
Information Security Awareness Program Manager
Role summary
MiniMed is seeking an Information Security Awareness Program Manager to design, execute, and enhance its enterprise-wide cybersecurity awareness and training program. This role focuses on reducing human risk by influencing employee behavior, fostering a strong security culture, and ensuring regulatory compliance. The Program Manager will develop a multi-year strategy, transition training from compliance-focused to behavior-driven, and establish role-based training frameworks. Key responsibilities include leading phishing simulations, stakeholder engagement across various departments, managing awareness platforms and LMS integration, and reporting on key metrics to executive leadership and the board. The ideal candidate will have a minimum of 7 years of relevant experience or an advanced degree with 5 years of experience, preferably in regulated industries like healthcare.
We anticipate the application window for this opening will close on - 8 Apr 2026
At MiniMed, you can begin a lifelong career of exploration and innovation, while helping make a difference in the lives of people living with diabetes around the globe. You'll lead with purpose, breaking down barriers to innovation for a more connected, compassionate world.
About The Role
The Information Security Awareness Program Manager is responsible for designing, executing, and continuously improving the enterprise-wide cybersecurity awareness and training program. This role drives human risk reduction by influencing employee behavior, strengthening security culture, and ensuring compliance with regulatory and industry standards.
This leader partners across Security Operations, GRC, Privacy, HR, Legal, and IT to deliver targeted, role-based training and measurable outcomes aligned to enterprise risk objectives.
Responsibilities may include the following and other duties may be assigned.
Program Strategy & Leadership
- Develop and execute a multi-year Security Awareness & Human Risk Management strategy
- Transition the program from compliance-based training → behavior-driven risk reduction
- Establish role-based training frameworks (e.g., executives, engineers, clinicians, finance)
- Regulatory requirements (e.g., HIPAA, FDA pre/post-market guidance)
- Annual mandatory training
- Just-in-time and microlearning modules
- Phishing and social engineering simulations
- Secure software development (SSDLC)
- Medical device/product security
- Data privacy & PHI handling
- Phishing susceptibility rate (click rate)
- Report rate (user reporting of suspicious emails)
- Repeat offender trends
- Time-to-report metrics
- Build dashboards for: Executive leadership and Board/Audit Committee reporting
- Use data to drive targeted interventions
- Phishing Simulation & Behavioral Testing
- Lead enterprise phishing simulation program
- Design adaptive campaigns based on: Threat intelligence, user risk segmentation
- Integrate with: SOC (incident response feedback loop) and Email security platforms
- Stakeholder Engagement: Partner with: HR (onboarding/offboarding training), Legal/Privacy (regulatory alignment), Engineering/Product teams (secure development awareness) and Executive leadership (risk communication)
- Deliver executive briefings and board-level updates
- Compliance & Framework Alignment - ensure alignment with: ISO 27001 and HIPAA Security Rule (Security Awareness & Training)
- Support internal and external audits
- Technology & Vendor Management
- Manage awareness platforms
- Oversee LMS integration and reporting
- Evaluate and onboard new training technologies
Required Knowledge And Experience
Requires a Baccalaureate degree and minimum of 7 years of relevant experience, or advanced degree with a minimum of 5 years relevant experience.
Preferred Qualifications
- 5–8+ years in cybersecurity, with 3+ years in security awareness or human risk programs
- Experience in regulated industries (healthcare, medical devices, financial services)
- Proven track record building or maturing an enterprise awareness program
- Phishing/social engineering attack vectors
- Security operations and incident response workflows
- Identity and access management concepts
- Phishing simulation platforms
- Learning Management Systems (LMS)
- Data analytics and reporting tools (e.g., Power BI, Tableau)
- ISO 27001
- HIPAA Security Rule
- NIST NICE Workforce Framework (Awareness & Training roles
- CISSP, CISM, or CRISC
- Certified Security Awareness Practitioner (CSAP) or equivalent
- Behavioral science or psychology principles in security
- Human Risk Management (HRM) frameworks
The base salary range is applicable across the United States, excluding Puerto Rico and specific locations in California. The offered rate complies with federal and local regulations and may vary based on factors such as experience, certification/education, market conditions, and location. Compensation and benefits information pertains solely to candidates hired within the United States (local market compensation and benefits will apply for others).
Physical Job Requirements
The above statements are intended to describe the general nature and level of work being performed by employees assigned to this position, but they are not an exhaustive list of all the required responsibilities and skills of this position.
The physical demands described within the Responsibilities section of this job description are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. For Office Roles: While performing the duties of this job, the employee is regularly required to be independently mobile. The employee is also required to interact with a computer and communicate with peers and co-workers. Contact your manager or local HR to understand the Work Conditions and Physical requirements that may be specific to each role.
Benefits & Compensation
MiniMed offers a competitive salary and flexible benefits package
At MiniMed, we put people first. A commitment to our employees lives at the core of our values: We recognize their contributions. They share in the success they help create. We offer a wide range of benefits, resources, and competitive compensation plans designed to support you at every stage of your career and life.
Salary ranges for U.S (excl. PR) locations (USD):$150,400.00 - $225,600.00
This position is eligible for a short-term incentive called the Short Term Incentive (STI).
At MiniMed, we are committed to supporting the well-being and financial security of our employees. Regular employees working 20 or more hours per week are eligible for a robust benefits package, including health, dental, and vision insurance, as well as access to a Health Savings Account, Healthcare Flexible Spending Account, life insurance, long-term disability leave, and a dependent daycare spending account. In addition, all regular employees enjoy incentive plans, a 401(k) plan with company match, short-term disability coverage, paid time off and holidays, participation in our Employee Stock Purchase Plan, and access to our Employee Assistance Program. Eligible employees may also benefit from our Non-qualified Retirement Plan Supplement and Capital Accumulation Plan, subject to IRS minimum earnings requirements. Please note that “regular employees” refers to those who are not temporary staff, such as interns, and some benefits may not apply to employees in Puerto Rico.
For further details about our comprehensive benefits, we encourage you to visit the link below.
About MiniMed
MiniMed Benefits Overview
MiniMed is a full-stack insulin delivery company dedicated to supporting people living with diabetes through every step of their journey — when and how they need it. For more than 40 years, we’ve been committed to redefining what’s possible: intelligent dosing systems designed for real life, predictive insights that stay a step ahead, and always on support when it’s needed most. At the heart of everything we do is a simple Mission: to make every day a better day for people with diabetes.
Learn more about our business, and our mission here.
It is the policy of MiniMed to provide equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, sexual orientation, gender identity and/or expression, genetic information, marital status, familial status, membership or activity in a local human rights commission, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state, or local law. In addition, MiniMed will provide reasonable accommodations for qualified individuals with disabilities.
If you are applying to perform work for MiniMed in any position which will involve performing at least two (2) hours of work on average each week within the unincorporated areas of Los Angeles County, you can find here a list of all material job duties of the specific job position which MiniMed reasonably believes that criminal history may have a direct, adverse and negative relationship potentially resulting in the withdrawal of a conditional offer of employment. MiniMed will consider for employment qualified job applicants with arrest or conviction records in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act.