The precision engine company.
Principal InfoSec GRC Specialist – Contract / Permanent
Location
India
Posted
36 days ago
Salary
0
Seniority
Lead
Job Description
Principal InfoSec GRC Specialist – Contract / Permanent
Velsera
• Bring ‘Security by design’ principles to product development activities • Managing the GRC program, defining the roadmap for maturity across governance, risk management, and compliance initiatives. • Lead, manage, and mature the organization's Information Security Management System including risk treatment, internal audits, and readiness for external certification audits • Serve as the SME for high-stakes compliance frameworks, specifically FedRAMP, and maintaining advanced leadership over HIPAA and the ISO 27001 family (including 27017/27018 for cloud security). • Lead the development and revision of enterprise-level security policies, standards, and control frameworks to align with regulatory requirements and business objectives. • Manage GRC with focus on lean, efficient implementation by leveraging automation of activities • Lead FedRAMP authorization (e.g., Readiness, Assessment, and Continuous Monitoring), including coordinating with the 3PAO (Third-Party Assessment Organization) and government agencies. • Provide solution oriented technical guidance to Cloud Engineering, Security Operations, DevOps, and Product teams on architecting, implementing, and documenting controls required for FedRAMP, HIPAA, and ISO 27001 within cloud environments (AWS, Azure, or GCP). • Oversee and conduct complex, high-impact risk assessments (e.g., BIA, PIA, Data Flow Mapping) and residual risk management across the enterprise, escalating critical risks to senior leadership. • Manage and respond to high-level customer and partner due diligence requests and contract reviews related to security and compliance. • Act as the primary InfoSec GRC liaison and subject matter expert, effectively collaborating with internal stakeholders including Legal, Internal Audit, Product Management, and Tech Leadership. • Translate highly technical security and compliance requirements providing clear, actionable, risk-informed recommendations. • Lead cross-functional remediation efforts, bringing a solution mindset to help technical teams design practical and compliant control implementations instead of simply identifying gaps. • Mentor and provide guidance to junior GRC team members, helping to build internal capabilities.
Job Requirements
- Minimum of 12+ years of extensive experience in Cloud Security and GRC
- Demonstrated capability in achieving & maintaining FedRAMP (moderate or high) compliance, including deep familiarity with NIST SP 800-53 controls.
- Expert-level hands on knowledge of HIPAA, SOC and FedRAMP controls
- Deep technical understanding of Cloud Service Provider (CSP) security models and compliance controls within complex cloud architectures.
- Education: Bachelor's or Master's degree in Information Security, IT, Computer Science, or related technical field.
- Certifications (Must have 1 or more of the following):
- CISSP (Certified Information Systems Security Professional)
- FedRAMP specific certifications (e.g., C3PAO Assessor training or significant practical experience).
- Cloud Security certification such as CCSP (Certified Cloud Security Professional) or CCSK.
Benefits
- Flexible Work & Time Off - Embrace hybrid work models and enjoy the freedom of unlimited paid time off to support work-life balance.
- Health & Well-being - Access comprehensive group medical and life insurance coverage, along with a 24/7 Employee Assistance Program (EAP) for mental health and wellness support.
- Growth & Learning - Fuel your professional journey with continuous learning and development programs designed to help you upskill and grow.
- Recognition & Rewards - Get recognized for your contributions through structured reward programs and campaigns.
- Engaging & Fun Work Culture - Experience a vibrant workplace with team events, celebrations, and engaging activities that make every workday enjoyable.
- & Many More...
Related Guides
Related Categories
Related Job Pages
More Compliance Jobs
Clinical Trials Regulatory Specialist III
Emory UniversityLocated in Atlanta, Georgia, Emory University is one of the world’s leading research universities. A top-ranked, private institution dedicated to serving huma
• The Regulatory Specialist III is an advanced level position supporting regulatory affairs in clinical trials research. • Employees in this job class support all trial complexities (basic to multiphase) and manage the study activation process. • Serves as the internal project manager for assigned specific oncology disease group(s), providing the group with timely updates on the status of submissions and regulatory guidance on study development. • Liaison between the sponsor, the investigator, Winship, Emory IRBs, external IRBs and internal departments/staff. • Independently prepare IRB documents, maintain regulatory files, and facilitate regulatory oversight of safety reporting. • In concert with IND Sponsors, prepare and review IND submissions, communicate with the FDA, and prepare for FDA audits. • Responsible for 35+ trial load per year of NCTN, industry and investigator-initiated trials. • Establishes and maintains processes and monitors practices to ensure regulatory documentation involving clinical trials complies with Institutional Review Board (IRB) policies and procedures and regulations. • Reviews processes involving regulatory documentation, including but not limited to NCTN/NCI informed consent review, to assure appropriate timelines are followed. • Maintain study regulatory binders and electronic files in accordance with institutional and sponsor requirements. • Coordinate protocol activation/maintenance process and communicates to allow for enrollment to start and maintain once regulatory documents (e.g. DSMC review) are in place. • Disseminates information and coordinates or conducts training. • Researches and analyzes problems and takes a leadership role in resolving. • Lead study start-up/maintenance: prepare and submit all required regulatory documents for new/current study applications and successfully open/close studies from inception to accrual. • Participates in the development and implementation of standard operating procedures, development and revision of regulatory orientation plans, and orientation and mentorship of newly hired staff. • Actively participates in designated committees within the unit and Emory University. • Direct the clinical team to ensure all facets of each protocol are compliant and fully covered. • Perform internal audit and quality assurance checks on regulatory documents. • Prepare, track and maintain all correspondence and regulatory documentation required by the IRB, FDA, IND Sponsors, and other institutional and federal oversight committees, including drafting and reviewing content as appropriate.
Director of Governance, Risk and Compliance
Coupa SoftwareSpend is the fuel to help your company deliver performance, profitability, and purpose!
• Develop and execute the comprehensive GRC strategy, roadmap, and framework, aligning them with the company’s business objectives, risk appetite, and regulatory obligations. • Oversee the formal Cyber Risk Management program, including risk identification, assessment, mitigation, and monitoring across all business functions. • Develop and manage the risk register, tracking key risks and control effectiveness, and reporting on the overall risk landscape. • Leading the design, implementation, and continuous maturation of the ThirdParty Risk Management (TPRM) program, reducing supply chain risk and ensuring vendor compliance with frameworks like SOC 2 and ISO 27001. • Design, implement, and continuously enhance the corporate compliance program, ensuring adherence to applicable laws, regulations (e.g., GDPR, CCPA, SOC 1, SOC 2, ISO 27001, SOX, export controls, etc.), and internal policies. • Manage external audits, regulatory examinations, and internal compliance reviews. • Develop and deliver company-wide training and awareness programs on compliance topics, policies, and the Code of Conduct. • Establish and maintain a robust framework of corporate governance, policies, and standards. • Collaborate with legal and business stakeholders to draft, review, and disseminate GRC-related policies and procedures. • Oversee the end-to-end metrics and reporting for the GRC program. • Develop executive-level reporting that is clear, concise, and business-based, ensuring risk and compliance status are clearly identified and communicated to senior management. • Partner with Legal, Internal Audit, Finance, and IT Security teams to ensure consistent application of GRC principles. • Provide expert guidance on compliance and risk considerations for new products, technologies, and market expansions.
• Support the Texas Education Agency on the Enterprise Risk Register and Governance Framework engagement. • Define end-to-end governance workflows covering risk identification and intake, risk review and validation, risk acceptance, mitigation or transfer, and ongoing monitoring and periodic reassessment. • Establish roles and responsibilities for risk owners, reviewers, and governance bodies within the enterprise risk framework. • Design escalation and reporting processes for high-risk and accepted risks. • Engage key stakeholders across business, technology, security, and governance functions to validate risk requirements and workflows. • Facilitate working sessions and workshops to socialize the risk register and governance processes with relevant personnel. • Support the onboarding of initial risks into the enterprise risk register. • Develop a standardized risk register template and taxonomy as a formal deliverable. • Produce documented likelihood and impact scales along with scoring methodology and prioritization logic. • Author audit-ready documentation covering risk register structure and data definitions, risk scoring methodology, and governance workflows and decision authorities. • Provide knowledge transfer to designated security staff to ensure ongoing operational sustainability following the conclusion of the engagement.
Plan Compliance Administration Analyst
AmeritasAmeritas is known for providing a range of insurance, employee benefits, and financial services to individuals and families, businesses, municipalities and inst
Role Description The Sr. Plan Administration Analyst provides administrative services for qualified retirement plans including, but not limited to: - Annual compliance testing - Contribution calculations - Preparation of the Form 5500 This role keeps plans qualified by ensuring all regulatory deadlines are met and working with clients to resolve compliance issues. This position works with and advises other departments on plan compliance matters. This position is remote (within the U.S.A.) and does not require regular in-office presence. Qualifications - Bachelor's Degree required or equivalent combination of education and experience in Retirement Plans - 1-3 years retirement plan administration experience required - Ability to manage data and process financial transactions with a high degree of accuracy - Ability to maintain data security by following all data security guidelines - Excellent mathematical and Excel skills required - Excellent communication skills required - Ability to work under tight deadlines and attention to detail are both desired Requirements - Communicate by phone or written correspondence with plan sponsors and their advisors regarding compliance related matters - Administer retirement plans according to plan documents - Calculate employer contributions - Determine participant eligibility and vesting according to plan document - Perform annual plan compliance testing, including ADP/ACP, Top Heavy, 410(b), and 402(g) and work with client on corrective measures for failed tests - Prepare and file Forms 5500 and 5330 - Provide support for plan audits - Utilize multiple systems to administer plans efficiently and by regulatory deadlines Benefits Ameritas offers a range of benefits: - For your money: - 401(k) Retirement Plan with company match and quarterly contribution - Tuition Reimbursement and Assistance - Incentive Program Bonuses - Competitive Pay - For your time: - Flexible Hybrid work - Thrive Days - Personal time off - Paid time off (PTO) - For your health and well-being: - Health Benefits: Medical, Dental, Vision - Health Savings Account (HSA) with employer contribution - Well-being programs with financial rewards - Employee assistance program (EAP) - For your professional growth: - Professional development programs - Leadership development programs - Employee resource groups - StrengthsFinder Program - For your community: - Matching donations program - Paid volunteer time– 8 hours per month - For your family: - Generous paid maternity leave and paternity leave - Fertility, surrogacy, and adoption assistance - Backup child, elder and pet care support Company Description Ameritas is an insurance, financial services and employee benefits provider. Our purpose is fulfilling life, meaning helping all kinds of people, at every age and stage, get more out of life. Ameritas has a reputation as a company that cares, and we’re committed to an inclusive culture and diverse workplace, enriched by our individual differences. We are an Equal Opportunity/Affirmative Action Employer. This position will be open for a minimum of 3 business days or until filled. This position is not open to individuals who are temporarily authorized to work in the U.S.




