Principle Cybersecurity Specialist
Medtronic
- Location
- Nanakramguda, Hyderabad, India
- Work model
- On-Site
- Level
- Staff
- H-1B history
- 106 approvals (FY2023)
- Posted
- 8h ago
Skills
About this role
Careers that change lives start here. Medtronic is a global leader in healthcare technology with a Mission to alleviate pain, restore health, and extend life. Our 95,000 employees work across more than 150 countries to put patients first — developing innovative medical technologies that improve the lives of 72+ million patients each year. Your unique talents will help shape the future of healthcare while building a career grounded in purpose, growth, and impact. A Day in the Life The Identity Lifecycle and Governance team is responsible for how users within an organization are given an identity, and how it is protected, which includes securing critical applications, data, and systems from unauthorized access while managing the identities and access rights of people the organization. The Principal Identity Governance Specialist is the senior technical resource with a primary focus on access certifications, entitlement governance, and audit readiness. Responsible for solution design, delivery and management of Access Governance processes, but also includes responsibility to ensure operational fitness of the system. Responsibilities may include the following and other duties may be assigned. Serve as the technical owner and is responsible for configuration of access certification and review program. Translate governance policies, regulatory requirements, and control objectives into scalable certification. Define integration requirements: Out-of-the-box and custom connectors API-based, file-based, database-based, and directory-based integrations Specify required attributes, aggregation rules, mappings, and correlation logic to support accurate certifications. Architect and configure: User, entitlement, role, and application certifications Reviewer assignment logic and delegation models Escalation paths, reminders, and completion SLAs Automated remediation and revocation workflows Review and approve changes impacting: Certification accuracy Control effectiveness Auditability or scalability Apply working knowledge of SQL and relational data structures to support reconciliation, reporting, and troubleshooting. Provide detailed technical explanations of certification logic, configurations, and automation to internal and external auditors. Collaborate with business and application teams to ensure governance requirements align with source system capabilities. Maintain configuration documentation, certification runbooks, and operational reporting. Continuously evaluate features and industry best practices to enhance certification effectiveness. Recommend governance and security enhancements to leadership based on risk, audit findings, and platform capabilities. Required Knowledge and Expertise: Bachelor’s degree / University degree 12+ years of IT experience with a Bachelor's Degree in Engineering, MCA, or MSc. with experience in Identity Governance & Administration (IGA) or IAM. Hands-on experience operating SailPoint Identity Security Cloud, with deep focus on access certifications and reviews. Strong expertise in: User, entitlement, and role certifications Identity correlation and aggregation Entitlement modeling and RBAC Familiarity with scripting or automation used alongside SailPoint (e.g., REST APIs, PowerShell). Experience with SailPoint integrations using connector-based, API-based, file-based, and database-backed approaches. Ability to analyze data quality issues that impact certification accuracy. Ability to clearly communicate certification design, risk, and evidence to audit, compliance, and business stakeholders.
NICE TO HAVE
Experience supporting identity lifecycle processes and deprovisioning workflows. Experience designing certification programs in large, complex, or regulated environments. Strong technical leadership and influence skills. Ability to establish and revise processes/documents based on new and changing security requirements. Demonstrated knowledge of information security policies, standards,