This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Governance Risk and Compliance Manager based in India.
This role offers the opportunity to lead a comprehensive Governance, Risk, and Compliance program within a highly regulated healthcare technology environment. You will oversee critical compliance frameworks including HIPAA, HITRUST, SOC 2, and PCI DSS while helping protect sensitive healthcare, payment, and personal data. The position also has a strong focus on AI governance, providing an opportunity to shape responsible adoption of generative AI, machine learning, and automation. You will partner with Information Security, IT, Legal, Privacy, Operations, Engineering, and executive stakeholders to identify and reduce organizational risk. The role combines strategic program leadership with hands-on audit, risk, vendor, compliance, and remediation activities. You will also help strengthen client assurance, governance processes, and security practices as the organization evolves.
Accountabilities:
- Develop, maintain, and continuously improve the enterprise Governance, Risk, and Compliance program.
- Lead compliance activities across HIPAA Privacy and Security Rules, HITRUST CSF, SOC 2 Type II, and PCI DSS.
- Ensure controls appropriately protect PHI, PII, payment card information, and other sensitive healthcare data.
- Maintain policies, standards, procedures, risk methodologies, and control documentation.
- Support compliance with Business Associate Agreements, client security requirements, and healthcare contractual obligations.
- Monitor changes in healthcare regulations, cybersecurity requirements, and relevant industry standards.
- Coordinate internal and external assessments, certifications, client audits, and regulatory reviews.
- Conduct enterprise risk assessments and maintain the organizational risk register.
- Lead or support third-party and vendor security risk assessments and monitor remediation activities.
- Develop risk mitigation strategies and provide executive reporting on key risks and remediation progress.
- Support business continuity and disaster recovery governance.
- Develop and maintain an AI governance framework for responsible use of artificial intelligence in healthcare revenue cycle management.
- Establish policies and controls covering generative AI, machine learning, automation, and AI-enabled decision-support technologies.
- Assess AI use cases for privacy, security, accuracy, bias, transparency, explainability, and regulatory risk.
- Ensure PHI is appropriately protected when using internally developed or third-party AI solutions.
- Establish approval and risk-review processes for new AI use cases and vendors.
- Maintain an inventory of approved AI systems, use cases, owners, data sources, and associated risks.
- Align AI governance practices with frameworks such as the NIST AI Risk Management Framework and ISO/IEC 42001 where appropriate.
- Lead preparation for SOC 2, HITRUST, HIPAA, PCI DSS, and customer security assessments.
- Coordinate evidence collection and control testing across business and technology teams.
- Manage remediation plans for audit findings, control deficiencies, and client security observations.
- Respond to customer security questionnaires and due diligence requests.
- Participate in security and compliance discussions with healthcare providers, health systems, physician groups, payers, and other clients.
- Maintain centralized compliance evidence, audit documentation, and client assurance materials.
- Evaluate vendors that access, process, transmit, or store PHI, PII, payment information, or other sensitive data.
- Review vendor security documentation, including SOC reports, HITRUST certifications, penetration tests, and risk assessments.
- Ensure appropriate BAAs, data protection agreements, and security requirements are established.
- Partner with Information Security and Privacy teams to maintain appropriate administrative, technical, and physical safeguards.
- Support identity and access management governance for systems containing healthcare information.
- Participate in incident response activities involving potential PHI exposure, security incidents, or compliance concerns.
- Support breach assessments and regulatory notification processes when required.
- Oversee security and compliance awareness programs for employees and contractors.
- Develop GRC dashboards and executive reporting covering risk, audit status, remediation, vendor risk, and compliance metrics.
- Track key risk and performance indicators and manage compliance calendars and recurring control activities.
- Lead cross-functional remediation and compliance initiatives while driving automation and continuous improvement.
- Bachelor's degree in Information Security, Cybersecurity, Information Systems, Business, or a related field, or equivalent professional experience.
- 6-8+ years of experience in Governance, Risk, and Compliance.
- Demonstrated experience managing SOC 2, HITRUST, and PCI DSS programs.
- Experience leading external audits, assessments, and remediation efforts.
- Strong understanding of information security principles, enterprise risk management, and internal controls.
- Experience implementing governance and compliance programs across multiple departments.
- Strong knowledge of healthcare compliance and data protection requirements, particularly around PHI and sensitive healthcare information.
- Experience with AI governance, risk management, or responsible AI practices is highly valuable.
- Familiarity with frameworks such as NIST AI Risk Management Framework and ISO/IEC 42001 is an advantage.
- Experience managing third-party and vendor security risk assessments.
- Experience using GRC platforms and managing compliance documentation and evidence.
- Strong project management skills with the ability to coordinate complex cross-functional initiatives.
- Excellent written and verbal communication skills, with the ability to present risks, findings, and recommendations to senior leadership.
- Strong stakeholder management skills and the ability to build relationships across technical, operational, legal, privacy, and executive teams.
- Highly organized, detail-oriented, and thorough, with a proactive approach to identifying and addressing risks.
- Curious and adaptable, with a willingness to learn new technologies, regulations, and cybersecurity practices.
- Ability to work independently while contributing effectively within a collaborative team environment.
- One or more relevant certifications is preferred, such as CISSP, CISM, CISA, CRISC, CCSFP, Certified HIPAA Professional, PCIP, ISO 27001 Lead Implementer or Lead Auditor, CGRC, or an equivalent AI governance/risk certification.
- Full-time employment.
- Remote work arrangement in India.
- Opportunity to lead an enterprise-wide GRC program within a healthcare technology environment.
- Exposure to major compliance frameworks including HIPAA, HITRUST, SOC 2, and PCI DSS.
- Significant ownership of AI governance and responsible AI initiatives.
- Opportunity to work across cybersecurity, privacy, compliance, risk, technology, operations, and legal functions.
- Collaboration with senior leadership and diverse cross-functional stakeholders.
- Opportunity to influence governance standards, risk management practices, and security controls.
- Exposure to emerging AI technologies and evolving regulatory requirements.
- Opportunity to drive automation and continuous improvement across GRC operations.
- Professional development through exposure to industry frameworks, audits, certifications, and emerging governance practices.
Requirements:
Benefits:

