Cybersecurity Lead - GRC

Medusind

Mumbai

On-site

INR 2,500,000 - 4,500,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Medusind is seeking a results‑driven GRC & Risk Compliance professional in Mumbai to identify, assess, and mitigate risks across IT security, processes, and regulatory compliance. You will develop, implement, and maintain GRC programs, assisting with audits, and ensuring corrective actions are taken where needed.

You will also drive policy governance, gap analyses, and vendor risk assessments, enabling robust controls and ongoing compliance across the organization.

Qualifications

  • 5+ years of direct experience in information security focusing on risk and compliance.
  • 3+ years of ISO 27001 and SOC 2 audits and audit responses.
  • Solid understanding of regulatory requirements (ISO27001, SOC 2, NIST, PCI, GDPR).
  • Knowledge of identity management, storage and DR in cloud and on‑premise.
  • Familiarity with GRC tool techniques and best practices.
  • Proven track record managing multiple risk and compliance projects.
  • Experience handling third‑party audits and compiling evidence.
  • Strong written communication for policies and procedures.
  • Analytical and problem‑solving abilities to drive corporate goals.

Responsibilities

  • Identify, assess, and mitigate risks across IT security, processes, and compliance.
  • Develop and maintain GRC programs to support compliance.
  • Assist with audits, respond to findings, implement corrective actions.
  • Review user access and governance controls.
  • Create and maintain governance policies and procedures.
  • Conduct gap analyses and implement ISO 27001, GDPR, NIST, SOC2 frameworks.
  • Lead vendor risk assessments against security requirements.
  • Continuously test and monitor security controls.
  • Collaborate with teams to integrate GRC into operations.

Skills

Risk management
ISO 27001
SOC 2
Audit management
NIST
GDPR
Vendor risk
Information security

Education

Bachelor’s degree in CS / IS / Cybersecurity

Tools

GRC software

Job description

Identifying, assessing, and mitigating potential risks across various areas of the organization, including IT security, business processes, and regulatory compliance.

Developing, implementing, and maintaining GRC programs and processes to support compliance and risk management efforts.

Assisting with internal and external audits, responding to audit findings, and ensuring corrective actions are implemented.

User Access review

Creating and maintaining policies and procedures related to governance, risk, and compliance.

Conducting gap analysis and implementing frameworks and standards such as ISO 27001, GDPR, NIST, and SOX.

Developing and revising policies, standards, processes, and guidelines for the organization. Conducting vendor risk assessments against organizational security requirements.

Continually testing and monitoring the effectiveness of security controls.

Conducting research to aid threat assessment or risk mitigation activities.

Assist the department in responding to inquiries from the business units about ongoing operational compliance

Working with various teams and departments to ensure GRC practices are integrated into business operations.

Responsibilities

5+ years of direct experience in information security, with a main emphasis on risk and compliance

3+ years of expertise conducting ISO 27001 and SOC 2 audits, as well as handling audit responses

Thorough understanding of market structures, including relevant regulatory compliance requirements (ISO27001, SOC 2, NIST, PCI, GDPR, etc.)

Knowledge of identity management standards, storage, and disaster recovery in the cloud and On Premise

Knowledge of GRC tool techniques and best practices

Proven track record of organizing and carrying out several risk and compliance projects

Ability to successfully manage third-party audits, compile evidence, and organize audit responses

Effective written communication skills to develop & maintain the policies and procedures; the capability to communicate with cross-functional teams.

Proven analytical and problem-solving abilities for managing initiatives that advance corporate goals

Qualifications

Bachelor’s degree in computer science, information systems, or Cybersecurity

About Us

Medusind is a healthcare company, founded in 2002, that provides revenue cycle management (RCM) solutions for medical and dental organizations, helping them maximize revenue and reduce costs through technology and expertise.

Job Info
  • Job Identification 163
  • Posting Date 12/04/2025, 08:57 AM
  • Locations 6th ,4th,3rd Floor,The Great Oasis,, Mumbai, Maharashtra, 400093, IN
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Lead - GRC
Cybersecurity Lead - GRC

Medusind Solutions, Inc. • Mumbai

On-site
INR 1,500,000 - 2,100,000
Cybersecurity - Risk & Compliance Analyst
Cybersecurity - Risk & Compliance Analyst

Scybers • Chennai District

On-site
INR 900,000 - 1,500,000
Cybersecurity Specialist – Governance, Risk & Compliance (GRC)
Cybersecurity Specialist – Governance, Risk & Compliance (GRC)

TalaKunchi Networks Pvt Ltd • Mumbai

On-site
INR 800,000 - 1,200,000
Opportunity to shape InfoSec practices
Work on cutting-edge cybersecurity initiatives
Be part of a forward-thinking team
GRC Manager - Cyber
GRC Manager - Cyber

Cubical Operations LLP • Chennai District

On-site
INR 800,000 - 1,200,000
GRC Manager/ GRC Lead
GRC Manager/ GRC Lead

Riskpro India Ventures • Mumbai

On-site
INR 1,000,000 - 1,500,000
Technical Manager
Technical Manager

Incedo Inc. • Gurugram District

On-site
INR 2,500,000 - 5,000,000
Senior Role - GRC & Infosec
Senior Role - GRC & Infosec

NPCI Bharat BillPay Limited • Mumbai

On-site
INR 2,000,000 - 3,000,000
Lead -Governance, Risk and Compliance (GRC)
Lead -Governance, Risk and Compliance (GRC)

ARCON • Mumbai

On-site
INR 1,500,000 - 2,500,000
Lead Security GRC Analyst
Lead Security GRC Analyst

Providence India • Hyderabad

On-site
INR 1,800,000 - 2,400,000
Cybersecurity GRC Analyst
Cybersecurity GRC Analyst

Power Bridge • Arishinakunte

On-site
INR 1,200,000 - 2,400,000
Health insurance
Long-term benefit savings plan with em
Professional development opportunities