Governance Risk and Complains Manager

Getix Health, LLC 1099

Karnataka

On-site

INR 2,400,000 - 3,600,000

Full time

4 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

GetixHealth is seeking a GRC Manager to oversee enterprise governance, risk, and compliance across HIPAA, HITRUST, SOC 2, and PCI-DSS. The role partners with Legal, Privacy, IT, and Operations to protect PHI and other sensitive data.

The ideal candidate has 6–8+ years in GRC, strong stakeholder skills, and experience leading audits. This is a senior, impact-driven position aimed at strengthening AI governance and risk controls across healthcare operations.

Qualifications

  • Bachelor's degree in Information Security, Cybersecurity, Information Systems, Business, or related field or equivalent years of experience.
  • 6–8+ years of experience in Governance, Risk, and Compliance.
  • Experience leading external audits and remediation efforts.
  • Strong understanding of information security principles, risk management, and internal controls.
  • Excellent communication, documentation, and stakeholder management skills.
  • Experience using GRC platforms.

Responsibilities

  • Develop, maintain, and improve the organization’s enterprise GRC program.
  • Lead compliance activities related to HIPAA Privacy and Security Rules, HITRUST CSF, SOC 2 Type II, and PCI DSS.
  • Ensure controls protect PHI, PII, payment data, and other sensitive health information.
  • Coordinate evidence collection and control testing for audits and assurance activities.
  • Manage remediation plans for audit findings and client security observations.
  • Present risk metrics and executive reports to senior leadership.

Skills

GRC expertise
Stakeholder mgmt
Documentation
Security principles

Education

Bachelor's degree in Information Security / Cybersecurity
Certifications: CISSP / CISM / CISA (preferred)

Tools

GRC platforms

Job description

This role will be responsible for ensuring the organization maintains strong controls across HIPAA, HITRUST, SOC 2, PCI-DSS, client contractual requirements, and emerging AI governance standards. The ideal candidate will have direct experience supporting healthcare organizations, healthcare technology companies, RCM providers, or business process outsourcing environments that handle protected health information (PHI), payment data, and other sensitive healthcare information. The GRC Manager will work closely with Information Security, IT, Operations, Legal, Privacy, Human Resources, Client Services, Engineering, and executive leadership to manage compliance obligations, reduce organizational risk, support customer audits, and enable responsible use of artificial intelligence across healthcare operations.

What you will do
Governance & Compliance
  • Develop, maintain, and continuously improve the organization’s enterprise GRC program.
  • Lead compliance activities related to:
  • HIPAA Privacy and Security Rules
  • HITRUST CSF
  • SOC 2 Type II
  • PCI-DSS
  • Ensure controls appropriately protect PHI, personally identifiable information (PII), payment card data, and other sensitive healthcare information.
  • Maintain policies, standards, procedures, risk methodologies, and control documentation.
  • Support compliance with Business Associate Agreements (BAAs), client security requirements, and healthcare customer contractual obligations.
  • Monitor changes in healthcare regulations, cybersecurity requirements, and industry standards.
  • Coordinate internal and external assessments, certifications, client audits, and regulatory reviews.
  • Conduct enterprise risk assessments and maintain the organizational risk register.
  • Perform third-party/vendor security risk assessments.
  • Develop mitigation strategies and monitor remediation activities.
  • Present risk metrics and executive reports to senior leadership.
  • Support business continuity and disaster recovery governance.
AI Governance & Responsible AI
  • Develop and maintain an AI governance framework for the responsible use of artificial intelligence within healthcare RCM.
  • Establish policies and controls governing generative AI, machine learning, automation, and AI-enabled decision-support technologies.
  • Evaluate AI use cases involving:
  • Coding assistance
  • Claims analytics
  • Revenue forecasting
  • Assess AI solutions for privacy, security, accuracy, bias, transparency, explainability, and regulatory risk.
  • Ensure PHI is appropriately protected when using internally developed or third-party AI tools.
  • Establish approval and risk-review processes for new AI use cases and vendors.
  • Maintain an inventory of approved AI systems, use cases, owners, data sources, and associated risks.
  • Align AI governance practices with frameworks such as the NIST AI Risk Management Framework and ISO/IEC 42001 where appropriate.
Audit & Client Assurance
  • Lead preparation for SOC 2, HITRUST, HIPAA, PCI DSS, and customer security assessments.
  • Coordinate evidence collection and control testing across business and technology teams.
  • Manage remediation plans for audit findings, control deficiencies, and client security observations.
  • Respond to customer security questionnaires and due diligence requests.
  • Participate in security and compliance discussions with healthcare providers, health systems, physician groups, payers, and other clients.
  • Maintain a centralized repository of compliance evidence, audit documentation, and client assurance materials.
Third-Party Risk Management
  • Lead or support vendor security and compliance assessments.
  • Evaluate vendors that access, process, transmit, or store PHI, PII, payment information, or other sensitive data.
  • Review security documentation including SOC reports, HITRUST certifications, penetration tests, and risk assessments.
  • Ensure appropriate BAAs, data protection agreements, and security requirements are in place.
  • Monitor critical vendors for changes in risk posture.
Security & Privacy Governance
  • Partner with Information Security and Privacy teams to maintain administrative, technical, and physical safeguards required by HIPAA.
  • Support identity and access management governance for systems containing healthcare information.
  • Participate in incident response activities involving potential PHI exposure, security incidents, or compliance concerns.
  • Support breach assessment and regulatory notification processes where required.
  • Oversee security and compliance awareness programs for employees and contractors.
  • Promote appropriate handling of healthcare data across operational teams.
Program Management & Reporting
  • Develop GRC dashboards and executive reporting for risk, audit status, remediation, vendor risk, and compliance metrics.
  • Track key risk indicators and key performance indicators for the compliance program.
  • Manage compliance calendars and recurring control activities.
  • Lead cross-functional remediation and compliance initiatives.
  • Present significant risks, findings, and recommendations to senior leadership.
  • Drive automation and continuous improvement within the GRC program.

Required Qualifications

  • Bachelor's degree in Information Security, Cybersecurity, Information Systems, Business, or related field or equivalent years of experience.
  • 6–8+ years of experience in Governance, Risk, and Compliance.
  • Demonstrated experience managing:
  • SOC 2
  • HITRUST
  • PCI DSS
  • Experience leading external audits and remediation efforts.
  • Strong understanding of information security principles, risk management, and internal controls.
  • Excellent communication, documentation, and stakeholder management skills.
  • Experience using GRC platforms.

One or more of the following certifications is preferred:

  • Certified Information Systems Security Professional (CISSP)
  • Certified Information Security Manager (CISM)
  • Certified Information Systems Auditor (CISA)
  • Certified in Risk and Information Systems Control (CRISC)
  • Certified HIPAA Professional (CHP)
  • PCI Professional (PCIP)
  • ISO 27001 Lead Implementer or Lead Auditor
  • Certified in Governance, Risk and Compliance (CGRC)
  • AI governance or risk certifications (e.g., ISO/IEC 42001 Lead Implementer, NIST AI RMF training, or equivalent).
You will be a good fit if:
  • You are known for being thorough and crossing every “T”.
  • You enjoy collaboration and building relationships at every level.
  • Curiosity and willingness to learn new things.
  • Excellent organization and planning skills, both technical and strategic.
  • Stay updated with the latest in technology and cybersecurity trends to recommend improvements to our IT and security infrastructure.
  • Ability to communicate regularly and have a desire to be a part of a team.
Additional Notes

This role profile is not intended to be an exhaustive list of qualifications, skills, efforts, duties, responsibilities or working conditions associated with the position.

GetixHealth is an equal employment opportunity employer.

Equal Opportunity Employer
This employer is required to notify all applicants of their rights pursuant to federal employment laws.For further information, please review the Know Your Rights notice from the Department of Labor.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

HIPAA & SOC 2 Compliance Specialist – IGDSJP#059
HIPAA & SOC 2 Compliance Specialist – IGDSJP#059

IGDS Technologies • India

On-site
INR 1,500,000 - 2,200,000
Information Security and Data Privacy Manager
Information Security and Data Privacy Manager

Tiger Analytics • Chennai District

Hybrid
INR 2,500,000 - 6,000,000
Lead - GRC and AI Governance
Lead - GRC and AI Governance

LeadSquared • Bengaluru

On-site
INR 1,800,000 - 2,600,000
Sr Engineer, Governance, Risk & Compliance
Sr Engineer, Governance, Risk & Compliance

NextGen Healthcare India • Bengaluru

On-site
INR 1,600,000 - 2,800,000
Senior Manager
Senior Manager

Pellera Technologies • India

On-site
INR 2,500,000 - 4,500,000
Sr. Governance Risk & Compliance Analyst
Sr. Governance Risk & Compliance Analyst

Providence India • Hyderabad

On-site
INR 1,200,000 - 1,800,000
Director Information Security Risk Management
Director Information Security Risk Management

Optum • Hyderabad

On-site
INR 3,500,000 - 7,000,000
Manager - GRC
Manager - GRC

ZS • Pune District

Hybrid
INR 2,500,000 - 4,500,000
Product GRC Consultant
Product GRC Consultant

CyRAACS™ • Bengaluru

On-site
INR 600,000 - 1,200,000
Senior GRC Analyst
Senior GRC Analyst

Litmos • India

On-site
INR 2,400,000 - 3,200,000