Apply now »

GRC Analyst, Cybersecurity

Boston Scientific's hybrid workplace includes remote and onsite roles. By applying to this position, you will have the opportunity to discuss your preferred working location with your Talent Acquisition Specialist.

Remote Eligible:  Remote in Country
Onsite Location(s): 

Marlborough, MA, US, 01752

Additional Location(s): US-MN-Arden Hills

Diversity - Innovation - Caring - Global Collaboration - Winning Spirit - High Performance

At Boston Scientific, we’ll give you the opportunity to harness all that’s within you by working in teams of diverse and high-performing employees, tackling some of the most important health industry challenges. With access to the latest tools, information and training, we’ll help you in advancing your skills and career. Here, you’ll be supported in progressing – whatever your ambitions.


About the role: 

Boston Scientific is seeking a Cybersecurity Analyst I to be part of the Global IT Cybersecurity, Governance Risk and Compliance team. This individual will support all Boston Scientific divisions (globally), overseeing processes to ensure existing and new enterprise IT systems and services meet cybersecurity, privacy, and risk requirements. Additionally, this role will be focused on monitoring and evaluating security controls, supporting audits for certification programs, risk and security assessments, supporting core documentation and compliance efforts, and helping review and enhance the security and compliance programs.

Your responsibilities will include:

  • Implement, maintain, and improve information security policies, standards, procedures, and controls to enable the business and assure compliance with relevant legal, regulatory, and contractual obligations. 
  • Facilitate regularly scheduled IT audit/compliance activities and follow up with responsible parties regarding outstanding requests and/or questions.
  • Maintain, organize, and store IT control testing evidence in preparation for upcoming scheduled audits.
  • Request, collect, review, and assess compliance reports from external organizations (i.e. SOC 2 type 2 reports).
  • Conduct information security risk assessments and security compliance audits throughout the IT organization.
  • Evaluate processes to determine adequacy of controls, compliance with policies and procedures, and comparison to leading practices.
  • Assess, document, and report security risks and control gaps.
  • Collaborate with business and IT leaders to ensure information security risk findings are reviewed and solutions are implemented.
  • Coordinate remediation efforts, and document exceptions as necessary.
  • Report findings to management and communicate recommendations for corrective actions.

What we're looking for: 
Required Qualifications

  • Bachelor's degree
  • 1-3 years Information security, compliance, or technology work experience.
  • Experience writing or interpreting technical and high-level risk reports.
  • Experience in developing, documenting, and maintaining security policies and procedures.
  • Understanding of concepts such as: information security and security governance, risk assessment and management, threat and vulnerability management, and identity and access management.
  • Experience with common Information Security management frameworks, such as: PCI-DSS 3.2.1, HIPAA, GDPR, SOX, ISO 27001/2, and NIST frameworks.
  • Strong understanding of Unix and Windows platforms 
  • Exceptional problem-solving skills.
  • Strong team skills with ability to listen and build consensus and collaborate with business, IT and Cybersecurity groups.

Preferred qualifications

  • CISA/CISM/CRISC or other Industry Certification
  • Strong knowledge of architectural principles, frameworks, design patterns and industry best practices for design and development
  • Hands-on experience with eGRC tools such as ServiceNow and RSA Archer
  • Experience in creating and maintaining security controls within cloud-based technologies, MSFT 365, Azure, and AWS
  • 1+ years of SAP IT general controls & privacy auditing, consulting and/or implementing



Requisition ID: 534633


As a leader in medical science for more than 40 years, we are committed to solving the challenges that matter most – united by a deep caring for human life. Our mission to advance science for life is about transforming lives through innovative medical solutions that improve patient lives, create value for our customers, and support our employees and the communities in which we operate. Now more than ever, we have a responsibility to apply those values to everything we do – as a global business and as a global corporate citizen.


So, choosing a career with Boston Scientific (NYSE: BSX) isn’t just business, it’s personal. And if you’re a natural problem-solver with the imagination, determination, and spirit to make a meaningful difference to people worldwide, we encourage you to apply and look forward to connecting with you!


At Boston Scientific, we recognize that nurturing a diverse and inclusive workplace helps us be more innovative and it is important in our work of advancing science for life and improving patient health. That is why we stand for inclusion, equality, and opportunity for all. By embracing the richness of our unique backgrounds and perspectives, we create a better, more rewarding place for our employees to work and reflect the patients, customers, and communities we serve. Boston Scientific is proud to be an equal opportunity and affirmative action employer.


Boston Scientific maintains a drug-free workplace. Pursuant to Va. Code § 2.2-4312 (2000), Boston Scientific is providing notification that the unlawful manufacture, sale, distribution, dispensation, possession, or use of a controlled substance or marijuana is prohibited in the workplace and that violations will result in disciplinary action up to and including termination.


Please be advised that certain US based positions, including without limitation field sales and service positions that call on hospitals and/or health care centers, require acceptable proof of COVID-19 vaccination status.  Candidates will be notified during the interview and selection process if the role(s) for which they have applied require proof of vaccination as a condition of employment.  Boston Scientific continues to evaluate its policies and protocols regarding the COVID-19 vaccine and will comply with all applicable state and federal law and healthcare credentialing requirements.   As employees of the Company, you will be expected to meet the ongoing requirements for your roles, including any new requirements, should the Company’s policies or protocols change with regard to COVID-19 vaccination.

Nearest Major Market: Boston

Job Segment: Compliance, Information Security, Unix, SAP, ERP, Legal, Technology

Apply now »