GRC & Compliance Executive (ISO 27001 / SOC 2 / HIPAA)
2 weeks ago
We're seeking a hands-on
GRC & Compliance leader
to own our end-to-end program across
ISO 27001:2022
,
SOC 2 Type II
,
HIPAA
, and India's
DPDP Act 2023
. You will run the ISMS, manage external audits,
face auditors and customers
, complete
security questionnaires
, and keep our multi-tenant healthcare SaaS (primarily
AWS
) continuously audit-ready. This role is highly cross-functional with IT, DevOps/SRE, Data, Legal, HR, and Sales.
Responsibilities
Own the ISMS & SOC 2 program
- Maintain control framework mapped to
ISO 27001 Annex A
and
SOC 2 TSC
; align with
HIPAA
(Security/Privacy) and
DPDP Act
. - Plan & drive
ISO (Stage 1/2, surveillance)
and
SOC 2 (readiness, Type I/II)
cycles; manage PBC lists, walkthroughs, findings, and closures.
Customer trust & questionnaires
- Lead responses for
CAIQ, SIG, VSAQ, RFP security sections
, due-diligence calls, and security addenda; maintain a reusable response library & evidence pack.
Policy, documentation & evidence
- Draft and version policies, SOPs, runbooks (Access, Asset, Logging/Monitoring, Vulnerability, Patch, IR, BCP/DR, Vendor Risk, SDLC/Change, DLP).
- Operationalize
recurring evidence collection
with automation where possible; maintain an auditable repository (Confluence/SharePoint + Jira).
Risk management
- Run periodic risk assessments (
ISO 27005/NIST
), maintain a risk register, drive treatment plans, and report risk posture & KPIs to leadership.
Security control operations (cloud-first)
- Partner with DevOps/SRE on
AWS
controls:
IAM
,
KMS
,
CloudTrail
,
Config
,
GuardDuty
,
Security Hub
,
VPC
segmentation,
Backup/DR
(RDS/S3/EBS). - Oversee
vulnerability management
(e.g., Tenable/Qualys/Nessus),
EDR
(e.g., Sophos), patch management, and
change management/CAB
.
Incident readiness & privacy
- Maintain
Incident Response
playbooks, on-call coordination, post-incident RCAs. Support
HIPAA
safeguards,
DPDP
requirements, DPIAs/ROPA as needed.
Vendor/Third-Party Risk
- Run
TPRM
(due diligence, DPAs/BAAs, ongoing monitoring) with Legal/Procurement; ensure critical vendors meet our control bar before go-live.
Awareness & drills
- Drive security awareness training, phishing simulations, and
BCP/DR
tabletop & failover drills with measurable outcomes.
Tooling & automation
- Administer GRC platforms (
Drata/Vanta/Sprinto/OneTrust/Secureframe
), integrate with
Jira/Confluence/Slack/ServiceNow
; build dashboards for execs.
Qualifications
Candidate with 2-3+ years
in GRC/compliance for
SaaS/cloud
, with
successful ISO 27001
certifications and
SOC 2 Type II
audits.
-
Lead compliance audits
1 week ago
Pune, Maharashtra, India Meraki Ventures Full time ₹ 12,00,000 - ₹ 36,00,000 per yearAbout the Role:The profiles shared earlier do not meet our requirement. We urgently need someone who can lead compliance audits, possessing the relevant certifications and hands-on experience with ISO 27001 and SOC 2 Type II audits.Given the critical and time-sensitive nature of this requirement, please ensure that the relevant profiles are shared by...
-
Principal GRC Security Specialist
2 weeks ago
Pune, Maharashtra, India Community Brands Software Development Solutions Full time ₹ 12,00,000 - ₹ 36,00,000 per yearJob Overview Were looking for an experienced and strategic Principal GRC Security Analyst to help lead our Governance, Risk, and Compliance efforts. In this role, youll work cross-functionally to drive security initiatives, support compliance frameworks, and partner with both internal teams and external customers to ensure trust, transparency, and...
-
GRC Analyst
6 days ago
Pune, Maharashtra, India FPL Technologies Full time ₹ 9,00,000 - ₹ 12,00,000 per yearRole: Governance, Risk and Compliance AnaystLocation: Aundh, Pune, MaharashtraAbout the companyCredit cards haven't changed much for over half a century so our team of seasoned bankers, technologists, and designers set out to redefine the credit card for you - the consumer. The result is OneCard - a credit card reimagined for the mobile generation. OneCard...
-
Information Security Associate
2 weeks ago
Pune, Maharashtra, India Zensar Technologies Full time ₹ 9,00,000 - ₹ 12,00,000 per yearGreetings from Zensar Technologies, PuneWe are hiring for the Position:Information Security AssociatePlace: PuneEducation: Degree in Computer ScienceMandatory Skill -Data privacy, iso, pcidss, gdpr.Certifications: ISO 27001 LA, CISA, CISM, CISSP, CompTIA or other globally accepted or reputed certification in the field if Information Security Governance, Risk...
-
ISO 27001 Implementation Consultant/Agency
1 week ago
Pune, Maharashtra, India Dizzaroo Pvt Ltd Full time ₹ 12,00,000 - ₹ 24,00,000 per yearISO 27001 Implementation Consultant/Agency (Contract)Pune, India (Hybrid/Remote possible)Dizzaroo Pvt LtdAbout UsDizzaroo Pvt Ltd is a rapidly growing AI-driven life sciences startup. We build advanced applications for pharmaceutical companies in the areas of clinical research, digital pathology, and drug discovery. As we expand globally, information...
-
IT Risk and Compliance Lead
1 week ago
Pune, Maharashtra, India Pi One Technologies (π 1) Full time ₹ 12,00,000 - ₹ 36,00,000 per yearPosition OverviewWe are seeking an experienced IT Risk and Compliance Lead to establish, maintain, and oversee our organization's information security and compliance framework. This role will be responsible for ensuring IT operations align with regulatory requirements, industry standards, and organizational policies while managing risk across the technology...
-
Associate IT Security and Compliance
2 weeks ago
Pune, Maharashtra, India Japheth Full time ₹ 9,00,000 - ₹ 12,00,000 per yearManage banking audits, track points, coordinate closure. Implement RBI, Cert-In advisories. Assist auditors, maintain policies, automate compliance, enhance security. Required Candidate profileExp in IT sec audits & compliance.ISO 27001 Lead Implementer, CISSP, or CISM.Skilled in ISO 27001, 22301, PCI DSS, SOC Type 2, and ISO.technical writing & MS office...
-
Assistant Manager
2 weeks ago
Pune, Maharashtra, India Deloitte Full time ₹ 15,00,000 - ₹ 25,00,000 per yearJob requisition ID :: 87541Date: Aug 18, 2025Location: PuneDesignation: Assistant ManagerEntity: Deloitte Touche Tohmatsu India LLPAbout the roleAs a Cybersecurity GRC Consultant / Assistant Manager, this position plays an vital role to support the implementation and management of governance, risk, and compliance initiatives that safeguard the organization's...
-
Cyber Risk
4 weeks ago
Pune, Maharashtra, India Atos Full timeAbout Atos Atos is a global leader in digital transformation with c 78 000 employees and annual revenue of c EUR 10 billion European number one in cybersecurity cloud and high-performance computing the Group provides tailored end-to-end solutions for all industries in 68 countries A pioneer in decarbonization services and products Atos is committed...
-
Pune, Maharashtra, India, Maharashtra PeopleGene Full timeAbout the role:We are seeking a hands-on Security & Compliance Lead to own and execute end-to-end security audits and compliance initiatives across applications, infrastructure, and organizational processes. This role ensures systems, applications, and business operations are secure, compliant, and aligned with both internal policies and regulatory...