access Request Management, Emergency Access Management, and Business Role Management.
  • Maintain SoD rulesets, risk functions, mitigating controls, access governance documentation, and related control evidence.
  • Assess access risks, including SoD conflicts, excessive entitlements, privileged access exposure, and control effectiveness concerns.
  • Monitor access-related exceptions, remediation plans, compensating controls, metrics, and trends to support risk reduction and compliance obligations.
  • Partner with application owners, IAM, SAP Security, and business stakeholders to evaluate and address identified access governance risks.
  • Coordinate and manage periodic User Access Reviews and access certification activities.
  • Monitor completion rates, overdue certifications, and non-compliance issues in accordance with governance requirements.
  • Support oversight of privileged access, emergency access, Firefighter governance, and related monitoring activities.
  • Review privileged access activity and maintain evidence supporting user access governance controls.
  • Administer and support SAP GRC Process Control activities used to monitor, assess, and validate SOX IT General Controls and security compliance requirements.
  • Support SOX ITGC compliance execution, control monitoring, audit evidence collection, validation, retention, and reporting.
  • Assist control owners and stakeholders with control procedures, evidence requirements, deficiencies, findings, remediation tracking, and closure activities.
  • Develop dashboards, metrics, and reporting to support management self-assessment, continuous control monitoring, and control effectiveness improvements.
  • Support internal audits, external audits, and regulatory assessments by coordinating evidence, documentation, walkthroughs, and audit responses.
  • Maintain audit-ready documentation repositories and supporting records.
  • Monitor remediation activities and validate completion of corrective actions.
  • Perform control assurance activities by reviewing evidence completeness, control execution, and remediation effectiveness.
  • Support the development, implementation, and maintenance of information security policies, standards, procedures, governance processes, and control frameworks.
  • Support control inventory management, exception management, compliance reporting, GRC tool administration, workflows, dashboards, and reporting capabilities.
  • Develop compliance and risk metrics to monitor program effectiveness and identify opportunities for process improvement, automation, and control optimization.
  • Contribute to scalable governance standards, operational procedures, and compliance monitoring practices that strengthen enterprise security governance.
  • Assess cybersecurity, technology, artificial intelligence, data protection, and operational risks through structured risk assessment and governance processes.
  • Facilitate information security risk assessments supporting governance, compliance, and enterprise risk management activities.
  • Maintain risk registers, treatment plans, issue logs, action tracking, KRIs, risk dashboards, and management reporting.
  • Evaluate mitigation strategies and control implementation activities to support informed business and technology decision-making.
  • Partner with Information Security, Information Technology, Finance, Privacy, Internal Audit, Legal, Enterprise Risk Management, and business stakeholders.
  • Translate technical risks, access governance issues, and compliance requirements into clear, business-focused recommendations.
  • Facilitate assessments, workshops, compliance reviews, and cross-functional discussions to promote risk-informed decision-making.
  • Provide subject matter guidance on governance, compliance, access governance, risk management, and security control requirements.
  • This role provides oversight, monitoring, reporting, governance, compliance, risk management, and assurance activities while maintaining appropriate second-line independence.

Skills

SAP GRC
SOX ITGC
Access governance
Risk management
Compliance

Education

Bachelor’s degree in Information Security, Cybersecurity, Information Systems, Risk Management, or related field

Tools

SAP GRC Access Control
SAP GRC Process Control
SAP GRC Risk Management

Job description

MiniMed seeks a Senior Information Security Governance, Risk & Compliance Analyst to enhance enterprise governance, risk, and compliance across SAP GRC and SOX ITGC in a global medical technology setting.

The role partners with IT, Privacy, Legal, Finance, Internal Audit, and business stakeholders to assess risks, monitor controls, and mature governance practices with independent second-line oversight.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior GRC & SAP Security Analyst — SoD/SOX
Senior GRC & SAP Security Analyst — SoD/SOX

MiniMed • Georgia

On-site
USD 129,000 - 193,000
Senior SAP GRC & Security Risk Analyst
Senior SAP GRC & Security Risk Analyst

MiniMed • Los Angeles (CA)

On-site
USD 121,000 - 205,000
Health, dental, and vision insurance
401(k) with company match
Employee Stock Purchase Plan
+2
Senior Principal SAP GRC, SOX & ITGC Governance Lead
Senior Principal SAP GRC, SOX & ITGC Governance Lead

USA-Medtronic MiniMed, Inc 1017 • Los Angeles (CA)

On-site
USD 150,000 - 256,000
Health insurance
Dental insurance
Vision insurance
+4
Senior IT Audit Manager — Lead Global IT Controls & SOX
Senior IT Audit Manager — Lead Global IT Controls & SOX

USA-MiniMed Distribution Corp. 1018 • Los Angeles (CA)

On-site
USD 154,000 - 256,000
Health Insurance
401(k) with match
Short-term incentive (STI)
Senior SAP Security & GRC Lead (SOX & Compliance)
Senior SAP Security & GRC Lead (SOX & Compliance)

PVH Corp. • Bridgewater (MA)

On-site
USD 140,000 - 190,000
Senior IT Security & Risk Engineer - SOX Controls Lead
Senior IT Security & Risk Engineer - SOX Controls Lead

Cardinal Health • Salt Lake City (UT)

On-site
USD 125,000 - 179,000
Medical, dental and vision coverage
Paid time off
401k savings plan
+7
SAP Security Platform Lead - Risk & GRC Architect
SAP Security Platform Lead - Risk & GRC Architect

Mondelēz International • East Hanover (NJ)

On-site
USD 140,300 - 192,940
Senior IT GRC Director — Governance & Compliance
Senior IT GRC Director — Governance & Compliance

Commercial Metals • Irving (TX)

On-site
USD 150,000 - 210,000
Day 1 Benefits Coverage with low cost
401(k) company match
Bonuses
+3
Remote SAP Security & GRC Analyst IV
Remote SAP Security & GRC Analyst IV

V2X • United States

Hybrid
USD 110,000 - 175,000
Healthcare coverage
Paid time off
Retirement plan
+2
Sr. IT Security Analyst
Sr. IT Security Analyst

The Marzetti Company • Columbus (OH)

On-site
USD 90,000 - 120,000