At Medtronic you can begin a life-long career of exploration and innovation, while helping champion healthcare access and equity for all. You’ll lead with purpose, breaking down barriers to innovation in a more connected, compassionate world.
In this pivotal role as Principal – Cybersecurity (OT), you will be responsible for developing, implementing, and managing IT security measures to protect the organization’s manufacturing and distribution environments. This role requires an understanding of both IT and OT security principles, extensive experience in cybersecurity, and the ability to collaborate across various departments to ensure the protection of the manufacturing sites.
Responsibilities may include the following and other duties may be assigned.
**A Day in the Life of an OT Security Leader**
The Principal - Cybersecurity (OT) refines the OT security strategy, mentors ’ peers , and site security champions, and integrates security into business strategies. They conduct risk assessments, implement mitigation strategies, and establish security policies. Aids in designing secure OT network architectures, ensuring regulatory compliance, and managing incident responses are key tasks. They collaborate with stakeholders, communicates security risks, and participates in industry forums. They develop and champion security awareness programs, train personnel, and promote a security-focused culture. Manage the OT security budget and planning, overseeing procurement, and evaluating vendor relationships ensure efficient resource allocation and robust security measures. Specifically, responsibilities include:
Strategic Leadership and Planning:
- Collaborate to develop and execute a comprehensive OT security strategy aligned with the organizational goals and industry best practices.
- Lead the OT security champions, providing direction, mentorship, and professional development.
- Collaborate with senior management to integrate OT security into overall business strategies and objectives.
Risk management and Assessment:
- Conduct risk assessments and vulnerability analysis for the OT environment.
- Develop and implement risk mitigation strategies to address identified vulnerabilities.
- Establish and enforce security policies, procedures, and standards specific to OT systems.
Security Architecture and Design:
- Aid in design and implement secure OT network architectures, ensuring segmentation and protection of critical assets.
- Evaluate and recommend security technologies and solutions for OT environments.
- Ensure that security designs comply with regulatory requirements and industry standards (e.g. NIST 800-82, IEC 62443)
Incident Response and Management
- Develop and maintain and OT incident response plan.
- Lead the response to OT security incidents, including investigation, containment, eradication, and recovery.
- Coordinate with IT security and other departments during incident response efforts.
Compliance and Governance
- Ensure compliance with relevant regulations, standards, and guidelines related to OT security (e.g., NIST, NERC CIP)
- Conduct regular audits and assessments to verify compliance and identify areas for improvement.
- Report on OT security performance metrics and compliance status to executive management.
Collaboration and communication
- Foster strong relationships with key stakeholders, including engineering, operations, IT, and external partners.
- Communicate OT security risks, strategies, and initiatives to both technical and non-technical audiences.
- Participate in industry forums, working groups, and conferences to stay current with emerging trends and threats in OT security.
Training and awareness
- Develop and deliver OT security awareness programs for employees and contractors.
- Ensure that OT personnel are trained on security policies, procedures, and best practices.
- Promote a culture of security awareness and continuous improvement within the organization.
Budgeting and Resource management
- Manage the OT security budget, ensuring efficient allocation of resources.
- Oversee the procurement of security tools, technologies, and services.
- Evaluate and manage relationships with external vendors and service providers.
Required Knowledge and Expertise:
- Bachelor’s degree with min 13+ years of cybersecurity experience.
NICE TO HAVE:
- Strongly Preferred:
- Previous Medtronic experience
- Experience with ICS systems and other OT environments.
- Experience developing and implementing OT security strategies and programs.
- Certifications:
- Relevant certifications such as CISA, CISSP, CISM, GICSP or equivalent.
- Skills:
- Knowledge of OT security frameworks, standards, and regulations.
- Leadership, project management and communications skills.
- Ability to analyze complex security issues and develop effective solutions.
Familiarity with risk management methodologies and tools.
-
Physical Job Requirements
The above statements are intended to describe the general nature and level of work being performed by employees assigned to this position, but they are not an exhaustive list of all the required responsibilities and skills of this position.
Medtronic offers a competitive Salary and flexible Benefits Package
A commitment to our employees lives at the core of our values. We recognize their contributions. They share in the success they help to create. We offer a wide range of benefits, resources, and competitive compensation plans designed to support you at every career and life stage.
This position is eligible for a short-term incentive called the Medtronic Incentive Plan (MIP).
We lead global healthcare technology and boldly attack the most challenging health problems facing humanity by searching out and finding solutions.
Our Mission — to alleviate pain, restore health, and extend life — unites a global team of 95,000+ passionate people.
We are engineers at heart— putting ambitious ideas to work to generate real solutions for real people. From the R&D lab, to the factory floor, to the conference room, every one of us experiments, creates, builds, improves and solves. We have the talent, diverse perspectives, and guts to engineer the extraordinary.
Learn more about our business, mission, and our commitment to diversity here