HIPAA & SOC 2 Compliance Specialist – IGDSJP#059

IGDS Technologies

India

On-site

INR 1,500,000 - 2,200,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

IGDS Technologies is seeking a HIPAA & SOC 2 Compliance Specialist to join our GRC team in India. You will drive HIPAA program management and SOC 2 Type II readiness across the organization, coordinating audits and evidence collection while ensuring PHI protection and secure governance.

The ideal candidate has 3–5 years' experience in information security, GRC or IT audit, with hands-on HIPAA and SOC 2 knowledge, familiar with IAM, MFA, encryption and risk assessments.

Qualifications

  • 3-5 years in Information Security, GRC, IT Audit or Compliance.
  • Hands-on HIPAA and SOC 2 Type II audit experience.
  • Strong knowledge of HIPAA Privacy/Security Rules and PHI requirements.
  • Experience with IAM, MFA, encryption, logging, vulnerability management and DR.

Responsibilities

  • Lead HIPAA compliance program and SOC 2 Type II audit lifecycle.
  • Coordinate SOC 2 observation periods, audit readiness, and recertifications.
  • Collect and maintain audit evidence demonstrating control effectiveness.
  • Develop and improve security policies, procedures and compliance docs.
  • Identify and address compliance gaps across infra, apps and processes.
  • Collaborate with cross-functional teams to strengthen controls.

Skills

HIPAA compliance
SOC 2 Type II
GRC
Audit readiness
Risk assessment
Documentation

Education

Bachelor's in CS/IT/CIS

Tools

Vanta
Drata
Secureframe
Sprinto

Job description

HIPAA & SOC 2 Compliance Specialist - IGDSJP#059
Experience: 3-5 Years

About the Role

We are seeking a highly motivatedHIPAA & SOC 2 Compliance Specialistto join our Governance, Risk, and Compliance (GRC) team. In this role, you will be responsible for driving and maintaining the organization’s HIPAA compliance program while leading SOC 2 Type II audit readiness and ongoing compliance initiatives.

You will work closely with Engineering, DevOps, Human Resources, Product, and Operations teams to ensure security controls are effectively implemented, monitored, and documented. The ideal candidate will have hands-on experience managing compliance frameworks, coordinating external audits, conducting risk assessments, and ensuring the protection of sensitive healthcare information (PHI).

Key Responsibilities

  • Lead and manage the organization’s HIPAA compliance program and SOC 2 Type II audit lifecycle.
  • Plan, coordinate, and manage SOC 2 Type II observation periods, audit readiness activities, and annual recertification efforts.
  • Collect, review, and maintain audit evidence to demonstrate the effectiveness of security and operational controls.
  • Develop, maintain, and improve security policies, procedures, and compliance documentation.
  • Perform periodic risk assessments and identify compliance gaps across infrastructure, applications, and business processes.
  • Collaborate with Engineering, DevOps, HR, and Operations teams to implement corrective actions and strengthen security controls.
  • Ensure appropriate safeguards are in place for Protected Health Information (PHI) in accordance with HIPAA Privacy and Security Rules.
  • Monitor compliance with access management, identity management, data retention, encryption, vulnerability management, and incident response policies.
  • Coordinate internal compliance reviews and support external auditors throughout audit engagements.
  • Track remediation activities and ensure timely closure of audit findings and compliance issues.
  • Provide compliance awareness and security best practice guidance across the organization.
  • Stay current with evolving regulatory requirements, industry standards, and emerging security risks.

Job Requirements

  • 3-5 years of experience in Information Security, Governance, Risk & Compliance (GRC), IT Audit, or Compliance roles.
  • Strong hands-on experience managing HIPAA compliance programs and SOC 2 Type II audits.
  • Thorough understanding of HIPAA Privacy Rule, Security Rule, and Protected Health Information (PHI) requirements.
  • Strong knowledge of SOC 2 Trust Services Criteria, including Security, Availability, Confidentiality, Processing Integrity, and Privacy.
  • Experience performing security control assessments, risk assessments, and compliance gap analyses.
  • Experience collecting, organizing, and maintaining audit evidence and compliance documentation.
  • Familiarity with security controls such as Identity and Access Management (IAM), Multi-Factor Authentication (MFA), encryption, logging, vulnerability management, backup, and disaster recovery.
  • Strong documentation, analytical, problem-solving, and organizational skills.
  • Excellent verbal and written communication skills with the ability to work effectively with auditors and cross-functional teams.
  • Bachelor's degree in Computer Science, Cyber Security, Information Technology, or a related field.

Nice to Have (Added Advantage)

  • Professional certifications such as CISA, CISM, CISSP, CRISC, HCISPP, or ISO 27001 Lead Implementer/Auditor.
  • Experience with additional compliance frameworks such as HITRUST, ISO 27001, NIST CSF, GDPR, or PCI DSS.
  • Experience working in cloud environments such as AWS, Microsoft Azure, or Google Cloud Platform (GCP).
  • Familiarity with compliance automation and GRC platforms such as Vanta, Drata, Secureframe, Sprinto, or similar tools.
  • Experience supporting healthcare technology, SaaS, or cloud-native platforms.

What You'll Work On

  • Leading HIPAA compliance initiatives across the organization.
  • Managing SOC 2 Type II audit readiness, evidence collection, and annual certification activities.
  • Protecting sensitive healthcare data through effective security governance.
  • Partnering with cross-functional teams to strengthen security controls and reduce organizational risk.
  • Driving continuous improvement of compliance processes, policies, and security best practices.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Governance Risk and Complains Manager
Governance Risk and Complains Manager

Getix Health, LLC 1099 • Karnataka

On-site
INR 2,400,000 - 3,600,000
Lead Compliance Specialist
Lead Compliance Specialist

TAC Security • Chandigarh

On-site
INR 2,600,000 - 3,200,000
Lead Security GRC Analyst
Lead Security GRC Analyst

Providence India • Hyderabad

On-site
INR 1,800,000 - 2,400,000
Information Security and Data Privacy Manager
Information Security and Data Privacy Manager

Tiger Analytics • Chennai District

Hybrid
INR 2,500,000 - 6,000,000
Senior GRC Analyst
Senior GRC Analyst

Exotel • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Senior Manager
Senior Manager

Pellera Technologies • India

On-site
INR 2,500,000 - 4,500,000
Senior Security Compliance Consultant (SOC 2 & GRC Specialist)
Senior Security Compliance Consultant (SOC 2 & GRC Specialist)

Embedded Shishya • Gopalganj

Hybrid
INR 1,800,000 - 2,800,000
Compliance Coordinator
Compliance Coordinator

Trackwizz • Mumbai

On-site
INR 650,000 - 1,000,000
Sr. Consultant - Compliance
Sr. Consultant - Compliance

TAC Security • Delhi

On-site
INR 1,800,000 - 3,000,000
Sr. Consultant - Compliance
Sr. Consultant - Compliance

TAC Security • New Delhi

On-site
INR 1,800,000 - 2,800,000