Senior InfoSec GRC Specialist

Posted 5 Days Ago
Be an Early Applicant
Pune, Mahārāshtra, IND
In-Office
Senior level
Healthtech • Biotech
The Role
Lead Velsera’s information security governance, risk, and compliance program. Responsibilities include maintaining ISO 27001 certification, managing the ISMS, conducting risk assessments and audits, collecting compliance evidence, overseeing vendor risk, implementing cloud security controls, tracking remediation, and delivering HIPAA and ISO 27001 awareness training. The role requires strong cloud security expertise, NIST 800-53 experience, cross-functional leadership, and coordination of internal and external audits.
Summary Generated by Built In

About Velsera

Medicine moves too slow. At Velsera, we are changing that.

Velsera was formed in 2023 through the shared vision of Seven Bridges and Pierian, with a mission to accelerate the discovery, development, and delivery of life-changing insights.

Velsera provides software and professional services for:

  • AI-powered multimodal data harmonization and analytics for drug discovery and development
  • IVD development, validation, and regulatory approval
  • Clinical NGS interpretation, reporting, and adoption

With our headquarters in Boston, MA, we are growing and expanding our teams located in different countries!


What will you do?

Compliance & Governance

  • Develop, implement, and maintain comprehensive information security policies, standards, and procedures aligned with the ISO 27001 framework
  • Lead, manage, and mature the organization's Information Security Management System including risk treatment, internal audits, and readiness for external certification audits.
  • Serve as the subject matter expert (SME) for Security and Privacy Rules, ensuring compliance for all systems, processes, and applications handling PII and Protected Health Information (PHI).
  • Conduct continuous monitoring and evidence collection to demonstrate compliance with relevant frameworks.
  • Plan, conduct and manage internal and supplier audits
  • Plan GRC activities, prioritise and implement them in timebound manner.
  • Perform detailed security risk assessments and gap analyses on new and existing systems, with a focus on cloud infrastructure
  • Collaborate with Product, Technology, IT and Security teams to implement security controls into cloud / infra / environments, ensuring compliance. Provide technical guidance to them on implementing controls and best practices, specifically related to cloud security architecture and configurations.
  • Review risk mitigations periodically and track remediation efforts to closure.
  • Conduct third-party vendor risk assessments, focusing on their adherence to required compliance standards.
  • Develop and deliver targeted security awareness and training programs focused on HIPAA and ISO 27001 requirements for all staff, including technical teams.
  • Evaluate and recommend new security technologies and processes to enhance the compliance and risk posture.
  • Stay current on emerging cloud security threats, regulatory changes, and updates to the ISO 27001 family of standards and HIPAA.

Requirements

What do you bring to the table?

· Experience:

  • Minimum of 8+ years of progressive experience in Information Security GRC, with a focus on risk management, compliance, and governance.
  • Proven, hands-on experience driving and maintaining ISO 27001 certification programs.
  • Deep practical knowledge and experience of implementing security controls ensuring compliance in a technical, cloud-centric environment.
  • Strong technical competency in Cloud Security (AWS, Azure, or GCP) and related cloud-native security services.
  • Education: Bachelor's degree in IT, Computer Science or related field.
  • Certifications (One or more highly preferred):
  • CISSP (Certified Information Systems Security Professional)
  • CISA (Certified Information Systems Auditor)
  • ISO 27001 Lead Implementer/Auditor
  • CCSK (Certificate of Cloud Security Knowledge) or equivalent Cloud-specific security certification (e.g., AWS Certified Security, Azure Security Engineer).
  • Hands-on experience with NIST 800-53 compliance frameworks is required.

Soft Skills

  • Proficiency in written and verbal communication skills with the ability to translate complex security and compliance requirements / controls into clear actionable
  • Strong project management and organizational skills to handle multiple, simultaneous audit and compliance initiatives.
  • A collaborative and proactive mindset, with the ability to influence and lead cross-functional teams without direct authority.

Benefits
  • Flexible Work & Time Off - Embrace hybrid work models and enjoy the freedom of unlimited paid time off to support work-life balance.
  • Health & Well-being - Access comprehensive group medical and life insurance coverage, along with a 24/7 Employee Assistance Program (EAP) for mental health and wellness support.
  • Growth & Learning - Fuel your professional journey with continuous learning and development programs designed to help you upskill and grow.
  • Engaging & Fun Work Culture - Experience a vibrant workplace with team events, celebrations, and engaging activities that make every workday enjoyable.
  • & Many More...

Skills Required

  • 8+ years of progressive experience in Information Security GRC, risk management, compliance, and governance
  • Hands-on experience driving and maintaining ISO 27001 certification programs
  • Practical experience implementing security controls in technical, cloud-centric environments
  • Strong technical competency in cloud security, including AWS, Azure, or GCP
  • Bachelor’s degree in IT, Computer Science, or a related field
  • Hands-on experience with the NIST 800-53 compliance framework
  • CISSP certification
  • CISA certification
  • ISO 27001 Lead Implementer or Lead Auditor certification
  • CCSK or equivalent cloud-specific security certification
  • Strong written and verbal communication skills
  • Strong project management and organizational skills
  • Collaborative and proactive mindset with ability to influence cross-functional teams without direct authority
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Charlestown, MA
622 Employees

What We Do

Velsera connects healthcare and life sciences to reveal the true promise of precision medicine — a continuous flow of knowledge between researchers, scientists, and clinicians around the world, fueling innovation and creating insights that radically improve human health. Our goal is to use data to radically improve healthcare globally and create value through multiomics and insights. If you’re interested in learning more about Velsera, please follow us and visit our website at velsera.com! Looking for someone to get in touch with? Please email [email protected]

Similar Jobs

TransUnion Logo TransUnion

Artificial Intelligence Engineer

Big Data • Fintech • Information Technology • Business Intelligence • Financial Services • Cybersecurity • Big Data Analytics
Hybrid
Pune, Mahārāshtra, IND
13000 Employees

TransUnion Logo TransUnion

Data Engineer

Big Data • Fintech • Information Technology • Business Intelligence • Financial Services • Cybersecurity • Big Data Analytics
Hybrid
Pune, Mahārāshtra, IND
13000 Employees

Optum Logo Optum

Employee Relations Analyst

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office
Pune, Mahārāshtra, IND
160000 Employees

Capco Logo Capco

Test Automation Engineer

Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Remote or Hybrid
India
6000 Employees

Similar Companies Hiring

Sailor Health Thumbnail
Healthtech • Social Impact • Telehealth
New York City, NY
20 Employees
Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
OneImaging Thumbnail
Healthtech
Miami, FL
62 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account