Senior Principal Information Security Risk Specialist

mdtkangarooΒ· IND-Medtronic MiniMed India Private Limited
Apply Now β†—
πŸ“ Pune, Maharashtra, IndiaFull time

About this role

At MiniMed, you can begin a lifelong career of exploration and innovation, while helping make a difference in the lives of people living with diabetes around the globe. You'll lead with purpose, breaking down barriers to innovation for a more connected, compassionate world.

About the Role

A Day in the Life

Our Global Diabetes Capability Center in Pune is expanding to serve more people living with diabetes globally. Our state-of-the-art facility is dedicated to transforming diabetes management through innovative solutions and Technologies that reduce the burden of living with diabetes.

This position is an exciting opportunity to work with Minimed’s Diabetes business. Medtronic has announced its intention to separate the Diabetes division to promote future growth and innovation within the business and reallocate investments and resources across Medtronic, subject to applicable information and consultation requirements. This separation provides our team with a bold opportunity to unleash our potential, enabling us to operate with greater speed and agility. As a separate entity, we anticipate leveraging increased investments to drive meaningful innovation and enhance our impact on patient care.

#BetterDaysStartNow

Responsibilities may include the following and other duties may be assigned.

Information Security Risk Management

  • Lead enterprise cybersecurity, technology, cloud, data, and AI risk assessments to identify, evaluate, prioritize, and monitor information security risks.

  • Maintain risk methodologies, scoring models, risk taxonomies, and the enterprise information security risk register.

  • Partner with risk owners to evaluate risk exposure, develop treatment strategies, document mitigation activities, and monitor remediation efforts.

  • Provide independent challenge and oversight of risk assessments, treatment plans, mitigation strategies, and risk acceptance recommendations.

  • Support continuous improvement of enterprise information security risk management processes, governance standards, and program maturity.

Cyber, Data & AI Risk Governance

  • Assess risks associated with cybersecurity, information protection, privacy, data governance, cloud services, emerging technologies, and artificial intelligence initiatives.

  • Support implementation of AI governance and risk management practices aligned to NIST AI RMF, ISO/IEC 42001, and organizational requirements.

  • Evaluate emerging threats, incidents, audit results, assessments, and control deficiencies to identify risk trends and opportunities for improvement.

  • Support secure adoption of technology and digital initiatives through risk-informed governance and advisory services.

Risk Reporting & Program Administration

  • Develop and maintain risk metrics, key risk indicators (KRIs), key performance indicators (KPIs), dashboards, governance reports, and program documentation.

  • Support administration, optimization, and continuous improvement of Governance, Risk & Compliance (GRC) technologies and risk management processes.

  • Provide risk reporting and analysis to support leadership decision-making, governance activities, and program effectiveness measurement.

Stakeholder Advisory & Collaboration

  • Partner with Information Security, Information Technology, Privacy, Compliance, Internal Audit, Legal, Enterprise Risk Management, and business stakeholders to support risk-informed decision-making.

  • Facilitate risk workshops, risk reviews, governance discussions, and remediation planning activities.

  • Serve as a trusted advisor and subject matter expert regarding information security risk management, cybersecurity governance, and emerging technology risk.

  • Communicate complex technical risks and recommendations to business, technical, and executive audiences.

Independence & Scope

This role operates as an independent second-line risk oversight function within the Information Security Governance, Risk & Compliance (InfoSec GRC) organization. The position is responsible for facilitating, assessing, monitoring, and reporting information security risks while providing objective challenge and oversight of risk management activities across the enterprise. The role maintains appropriate independence from operational control ownership, control execution, technology implementation, security operations, engineering activities, remediation ownership, and internal audit responsibilities.

Specialist Career Stream

Typically an individual contributor recognized as a subject matter expert within Information Security Risk Management. Leads complex initiatives, influences risk management practices, and provides guidance to less experienced professionals while driving continuous improvement of enterprise risk management capabilities.

Differentiating Factors

Autonomy

  • Recognized subject matter expert operating with significant independence.

  • Applies advanced judgment to complex cybersecurity, technology, data, and artificial intelligence risk scenarios.

Organizational Impact

  • Influences enterprise risk management practices, governance processes, and leadership decision-making.

  • Contributes directly to organizational risk transparency, governance effectiveness, and program maturity.

Innovation & Complexity

  • Evaluates complex cyber, technology, cloud, data, and AI risks requiring analysis of technical, operational, regulatory, and business considerations.

  • Develops practical risk management solutions, governance improvements, and strategic recommendations.

Communication & Leadership

  • Communicates effectively with technical, business, and executive stakeholders.

  • Leads cross-functional risk initiatives and mentors less experienced professionals.

Required Knowledge & Experience

  • Bachelor's degree and a minimum of 10 years of relevant experience, an advanced degree with a minimum of 8 years of relevant experience, or an equivalent combination of education and experience.

  • Expertise in Information Security Risk Management, cybersecurity governance, technology risk management, Governance, Risk & Compliance (GRC), information assurance, enterprise risk management, audit, or related disciplines.

  • Experience executing risk assessments, maintaining risk registers, administering risk methodologies, evaluating mitigation effectiveness, and supporting governance processes.

  • Strong understanding of cybersecurity, cloud computing, artificial intelligence, privacy, data governance, regulatory compliance, and emerging technology risks.

  • Experience facilitating risk workshops and translating complex technical findings into business-focused risk recommendations.

  • Experience supporting risk quantification, business impact analysis, and risk treatment decision-making processes.

  • Strong analytical, communication, facilitation, and stakeholder management skills.

Preferred Qualifications

  • Experience supporting enterprise Information Security Risk Management Programs within large, complex, or global organizations.

  • Experience developing risk dashboards, KRIs, KPIs, executive reporting, governance metrics, and risk heat maps.

  • Experience supporting cyber risk quantification programs utilizing FAIR methodologies or similar quantitative risk models.

  • Experience facilitating cyber, cloud, data, artificial intelligence, and technology risk assessments.

  • Experience supporting AI governance initiatives and implementation of NIST AI RMF and ISO/IEC 42001.

  • Experience integrating cybersecurity, privacy, AI governance, data governance, and risk management practices into enterprise governance frameworks.

  • Experience within healthcare, medical technology, life sciences, manufacturing, or other highly regulated industries.

  • Experience working with ServiceNow IRM, SAP GRC, AuditBoard, or similar GRC technologies.

  • Knowledge of NIST CSF, RMF, ISO/IEC 27001, ISO/IEC 31000, ISO/IEC 42001, HIPAA, NIS2, and related privacy and regulatory frameworks.

Preferred Certifications

  • CRISC

  • CISSP

  • CISM

  • CISA

  • CGRC

  • Open FAIR Foundation or Open FAIR Practitioner

  • ISO/IEC 27001 Lead Implementer or Lead Auditor

  • ISO/IEC 42001 Artificial Intelligence Management Systems Certification

  • AI Governance, AI Assurance, Responsible AI, or Emerging Technology Risk Certifications

Physical Job Requirements

The above statements are intended to describe the general nature and level of work being performed by employees assigned to this position, but they are not an exhaustive list of all the required responsibilities and skills of this position.

Benefits & Compensation

MiniMed offers a competitive salary and flexible benefits package

At MiniMed, we put people first. A commitment to our employees lives at the core of our values: We recognize their contributions. They share in the success they help create. We offer a wide range of benefits, resources, and competitive compensation plans designed to support you at every stage of your career and life.


Β 

About MiniMed

We want to make every day a better day for people living with diabetes. Our team of creative innovators around the globe share a passion for finding the simplest solutions to the problems that people with diabetes face on a daily basis. For more than 40 years, we've been redefining what's possible, from intelligent dosing systems designed for real life to predictive insights that stay a step ahead, and we're dedicated to continuing to support our customers through every step of their journey β€” meeting them where and how they need it.

Frequently Asked Questions

Is the salary disclosed for the Senior Principal Information Security Risk Specialist position at mdtkangaroo?
The salary for this Senior Principal Information Security Risk Specialist role at mdtkangaroo is not publicly listed. Click "Apply Now" to learn more about the compensation package on their official careers page.
Where is the Senior Principal Information Security Risk Specialist position at mdtkangaroo located?
This Senior Principal Information Security Risk Specialist role at mdtkangaroo is based in Pune, Maharashtra, India. The position is listed as on-site or hybrid. Check the full job description or apply directly to confirm the work arrangement.
Is the Senior Principal Information Security Risk Specialist role at mdtkangaroo full-time or part-time?
This is listed as a Full time position. It is posted as a Senior Principal Information Security Risk Specialist role in the IND-Medtronic MiniMed India Private Limited department at mdtkangaroo.
Which team or department does the Senior Principal Information Security Risk Specialist at mdtkangaroo belong to?
This Senior Principal Information Security Risk Specialist position is part of the IND-Medtronic MiniMed India Private Limited department at mdtkangaroo. See the full job description for more information about the team structure and responsibilities.
How do I apply for the Senior Principal Information Security Risk Specialist position at mdtkangaroo?
Click the "Apply Now" button on this page. You will be redirected to mdtkangaroo's official application portal hosted on workday where you can submit your application directly.
When was the Senior Principal Information Security Risk Specialist job at mdtkangaroo posted?
This Senior Principal Information Security Risk Specialist position at mdtkangaroo was posted on Aug 12, 2026. Apply as soon as possible β€” early applications are often reviewed first.
Senior Principal Information Security Risk Specialist
mdtkangaroo
Apply for this role β†—

You'll be redirected to mdtkangaroo's official application page on Workday.