Principal Analyst, HR Technology Risk and Access Governance

Boston ScientificArden Hills, MN
$106,800 - $202,900Hybrid

About The Position

At Boston Scientific, we are committed to protecting the integrity, confidentiality and operational reliability of our HR technology ecosystem while enabling efficient, scalable HR service delivery. The Principal Analyst, HR Technology Risk and Access Governance will lead access governance, logical access controls, privileged access oversight, HRIS Sarbanes-Oxley readiness and sensitive employee data protection across SAP SuccessFactors and other in-scope HR platforms. This role will translate control expectations, audit findings and privacy requirements into sustainable operating practices that reduce risk and strengthen HR systems governance. The Principal Analyst will partner with HR Operations, HR Technology, IT SOX, Cybersecurity, Identity and Access Management, Global Internal Audit, Privacy, Legal, Compliance and HR leadership to build effective access governance, role ownership, evidence and remediation processes across the employee lifecycle.

Requirements

  • Bachelor’s degree in human resources, information systems, business, risk management, finance, operations, computer science or a related field.
  • Minimum of 8 years’ experience in HR technology, HR operations, access governance, audit remediation, controls, risk, compliance, identity and access management or enterprise systems governance.
  • Experience working with SAP SuccessFactors, Workday, Oracle HCM, SAP HCM or a comparable enterprise HR platform.
  • Hands-on experience with role-based access, privileged access, logical access controls, periodic access reviews, user lifecycle controls, role ownership and exception management.
  • Working knowledge of SOX and IT general control environments, including control design, evidence requirements, operating effectiveness, audit walkthroughs, remediation plans and testing expectations.
  • Strong analytical and problem-solving skills, with experience using data to identify risk, improve processes and strengthen control execution.
  • Demonstrated ability to influence cross-functional stakeholders and drive alignment across teams without direct reporting authority.
  • Strong written and verbal communication skills, with the ability to translate technical access and control issues into clear business implications.
  • Experience managing multiple remediation workstreams, dependencies, risks and executive-level updates.

Nice To Haves

  • Advanced degree in a related field.
  • Experience working across HR, HR Technology, IT, Security, Finance, Compliance, Internal Audit, Legal and Privacy.
  • Experience designing governance models and building supporting processes, documentation, evidence, dashboards and operating mechanisms.
  • CISA, CRISC, CISM, CISSP, CIPM, CIPP, SAP SuccessFactors, PMP, Agile, Lean or Six Sigma certification.

Responsibilities

  • Establish and maintain the HR technology risk and access governance operating model, including governance forums, decision rights, responsibility matrices, escalation paths and control ownership.
  • Translate SOX requirements, privacy expectations, audit findings and enterprise security standards into clear HR processes with defined evidence, accountability and sustainability requirements.
  • Maintain a multiquarter roadmap for preventive controls, access lifecycle management, role governance, privileged access oversight and ongoing monitoring.
  • Partner with HR Operations, HR Technology, IT, Security, Identity and Access Management, Internal Audit, Risk, Compliance, Legal and Privacy to align governance requirements, resolve control gaps and support audit readiness.
  • Serve as the HR subject matter expert for access governance, HRIS control design, sensitive data protection, risk remediation and control self-assessments.
  • Lead the design and continuous improvement of HR system access processes, including requests, approvals, provisioning, modifications, terminations, recertifications, exceptions and removals.
  • Define and maintain access standards for HR employees, shared services, centers of excellence, HR business partners, managers, administrators, vendors, integrations, support roles, service accounts and privileged-access users.
  • Maintain role ownership models and role catalogs for critical HR system roles, including role purpose, approved user populations, sensitive permissions, owners, approval criteria and review frequency.
  • Strengthen controls for administrative access, emergency access, integration accounts, proxy access, vendor support and other elevated- or high-risk access.
  • Ensure HR system access is appropriately approved, justified, traceable, monitored, periodically reviewed, supported by evidence and removed when no longer required.
  • Identify and remediate access risks, including excessive permissions, inherited access, incompatible role combinations, inactive or terminated users, shared accounts, insufficient business justification and gaps identified through audits, testing or control self-assessments.
  • Serve as a key HR partner for HRIS-related IT SOX controls, including control design, documentation, operating effectiveness, evidence quality and remediation.
  • Partner with IT SOX, control owners, HR Technology and Internal Audit to define control objectives, narratives, risk-control matrices, test procedures and evidence standards.
  • Build and maintain a control calendar for recurring access reviews, privileged-access reviews, role-owner attestations, access exceptions and evidence collection.
  • Ensure HR control execution is timely, complete, consistent and ready for internal and external audit review.
  • Conduct root-cause analyses for control failures and implement sustainable corrective actions.
  • Partner with Privacy, Legal, Security, HR Technology and HR process owners to strengthen governance over sensitive employee data.
  • Define access principles for sensitive HR data, including need-to-know access, data minimization, role-based visibility and review of sensitive reports or extracts.
  • Support privacy-by-design reviews for HR technology changes, integrations, expanded access requests, reporting needs and downstream uses of HR data.
  • Establish governance for sensitive reports, mass data exports, vendor access, confidential employee populations and restricted data domains.
  • Lead or support remediation workstreams related to access governance, privileged access, role assignments, logical access controls and HRIS control discipline.
  • Translate audit findings into remediation plans with clear owners, due dates, dependencies, evidence requirements, milestones and executive-level reporting.
  • Validate that remediation actions address root causes and are embedded into standard operating processes.
  • Develop standard operating procedures, control procedures, role-review playbooks, access-review instructions, evidence templates and training materials.
  • Maintain an issues-and-actions log for HR technology risks, governance gaps, control deficiencies, exceptions and remediation commitments.
  • Establish dashboards and key performance indicators for access-review completion, exception aging, privileged-access counts, control execution, evidence quality, remediation progress and recurring issues.
  • Conduct recurring quality reviews and identify opportunities for automation, simplification and improved control reliability.
  • Present risks, tradeoffs, recommendations and remediation status to senior HR, HR Operations, HR Technology, IT, Security, Privacy and Internal Audit leaders.
  • Evaluate emerging HR technology risks and recommend appropriate mitigation strategies.
  • Coach HR Operations, HR Technology and control owners on access governance, SOX discipline, evidence quality and privacy-aware decision-making.

Benefits

  • Relocation assistance is not available for this position at this time.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service