Senior InfoSec GRC Specialist

Velsera

Pune District

On-site

INR 4,000,000 - 6,500,000

Full time

6 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Unlimited paid time off
Group medical & life insurance
EAP for mental health
Learning & development opportunities
Team events

Job summary

Velsera is seeking an experienced Information Security GRC professional to lead governance, risk, and compliance in a hybrid role based in Pune, India. You will develop ISO 27001 policies, drive audits, and manage risk across cloud environments with PHI/PII considerations, collaborating with cross-functional teams.

You will also oversee third-party risk assessments, deliver HIPAA- and ISO 27001-focused training, and guide security controls across Product, Technology, and IT groups to strengthen

Qualifications

  • 8+ years of progressive Information Security GRC experience with risk management, compliance, and governance.
  • Hands-on experience driving and maintaining ISO 27001 certification programs.
  • Deep practical knowledge implementing security controls ensuring compliance in a cloud-centric environment.
  • Strong technical competency in Cloud Security (AWS, Azure, or GCP).
  • Bachelor's degree in IT, Computer Science or related field.
  • Certifications: CISSP, CISA, ISO 27001 Lead Implementer/Auditor, CCSK or equivalent.

Responsibilities

  • Develop, implement, and maintain information security policies, standards, and procedures aligned with ISO 27001.
  • Lead, manage, and mature the organization's ISMS including risk treatment, audits, and external certification readiness.
  • Serve as SME for Security/Privacy Rules to ensure PHI/PII compliance across systems.
  • Conduct continuous monitoring and evidence collection for regulatory compliance.
  • Plan and manage internal and supplier audits; drive remediation to closure.
  • Perform risk assessments and gap analyses focusing on cloud infrastructure.
  • Collaborate with Product, Technology, IT and Security to implement controls in cloud environments.
  • Review risk mitigations and track remediation; conduct vendor risk assessments.
  • Develop security awareness training focused on HIPAA and ISO 27001.

Skills

Cloud security
ISO 27001
HIPAA compliance
Communication skills
Project management
Cross-functional collaboration
Vendor risk assessment

Education

Bachelor's degree in IT/CS or related field
CISSP
CISA
ISO 27001 Lead Implementer/Auditor
CCSK or cloud security cert
NIST 800-53 experience

Job description

About Velsera

Medicine moves too slow. At Velsera, we are changing that.

Velsera was formed in 2023 through the shared vision of Seven Bridges and Pierian, with a mission to accelerate the discovery, development, and delivery of life-changing insights.

Velsera provides software and professional services for:

  • AI-powered multimodal data harmonization and analytics for drug discovery and development
  • IVD development, validation, and regulatory approval
  • Clinical NGS interpretation, reporting, and adoption

With our headquarters in Boston, MA, we are growing and expanding our teams located in different countries!

What will you do?

Compliance & Governance

  • Develop, implement, and maintain comprehensive information security policies, standards, and procedures aligned with the ISO 27001 framework
  • Lead, manage, and mature the organization's Information Security Management System including risk treatment, internal audits, and readiness for external certification audits.
  • Serve as the subject matter expert (SME) for Security and Privacy Rules, ensuring compliance for all systems, processes, and applications handling PII and Protected Health Information (PHI).
  • Conduct continuous monitoring and evidence collection to demonstrate compliance with relevant frameworks.
  • Plan, conduct and manage internal and supplier audits
  • Plan GRC activities, prioritise and implement them in timebound manner.
  • Perform detailed security risk assessments and gap analyses on new and existing systems, with a focus on cloud infrastructure
  • Collaborate with Product, Technology, IT and Security teams to implement security controls into cloud / infra / environments, ensuring compliance. Provide technical guidance to them on implementing controls and best practices, specifically related to cloud security architecture and configurations.
  • Review risk mitigations periodically and track remediation efforts to closure.
  • Conduct third-party vendor risk assessments, focusing on their adherence to required compliance standards.
  • Develop and deliver targeted security awareness and training programs focused on HIPAA and ISO 27001 requirements for all staff, including technical teams.
  • Evaluate and recommend new security technologies and processes to enhance the compliance and risk posture.
  • Stay current on emerging cloud security threats, regulatory changes, and updates to the ISO 27001 family of standards and HIPAA.
What do you bring to the table?

Experience:

  • Minimum of 8+ years of progressive experience in Information Security GRC, with a focus on risk management, compliance, and governance.
  • Proven, hands‑on experience driving and maintaining ISO 27001 certification programs.
  • Deep practical knowledge and experience of implementing security controls ensuring compliance in a technical, cloud‑centric environment.
  • Strong technical competency in Cloud Security (AWS, Azure, or GCP) and related cloud‑native security services.
  • Education: Bachelor's degree in IT, Computer Science or related field.
  • Certifications (One or more highly preferred):
  • CISSP (Certified Information Systems Security Professional)
  • CISA (Certified Information Systems Auditor)
  • ISO 27001 Lead Implementer/Auditor
  • CCSK (Certificate of Cloud Security Knowledge) or equivalent Cloud-specific security certification (e.g., AWS Certified Security, Azure Security Engineer).
  • Hands‑on experience with NIST 800‑53 compliance frameworks is required.
Soft Skills
  • Proficiency in written and verbal communication skills with the ability to translate complex security and compliance requirements / controls into clear actionable
  • Strong project management and organizational skills to handle multiple, simultaneous audit and compliance initiatives.
  • A collaborative and proactive mindset, with the ability to influence and lead cross‑functional teams without direct authority.
  • Flexible Work & Time Off - Embrace hybrid work models and enjoy the freedom of unlimited paid time off to support work-life balance.
  • Health & Well-being - Access comprehensive group medical and life insurance coverage, along with a 24/7 Employee Assistance Program (EAP) for mental health and wellness support.
  • Growth & Learning - Fuel your professional journey with continuous learning and development programs designed to help you upskill and grow.
  • Engaging & Fun Work Culture - Experience a vibrant workplace with team events, celebrations, and engaging activities that make every workday enjoyable.
  • & Many More...
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Operations Engineer
Senior Security Operations Engineer

Velsera • Maharashtra

Hybrid
INR 800,000 - 1,500,000
Unlimited paid time off
Comprehensive medical and life insurance
Continuous learning and development programs
+1
Technical Lead, Engineering
Technical Lead, Engineering

Velsera • Pune District

Hybrid
INR 2,000,000 - 3,000,000
Flexible Work & Time Off
Health & Well-being
Growth & Learning
+2
Technical Lead, Engineering
Technical Lead, Engineering

Velsera Inc. • Pune District

Hybrid
INR 2,000,000 - 3,000,000
Unlimited paid time off
Comprehensive medical and life insurance
Continuous learning and development programs
+2
Senior Director, Engineering
Senior Director, Engineering

PierianDx India Private Limited • Pune District

On-site
INR 1,500,000 - 2,500,000
AI/LLM Architect
AI/LLM Architect

PierianDx India Private Limited • Pune District

On-site
INR 2,500,000 - 3,500,000
Senior Software Engineer (Python)
Senior Software Engineer (Python)

PierianDx India Private Limited • Pune District

On-site
INR 1,000,000 - 1,500,000
GRC Analyst
GRC Analyst

Embedded Shishya • Gopalganj

Hybrid
INR 12,823,000 - 19,330,000
Competitive compensation with equity
Inclusive healthcare package
Mentorship and event opportunities
Technical Lead, Engineering
Technical Lead, Engineering

PierianDx India Private Limited • Pune District

On-site
INR 1,500,000 - 2,500,000
Senior Bioinformatics Engineer
Senior Bioinformatics Engineer

PierianDx India Private Limited • Pune District

On-site
INR 1,200,000 - 1,800,000
GRC Analyst
GRC Analyst

Cyderes • Bengaluru

Hybrid
INR 1,200,000 - 2,400,000
Medical Insurance
Life Insurance
Retirement Match Program
+6