C

Governance Risk Compliance (GRC)

CitiusTech · Pune/Pimpri-Chinchwad Area

3–9 yrs experiencefull_timePosted Today

Job description

Job Description: Senior Executive / AM – Governance, Risk & Compliance (GRC) Company: CitiusTech Location: Navi Mumbai / Pune / Pimpri-Chinchwad (Hybrid) Position Type: Full-time (Mid-level, 4–6 Years Experience) Application Deadline: August 20th 2026 About CitiusTech CitiusTech is a global technology services, consulting, and business solutions enterprise dedicated to the healthcare and life sciences industry. The company partners with over 140 organizations to build human-centered ecosystems that are efficient, effective, and equitable. By combining deep healthcare domain expertise with AI, Cloud, Data, and Intelligent Automation, CitiusTech helps clients accelerate digital transformation and achieve measurable business outcomes. With a team of more than 7,700 healthcare technology professionals worldwide, CitiusTech drives innovation, convergence, and large-scale transformation through advanced solutions and products. Role Summary We are seeking an experienced Governance, Risk & Compliance (GRC) Professional to oversee enterprise governance frameworks, manage risk assessments, and support compliance programs aligned with healthcare regulations and internal policies. Working in a hybrid environment based in Pune or Navi Mumbai, you will collaborate closely with Technology, Operations, and Legal teams to ensure consistent, effective, and sustainable GRC practices. Key Responsibilities 1. Governance & Policy Management \\* Maintain and enhance organizational GRC frameworks, ensuring alignment with ISO standards, healthcare regulations, and customer requirements. \\* Support the development, review, and lifecycle management of enterprise policies, standards, and Standard Operating Procedures (SOPs). \\* Plan and deliver organization-wide training and awareness programs on risk management, regulatory requirements, and security policies. 2. Compliance & Audit Management \\* Oversee and monitor organizational compliance with key frameworks, specifically ISO 27001, HIPAA, and global data privacy standards. \\* Conduct periodic internal compliance audits, control testing, and gap assessments to evaluate the effectiveness of organizational controls. \\* Facilitate external audits and client security assessments, serving as a key point of contact for compliance verifications. 3. Risk Assessment & Gap Remediation \\* Execute end-to-end risk assessment methodologies to identify, analyze, and document operational, technological, and regulatory risks. \\* Work cross-functionally with IT, Operations, and Legal stakeholders to develop actionable remediation plans (CAPA) and close identified control gaps. \\* Maintain enterprise risk registers and tracking mechanisms to monitor risk response actions and residual risk levels. 4. Monitoring & Reporting \\* Continuously monitor updates in international healthcare regulations, information security standards, and data privacy laws. \\* Prepare clear, data-driven compliance dashboards, key risk indicators (KRIs), and status reports for leadership and management committees. Qualifications & Skill Requirements Mandatory Requirements: \\* Experience: 4 to 6 years of core hands-on experience in enterprise Governance, Risk, and Compliance (GRC). \\* Certification: ISO 27001 Certification (Lead Auditor / Lead Implementer) is mandatory. \\* Education: Bachelor’s degree in Law, Information Security, Computer Science, Business Administration, or a related field. \\* Location: Ability to work in a hybrid setup from Navi Mumbai, Pune, or Pimpri-Chinchwad. Key Competencies & Soft Skills: \\* Regulatory Knowledge: Solid understanding of data privacy, legal compliance frameworks, and information security requirements. \\* Healthcare Domain Advantage: Prior exposure to healthcare/life sciences regulations (e.g., HIPAA, HITRUST, PIMS/GDPR/DPDPA) is strongly preferred. \\* Analytical Skills: Strong ability to interpret complex regulatory texts, evaluate control effectiveness, and provide pragmatic risk mitigation advice. \\* Technical Aptitude: Experience working with enterprise GRC tools/platforms, risk matrices, and audit tools. \\* Communication: Exceptional verbal and written communication skills for cross-functional collaboration and leadership reporting.