





Tier-1 brand and Hyderabad metro raise competition, but specialized GRC focus reduces candidate pool.
Role requires healthcare-regulated cybersecurity and GRC expertise, making background fit highly industry-specific.
Mandatory 7+ years, specific GRC experience and CISSP/CRISC/CISA certifications make shortlisting strict.
Login to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Lead internal cybersecurity risk assessments from start to finish including identification, evaluation, treatment, monitoring, and closure of risks.
Develop and maintain audit-ready risk records and drive risk-related decision making in compliance with regulatory standards such as HIPAA and GDPR.
Improve GRC processes through workflow design, automation, and integration, collaborating with cross-functional teams across IT, legal, compliance, and product security.
7+ years of IT experience with a Bachelor’s degree in Engineering, MCA, or MSc.
7+ years’ experience in cybersecurity GRC or internal/external audit, preferably in healthcare or medical device industry.
At least 5 years executing risk assessments using methodologies like FAIR and NIST, including hands-on program design and implementation experience.
Certifications required: CISSP, CRISC, and CISA.
Experienced in applying cybersecurity risk management frameworks (NIST CSF, ISO 27001, FAIR) within large, complex regulated environments.
Strong technical background in cybersecurity controls, system architecture, and regulatory compliance (HIPAA, GDPR) in healthcare contexts.
Skilled in driving GRC process improvements leveraging automation and integration in tools such as ServiceNow, Archer, or LogicGate.