GRC & Compliance Executive (ISO 27001 / SOC 2 / HIPAA)

2 weeks ago


Pune, Maharashtra, India AutomationEdge Full time ₹ 10,00,000 - ₹ 25,00,000 per year

We're seeking a hands-on
GRC & Compliance leader
to own our end-to-end program across
ISO 27001:2022
,
SOC 2 Type II
,
HIPAA
, and India's
DPDP Act 2023
. You will run the ISMS, manage external audits,
face auditors and customers
, complete
security questionnaires
, and keep our multi-tenant healthcare SaaS (primarily
AWS
) continuously audit-ready. This role is highly cross-functional with IT, DevOps/SRE, Data, Legal, HR, and Sales.

Responsibilities

Own the ISMS & SOC 2 program

  • Maintain control framework mapped to
    ISO 27001 Annex A
    and
    SOC 2 TSC
    ; align with
    HIPAA
    (Security/Privacy) and
    DPDP Act
    .
  • Plan & drive
    ISO (Stage 1/2, surveillance)
    and
    SOC 2 (readiness, Type I/II)
    cycles; manage PBC lists, walkthroughs, findings, and closures.

Customer trust & questionnaires

  • Lead responses for
    CAIQ, SIG, VSAQ, RFP security sections
    , due-diligence calls, and security addenda; maintain a reusable response library & evidence pack.

Policy, documentation & evidence

  • Draft and version policies, SOPs, runbooks (Access, Asset, Logging/Monitoring, Vulnerability, Patch, IR, BCP/DR, Vendor Risk, SDLC/Change, DLP).
  • Operationalize
    recurring evidence collection
    with automation where possible; maintain an auditable repository (Confluence/SharePoint + Jira).

Risk management

  • Run periodic risk assessments (
    ISO 27005/NIST
    ), maintain a risk register, drive treatment plans, and report risk posture & KPIs to leadership.

Security control operations (cloud-first)

  • Partner with DevOps/SRE on
    AWS
    controls:
    IAM
    ,
    KMS
    ,
    CloudTrail
    ,
    Config
    ,
    GuardDuty
    ,
    Security Hub
    ,
    VPC
    segmentation,
    Backup/DR
    (RDS/S3/EBS).
  • Oversee
    vulnerability management
    (e.g., Tenable/Qualys/Nessus),
    EDR
    (e.g., Sophos), patch management, and
    change management/CAB
    .

Incident readiness & privacy

  • Maintain
    Incident Response
    playbooks, on-call coordination, post-incident RCAs. Support
    HIPAA
    safeguards,
    DPDP
    requirements, DPIAs/ROPA as needed.

Vendor/Third-Party Risk

  • Run
    TPRM
    (due diligence, DPAs/BAAs, ongoing monitoring) with Legal/Procurement; ensure critical vendors meet our control bar before go-live.

Awareness & drills

  • Drive security awareness training, phishing simulations, and
    BCP/DR
    tabletop & failover drills with measurable outcomes.

Tooling & automation

  • Administer GRC platforms (
    Drata/Vanta/Sprinto/OneTrust/Secureframe
    ), integrate with
    Jira/Confluence/Slack/ServiceNow
    ; build dashboards for execs.

Qualifications

Candidate with 2-3+ years
in GRC/compliance for
SaaS/cloud
, with
successful ISO 27001
certifications and
SOC 2 Type II
audits.



  • Pune, Maharashtra, India Meraki Ventures Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    About the Role:The profiles shared earlier do not meet our requirement. We urgently need someone who can lead compliance audits, possessing the relevant certifications and hands-on experience with ISO 27001 and SOC 2 Type II audits.Given the critical and time-sensitive nature of this requirement, please ensure that the relevant profiles are shared by...


  • Pune, Maharashtra, India Community Brands Software Development Solutions Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    Job Overview Were looking for an experienced and strategic Principal GRC Security Analyst to help lead our Governance, Risk, and Compliance efforts. In this role, youll work cross-functionally to drive security initiatives, support compliance frameworks, and partner with both internal teams and external customers to ensure trust, transparency, and...

  • GRC Analyst

    6 days ago


    Pune, Maharashtra, India FPL Technologies Full time ₹ 9,00,000 - ₹ 12,00,000 per year

    Role: Governance, Risk and Compliance AnaystLocation: Aundh, Pune, MaharashtraAbout the companyCredit cards haven't changed much for over half a century so our team of seasoned bankers, technologists, and designers set out to redefine the credit card for you - the consumer. The result is OneCard - a credit card reimagined for the mobile generation. OneCard...


  • Pune, Maharashtra, India Zensar Technologies Full time ₹ 9,00,000 - ₹ 12,00,000 per year

    Greetings from Zensar Technologies, PuneWe are hiring for the Position:Information Security AssociatePlace: PuneEducation: Degree in Computer ScienceMandatory Skill -Data privacy, iso, pcidss, gdpr.Certifications: ISO 27001 LA, CISA, CISM, CISSP, CompTIA or other globally accepted or reputed certification in the field if Information Security Governance, Risk...


  • Pune, Maharashtra, India Dizzaroo Pvt Ltd Full time ₹ 12,00,000 - ₹ 24,00,000 per year

    ISO 27001 Implementation Consultant/Agency (Contract)Pune, India (Hybrid/Remote possible)Dizzaroo Pvt LtdAbout UsDizzaroo Pvt Ltd is a rapidly growing AI-driven life sciences startup. We build advanced applications for pharmaceutical companies in the areas of clinical research, digital pathology, and drug discovery. As we expand globally, information...


  • Pune, Maharashtra, India Pi One Technologies (π 1) Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    Position OverviewWe are seeking an experienced IT Risk and Compliance Lead to establish, maintain, and oversee our organization's information security and compliance framework. This role will be responsible for ensuring IT operations align with regulatory requirements, industry standards, and organizational policies while managing risk across the technology...


  • Pune, Maharashtra, India Japheth Full time ₹ 9,00,000 - ₹ 12,00,000 per year

    Manage banking audits, track points, coordinate closure. Implement RBI, Cert-In advisories. Assist auditors, maintain policies, automate compliance, enhance security. Required Candidate profileExp in IT sec audits & compliance.ISO 27001 Lead Implementer, CISSP, or CISM.Skilled in ISO 27001, 22301, PCI DSS, SOC Type 2, and ISO.technical writing & MS office...

  • Assistant Manager

    2 weeks ago


    Pune, Maharashtra, India Deloitte Full time ₹ 15,00,000 - ₹ 25,00,000 per year

    Job requisition ID :: 87541Date: Aug 18, 2025Location: PuneDesignation: Assistant ManagerEntity: Deloitte Touche Tohmatsu India LLPAbout the roleAs a Cybersecurity GRC Consultant / Assistant Manager, this position plays an vital role to support the implementation and management of governance, risk, and compliance initiatives that safeguard the organization's...

  • Cyber Risk

    4 weeks ago


    Pune, Maharashtra, India Atos Full time

    About Atos Atos is a global leader in digital transformation with c 78 000 employees and annual revenue of c EUR 10 billion European number one in cybersecurity cloud and high-performance computing the Group provides tailored end-to-end solutions for all industries in 68 countries A pioneer in decarbonization services and products Atos is committed...


  • Pune, Maharashtra, India, Maharashtra PeopleGene Full time

    About the role:We are seeking a hands-on Security & Compliance Lead to own and execute end-to-end security audits and compliance initiatives across applications, infrastructure, and organizational processes. This role ensures systems, applications, and business operations are secure, compliant, and aligned with both internal policies and regulatory...