Search by job, company or skills

Information Security Risk Advisor

6-8 Years
  • Posted 2 hours ago
  • Be among the first 10 applicants

Job Description

At MiniMed, you can begin a lifelong career of exploration and innovation, while helping make a difference in the lives of people living with diabetes around the globe. You'll lead with purpose, breaking down barriers to innovation for a more connected, compassionate world.

About The Role

The Information Security Risk Management Advisor is responsible for executing and continuously maturing the enterprise Information Security Risk Management Program. This role serves as a second-line risk advisor within the Information Security Governance, Risk, and Compliance (GRC) function and supports the implementation of risk management processes and activities across cybersecurity, technology, data, artificial intelligence (AI), and emerging technology domains.

Working under the direction of the InfoSec GRC Director, the Advisor partners with Information Security, Information Technology, Data Governance, Privacy, Compliance, Internal Audit, and business stakeholders to identify, assess, document, monitor, and track risk exposure. The role supports risk-informed decision-making through execution of risk assessments, maintenance of risk registers, development of risk metrics, monitoring of mitigation activities, and administration of risk governance processes while maintaining independence from operational control ownership, operational security functions, and testing activities.

The Advisor serves as a subject matter expert in information security risk management and supports the operationalization of risk methodologies, taxonomies, assessment frameworks, key risk indicators (KRIs), reporting processes, and governance standards established by the InfoSec GRC Director. The role also supports the integration of cybersecurity, data, and AI risk management practices into business and technology initiatives across the organization.

The Advisor supports the ongoing administration and maturity of risk management practices aligned with industry-leading frameworks and standards, including the NIST Cybersecurity Framework (CSF), NIST Artificial Intelligence Risk Management Framework (AI RMF), ISO/IEC 27001, ISO/IEC 31000, ISO/IEC 42001 Artificial Intelligence Management Systems (AIMS), FAIR, and other applicable frameworks supporting cyber, technology, data, and AI risk management.

Responsibilities may include the following and other duties may be assigned.

Develops, implements, administers, and continuously improves information security risk management processes, procedures, standards, and governance activities supporting the Information Security Risk Management Program.

Executes enterprise cybersecurity, technology, data, and artificial intelligence risk management activities in accordance with methodologies, governance standards, and program objectives established by the InfoSec GRC Director.

Maintains and administers cybersecurity, technology, information, data, and artificial intelligence risk assessment methodologies, risk taxonomies, scoring models, and supporting risk program documentation.

Leads and facilitates risk assessments across cybersecurity, information technology, enterprise applications, cloud services, infrastructure, digital platforms, data environments, artificial intelligence initiatives, and other technology-enabled business processes.

Maintains the enterprise information security risk register, ensuring risks are appropriately identified, assessed, documented, prioritized, assigned, monitored, escalated, and reported throughout their lifecycle.

Coordinates with risk owners to document mitigation plans, risk treatment activities, residual risk decisions, target completion dates, and status updates.

Partners with business leaders, technology teams, security stakeholders, and risk owners to evaluate risk exposure and recommend risk treatment strategies, including mitigation, transfer, acceptance, and avoidance options.

Provides independent challenge and oversight of risk assessments, treatment plans, and risk acceptance recommendations to ensure alignment with established risk management methodologies, governance expectations, and organizational risk appetite.

Develops, maintains, and monitors key risk indicators (KRIs), key performance indicators (KPIs), risk metrics, dashboards, and reporting artifacts used to support risk monitoring, governance activities, and program effectiveness measurement.

Maintains risk reporting data, metrics, dashboards, and supporting documentation used by the InfoSec GRC Director and Information Security leadership for governance, oversight, and reporting activities.

Assesses risks associated with information protection, data classification, access management, data governance, data retention, data sharing, data residency, integrity, availability, and protection of sensitive information.

Evaluates emerging technology and artificial intelligence risks, including governance, data protection, third-party dependencies, model integrity, transparency, explainability, human oversight, bias, and responsible-use considerations.

Develops and maintains governance processes supporting artificial intelligence risk management activities and advises stakeholders on alignment with applicable AI governance frameworks, standards, and regulatory expectations, including the NIST Artificial Intelligence Risk Management Framework (AI RMF) and ISO/IEC 42001 Artificial Intelligence Management Systems (AIMS).

Partners with Information Security, Privacy, Compliance, Internal Audit, Third-Party Risk Management, and business stakeholders to ensure risk information is appropriately integrated across governance, assurance, and risk management activities.

Provides risk-based advisory support for cybersecurity, privacy, regulatory, audit, and compliance initiatives, including risk-scoping activities associated with SOX, information security, data protection, and emerging regulatory requirements.

Analyzes risk events, incidents, audit findings, assessments, threat intelligence, control deficiencies, and industry trends to identify risk themes, emerging concerns, and opportunities for continuous improvement.

Supports implementation, optimization, and ongoing administration of Governance, Risk, and Compliance (GRC) technologies used to manage risk workflows, risk registers, reporting, metrics, and issue tracking.

Facilitates risk assessment workshops, risk reviews, and remediation discussions across business and technology functions to promote risk-informed decision-making and consistent application of risk management practices.

Supports the InfoSec GRC Director by maintaining risk information and documentation that may be leveraged for governance, compliance, audit, enterprise risk management, and leadership reporting purposes.

Maintains risk management procedures, standards, templates, workflows, and supporting documentation to ensure consistency and repeatability of program activities.

Serves as a subject matter expert and trusted advisor to stakeholders on information security risk management methodologies, governance processes, risk assessment activities, and emerging technology risks.

Scope Boundaries

This role is intentionally structured as a second-line risk management function and maintains clear separation from operational responsibilities.

This Role

  • Does not own or operate cybersecurity, information technology, privacy, or business controls.
  • Does not perform independent control testing or audit activities.
  • Does not own compliance programs, regulatory frameworks, or control inventories.
  • Does not own third-party risk assessments but incorporates relevant third-party risk information into enterprise risk management activities.
  • Does not independently approve risk acceptances but facilitates, documents, and supports risk acceptance decisions within established governance processes.
  • Does not own security operations, incident response, engineering, architecture, privacy operations, or technology implementation activities.
  • Does not own executive risk communications, board reporting, enterprise risk management engagement, or risk appetite and tolerance statements, which are the responsibility of the InfoSec GRC Director.

SPECIALIST CAREER STREAM

Typically an individual contributor with responsibility in a professional discipline or specialty. Delivers and manages projects and strategic initiatives assigned and works with stakeholders across the organization to achieve desired results. May act as a mentor to colleagues or provide guidance to less experienced professionals. The majority of time is spent executing, administering, and continuously improving Information Security Risk Management Program activities while leveraging specialized knowledge and skills acquired through advanced education and professional experience.

DIFFERENTIATING FACTORS

Autonomy

Recognized as a subject matter expert in Information Security Risk Management. Works independently to execute risk management activities, administer risk assessment processes, maintain risk artifacts, facilitate risk workshops, and support program objectives established by the InfoSec GRC Director. Exercises judgment in applying approved risk methodologies, governance standards, and assessment practices to complex cybersecurity, technology, data, and AI risk scenarios.

Organizational Impact

Contributes directly to the effectiveness and maturity of the Information Security Risk Management Program through execution of risk assessments, maintenance of risk registers and metrics, monitoring of remediation activities, administration of governance processes, and support of risk reporting activities. Provides risk analysis, recommendations, and operational support that enable effective risk management and informed decision-making across the organization.

Innovation and Complexity

Addresses complex cybersecurity, technology, information, data, and emerging technology risks requiring evaluation of technical, operational, regulatory, business, and governance considerations. Applies industry best practices and established methodologies to develop practical risk management solutions and recommendations.

Communication and Influence

Communicates risk concepts, assessment results, and treatment recommendations to technical and business stakeholders. Facilitates risk assessment workshops, risk reviews, and remediation discussions. Builds collaborative relationships across Information Security, Technology, Privacy, Compliance, Audit, and business functions to support effective and consistent risk management practices.

Leadership and Talent Management

Provides guidance, coaching, and mentorship regarding risk management methodologies, risk assessment processes, and governance practices. Leads operational risk management initiatives and coordinates cross-functional participation in risk assessments, remediation tracking, and governance activities.

Required Knowledge And Experience

Requires a Baccalaureate degree and a minimum of 8 years of relevant experience, or an advanced degree with a minimum of 6 years of relevant experience.

Requires extensive experience in information security risk management, cybersecurity governance, technology risk management, governance risk and compliance (GRC), enterprise risk management, internal audit, IT audit, or related disciplines.

Demonstrated experience executing risk assessments, maintaining risk registers, administering risk methodologies, tracking remediation plans, developing key risk indicators, and supporting governance processes.

Strong understanding of cybersecurity, information technology, cloud computing, artificial intelligence, information protection, data governance, privacy, and emerging technology risk domains.

Experience facilitating risk workshops and translating technical findings into business-focused risk statements and recommendations.

Experience supporting risk quantification, risk analysis, business impact analysis, and risk treatment decision-making processes.

Strong analytical, communication, facilitation, organizational, and stakeholder management skills.

Experience working with Governance, Risk, and Compliance (GRC) technologies and risk management platforms.

Experience maintaining risk registers, metrics, dashboards, issues, exceptions, and remediation tracking processes.

Preferred Qualifications

Experience within healthcare, medical technology, life sciences, manufacturing, or other highly regulated industries.

Knowledge of cybersecurity, risk management, data governance, and artificial intelligence governance frameworks including:

  • NIST Cybersecurity Framework (CSF)
  • NIST Risk Management Framework (RMF)
  • NIST Artificial Intelligence Risk Management Framework (AI RMF)
  • ISO/IEC 27001 Information Security Management Systems
  • ISO/IEC 31000 Risk Management
  • ISO/IEC 42001 Artificial Intelligence Management Systems (AIMS)
  • FAIR (Factor Analysis of Information Risk)
  • COSO Enterprise Risk Management (ERM)
  • Relevant privacy, data governance, and regulatory frameworks

Experience supporting artificial intelligence governance, responsible AI programs, AI risk assessments, or implementation of AI governance frameworks such as NIST AI RMF and ISO/IEC 42001.

Professional Certifications Such As

  • Certified in Risk and Information Systems Control (CRISC)
  • Certified Information Systems Security Professional (CISSP)
  • Certified Information Security Manager (CISM)
  • Certified Information Systems Auditor (CISA)
  • Certified in Governance, Risk and Compliance (CGRC)
  • Open FAIR Foundation or Open FAIR Practitioner
  • AI governance, AI assurance, or emerging technology risk certifications

Experience supporting cybersecurity, privacy, regulatory, audit, SOX, integrated risk management, or governance initiatives.

Experience working with Governance, Risk, and Compliance platforms such as ServiceNow IRM, RSA Archer, SAP GRC, AuditBoard, MetricStream, or similar solutions.

Reporting Relationship

Reports To: Director, Information Security Governance, Risk & Compliance (InfoSec GRC)

Function: Information Security Governance, Risk & Compliance

Role Type: Individual Contributor

Line of Defense: Second Line (Risk Oversight)

FLSA Status: Exempt

Summary Positioning

This role serves as the operational lead for the Information Security Risk Management Program, responsible for executing the day-to-day activities necessary to identify, assess, monitor, track, and report cybersecurity, technology, data, and AI risk. Strategic program direction, executive communications, board reporting, enterprise risk management engagement, and overall program accountability remain the responsibility of the InfoSec GRC Director.

Physical Job Requirements

The above statements are intended to describe the general nature and level of work being performed by employees assigned to this position, but they are not an exhaustive list of all the required responsibilities and skills of this position.

Benefits & Compensation

MiniMed offers a competitive salary and flexible benefits package

At MiniMed, we put people first. A commitment to our employees lives at the core of our values: We recognize their contributions. They share in the success they help create. We offer a wide range of benefits, resources, and competitive compensation plans designed to support you at every stage of your career and life.

About MiniMed

We want to make every day a better day for people living with diabetes. Our team of creative innovators around the globe share a passion for finding the simplest solutions to the problems that people with diabetes face on a daily basis. For more than 40 years, we've been redefining what's possible, from intelligent dosing systems designed for real life to predictive insights that stay a step ahead, and we're dedicated to continuing to support our customers through every step of their journey — meeting them where and how they need it.

More Info

Job Type:
Industry:
Employment Type:

About Company

Job ID: 152187297

Beware of Scammers

We don’t charge money for job offers