Closing Date: 19th September, 2026
Description:
We anticipate the application window for this opening will close on - 19 Sep 2026Careers that change lives start here. Medtronic is a global leader in healthcare technology with a Mission to alleviate pain, restore health, and extend life. Our 95,000 employees work across more than 150 countries to put patients first — developing innovative medical technologies that improve the lives of 72+ million patients each year. Your unique talents will help shape the future of healthcare while building a career grounded in purpose, growth, and impact.
A day in the life:
The Medtronic Legal function partners across the enterprise to enable business objectives while managing legal and regulatory risk. This role sits within the legal team supporting Global Information Technology (IT) and cybersecurity matters, serving as a strategic advisor to enterprise leaders responsible for information security, cyber resilience, product security, privacy, compliance, and risk management. The position provides legal guidance across Medtronic's global operations, helping drive cybersecurity governance, regulatory compliance, incident preparedness, third-party risk management, and secure business transformation initiatives.
This position may be based in Minneapolis, Minnesota or Washington, D.C. and follows an onsite work model. Travel up to 25% may be required, primarily to Medtronic facilities to support business and legal priorities.
Serve as a trusted legal advisor on enterprise cybersecurity, information security, and technology risk matters across a global healthcare technology organization. This role partners closely with Global IT leadership and cross-functional stakeholders to address evolving cybersecurity regulations, support strategic initiatives, manage legal risk, and help strengthen organizational cyber resilience.
Primary Responsibilities:
- Serve as the primary legal advisor to Global IT Information Security leadership on cybersecurity governance, regulatory compliance, enforcement matters, and enterprise risk management initiatives.
- Lead the development and enhancement of cybersecurity legal frameworks, policies, standards, governance processes, and internal controls supporting global operations.
- Advise business and functional leaders on cybersecurity considerations related to strategic initiatives, technology transformation efforts, and operational risk management.
- Support cybersecurity incident preparedness and response activities, including regulatory inquiries, investigations, audits, enforcement actions, and litigation matters.
- Conduct cybersecurity legal due diligence for mergers, acquisitions, divestitures, and other business development activities, including integration and separation planning.
- Counsel stakeholders on third-party cybersecurity risk, supply chain resilience, and contractual risk mitigation strategies aligned with regulatory and business requirements.
- Partner with product security, privacy, compliance, communications, and business counsel teams to support secure-by-design initiatives and enterprise cybersecurity programs.
- Monitor global cybersecurity regulatory, enforcement, and litigation developments and provide actionable guidance to business, legal, and compliance stakeholders.
Required Qualifications:
- Juris Doctor (J.D.) from a nationally recognized US law school and 8+ years of legal experience, including experience advising on cybersecurity, information technology, and privacy matters.
- Licensed to practice law and in good standing under the Bar of at least one state in the US or in Washington DC.
- Experience providing legal counsel on cybersecurity governance, compliance, regulatory, enforcement, and risk management matters.
- Experience advising cross-functional business and technology stakeholders on complex legal and operational cybersecurity issues.
Preferred Qualifications:
- Experience drafting, reviewing, and negotiating cybersecurity, information security, and third-party risk contractual provisions.
- Knowledge of global cybersecurity regulatory frameworks, investigations, audits, and enforcement trends.
- Experience supporting cybersecurity aspects of mergers, acquisitions, divestitures, or other business development activities.
- Ability to communicate complex cybersecurity and technology concepts effectively to executive leadership and non-technical stakeholders.
- Experience partnering with enterprise risk management, insurance, privacy, compliance, or product security teams within a global organization.
Physical Job Requirements
The above statements are intended to describe the general nature and level of work being performed by employees assigned to this position, but they are not an exhaustive list of all the required responsibilities and skills of this position.
The physical demands described within the Responsibilities section of this job description are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. For Office Roles: While performing the duties of this job, the employee is regularly required to be independently mobile. The employee is also required to interact with a computer, and communicate with peers and co-workers. Contact your manager or local HR to understand the Work Conditions and Physical requirements that may be specific to each role.
U.S. Work Authorization & Sponsorship
At Medtronic, we are committed to fostering an environment where employees can thrive and make a meaningful impact. In alignment with our enterprise-wide workforce planning approach, U.S. work authorization sponsorship (H-1B, TN, J, etc.) is offered exclusively for Principal-level roles and above, where specialized expertise aligns with long-term business needs. Roles below the Principal level require candidates to possess unrestricted U.S. work authorization at the time of hire and for the duration of employment.