GRC & Compliance Executive (ISO 27001 / SOC 2 / HIPAA)

2 years

0 Lacs

Posted:2 weeks ago| Platform: Linkedin logo

Apply

Work Mode

On-site

Job Type

Full Time

Job Description

GRC & Compliance leader


Responsibilities

Own the ISMS & SOC 2 program

  • Maintain control framework mapped to

    ISO 27001 Annex A

    and

    SOC 2 TSC

    ; align with

    HIPAA

    (Security/Privacy) and

    DPDP Act

    .
  • Plan & drive

    ISO (Stage 1/2, surveillance)

    and

    SOC 2 (readiness, Type I/II)

    cycles; manage PBC lists, walkthroughs, findings, and closures.

Customer trust & questionnaires

  • Lead responses for

    CAIQ, SIG, VSAQ, RFP security sections

    , due-diligence calls, and security addenda; maintain a reusable response library & evidence pack.

Policy, documentation & evidence

  • Draft and version policies, SOPs, runbooks (Access, Asset, Logging/Monitoring, Vulnerability, Patch, IR, BCP/DR, Vendor Risk, SDLC/Change, DLP).
  • Operationalize

    recurring evidence collection

    with automation where possible; maintain an auditable repository (Confluence/SharePoint + Jira).

Risk management

  • Run periodic risk assessments (

    ISO 27005/NIST

    ), maintain a risk register, drive treatment plans, and report risk posture & KPIs to leadership.

Security control operations (cloud-first)

  • Partner with DevOps/SRE on

    AWS

    controls:

    IAM

    ,

    KMS

    ,

    CloudTrail

    ,

    Config

    ,

    GuardDuty

    ,

    Security Hub

    ,

    VPC

    segmentation,

    Backup/DR

    (RDS/S3/EBS).
  • Oversee

    vulnerability management

    (e.g., Tenable/Qualys/Nessus),

    EDR

    (e.g., Sophos), patch management, and

    change management/CAB

    .

Incident readiness & privacy

  • Maintain

    Incident Response

    playbooks, on-call coordination, post-incident RCAs. Support

    HIPAA

    safeguards,

    DPDP

    requirements, DPIAs/ROPA as needed.

Vendor/Third-Party Risk

  • Run

    TPRM

    (due diligence, DPAs/BAAs, ongoing monitoring) with Legal/Procurement; ensure critical vendors meet our control bar before go-live.

Awareness & drills

  • Drive security awareness training, phishing simulations, and

    BCP/DR

    tabletop & failover drills with measurable outcomes.

Tooling & automation

  • Administer GRC platforms (

    Drata/Vanta/Sprinto/OneTrust/Secureframe

    ), integrate with

    Jira/Confluence/Slack/ServiceNow

    ; build dashboards for execs.



Qualifications

Candidate with 2-3+ years

Mock Interview

Practice Video Interview with JobPe AI

Start DevOps Interview
cta

Start Your Job Search Today

Browse through a variety of job opportunities tailored to your skills and preferences. Filter by location, experience, salary, and more to find your perfect fit.

Job Application AI Bot

Job Application AI Bot

Apply to 20+ Portals in one click

Download Now

Download the Mobile App

Instantly access job listings, apply easily, and track applications.

coding practice

Enhance Your Skills

Practice coding challenges to boost your skills

Start Practicing Now

RecommendedJobs for You