CONMED

Lead Information Security Analyst

CONMED$104K — $163K *
US-AnywhereRemote in Largo, FL
Healthcare
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Cybersecurity, Engineering, IT, or related field
  • 5+ years of experience in cybersecurity in regulated industries
  • Hands-on experience with SIEM/XDR platforms and incident response
  • Strong knowledge of security frameworks like NIST and ISO 27001
  • Experience with network segmentation and Zero Trust principles

Responsibilities

  • Lead detection and response for cybersecurity incidents
  • Manage SOC operations focusing on IT security and production integrity
  • Investigate incidents involving intellectual property theft and production disruptions
  • Partner with IT and engineering to embed secure design principles
  • Conduct security risk assessments for medical devices
  • Implement segmentation between IT and OT networks
  • Monitor the threat landscape with emphasis on nation-state attacks

Benefits

  • Competitive compensation
  • Excellent healthcare including medical, dental, vision, and prescription coverage
  • Short & long term disability plus life insurance fully paid by CONMED
  • Retirement Savings Plan (401K) with dollar-for-dollar matching
  • Employee Stock Purchase Plan at a discounted price
  • Tuition assistance for undergraduate and graduate courses
Full Job Description
The Lead Information Security Analyst is a senior cybersecurity leader responsible for protecting the organization's digital ecosystem across product development, manufacturing, and enterprise IT systems. This role ensures the security of connected medical/surgical devices, intellectual property, and regulated environments, while maintaining compliance with cybersecurity guidance, ISO standards, and global regulations.

This position plays a critical role in enabling secure product innovation, patient safety, and operational resilience across the device lifecycle.

Key Responsibilities:

Security Operations & Incident Response
  • Lead detection and response for incidents affecting: Manufacturing systems (OT/ICS), Connected medical/surgical devices, Enterprise IT environments
  • Manage SOC operations with prioritization of IT security, production integrity, and supply chain impact
  • Investigate and respond to incidents involving: Intellectual property theft, Disruptions and/or ransomware affecting production lines, IT vulnerabilities
  • Lead regulatory-aligned incident handling and disclosure (local/global authorities)


Production & IT Security (Critical Focus Area)
  • Partner with IT, production, and engineering to embed secure-by-design principles across the IT & product lifecycle
  • Conduct threat modeling and security risk assessments for surgical and medical devices
  • Support compliance with: IT security guidance, SOX, ISO27001, EU GDPR / NIS2
  • Identify and remediate product vulnerabilities (secure firmware, APIs, connectivity)
  • Support coordinated vulnerability disclosure (CVD) processes


Manufacturing & Operational Technology (OT) Security
  • Secure manufacturing environments (plants, production lines, robotics, control systems)
  • Implement segmentation between IT and OT networks
  • Lead vulnerability and patch management for industrial control systems
  • Reduce risk to production continuity and product integrity


Threat & Vulnerability Management
  • Monitor threat landscape with emphasis on: Nation-state attacks targeting IP, Supply chain compromise, Medical device exploitation
  • Lead proactive threat hunting across: Cloud environments, OT/manufacturing systems, Product telemetry (if applicable)
  • Drive enterprise-wide vulnerability management with prioritization based on patient and product impact


Security Engineering & Architecture
  • Implement Zero Trust principles across corporate IT and manufacturing environments
  • Drive consolidation and optimization of: SIEM/XDR (Sentinel, Defender, etc.), Identity platforms (Entra ID, PAM), Data protection tools (DLP, encryption for IP and regulated data)
  • Secure cloud platforms supporting R&D, analytics, and digital health capabilities


Regulatory Compliance & Risk Management
  • Ensure alignment with: SOX, ISO 27001, NIST CSF / NIST 800-53, Global data protection regulations (GDPR where applicable)
  • Lead cyber risk assessments tied to patient safety, product risk, and regulatory exposure
  • Support internal and external audits and regulatory inspections
  • Translate cybersecurity risk into business impact (recalls, production disruption, liability)


Data Protection & Intellectual Property Security
  • Protect sensitive data, designs, and trade secrets
  • Implement controls for: Secure collaboration with third-party manufacturers and partners, Data encryption and access governance
  • Monitor for data exfiltration and insider threats


Leadership & Mentorship
  • Provide technical leadership across security operations and engineering functions
  • Mentor analysts and engineers on: IT/OT security, Production security, Incident response in regulated environments
  • Act as escalation point for high-impact security events affecting products or manufacturing


Stakeholder Collaboration
  • Partner with: CIO, CISO, and Chief Product/Engineering Officers, Quality & Regulatory Affairs, Manufacturing / Plant leadership, Legal and Compliance teams
  • Communicate cybersecurity risks in terms of: IT security & safety, Regulatory impact, Revenue / production risk.


Job Requirements
  • Bachelor's degree in Cybersecurity, Engineering, IT, or related field (or equivalent experience)
  • 5+ years of experience in cybersecurity, with exposure to regulated industries or manufacturing environments, with 7+ years highly preferred
  • Hands-on experience with: SIEM/XDR platforms, Endpoint, network, and cloud security, Vulnerability and incident response programs
  • Strong knowledge of: Security frameworks (NIST, ISO 27001), Identity and access management, Network segmentation and Zero Trust principles


Preferred Experience
  • Experience in medical device, healthcare technology, or manufacturing (OT/ICS)
  • Familiarity with: ISO27001, NIS2, SOX, NIST CF 800-53, EU GDPR
  • Preferred Certifications: CISSP, CEH, GIAC, GICSP (Industrial Control Systems) or HCISPP (strong plus)
  • Experience with: IT/Production security testing, Threat modeling (e.g., STRIDE), Secure SDLC practices


This position is not eligible for employer-visa sponsorship

Disclosure as required by applicable law, the annual salary range for this position is $104,134 - $163,640. The actual compensation may vary based on geographic location, work experience, education and skill level. The salary range is CONMED's good faith belief at the time of this posting.

This job posting is anticipated to close on July 24, 2026. We may, however, extend this time period, in which case the posting will remain available on careers.conmed.com. Please submit your application as soon as possible as we will be reviewing applications on a rolling basis as we receive them.

Benefits:

CONMED offers a wide array of benefits to fit your unique needs. Visit our Benefits Page for more information.
  • Competitive compensation
  • Excellent healthcare including medical, dental, vision and prescription coverage
  • Short & long term disability plus life insurance -- cost paid fully by CONMED
  • Retirement Savings Plan (401K) -- CONMED matches your contributions dollar for dollar, with the potential for up to 7% per pay period
  • Employee Stock Purchase Plan -- allows stock purchases at discounted price
  • Tuition assistance for undergraduate and graduate level courses


Know someone at CONMED? Have them submit you as a referral before applying for this position to be eligible for our Employee Referral Program incentives!

About CONMED

CONMED is a medical technology company that provides surgical devices and equipment for minimally invasive procedures. The company's products are used in arthroscopy, electrosurgery, endoscopy, and laparoscopy. CONMED's products are sold globally to hospitals, surgery centers, and other medical facilities. The company was founded in 1970 and is headquartered in Utica, New York.
Learn more about CONMED
Size
3,800 employees
Market Cap
$2.6 billion
Industry
Net Income
$9.5 million
Founded
1970
5 Year Trend
+5.8%
Revenue
$862.4 million
NASDAQ

Similar Jobs

More Jobs at CONMED

More Healthcare Jobs

Find similar Lead Information Security Analyst jobs: