Live opening · Posted 3 days ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
Seeking a GRC and Privacy professional with 3 - 4 years of experience to support and enhance governance, risk, and compliance programs across ISO/IEC 27001 2022 SOC 2 Type II, HIPAA, HITRUST, and ISO/IEC 27701 The role involves audit readiness, risk management, policy governance, and third-party risk oversight across internal programs or client engagements.
Responsibilities:
Lead ISMS implementation aligned with ISO/IEC 27001:2022 and PIMS aligned with ISO/IEC 27701 HIPAA, and HITRUST.
Perform control mapping across frameworks to build a unified control framework.
Develop, review, and update policies, standards, and procedures.
Execute SOC 2 Type II audits (control mapping, walkthroughs, evidence validation).
Coordinate internal/external audits and manage audit evidence lifecycle.
Support continuous control monitoring (CCM) and periodic compliance reviews.
Prepare reports for leadership and support management review meetings.
Participate in customer/vendor audits (client-facing audits).
Lead enterprise risk assessments and maintain risk register.
Support risk prioritisation using qualitative/quantitative methods.
Perform control gap assessments and drive remediation tracking.
Manage risk acceptances, exceptions, and deviations with proper approvals and tracking.
Perform vendor risk assessments for critical/high-risk vendors.
Conduct detailed contractual reviews of vendor agreements to ensure inclusion and compliance with security, privacy, and regulatory requirements.
Govern data lifecycle management including classification, retention, archival, and deletion.
Conduct Privacy Impact Assessments (PIA/DPIA).
Ensure proper handling of PII/PHI data by the teams.
Support handling of data subject rights requests (DSAR) such as access, deletion, and rectification.
Conduct security and privacy awareness training programs and track participation.
Collaborate with IT / Security / Tech / HR teams for control implementation and monitoring.
Collaborate with legal, privacy, and business teams on regulatory and data protection requirements.
Support privacy incident/data breach assessments and reporting obligations.
Requirements:
Hands-on experience with ISO/IEC 27001:2022 ISO/IEC 27701 implementation and SOC 2 Type II audits (mandatory), HIPAA and HITRUST.
Strong understanding of conducting risk assessments, maintaining risk registers, and tracking remediation activities across internal operations, client engagements, and vendor ecosystems.
Experience in audit coordination, evidence management, and audit lifecycle handling.
Working knowledge of privacy frameworks (ISO 27701 / HIPAA basics).
Working knowledge of global privacy regulations (e. g., General Data Protection Regulation, India DPDP Act).
Experience in GRC tools, policy development, and documentation.
Ability to work with cross-functional stakeholders (IT, Legal, Business).
Certifications like ISO/IEC 27001 Lead Implementer / Lead Auditor, ISO 27701 Lead Implementer / Auditor.
Experience
3-5 yrs
More openings worth a look
Recently tracked roles with full details and direct application links.