Principal Analyst, HR Technology Risk and Access Governance
Arden Hills, MN, US, 55112
Additional Location(s): US-MA-Marlborough; US-MN-Arden Hills; US-MN-Maple Grove
Diversity - Innovation - Caring - Global Collaboration - Winning Spirit - High Performance
At Boston Scientific, we’ll give you the opportunity to harness all that’s within you by working in teams of diverse and high-performing employees, tackling some of the most important health industry challenges. With access to the latest tools, information and training, we’ll help you in advancing your skills and career. Here, you’ll be supported in progressing – whatever your ambitions.
About the role:
At Boston Scientific, we are committed to protecting the integrity, confidentiality and operational reliability of our HR technology ecosystem while enabling efficient, scalable HR service delivery.
The Principal Analyst, HR Technology Risk and Access Governance will lead access governance, logical access controls, privileged access oversight, HRIS Sarbanes-Oxley readiness and sensitive employee data protection across SAP SuccessFactors and other in-scope HR platforms.
This role will translate control expectations, audit findings and privacy requirements into sustainable operating practices that reduce risk and strengthen HR systems governance. The Principal Analyst will partner with HR Operations, HR Technology, IT SOX, Cybersecurity, Identity and Access Management, Global Internal Audit, Privacy, Legal, Compliance and HR leadership to build effective access governance, role ownership, evidence and remediation processes across the employee lifecycle.
Boston Scientific was recently recognized as a Glassdoor Best Place to Work in 2026, ranking No. 15 on the Top 100 list, reflecting the culture our employees experience every day.
At Boston Scientific, we value collaboration and synergy. This role follows a hybrid work model requiring employees to be in our local office at least three days per week. Boston Scientific will not offer sponsorship or take over sponsorship of an employment visa for this position at this time. Relocation assistance is not available for this position at this time. This role may require up to 20% travel.
Your responsibilities will include:
- Establish and maintain the HR technology risk and access governance operating model, including governance forums, decision rights, responsibility matrices, escalation paths and control ownership.
- Translate SOX requirements, privacy expectations, audit findings and enterprise security standards into clear HR processes with defined evidence, accountability and sustainability requirements.
- Maintain a multiquarter roadmap for preventive controls, access lifecycle management, role governance, privileged access oversight and ongoing monitoring.
- Partner with HR Operations, HR Technology, IT, Security, Identity and Access Management, Internal Audit, Risk, Compliance, Legal and Privacy to align governance requirements, resolve control gaps and support audit readiness.
- Serve as the HR subject matter expert for access governance, HRIS control design, sensitive data protection, risk remediation and control self-assessments.
- Lead the design and continuous improvement of HR system access processes, including requests, approvals, provisioning, modifications, terminations, recertifications, exceptions and removals.
- Define and maintain access standards for HR employees, shared services, centers of excellence, HR business partners, managers, administrators, vendors, integrations, support roles, service accounts and privileged-access users.
- Maintain role ownership models and role catalogs for critical HR system roles, including role purpose, approved user populations, sensitive permissions, owners, approval criteria and review frequency.
- Strengthen controls for administrative access, emergency access, integration accounts, proxy access, vendor support and other elevated- or high-risk access.
- Ensure HR system access is appropriately approved, justified, traceable, monitored, periodically reviewed, supported by evidence and removed when no longer required.
- Identify and remediate access risks, including excessive permissions, inherited access, incompatible role combinations, inactive or terminated users, shared accounts, insufficient business justification and gaps identified through audits, testing or control self-assessments.
- Serve as a key HR partner for HRIS-related IT SOX controls, including control design, documentation, operating effectiveness, evidence quality and remediation.
- Partner with IT SOX, control owners, HR Technology and Internal Audit to define control objectives, narratives, risk-control matrices, test procedures and evidence standards.
- Build and maintain a control calendar for recurring access reviews, privileged-access reviews, role-owner attestations, access exceptions and evidence collection.
- Ensure HR control execution is timely, complete, consistent and ready for internal and external audit review.
- Conduct root-cause analyses for control failures and implement sustainable corrective actions.
- Partner with Privacy, Legal, Security, HR Technology and HR process owners to strengthen governance over sensitive employee data.
- Define access principles for sensitive HR data, including need-to-know access, data minimization, role-based visibility and review of sensitive reports or extracts.
- Support privacy-by-design reviews for HR technology changes, integrations, expanded access requests, reporting needs and downstream uses of HR data.
- Establish governance for sensitive reports, mass data exports, vendor access, confidential employee populations and restricted data domains.
- Lead or support remediation workstreams related to access governance, privileged access, role assignments, logical access controls and HRIS control discipline.
- Translate audit findings into remediation plans with clear owners, due dates, dependencies, evidence requirements, milestones and executive-level reporting.
- Validate that remediation actions address root causes and are embedded into standard operating processes.
- Develop standard operating procedures, control procedures, role-review playbooks, access-review instructions, evidence templates and training materials.
- Maintain an issues-and-actions log for HR technology risks, governance gaps, control deficiencies, exceptions and remediation commitments.
- Establish dashboards and key performance indicators for access-review completion, exception aging, privileged-access counts, control execution, evidence quality, remediation progress and recurring issues.
- Conduct recurring quality reviews and identify opportunities for automation, simplification and improved control reliability.
- Present risks, tradeoffs, recommendations and remediation status to senior HR, HR Operations, HR Technology, IT, Security, Privacy and Internal Audit leaders.
- Evaluate emerging HR technology risks and recommend appropriate mitigation strategies.
- Coach HR Operations, HR Technology and control owners on access governance, SOX discipline, evidence quality and privacy-aware decision-making.
Required qualifications:
- Bachelor’s degree in human resources, information systems, business, risk management, finance, operations, computer science or a related field.
- Minimum of 8 years’ experience in HR technology, HR operations, access governance, audit remediation, controls, risk, compliance, identity and access management or enterprise systems governance.
- Experience working with SAP SuccessFactors, Workday, Oracle HCM, SAP HCM or a comparable enterprise HR platform.
- Hands-on experience with role-based access, privileged access, logical access controls, periodic access reviews, user lifecycle controls, role ownership and exception management.
- Working knowledge of SOX and IT general control environments, including control design, evidence requirements, operating effectiveness, audit walkthroughs, remediation plans and testing expectations.
- Strong analytical and problem-solving skills, with experience using data to identify risk, improve processes and strengthen control execution.
- Demonstrated ability to influence cross-functional stakeholders and drive alignment across teams without direct reporting authority.
- Strong written and verbal communication skills, with the ability to translate technical access and control issues into clear business implications.
- Experience managing multiple remediation workstreams, dependencies, risks and executive-level updates.
Preferred qualifications:
- Advanced degree in a related field.
- Experience working across HR, HR Technology, IT, Security, Finance, Compliance, Internal Audit, Legal and Privacy.
- Experience designing governance models and building supporting processes, documentation, evidence, dashboards and operating mechanisms.
- CISA, CRISC, CISM, CISSP, CIPM, CIPP, SAP SuccessFactors, PMP, Agile, Lean or Six Sigma certification.
Requisition ID: 632066
Minimum Salary: $106800
Maximum Salary: $202900
The anticipated compensation listed above and the value of core and optional employee benefits offered by Boston Scientific (BSC) – see www.bscbenefitsconnect.com—will vary based on actual location of the position and other pertinent factors considered in determining actual compensation for the role. Compensation will be commensurate with demonstrable level of experience and training, pertinent education including licensure and certifications, among other relevant business or organizational needs. At BSC, it is not typical for an individual to be hired near the bottom or top of the anticipated salary range listed above.
Compensation for non-exempt (hourly), non-sales roles may also include variable compensation from time to time (e.g., any overtime and shift differential) and annual bonus target (subject to plan eligibility and other requirements).
Compensation for exempt, non-sales roles may also include variable compensation, i.e., annual bonus target and long-term incentives (subject to plan eligibility and other requirements).
For MA positions: It is unlawful to require or administer a lie detector test for employment. Violators are subject to criminal penalties and civil liability.
Boston Scientific transforms lives through innovative medical technologies that improve the health of patients around the world. As a global medical technology leader for more than 45 years, we advance science for life by providing a broad range of high-performance solutions that address unmet patient needs and reduce the cost of healthcare. Our portfolio of devices and therapies helps physicians diagnose and treat complex cardiovascular, respiratory, digestive, oncological, neurological and urological diseases and conditions. Learn more at www.bostonscientific.com and follow us on LinkedIn.
Boston Scientific Corporation has been and will continue to be an equal opportunity employer. To ensure full implementation of its equal employment policy, the Company will continue to take steps to assure that recruitment, hiring, assignment, promotion, compensation, and all other personnel decisions are made and administered without regard to race, religion, color, national origin, citizenship, sex, sexual orientation, gender identity, gender expression, veteran status, age, mental or physical disability, genetic information or any other protected class.
Please be advised that certain US based positions, including without limitation field sales and service positions that call on hospitals and/or health care centers, require acceptable proof of COVID-19 vaccination status. Candidates will be notified during the interview and selection process if the role(s) for which they have applied require proof of vaccination as a condition of employment. Boston Scientific continues to evaluate its policies and protocols regarding the COVID-19 vaccine and will comply with all applicable state and federal law and healthcare credentialing requirements. As employees of the Company, you will be expected to meet the ongoing requirements for your roles, including any new requirements, should the Company’s policies or protocols change with regard to COVID-19 vaccination.
Nearest Major Market: Minneapolis
Job Segment:
HRIS, Internal Audit, Information Systems, HR, Lean Six Sigma, Human Resources, Finance, Technology, Management