Principal Security Analyst, Governance Risk, and Compliance

HISTOSONICS INCPlymouth, MN
$140,000 - $175,000Hybrid

About The Position

The Principal Security Analyst, Governance Risk and Compliance is the senior-most individual contributor within the HistoSonics governance, risk, and compliance function and is a member of a larger, multi-site Information Systems and Security team that supports HistoSonics as a whole. This is a hybrid position based out of the Plymouth, MN office. The role owns the organization’s information security policy portfolio and Information Security Management System documentation, the mapping of internal ISO 27001 controls to the NIST Cybersecurity Framework, the resulting security maturity baseline and roadmap, third-party risk management, and security training and awareness. The Principal Security Analyst provides the primary execution behind the Information Systems partnership with Legal on privacy policy and data protection matters, a partnership owned by the Senior Director, Information Systems and Security. The role serves as the highest level of escalation for security governance, risk, and compliance matters and sets standards and practices for the function.

Requirements

  • Bachelor’s degree in Information Technology, Information Security, Computer Science, or a related field.
  • 10+ years of progressive experience in information security governance, risk, and compliance, security audit, or a closely related discipline, including experience above senior level.
  • Expert-level working knowledge of ISO 27001 and the NIST Cybersecurity Framework, including experience building and maintaining control mappings across frameworks, using them to produce defensible maturity assessments, and supporting internal and external audits and certification activities through evidence collection, auditor engagement, and closure of findings.
  • Demonstrated experience owning an information security policy portfolio or Information Security Management System, including policy authorship, review cycles, exception handling, and control ownership.
  • Demonstrated experience designing and running a third-party risk management program end to end, including vendor tiering, security assessment, attestation review, remediation tracking, and reassessment.
  • Demonstrated experience owning a security training and awareness program, including administration of an awareness platform and design and execution of phishing simulation campaigns.
  • Working knowledge of privacy requirements and their operational application, including HIPAA and GDPR, and experience partnering with Legal on privacy policy, contractual, and data protection matters.
  • Sufficient technical depth across cloud platforms, enterprise identity and access management, endpoint management, and network and application security to assess control design and implementation and hold credible technical discussions with engineering staff.
  • Strong analytical and problem-solving skills, with sound judgment in balancing risk, business objectives, and operational reality, and a bias toward durable documentation, repeatable process, and evidence-backed conclusions.
  • Excellent communication and interpersonal skills, with the ability to explain security and privacy risk and trade-offs to technical and non-technical audiences, and to prioritize tasks and manage time effectively while working independently and as part of a team.
  • Ability to set direction and influence outcomes across teams and departments without direct reporting authority.

Nice To Haves

  • Experience in a regulated industry such as medical device, healthcare, or manufacturing, including familiarity with quality management system processes and validation.
  • Experience administering a governance, risk, and compliance or compliance automation platform, responding to customer and partner security assessments, and supporting business continuity and disaster recovery governance.
  • Relevant industry certifications are a plus.

Responsibilities

  • Own the organization’s information security policy portfolio and Information Security Management System documentation, including authorship, periodic review, approval routing, version control, and retirement of policies, standards, and procedures.
  • Lead the transition of Information Security Management System ownership and administration into the Information Systems and Security organization, and administer the policy exception and risk acceptance process, including analysis, compensating control review, documented approval by the appropriate authority, expiration tracking, and reporting.
  • Maintain authoritative control mappings between the organization’s ISO 27001 control set, the NIST Cybersecurity Framework, and other standards or customer and regulatory requirements adopted by the organization, keeping mappings current as controls, systems, and standards change.
  • Conduct recurring security maturity assessments using the mapped framework, produce the maturity baseline, and maintain a prioritized multi-year improvement roadmap with defined target states, owners, and measures of completion.
  • Coordinate internal and external audits and certification activities, including scoping, evidence collection standards, auditor engagement, and tracking of findings and corrective actions through closure, and maintain the control inventory and control owner assignments, verifying that assigned controls operate and are evidenced as designed.
  • Own the enterprise information security risk register, including risk identification, analysis, scoring methodology, treatment planning, ownership assignment, and periodic reporting to leadership.
  • Design, implement, and administer the third-party risk management program, including vendor intake and tiering, security questionnaires, review of attestations such as SOC 2 reports and ISO 27001 certificates, remediation tracking, periodic reassessment, and offboarding.
  • Partner with Legal, Procurement, Quality, and business stakeholders on security and data protection terms in vendor agreements, and provide risk input to purchasing, renewal, and contract review decisions.
  • Design, implement, and administer the enterprise security training and awareness program, including the awareness platform (KnowBe4 or comparable), annual and role-based training content, onboarding training, completion tracking, and audit evidence.
  • Plan and execute the phishing simulation program, including campaign design, difficulty progression, and targeted follow-up training, own the user-facing suspicious message reporting workflow in coordination with security operations, and report program metrics and trends to leadership.
  • Serve as the primary Information Systems and Security resource to Legal on privacy matters, including privacy policy and notice development, data protection and business associate agreements, data inventory and mapping, data retention standards, and individual rights requests.
  • In partnership with Legal, assess the privacy and regulatory implications of new systems, integrations, data flows, and vendor relationships, translate requirements including HIPAA and GDPR into implementable technical and administrative controls, and support security and privacy incident response from a governance perspective, including documentation, notification analysis with Legal, and corrective action tracking.
  • Serve as the final internal escalation point for security governance, risk, and compliance matters, and provide mentorship, work review, and knowledge transfer to current and future governance, risk, and compliance staff.
  • Represent security governance and compliance in architecture reviews, change control, and project intake, provide requirements and risk input to Information Systems, Security, Quality, Regulatory, and the CTO organization, and support validation in alignment with the HistoSonics Quality Management System.
  • Escalate cross-organizational governance conflicts, scope disputes, and resourcing trade-offs to the Senior Director, Information Systems and Security, and evaluate, recommend, and implement governance, risk, and compliance tooling, including assessment of functionality, security posture, integration requirements, and licensing costs.

Benefits

  • health, dental, and vision insurance
  • life, short-term and long-term disability insurance
  • 401(k)
  • paid time off
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service