657,963open jobs
38,241companies
93,447added this week
Browse all
Location
Remote (India)
Seniority
Staff · 8+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Jobgether is a Belgian recruitment platform built entirely around remote and flexible work, aggregating openings from thousands of employers that allow work from outside an office. Its matching engine ranks roles against a candidate's skills, seniority and stated preferences on location and flexibility, rather than leaving people to filter a keyword search, and it verifies how genuinely remote each posting is. The company also runs an AI screening layer that shortlists applicants for employers, and publishes research and guidance on distributed work practices alongside the job marketplace itself.

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Governance Risk and Compliance Manager based in India.

This role offers the opportunity to lead a comprehensive Governance, Risk, and Compliance program within a highly regulated healthcare technology environment. You will oversee critical compliance frameworks including HIPAA, HITRUST, SOC 2, and PCI DSS while helping protect sensitive healthcare, payment, and personal data. The position also has a strong focus on AI governance, providing an opportunity to shape responsible adoption of generative AI, machine learning, and automation. You will partner with Information Security, IT, Legal, Privacy, Operations, Engineering, and executive stakeholders to identify and reduce organizational risk. The role combines strategic program leadership with hands-on audit, risk, vendor, compliance, and remediation activities. You will also help strengthen client assurance, governance processes, and security practices as the organization evolves.

Accountabilities:

    • Develop, maintain, and continuously improve the enterprise Governance, Risk, and Compliance program.
    • Lead compliance activities across HIPAA Privacy and Security Rules, HITRUST CSF, SOC 2 Type II, and PCI DSS.
    • Ensure controls appropriately protect PHI, PII, payment card information, and other sensitive healthcare data.
    • Maintain policies, standards, procedures, risk methodologies, and control documentation.
    • Support compliance with Business Associate Agreements, client security requirements, and healthcare contractual obligations.
    • Monitor changes in healthcare regulations, cybersecurity requirements, and relevant industry standards.
    • Coordinate internal and external assessments, certifications, client audits, and regulatory reviews.
    • Conduct enterprise risk assessments and maintain the organizational risk register.
    • Lead or support third-party and vendor security risk assessments and monitor remediation activities.
    • Develop risk mitigation strategies and provide executive reporting on key risks and remediation progress.
    • Support business continuity and disaster recovery governance.
    • Develop and maintain an AI governance framework for responsible use of artificial intelligence in healthcare revenue cycle management.
    • Establish policies and controls covering generative AI, machine learning, automation, and AI-enabled decision-support technologies.
    • Assess AI use cases for privacy, security, accuracy, bias, transparency, explainability, and regulatory risk.
    • Ensure PHI is appropriately protected when using internally developed or third-party AI solutions.
    • Establish approval and risk-review processes for new AI use cases and vendors.
    • Maintain an inventory of approved AI systems, use cases, owners, data sources, and associated risks.
    • Align AI governance practices with frameworks such as the NIST AI Risk Management Framework and ISO/IEC 42001 where appropriate.
    • Lead preparation for SOC 2, HITRUST, HIPAA, PCI DSS, and customer security assessments.
    • Coordinate evidence collection and control testing across business and technology teams.
    • Manage remediation plans for audit findings, control deficiencies, and client security observations.
    • Respond to customer security questionnaires and due diligence requests.
    • Participate in security and compliance discussions with healthcare providers, health systems, physician groups, payers, and other clients.
    • Maintain centralized compliance evidence, audit documentation, and client assurance materials.
    • Evaluate vendors that access, process, transmit, or store PHI, PII, payment information, or other sensitive data.
    • Review vendor security documentation, including SOC reports, HITRUST certifications, penetration tests, and risk assessments.
    • Ensure appropriate BAAs, data protection agreements, and security requirements are established.
    • Partner with Information Security and Privacy teams to maintain appropriate administrative, technical, and physical safeguards.
    • Support identity and access management governance for systems containing healthcare information.
    • Participate in incident response activities involving potential PHI exposure, security incidents, or compliance concerns.
    • Support breach assessments and regulatory notification processes when required.
    • Oversee security and compliance awareness programs for employees and contractors.
    • Develop GRC dashboards and executive reporting covering risk, audit status, remediation, vendor risk, and compliance metrics.
    • Track key risk and performance indicators and manage compliance calendars and recurring control activities.
    • Lead cross-functional remediation and compliance initiatives while driving automation and continuous improvement.
    • Requirements:

      • Bachelor's degree in Information Security, Cybersecurity, Information Systems, Business, or a related field, or equivalent professional experience.
      • 6-8+ years of experience in Governance, Risk, and Compliance.
      • Demonstrated experience managing SOC 2, HITRUST, and PCI DSS programs.
      • Experience leading external audits, assessments, and remediation efforts.
      • Strong understanding of information security principles, enterprise risk management, and internal controls.
      • Experience implementing governance and compliance programs across multiple departments.
      • Strong knowledge of healthcare compliance and data protection requirements, particularly around PHI and sensitive healthcare information.
      • Experience with AI governance, risk management, or responsible AI practices is highly valuable.
      • Familiarity with frameworks such as NIST AI Risk Management Framework and ISO/IEC 42001 is an advantage.
      • Experience managing third-party and vendor security risk assessments.
      • Experience using GRC platforms and managing compliance documentation and evidence.
      • Strong project management skills with the ability to coordinate complex cross-functional initiatives.
      • Excellent written and verbal communication skills, with the ability to present risks, findings, and recommendations to senior leadership.
      • Strong stakeholder management skills and the ability to build relationships across technical, operational, legal, privacy, and executive teams.
      • Highly organized, detail-oriented, and thorough, with a proactive approach to identifying and addressing risks.
      • Curious and adaptable, with a willingness to learn new technologies, regulations, and cybersecurity practices.
      • Ability to work independently while contributing effectively within a collaborative team environment.
      • One or more relevant certifications is preferred, such as CISSP, CISM, CISA, CRISC, CCSFP, Certified HIPAA Professional, PCIP, ISO 27001 Lead Implementer or Lead Auditor, CGRC, or an equivalent AI governance/risk certification.
      • Benefits:

        • Full-time employment.
        • Remote work arrangement in India.
        • Opportunity to lead an enterprise-wide GRC program within a healthcare technology environment.
        • Exposure to major compliance frameworks including HIPAA, HITRUST, SOC 2, and PCI DSS.
        • Significant ownership of AI governance and responsible AI initiatives.
        • Opportunity to work across cybersecurity, privacy, compliance, risk, technology, operations, and legal functions.
        • Collaboration with senior leadership and diverse cross-functional stakeholders.
        • Opportunity to influence governance standards, risk management practices, and security controls.
        • Exposure to emerging AI technologies and evolving regulatory requirements.
        • Opportunity to drive automation and continuous improvement across GRC operations.
        • Professional development through exposure to industry frameworks, audits, certifications, and emerging governance practices.
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
657,963 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$26k – $61k per year (Estimated) • Remote • Full-Time • 5+ years exp
AI/ML
LLM
RAG
Hallucination
DevOps
CI/CD
AWS
Cybersecurity
PCI DSS
SOC 2
HIPAA
Management
Intercom
Freshdesk
QA
Selenium
Cypress
Playwright
Postman
Rest-Assured
Apply
$39k – $78k per year (Estimated) • In office • Full-Time • 7+ years exp • Bachelor's Degree • Bengaluru
Python
TypeScript
Databases
Weaviate
Pinecone
AI/ML
AutoGen
Weights & Biases
LangChain
LlamaIndex
AI Agents
Arize Phoenix
DeepEval
LangSmith
Promptfoo
Ragas
AWS Bedrock
LLM
RAG
TruLens
OpenAI
Anthropic
Giskard
Agentic Workflows
DevOps
GCP
GitHub Actions
OpenTelemetry
Prometheus
GitLab CI
Azure
CI/CD
Jenkins
AWS
Docker
Kubernetes
Grafana
Shift-Left
Vector
Cybersecurity
ISO 27001
SOC 2
Shift-Left Security
QA
Selenium
Cypress
Playwright
Pytest
Apply
$66k – $172k per year (Estimated) • Remote/Hybrid • Full-Time • Warwick
Python
AI/ML
Anomaly Detection
DevOps
Rest API
Terraform
Ansible
Azure
CI/CD
GitOps
AWS
Configuration Management
Self-Healing
AIOps
Cybersecurity
Zscaler
ISO 27001
Zero Trust
Management
Agile
Apply
$22k – $53k per year (Estimated) • Remote • Bachelor's Degree • Krasnodar
Cybersecurity
PCI DSS
Management
Agile
Apply
$22k – $53k per year (Estimated) • Remote • Bachelor's Degree • Samara
Cybersecurity
PCI DSS
Management
Agile
Apply
$145k – $193k per year • Remote • Full-Time • 5+ years exp
Python
JavaScript
PHP
SQL
Ruby
Node JS
Elixir
Python
FastAPI
PHP
Laravel
Ruby
Ruby on Rails
RSpec
Sidekiq
Elixir
Oban
Databases
MySQL
PostgreSQL
RabbitMQ
Apache Kafka
AI/ML
AI Agents
Agentic Workflows
Frontend
GraphQL
Mobile
Clean Architecture
DevOps
gRPC
GCP
Datadog
Git
AWS
Kubernetes
GitHub
Management
Agile
Scrum
QA
Jest
Pytest
Apply
$186k – $321k per year (Estimated) • Remote • Full-Time • 15+ years exp • Bachelor's Degree
AI/ML
Model Context Protocol
Fine-tuning
AI Agents
Context Engineering
LLM Evaluation
LLM Guardrails
Agentic Workflows
Apply
$148k – $267k per year (Estimated) • Remote • Full-Time • 10+ years exp • Master's Degree
Apply
$100k – $167k per year • Remote • Full-Time • 3+ years exp • Bachelor's Degree
Apply
$129k – $255k per year (Estimated) • Remote • Full-Time • 6+ years exp • Master's Degree
Apply
See all jobs
This is one of many
657,963 more open roles from verified company boards, updated every day.