Senior InfoSec GRC Specialist

Velsera

Maharashtra

On-site

INR 4,200,000 - 6,200,000

Full time

7 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Flexible Work & Time Off
Health & Well-being
Growth & Learning
Engaging & Fun Work Culture
And Many More..

Job summary

Velsera seeks a senior Information Security GRC leader to drive risk management, compliance, and governance across cloud environments. You will shape policies, lead ISO 27001 programs, and coordinate audits with cross-functional teams.

The role requires 8+ years of hands-on experience in security governance and a solid track record implementing controls for HIPAA and ISO 27001 alignment. You will mentor staff while advancing Velsera's security posture globally.

Qualifications

  • 8+ years of progressive experience in Information Security GRC.
  • Experience driving and maintaining ISO 27001 programs.
  • Security controls implementation in cloud-centric environments.

Responsibilities

  • Develop, implement, and maintain information security policies, standards, and procedures per ISO 27001.
  • Lead and mature the ISMS including risk treatment and audits.
  • Act as SME for Security and Privacy Rules for PII/PHI across systems.
  • Conduct continuous monitoring and evidence collection for compliance.
  • Plan and manage internal and supplier audits.
  • Lead GRC activities and ensure timely execution.
  • Perform risk assessments and cloud infrastructure gap analyses.
  • Collaborate with Product/Tech/IT to implement security controls in cloud environments.
  • Review remediation efforts and vendor risk assessments.
  • Develop security awareness and training on HIPAA and ISO 27001.
  • Evaluate new security technologies to improve posture.

Skills

ISO 27001
Cloud Security
GRC
Audits

Education

Bachelor's degree in IT/CS
CISSP
CISA
ISO 27001 Lead Implementer/Auditor
CCSK
NIST 800-53

Tools

Cloud-native security services

Job description

About Velsera

Medicine moves too slow. At Velsera, we are changing that.

Velsera was formed in 2023 through the shared vision of Seven Bridges and Pierian, with a mission to accelerate the discovery, development, and delivery of life-changing insights.

With our headquarters in Boston, MA, we are growing and expanding our teams located in different countries!

Velsera provides software and professional services for:

  • AI-powered multimodal data harmonization and analytics for drug discovery and development
  • IVD development, validation, and regulatory approval
  • Clinical NGS interpretation, reporting, and adoption
What will you do?
Compliance & Governance
  • Develop, implement, and maintain comprehensive information security policies, standards, and procedures aligned with the ISO 27001 framework
  • Lead, manage, and mature the organization's Information Security Management System including risk treatment, internal audits, and readiness for external certification audits
  • Serve as the subject matter expert (SME) for Security and Privacy Rules, ensuring compliance for all systems, processes, and applications handling PII and Protected Health Information (PHI)
  • Conduct continuous monitoring and evidence collection to demonstrate compliance with relevant frameworks
  • Plan, conduct and manage internal and supplier audits
  • Plan GRC activities, prioritise and implement them in timebound manner
  • Perform detailed security risk assessments and gap analyses on new and existing systems, with a focus on cloud infrastructure
  • Collaborate with Product, Technology, IT and Security teams to implement security controls into cloud / infra / environments, ensuring compliance. Provide technical guidance to them on implementing controls and best practices, specifically related to cloud security architecture and configurations
  • Review risk mitigations periodically and track remediation efforts to closure
  • Conduct third-party vendor risk assessments, focusing on their adherence to required compliance standards
  • Develop and deliver targeted security awareness and training programs focused on HIPAA and ISO 27001 requirements for all staff, including technical teams
  • Evaluate and recommend new security technologies and processes to enhance the compliance and risk posture
  • Stay current on emerging cloud security threats, regulatory changes, and updates to the ISO 27001 family of standards and HIPAA
Requirements
What do you bring to the table?
  • Experience:
  • Minimum of 8+ years of progressive experience in Information Security GRC, with a focus on risk management, compliance, and governance
  • Proven, hands-on experience driving and maintaining ISO 27001 certification programs
  • Deep practical knowledge and experience of implementing security controls ensuring compliance in a technical, cloud-centric environment
  • Strong technical competency in Cloud Security (AWS, Azure, or GCP) and related cloud-native security services
  • Education: Bachelor's degree in IT, Computer Science or related field
  • Certifications (One or more highly preferred):
  • CISSP (Certified Information Systems Security Professional)
  • CISA (Certified Information Systems Auditor)
  • ISO 27001 Lead Implementer/Auditor
  • CCSK (Certificate of Cloud Security Knowledge) or equivalent Cloud-specific security certification (e.g., AWS Certified Security, Azure Security Engineer)
  • Hands-on experience with NIST 800-53 compliance frameworks is required
Soft Skills
  • Proficiency in written and verbal communication skills with the ability to translate complex security and compliance requirements / controls into clear actionable
  • Strong project management and organizational skills to handle multiple, simultaneous audit and compliance initiatives
  • A collaborative and proactive mindset, with the ability to influence and lead cross-functional teams without direct authority
Benefits
  • Flexible Work & Time Off - Embrace hybrid work models and enjoy the freedom of unlimited paid time off to support work-life balance
  • Health & Well-being - Access comprehensive group medical and life insurance coverage, along with a 24/7 Employee Assistance Program (EAP) for mental health and wellness support
  • Growth & Learning - Fuel your professional journey with continuous learning and development programs designed to help you upskill and grow
  • Engaging & Fun Work Culture - Experience a vibrant workplace with team events, celebrations, and engaging activities that make every workday enjoyable
  • & Many More..
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior InfoSec GRC Specialist
Senior InfoSec GRC Specialist

Velsera • Pune District

On-site
INR 4,000,000 - 6,500,000
Unlimited paid time off
Group medical & life insurance
EAP for mental health
+2
Senior GRC Expert
Senior GRC Expert

Velsera • Pune District

Hybrid
INR 3,000,000 - 5,200,000
Hybrid work model
Unlimited paid time off
Health insurance
+1
Senior Security Operations Engineer
Senior Security Operations Engineer

Velsera • Maharashtra

Hybrid
INR 800,000 - 1,500,000
Unlimited paid time off
Comprehensive medical and life insurance
Continuous learning and development programs
+1
Senior Software Quality Assurance Specialist
Senior Software Quality Assurance Specialist

Velsera • Maharashtra

Hybrid
INR 1,200,000 - 2,400,000
Flexible Work & Time Off
Health & Life Insurance
Growth & Learning Programs
+2
Senior Software Quality Assurance Specialist
Senior Software Quality Assurance Specialist

Velsera • Pune District

Hybrid
INR 1,200,000 - 2,100,000
Hybrid work model
Unlimited paid time off
Group medical and life insurance
+2
Technical Lead, Engineering
Technical Lead, Engineering

Velsera • Maharashtra

Hybrid
INR 4,000,000 - 6,500,000
Hybrid work model
Health insurance
Unlimited PTO
Senior Director, Engineering
Senior Director, Engineering

PierianDx India Private Limited • Pune District

On-site
INR 1,500,000 - 2,500,000
AI/LLM Architect
AI/LLM Architect

PierianDx India Private Limited • Pune District

On-site
INR 2,500,000 - 3,500,000
Senior Software Engineer (Python)
Senior Software Engineer (Python)

PierianDx India Private Limited • Pune District

On-site
INR 1,000,000 - 1,500,000
GRC Analyst
GRC Analyst

Embedded Shishya • Gopalganj

Hybrid
INR 12,823,000 - 19,330,000
Competitive compensation with equity
Inclusive healthcare package
Mentorship and event opportunities