Director of Identity and Access Management (IAM)
The application window for this opening will close on 15 Sep 2026.
About the role
The Global Cyber & Information Security Office protects Medtronic’s systems, data, products, and digital capabilities. Within this organization, the Identity & Access Management (IAM) function is responsible for strategy, governance, architecture, and delivery of enterprise identity services that enable secure access for employees, contractors, partners, applications, devices, and other digital identities across a complex global environment.
The Director of Identity and Access Management may be based in Minnesota or one of Medtronic’s major U.S. hub locations: Mounds View, Minnesota; Fridley, Minnesota (OHQ); Rice Creek, Minnesota; Boston, Massachusetts; Lafayette, Colorado; Irvine, California (UCI); Jacksonville, Florida; Fort Worth, Texas; Memphis, Tennessee; North Haven, CT.
This role follows an on-site work model with 4 days on-site and 1 day remote.
Responsibilities
- Define and execute the enterprise Identity and Access Management strategy, roadmap, and operating model aligned with cybersecurity, technology, and business priorities.
- Lead the end-to-end IAM portfolio, including workforce identity, identity governance and administration, privileged access management, authentication, authorization, and identity lifecycle services.
- Establish and maintain IAM architecture standards, policies, controls, and governance processes across global business and technology environments.
- Drive modernization of identity services through capabilities such as single sign-on, multifactor authentication, conditional access, role-based access controls, and least-privilege access models.
- Partner with technology, business, compliance, audit, privacy, and security stakeholders to integrate identity controls into enterprise processes and platforms.
- Oversee identity-related risk management, control remediation, audit responses, and incident response activities involving access misuse, credential compromise, or unauthorized access.
- Develop service management, vendor management, financial planning, performance metrics, and continuous improvement practices for IAM products and services.
- Build, lead, and develop a high-performing team while establishing clear accountability, delivery expectations, and operational excellence standards.
Required Qualifications
- 10+ years of experience with a bachelor’s degree or 8+ years of experience with an advanced degree.
- 7+ years of managerial experience.
- Leadership experience in Identity and Access Management, cybersecurity, infrastructure security, or a closely related discipline within a large, complex organization.
- Demonstrated experience leading enterprise-scale Identity and Access Management transformation initiatives across multiple business units, regions, and technology environments.
- Experience developing and implementing Identity and Access Management strategies, governance frameworks, and operating models that support business objectives and risk management requirements.
- Strong expertise in identity governance, authentication, authorization, privileged access management, access certification, identity lifecycle management, and least-privilege principles.
- Experience communicating technical risk, investment priorities, and program outcomes to executive leadership and key stakeholders.
Preferred Qualifications
- Master’s degree in Cybersecurity, Information Systems, Business Administration, or a related field.
- Professional certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified in Risk and Information Systems Control (CRISC), Certified Cloud Security Professional (CCSP), or comparable identity and cloud security certifications.
- Experience with enterprise Identity and Access Management platforms, Identity Governance and Administration (IGA), Privileged Access Management (PAM), Customer Identity and Access Management (CIAM), and Cloud Infrastructure Entitlement Management (CIEM) solutions.
- Experience implementing phishing-resistant authentication, conditional access, zero-trust access models, device trust, and modern authorization frameworks.
- Experience supporting regulated industries with complex compliance, privacy, security, and audit requirements, including healthcare, medical technology, or similarly regulated environments.
- For Baccalaureate degrees earned outside of the United States, a degree that satisfies the requirements of 8 C.F.R. 214.2(h)(4)(iii)(A) is required.
Pay
Salary range for U.S. (excluding Puerto Rico) locations: $183,200.00 – $274,800.00.
This position is eligible for a short-term incentive called the Medtronic Incentive Plan (MIP) and an annual long-term incentive plan.
The base salary range is applicable across the United States, excluding Puerto Rico and specific locations in California. The offered rate complies with federal and local regulations and may vary based on factors such as experience, certification/education, market conditions, and location.
Benefits
- Health, dental and vision insurance.
- Health Savings Account and Healthcare Flexible Spending Account.
- Life insurance and long-term disability leave.
- Dependent daycare spending account.
- Tuition assistance/reimbursement.
- Simple Steps (global well-being program).
- Incentive plans and 401(k) plan plus employer contribution and match.
- Short-term disability, paid time off, and paid holidays.
- Employee Stock Purchase Plan and Employee Assistance Program.
- Non-qualified Retirement Plan Supplement (subject to IRS earning minimums).
- Capital Accumulation Plan (available to Vice Presidents and above, or subject to IRS earning minimums).