Develop, implement, and maintain comprehensive information security policies, standards, and procedures aligned with the ISO 27001 framework
Lead, manage, and mature the organization's Information Security Management System including risk treatment, internal audits, and readiness for external certification audits.
Serve as the subject matter expert (SME) for Security and Privacy Rules, ensuring compliance for all systems, processes, and applications handling PII and Protected Health Information (PHI).
Conduct continuous monitoring and evidence collection to demonstrate compliance with relevant frameworks.
Plan, conduct and manage internal and supplier audits
Plan GRC activities, prioritise and implement them in timebound manner.
Perform detailed security risk assessments and gap analyses on new and existing systems, with a focus on cloud infrastructure
Collaborate with Product, Technology, IT and Security teams to implement security controls into cloud / infra / environments, ensuring compliance. Provide technical guidance to them on implementing controls and best practices, specifically related to cloud security architecture and configurations.
Review risk mitigations periodically and track remediation efforts to closure.
Conduct third-party vendor risk assessments, focusing on their adherence to required compliance standards.
Develop and deliver targeted security awareness and training programs focused on HIPAA and ISO 27001 requirements for all staff, including technical teams.
Evaluate and recommend new security technologies and processes to enhance the compliance and risk posture.
Stay current on emerging cloud security threats, regulatory changes, and updates to the ISO 27001 family of standards and HIPAA.
Requirements
What do you bring to the table?
Experience :
Minimum of 8+ years of progressive experience in Information Security GRC, with a focus on risk management, compliance, and governance.
Proven, hands-on experience driving and maintaining ISO 27001 certification programs.
Deep practical knowledge and experience of implementing security controls ensuring compliance in a technical, cloud-centric environment.
Strong technical competency in Cloud Security (AWS, Azure, or GCP) and related cloud-native security services.
Education : Bachelor's degree in IT, Computer Science or related field.
Certifications (One or more highly preferred) :
CISSP (Certified Information Systems Security Professional)
CISA (Certified Information Systems Auditor)
ISO 27001 Lead Implementer / Auditor
CCSK (Certificate of Cloud Security Knowledge) or equivalent Cloud-specific security certification (e.g., AWS Certified Security, Azure Security Engineer).
Soft Skills
Proficiency in written and verbal communication skills with the ability to translate complex security and compliance requirements / controls into clear actionable
Strong project management and organizational skills to handle multiple, simultaneous audit and compliance initiatives.
A collaborative and proactive mindset, with the ability to influence and lead cross-functional teams without direct authority.
Benefits
Flexible Work & Time Off - Embrace hybrid work models and enjoy the freedom of unlimited paid time off to support work-life balance.
Health & Well-being - Access comprehensive group medical and life insurance coverage, along with a 24 / 7 Employee Assistance Program (EAP) for mental health and wellness support.
Growth & Learning - Fuel your professional journey with continuous learning and development programs designed to help you upskill and grow.
Recognition & Rewards - Get recognized for your contributions through structured reward programs and campaigns.
Engaging & Fun Work Culture - Experience a vibrant workplace with team events, celebrations, and engaging activities that make every workday enjoyable.
& Many More...
Create a job alert for this search
Grc Specialist • Pune, MH, IN
Related jobs
Promoted
Senior Information Security Specialist
ACL DigitalPune, Maharashtra, India
We are a leading organization in the field of information security, dedicated to protecting our clients' data and ensuring their digital safety.
Our mission is to provide innovative security solutio...Show moreLast updated: 4 days ago
Promoted
Senior Cloud Security Specialist
ACL DigitalPune, Maharashtra, India
We are a leading organization in the field of information security, dedicated to protecting our clients' data and ensuring their digital safety.
Our mission is to provide innovative security solutio...Show moreLast updated: 2 days ago
Promoted
SAP GRC Consultant
Avigna ABPune, Maharashtra, India
Avigna is hiring SAP GRC Consultant (Process Control & Risk Management).Our SAP Delivery Center aims to build strong and sustainable solutions for customers across Europe.If you want to grow and bu...Show moreLast updated: 4 days ago
Promoted
Solytics Partners - Senior Manager - Information Security
Solytics PartnersPune, India
About Us : Solytics Partners is a Global Analytics firm, recognized with multiple industry awards for innovation and excellence.
Our team comprises experts with deep do...Show moreLast updated: 30+ days ago
Promoted
Senior Manager Information Security
Ocwen Financial Solutions Pvt. Ltd. - APACPune, Maharashtra, India
The Incumbent would be responsible to manage the information security governance, risk, and compliance process.Standardize GRC policies, evaluate their impacts, and implement the relevant measure.L...Show moreLast updated: 4 days ago
We are seeking a hands-on Security & Compliance Lead to own and execute end-to-end security audits and compliance initiatives across applications, infrastructure, and organizational processes.This ...Show moreLast updated: 4 days ago
Promoted
GRC Consultant
Solytics PartnersPune, Maharashtra, India
Solytics Partners is a Global Analytics firm, recognized with multiple industry awards for innovation and excellence.Our team comprises experts with deep knowledge in risk, analytics, AI / ML, AML / FC...Show moreLast updated: 4 days ago
Promoted
Senior Manager - InfoSec Governance
ConfidentialPune, India
Position Summary : Sr Manager – Information Security Governance.The Incumbent would be responsible to manage the information security governance, risk, and compliance process.Standardize GRC policie...Show moreLast updated: 8 days ago
Promoted
Information Technology Specialist
Sharp Brainspune, maharashtra, in
Network Troubleshooting and Optimization : Diagnose and resolve issues across Ethernet,.Optimize network performance through regular maintenance.
Installation and System Upgrades : Deploy and configur...Show moreLast updated: 30+ days ago
Promoted
Lead DevOps Engineer
OllionPune / Pimpri-Chinchwad Area, India
Let’s be honest : there are lots of people out there doing what we do.We’re just not convinced they’re doing it right.Businesses are hungry for innovation and opportunity, but not at the cost of the...Show moreLast updated: 26 days ago
Promoted
InfoSec Specialist - AS
Deutsche BankPune, India
As a Cyber security associate, you will play SME role to give operations support to business applications in scanning, automation and remediation guidance.
As part of our flexible scheme, here are j...Show moreLast updated: 20 days ago
Promoted
Senior IP Analyst
Lear Corporationpune, maharashtra, in
Lear, a global automotive technology leader in Seating and E-Systems, enables superior in-vehicle experiences for consumers around the world.
Our diverse team of talented employees in 38 countries i...Show moreLast updated: 1 day ago
Promoted
Cloud Security and GRC Engineer (Compliance / Security Architecture)
PeopleGenepune, maharashtra, in
We are seeking a hands-on Security & Compliance Lead to own and execute end-to-end security audits and compliance initiatives across applications, infrastructure, and organizational processes.This ...Show moreLast updated: 24 days ago
Promoted
New!
Cybersecurity GRC Lead
Northern TrustPune, India
Northern Trust, a Fortune 500 company, is a globally recognized, award-winning financial institution that has been in continuous operation since 1889.
Northern Trust is proud to provide innovative f...Show moreLast updated: less than 1 hour ago
Promoted
Senior InfoSec GRC Specialist
ConfidentialPune, India
Develop, implement, and maintain comprehensive information security policies, standards, and procedures aligned with the ISO 27001 framework.
Lead, manage, and mature the organization's Information ...Show moreLast updated: 3 days ago
Promoted
Senior Consultant
ProglitePune, IN
We are seeking a motivated and skilled.Network / Cloud / Security Engineer.AWS, Google Cloud Platform (GCP), Cisco Meraki, and Palo Alto firewalls.
The ideal candidate will be responsible for design...Show moreLast updated: 30+ days ago
Promoted
Cybersecurity GRC Associate
Northern TrustPune, India
Northern Trust, a Fortune 500 company, is a globally recognized, award-winning financial institution that has been in continuous operation since 1889.
Northern Trust is proud to provide innovative f...Show moreLast updated: 20 days ago
Promoted
HR Business System Analyst
BMC Softwarepimpri-chinchwad, maharashtra, in
We are looking for a HRIS Analyst with strong Oracle HCM skills to support and optimise our HR systems.This role is perfect for someone who enjoys problem-solving, leading system enhancements, and ...Show moreLast updated: 2 days ago