About this role
Terumo Medical Corporation (TMC) develops, manufactures, and markets a complete, solutions-based portfolio of high-quality medical devices used in a broad range of applications for numerous areas of the healthcare industry. TMC places a premium on providing customers with world-class products, training and education programs that drive clear economic value, better clinical outcomes and improved quality of life for patients. TMC is part of Tokyo-based Terumo Corporation; one of the world’s leading medical device manufacturers with $6+ billion in sales, 30,000+ employees worldwide and operations in more than 160 nations. Terumo Medical Corporation is comprised of two strategic business divisions: Terumo Interventional Systems and Terumo Medical Products.
Job Summary
The Security Analyst specializes in data loss prevention, protecting Terumo's data at every stage of its lifecycle and ensuring access is controlled according to the company's information security principles. Working alongside IT, Cybersecurity, Legal, Compliance, and other teams, this role identifies and reduces data loss risks, puts safeguards in place against insider threats and breaches, and verifies that security controls align with company policies and risk management standards. When a data leakage event occurs or is suspected, the analyst partners closely with HR, Legal, and the affected business unit to investigate and resolve the situation.
Under broad supervision apply business insight and technical expertise within the area of information security for electronic and non-electronic means of storing, accessing, and exchanging information. Participate in a highly collaborative and diverse environment working closely with partners throughout the company and with the information-security professional community of practice.
Job Details/Responsibilities
- Serve as a key member of the Cybersecurity team, identifying, implementing, and maintaining data protection technical controls (DLP, data classification, data governance) across all Terumo business units and technology ecosystems, in line with business and compliance requirements.
- Collaborate with cross-functional teams and business units to understand their processes, plans, and risk tolerance, and to identify, assess, and mitigate data loss risks across the organization.
- Locate sensitive data to assess risk, document data protection policy exceptions, and periodically review them with business units.
- Monitor and investigate potential data loss incidents, including breaches, insider threats, and unauthorized data exfiltration.
- Recommend improvements that enforce least-privilege access and rigorous security practices while preserving user productivity and minimizing incentives to circumvent controls.
- Execute tactical requests that support the strategic vision for rigorous, scalable data protection controls.
- Stay current on emerging threats, adjusting DLP strategies and technologies accordingly.
- Perform analysis to assess potential and actual risks, threats, and vulnerabilities that pertain to the protection of company a) information that is proprietary, confidential and/or otherwise requires protection from unauthorized access, and b) electronic devices upon which the company or its associates rely, for business purposes, to be free from compromise in availability, reliability and security.
- Assess individual devices (servers, workstations, laptops, smartphones, network devices, etc.), departments, and network segments for security risks and standards compliance
- Understand and develop procedures to regulate access to computer data files and prevent unauthorized modification, destruction, and disclosure of information and maintain role-based access controls (RBAC).
- Work with service desk and development staffs to request programming changes. Plan data security for new or modified software, accommodating issues such as associate data access needs and risk of data loss or disclosure.
- Establish and maintain change and project management to support transition processes and constructing quality work plans and deliverables to meet communicated deadlines
- Research issues, problems or data security breaches and develop solutions to problems that are rare and unusually complex and creates new methods or processes
- Monitor security systems for potential incidents
Knowledge, Skills and Abilities (KSA)
- Experience with the architecture associated with a security operations center
- Experience with the implementation of encryption software
- Experience with security information and event management systems
- Experience implementing technical solutions in support of a defense-in-depth strategy
- Solution-oriented and analytical – comfortable navigating uncertainty, experimenting tactically to find a path forward, and breaking down complex data security issues to develop effective solutions.
- Data-driven – makes purposeful, timely decisions grounded in data.
- Customer-centric – responsive by nature, approaching all work with the end user's best interests in mind.
- Strong communication and interpersonal skills – conveys technical information clearly to both technical and non-technical audiences, anticipates others' information needs, adapts to different communication styles, and collaborates effectively with cross-functional teams.
- Regex and pattern development – able to write and test regular expression patterns for detecting sensitive data (e.g., credit card numbers, national IDs, keywords), with willingness to develop tuning skills that reduce false positives.
- DLP alert triage – able to review alerts, distinguish true from false positives, assess severity, escalate per established playbooks, and document findings accurately.
- Hands-on DLP tooling experience – practical experience with Data Loss Prevention tools and Data Governance technologies spanning network, endpoint, email, and cloud environments (e.g., Proofpoint, Cyberhaven, Varonis, CASB solutions, or comparable platforms).
- Advanced knowledge of the techniques used to cause, detect and prevent or remediate security problems and end-user devices, computers and network systems
- Demonstrated skill in performing post-incident computer forensics without destruction of critical data
- Sufficient technical expertise to recognize the applicability of emerging technologies to Terumo BCT’s business needs and to direct evaluations, cost/benefit analyses, and implementations of new technology
- Knowledge of security standards and experience in their implementation
- Ability to design, implement, operate and maintain technical solutions to information security-related problems
- Advanced knowledge of business protection systems and technology associated with information security
- Advanced knowledge of information security best practices and regulations
- Ability to install and configure security software in computer networks
- Knowledge and use of relevant PC software applications and skills to use them effectively
- Demonstrated ability to communicate effectively both verbally and in writing
Qualifications/ Background Experiences
- Bachelor’s degree or, equivalent of education and experience sufficient to successfully perform the essential functions of the job may be considered.
- Minimum 1 years’ experience
It is Terumo’s policy to provide equal employment opportunity to all its employees and applicants for employment regardless of their race, creed, color, national origin, age, ancestry, nationality, marital or domestic partnership or civil union status, sex, pregnancy, gender identity or expression, disability status, liability for military service, protected veteran status, sexual orientation, atypical cellular or blood trait, genetic information (including the refusal to submit to genetic testing), or any other category protected by law. As a Company, we value diversity of background and opinion, and prohibit discrimination or harassment on the basis of any legally protected class in the areas of hiring, recruitment, promotion, transfer, demotion, training, compensation, pay, fringe benefits, layoff, termination or any other terms and conditions of employment.
Final compensation packages may be higher or lower than what is listed, and will ultimately depend on factors including relevant experience, internal equity, skillset, knowledge, geography, education, business needs and market demand. We provide competitive and comprehensive benefit options which include: annual bonus, paid vacation, paid holidays, health, dental and vision benefits, 401(k), with matching contributions, tax advantage savings accounts, legal plan, voluntary life and AD&D insurance, voluntary long-term disability, short term disability, critical illness and accident insurance, parental leave, personal leave, tuition reimbursement, travel assistance, and an employee assistance program. Pay range: $61k - $86k