About this role
Careers that change lives start here. Medtronic is a global leader in healthcare technology with a Mission to alleviate pain, restore health, and extend life. Our 95,000 employees work across more than 150 countries to put patients first — developing innovative medical technologies that improve the lives of 72+ million patients each year. Your unique talents will help shape the future of healthcare while building a career grounded in purpose, growth, and impact.
# A Day in the Life
We’re a mission-driven leader in medical technology and solutions with a legacy of integrity and innovation. Work with us to incentivize better patient care and partner across the industry to make healthcare more affordable and accessible. Be a part of a community of experts committed to ensuring quality, affordable healthcare worldwide.
The Principal Cybersecurity Incident Responder is responsible for leading complex cyber incident investigations and protecting enterprise systems, data, and business operations across endpoint, identity, cloud, email, and network environments. As part of Medtronic's Global Forensics & Incident Response team, this role partners with Security Operations, Threat Intelligence, IT, Privacy, Legal, and business stakeholders to contain threats, reduce risk, and strengthen cybersecurity capabilities through incident response, forensic analysis, and continuous improvement.
This position is based onsite in Bogotá, Colombia and is ideal for professionals who thrive in a fast-paced environment, enjoy solving complex security challenges, and have a strong focus on collaboration, automation, and operational excellence.
Responsibilities may include the following and other duties may be assigned:
· Lead end-to-end cyber incident investigations, driving response activities from identification through resolution and post-incident review
· Investigate security alerts and suspicious activity across endpoint, identity, cloud, email, and network environments
· Utilize SIEM, CrowdStrike, EDR, XDR, and other security platforms to identify, investigate, and respond to cyber threats
· Conduct digital forensic investigations to determine attacker behavior, root cause, scope of compromise, and business impact
· Coordinate response and remediation activities with Security Operations, Information Technology, Privacy, Legal, and business stakeholders
· Develop and enhance investigation workflows, response playbooks, operational dashboards, and automation capabilities
· Drive process improvements that increase efficiency, visibility, and incident response effectiveness
· Communicate technical findings and incident updates to both technical and non-technical audiences, including leadership teams
· Participate in the team's on-call rotation and support high-priority incidents as required
· Contribute to a collaborative culture focused on teamwork, knowledge sharing, and continuous improvement
Required Knowledge and Experience:
· Bachelor's degree with 7+ years of cybersecurity experience or Master's degree with 5+ years of cybersecurity experience
· Hands-on experience leading and conducting cybersecurity incident response investigations.
· Strong experience with Security Information and Event Management (SIEM) platforms
· Experience utilizing CrowdStrike or similar Endpoint Detection and Response (EDR) solutions
· Experience investigating incidents across endpoint, identity, email, cloud, and network environments
· Strong analytical, troubleshooting, and problem-solving skills
· Ability to manage multiple priorities in a fast-paced environment
· Experience communicating technical findings to a variety of stakeholder groups
· Experience developing automation or scripting solutions using PowerShell, Python, or similar technologies
Preferred Qualifications
· Experience in Digital Forensics and Incident Response (DFIR)
· Experience performing threat hunting and advanced security investigations
· Experience developing automation workflows, dashboards, and operational reporting solutions
· Experience working within a Security Operations Center (SOC), Incident Response, or Managed Security Services environment
· Experience supporting global teams across multiple time zones
· GIAC/SANS certifications such as GCIH, GCFA, GCFE, GCIA, GCFR, or similar cybersecurity certifications
Physical Job Requirements
The above statements are intended to describe the general nature and level of work being performed by employees assigned to this position, but they are not an exhaustive list of all the required responsibilities and skills of this position.
Recruitment Fraud Alert
We are aware of phishing scams targeting job seekers. Please keep the following in mind:
Apply only through official Medtronic channels. All legitimate Medtronic recruiting communications come from approved Medtronic platforms and official @medtronic.com email addresses.
Medtronic will never ask for payment or sensitive personal information (such as bank account or Social Security details) during early stages of the hiring process. Any such requests are not legitimate.
If you receive a suspicious message claiming to be from Medtronic, do not respond, click links, or open attachments.
If you have any questions, concerns regarding the authenticity of a communication alleged to have been made by or on behalf of Medtronic, please contact us immediately at [email protected] .
Benefits & Compensation
Medtronic offers a competitive Salary and flexible Benefits Package
A commitment to our employees lives at the core of our values. We recognize their contributions. They share in the success they help to create. We offer a wide range of benefits, resources, and competitive compensation plans designed to support you at every career and life stage.
This position is eligible for a short-term incentive called the Medtronic Incentive Plan (MIP).