Job Details:
Job Title: Technical Security Program Manager
Location: 100% Remote
Duration: 6+ months Contract (30 to 40 hours per week)
Description:
Resource Profile: Security Program Manager: MiniMed (Medtronic Diabetes Carve-Out)
The Ask
One technical program manager to take roughly 30 in-flight and planned hardening projects, turn them into one coherent program, drive the client''s internal teams to execute, and produce exec-ready reporting for the sponsor.
MiniMed is spinning out of Medtronic. We are already engaged there on identity, so we have a relationship and history. DLP and data cleanup program, and an environment hardening program covering endpoint, identity, awareness training, SIEM and logging, cloud, OT, and segmentation. Crown jewels in priority order: patient safety, PII, PHI, source code. Build to the most stringent of their overlapping regulations.
Other context: most of the infrastructure is still Medtronic''s. A large share of the backlog cannot be executed by MiniMed alone, so this person owns an ongoing Medtronic coordination track and has to confirm MiniMed inherits equivalent controls when it stands up its own systems.
Responsibilities
- Pressure-test the client''s project list and push back where sequencing or scope is wrong.
- Consolidate the workstreams into one program with real dependencies, not 30 isolated efforts.
- Prioritize the first three to six initiatives for months one through nine against the crown jewels.
- Own the coordination loop with each client team, plus the Medtronic track.
- Produce exec reporting the sponsor hands up unchanged. On track, delayed, complete, with reason and recovery path.
- Pull in AHEAD specialists through the hours pool where the client''s team hits a wall.
Must-Haves
- Technical breadth across identity, endpoint, data, network, and logging. Enough to challenge a client engineer''s answer and be right.
- The sniff test. When a client team says "the tool can''t do that," they need to recognize something may be off, take it away and look into it, and then call it out if warranted. Not an on-the-spot rebuttal. This is the hardest thing to staff for, and the client raised it directly.
- Real PM discipline. Plan construction, dependencies, RAID, holding other teams to dates without authority.
- Ability to materially improve a technical project plan, not just track it.
- Exec communication and client-facing polish. The interview is part of the sell.
- Regulated-industry experience. Healthcare or medical device ideal.
Nice-to-Haves
- Security cert paired with PM credentials, not PM alone.
- Carve-out or M&A separation experience where a parent still owns the estate.
- Practical DLP and data discovery exposure.
- CISA ZTMM as a structuring lens, with per-pillar maturity targets rather than a uniform score.
- HIPAA, PCI, NIST, ISO working knowledge.