Director- GRC Cybersecurity

1 day ago


Gurgaon, Haryana, India R1 RCM Full time ₹ 12,00,000 - ₹ 36,00,000 per year

R1 is the leading provider of technology-driven solutions that transform the patient experience and financial performance of hospitals, health systems and medical groups. We are the one company that combines the deep expertise of a global workforce of revenue cycle professionals with the industry's most advanced technology platform, encompassing sophisticated analytics, AI, intelligent automation and workflow orchestration.

With over 30,000 employees globally and a robust presence in India, comprising over 17,000 employees across Delhi NCR, Hyderabad, Bangalore, and Chennai, we foster an inclusive culture where every team member feels valued and empowered. Our mission is to transform the healthcare industry by driving efficiency for healthcare systems, hospitals, and physician practices, continuously striving to make healthcare work better for everyone.

Position Summary:

We are seeking an experienced and strategic Director – GRC Cybersecurity to lead our Cybersecurity risk and governance efforts for India/Philippines market of R1 RCM. This role will be responsible for overseeing the cybersecurity risk posture of the organization, client onboarding/offboarding processes, supporting security audits, and ensuring compliance with HIPAA, HITECH, and other healthcare regulatory frameworks. The ideal candidate will bring strong leadership, a deep understanding of healthcare cybersecurity risks, and the ability to operationalize governance processes at scale.

Key duties & responsibilities

Cybersecurity Risk Governance

  • Lead the third-party cybersecurity risk management program with a focus on PHI/PII protection, HIPAA compliance, and critical vendor oversight.
  • Drive assessments aligned with NIST CSF and ISO framework to evaluate and mature cybersecurity program
  • Establish and maintain exception management, approval management and periodic monitoring
  • Collaborate with global cybersecurity and IT teams for implementing automation through GRC tools.
  • Oversee onboarding and offboarding processes to ensure alignment with security policies, BAAs (Business Associate Agreements), and regulatory requirements.
  • Monitor and govern third-party relationships, conducting periodic risk assessments and ensuring timely remediation of findings.

Security awareness and culture

  • Design and oversee India and Philippines cybersecurity awareness and training program for employees, contractors and vendors
  • Develop and communicate governance dashboards and awareness campaigns to foster a culture of shared cybersecurity responsibility
  • Evaluate effectiveness of training program and tailor it based on organizational requirements

Audit & Compliance Leadership:

  • Serve as key POC for client, regulatory, and third-party cybersecurity audits.
  • Ensure readiness and timely response for HIPAA, SOC 2, CERT-IN assessments, and client cybersecurity reviews and audits
  • Lead audit coordination across departments, track findings, and drive remediation activities to closure.
  • Represent the organization during client cybersecurity audits and on-site reviews.

Governance Frameworks, Metrics & Reporting:

  • Establish and maintain standard operating procedures for the organization, client onboarding/offboarding, and evidence handling.
  • Define and report on KPIs and KRIs for cybersecurity governance.
  • Develop executive dashboards and actionable insights for leadership, audit committees, and compliance teams.

Cross-Functional Collaboration & Risk Advisory:

  • Work closely with Legal, Procurement, Compliance, and Privacy teams to embed cybersecurity controls into contracts, RFPs, and vendor due diligence.
  • Advise internal business owners on security risks, remediation plans, and vendor-related compliance obligations.

Qualification

  • Bachelor's or Master's degree in Technology, Cybersecurity, Risk Management, or a related field.

Experience, Skills and Knowledge

  • 12+ years of cybersecurity or GRC experience, with at least 5 years in a leadership role, ideally in a healthcare organization or health-tech environment.
  • Good understanding of HIPAA, HITECH, HITRUST, ISO 27001, CERT-IN and regulatory frameworks.
  • Proven experience managing cybersecurity risk and audit programs at scale.
  • Excellent communication skills, with ability to interface with clients, vendors, operational, legal, and IT leadership.

Key competency profile

  • Certified Information Security Manager (CISM)
  • Certified Information Systems Auditor (CISA)
  • Certified in Risk and Information Systems Control (CRISC)
  • HITRUST CCSFP or ISO 27001 Lead Implementer

Working in an evolving healthcare setting, we use our shared expertise to deliver innovative solutions. Our fast-growing team has opportunities to learn and grow through rewarding interactions, collaboration and the freedom to explore professional interests.

Our associates are given valuable opportunities to contribute, to innovate and create meaningful work that makes an impact in the communities we serve around the world. We also offer a culture of excellence that drives customer success and improves patient care. We believe in giving back to the community and offer a competitive benefits package. To learn more, visit:

Visit us on Facebook



  • Gurgaon, Haryana, India R1 RCM Full time ₹ 2,00,00,000 - ₹ 2,50,00,000 per year

    R1 is the leading provider of technology-driven solutions that transform the patient experience and financial performance of hospitals, health systems and medical groups. We are the one company that combines the deep expertise of a global workforce of revenue cycle professionals with the industry's most advanced technology platform, encompassing...


  • Gurgaon, Haryana, India Fluidech Full time ₹ 12,00,000 - ₹ 30,00,000 per year

    Title:Vice President – Cybersecurity (IT Systems)Location:Onsite – Gurugram, Haryana, IndiaDuration:Full-Time RoleCompany: Fluidech IT Services Private LimitedCompany Overview:FLUIDECH, an ESCONET group company and a deemed public company, is a technology consulting and managed services firm specialising in cybersecurity.Founded in 2014 and headquartered...

  • Grc Manager

    2 weeks ago


    Gurgaon, Haryana, India Clix Capital Services Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    Role & responsibilitiesT Infrastructure Management:Oversee the design, implementation, and maintenance of the organizations IT infrastructure, including servers, networks, storage, and On-prim systems.Manage and optimize the performance, scalability, and security of IT systems.Ensure high availability and disaster recovery plans are in place and tested...


  • Gurgaon, Haryana, India Grant Thornton Bharat Llp Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    Job Role OverviewTitle: Cybersecurity Data Protection / Governance, Risk & Compliance (GRC) AnalystKey ResponsibilitiesSecurity Architecture & ControlsDesign and maintain data protection architecture.Collaborate with IT and business units to define security needs.Stay updated on data protection technologies.Governance, Risk & ComplianceManage Microsoft...


  • Gurgaon, Haryana, India AIONOS Full time ₹ 15,00,000 - ₹ 60,00,000 per year

    Company DescriptionAIONOS is a next-generation AI- led digital transformation company launched in April 2024 as a joint venture between InterGlobe Enterprises and Assago Ventures. Headquartered in Singapore with delivery hubs in Gurgaon, Noida, and Hyderabad, we serve Fortune 500 clients across India, the US, Europe, the Middle East, and Southeast Asia. Our...


  • Gurgaon, Haryana, India Delhivery Full time ₹ 20,00,000 - ₹ 25,00,000 per year

    Experience & Skills5+ years of progressive experience in cybersecurity roles, with a proven track record in managing complex security initiatives.Minimum of 1-2 years of proven team handling or techno managerial leadership experience mentoring engineers, defining project tasks, and managing team workload.Key Responsibilitie s Governance & ComplianceLead...


  • Gurgaon, Haryana, India Crocs, Inc. Full time ₹ 20,00,000 - ₹ 25,00,000 per year

    Overview Reporting into Information Security, the Governance, Risk, and Compliance (GRC) Engineer plays an instrumental role in guiding GRC strategies and processes. As the primary GRC authority in India and supporting the global GRC team, this engineer works directly with other partners such as Legal, Risk, Internal Audit, etc. to ensure the alignment of...


  • Gurgaon, Haryana, India Niva Bupa Health Insurance Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    We're looking for an experiencedGRC Specialistto join our team, with a strong emphasis on cybersecurity skills. The ideal candidate will have a minimum of8 years of hands-on experiencein Governance, Risk, and Compliance, with a strong focus on the health insurance industry. You must possess extensive knowledge of regulatory frameworks in the...


  • Gurgaon, Haryana, India Pierag Consulting Full time ₹ 20,00,000 - ₹ 25,00,000 per year

    Position Summary:You will be part of and establishing a team of cybersecurity professionals focused on providing advisory to the Firm's clients across several cybersecurity offerings.Your key responsibilities will include: Develop and maintain a team of cybersecurity professionals. Actively contribute to Firm initiatives and activities such as publishing...


  • Gurgaon, Haryana, India American Express Full time ₹ 1,04,000 - ₹ 1,30,878 per year

    You Lead the Way. We've Got Your Back.With the right backing, people and businesses have the power to progress in incredible ways. When you join Team Amex, you become part of a global and diverse community of colleagues with an unwavering commitment to back our customers, communities and each other. Here, you'll learn and grow as we help you create a career...