HistoSonics is a commercial-stage medtech company advancing the Edison® System, a novel non-invasive sonic beam therapy based on histotripsy. Since receiving FDA De Novo grant for the non-invasive destruction of liver tumors in 2023, the company has progressed beyond initial market entry into commercial expansion, reimbursement momentum, and ongoing clinical and pipeline development. In addition to its current liver tumor indication, HistoSonics is pursuing future indications across multiple applications including kidney, pancreas, prostate, neuro, women’s health, and other significant underserved human health areas, to realize the broader potential histotripsy across multiple disease states and medical specialties.
We offer an exciting work culture where cutting-edge science meets real-world application, and each team member’s contribution is important to our success in ensuring our physicians and their patients get what they need most.
Location: Plymouth, MN
Position Summary (Why this role matters):
The Principal Security Analyst, Governance Risk and Compliance is the senior-most individual contributor within the HistoSonics governance, risk, and compliance function and is a member of a larger, multi-site Information Systems and Security team that supports HistoSonics as a whole. This is a hybrid position based out of the Plymouth, MN office. The role owns the organization’s information security policy portfolio and Information Security Management System documentation, the mapping of internal ISO 27001 controls to the NIST Cybersecurity Framework, the resulting security maturity baseline and roadmap, third-party risk management, and security training and awareness. The Principal Security Analyst provides the primary execution behind the Information Systems partnership with Legal on privacy policy and data protection matters, a partnership owned by the Senior Director, Information Systems and Security. The role serves as the highest level of escalation for security governance, risk, and compliance matters and sets standards and practices for the function.
Key Responsibilities (What you’ll do):
Security Governance and Policy
- Own the organization’s information security policy portfolio and Information Security Management System documentation, including authorship, periodic review, approval routing, version control, and retirement of policies, standards, and procedures.
- Lead the transition of Information Security Management System ownership and administration into the Information Systems and Security organization, and administer the policy exception and risk acceptance process, including analysis, compensating control review, documented approval by the appropriate authority, expiration tracking, and reporting.
Framework Alignment and Security Maturity
- Maintain authoritative control mappings between the organization’s ISO 27001 control set, the NIST Cybersecurity Framework, and other standards or customer and regulatory requirements adopted by the organization, keeping mappings current as controls, systems, and standards change.
- Conduct recurring security maturity assessments using the mapped framework, produce the maturity baseline, and maintain a prioritized multi-year improvement roadmap with defined target states, owners, and measures of completion.
- Coordinate internal and external audits and certification activities, including scoping, evidence collection standards, auditor engagement, and tracking of findings and corrective actions through closure, and maintain the control inventory and control owner assignments, verifying that assigned controls operate and are evidenced as designed.
Risk Management and Third-Party Risk
- Own the enterprise information security risk register, including risk identification, analysis, scoring methodology, treatment planning, ownership assignment, and periodic reporting to leadership.
- Design, implement, and administer the third-party risk management program, including vendor intake and tiering, security questionnaires, review of attestations such as SOC 2 reports and ISO 27001 certificates, remediation tracking, periodic reassessment, and offboarding.
- Partner with Legal, Procurement, Quality, and business stakeholders on security and data protection terms in vendor agreements, and provide risk input to purchasing, renewal, and contract review decisions.
Security Training and Awareness
- Design, implement, and administer the enterprise security training and awareness program, including the awareness platform (KnowBe4 or comparable), annual and role-based training content, onboarding training, completion tracking, and audit evidence.
- Plan and execute the phishing simulation program, including campaign design, difficulty progression, and targeted follow-up training, own the user-facing suspicious message reporting workflow in coordination with security operations, and report program metrics and trends to leadership.
Privacy and Legal Partnership
- Serve as the primary Information Systems and Security resource to Legal on privacy matters, including privacy policy and notice development, data protection and business associate agreements, data inventory and mapping, data retention standards, and individual rights requests.
- In partnership with Legal, assess the privacy and regulatory implications of new systems, integrations, data flows, and vendor relationships, translate requirements including HIPAA and GDPR into implementable technical and administrative controls, and support security and privacy incident response from a governance perspective, including documentation, notification analysis with Legal, and corrective action tracking.
Leadership and Collaboration
- Serve as the final internal escalation point for security governance, risk, and compliance matters, and provide mentorship, work review, and knowledge transfer to current and future governance, risk, and compliance staff.
- Represent security governance and compliance in architecture reviews, change control, and project intake, provide requirements and risk input to Information Systems, Security, Quality, Regulatory, and the CTO organization, and support validation in alignment with the HistoSonics Quality Management System.
- Escalate cross-organizational governance conflicts, scope disputes, and resourcing trade-offs to the Senior Director, Information Systems and Security, and evaluate, recommend, and implement governance, risk, and compliance tooling, including assessment of functionality, security posture, integration requirements, and licensing costs.
Qualifications and Skills:
Required:
- Bachelor’s degree in Information Technology, Information Security, Computer Science, or a related field.Â
- 10+ years of progressive experience in information security governance, risk, and compliance, security audit, or a closely related discipline, including experience above senior level.
- Expert-level working knowledge of ISO 27001 and the NIST Cybersecurity Framework, including experience building and maintaining control mappings across frameworks, using them to produce defensible maturity assessments, and supporting internal and external audits and certification activities through evidence collection, auditor engagement, and closure of findings.
- Demonstrated experience owning an information security policy portfolio or Information Security Management System, including policy authorship, review cycles, exception handling, and control ownership.
- Demonstrated experience designing and running a third-party risk management program end to end, including vendor tiering, security assessment, attestation review, remediation tracking, and reassessment.
- Demonstrated experience owning a security training and awareness program, including administration of an awareness platform and design and execution of phishing simulation campaigns.
- Working knowledge of privacy requirements and their operational application, including HIPAA and GDPR, and experience partnering with Legal on privacy policy, contractual, and data protection matters.
- Sufficient technical depth across cloud platforms, enterprise identity and access management, endpoint management, and network and application security to assess control design and implementation and hold credible technical discussions with engineering staff.
Preferred:
- Experience ina regulated industry such as medical device, healthcare, or manufacturing, including familiarity with quality management system processes and validation.
- Experience administering a governance, risk, and compliance or compliance automation platform, responding to customer and partner security assessments, and supporting business continuity and disaster recovery governance.
- Relevant industry certifications are a plus.
Key Competencies:
- Strong analytical and problem-solving skills, with sound judgment in balancing risk, business objectives, and operational reality, and a bias toward durable documentation, repeatable process, and evidence-backed conclusions.
- Excellent communication and interpersonal skills, with the ability to explain security and privacy risk and trade-offs to technical and non-technical audiences, and to prioritize tasks and manage time effectively while working independently and as part of a team.
- Ability to set direction and influence outcomes across teams and departments without direct reporting authority.
Benefits:Â We offer a comprehensive benefits package for full-time employees. This includes health, dental, and vision insurance, life, short-term and long-term disability insurance, 401(k), paid time off, and more.
We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.
U.S. Work Authorization & Sponsorship: Employer will not sponsor visas for position.
#LI-hybrid
Learn more about this Employer on their Career Site
