Skip to content

Open nowPosted 8 hours ago

Senior InfoSec GRC Specialist

Workable (global search)107,778 open roles

Where
Pune, MH, India
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSenior InfoSec GRC SpecialistWorkable (global search) · Pune, MH, India
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Workable (global search)'s own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.2% of postings close within 7 days. Measured by our own scanner across the market. Workable (global search) postings stay open a median of 3 days.

Share of postings closed within
  1. 1.9%1 day
  2. 3.8%3 days
  3. 8.2%7 days
  4. 15.2%14 days
  5. 34.1%30 days
This job: posted 8 hours ago

Workable (global search) median: 3 days open

The posting

About Velsera

Medicine moves too slow. At Velsera, we are changing that.

Velsera was formed in 2023 through the shared vision of Seven Bridges and Pierian, with a mission to accelerate the discovery, development, and delivery of life-changing insights.

Velsera provides software and professional services for:

  • AI-powered multimodal data harmonization and analytics for drug discovery and development
  • IVD development, validation, and regulatory approval
  • Clinical NGS interpretation, reporting, and adoption

With our headquarters in Boston, MA, we are growing and expanding our teams located in different countries!

What will you do?

Compliance & Governance

  • Develop, implement, and maintain comprehensive information security policies, standards, and procedures aligned with the ISO 27001 framework
  • Lead, manage, and mature the organization's Information Security Management System including risk treatment, internal audits, and readiness for external certification audits.
  • Serve as the subject matter expert (SME) for Security and Privacy Rules, ensuring compliance for all systems, processes, and applications handling PII and Protected Health Information (PHI).
  • Conduct continuous monitoring and evidence collection to demonstrate compliance with relevant frameworks.
  • Plan, conduct and manage internal and supplier audits
  • Plan GRC activities, prioritise and implement them in timebound manner.
  • Perform detailed security risk assessments and gap analyses on new and existing systems, with a focus on cloud infrastructure
  • Collaborate with Product, Technology, IT and Security teams to implement security controls into cloud / infra / environments, ensuring compliance. Provide technical guidance to them on implementing controls and best practices, specifically related to cloud security architecture and configurations.
  • Review risk mitigations periodically and track remediation efforts to closure.
  • Conduct third-party vendor risk assessments, focusing on their adherence to required compliance standards.
  • Develop and deliver targeted security awareness and training programs focused on HIPAA and ISO 27001 requirements for all staff, including technical teams.
  • Evaluate and recommend new security technologies and processes to enhance the compliance and risk posture.
  • Stay current on emerging cloud security threats, regulatory changes, and updates to the ISO 27001 family of standards and HIPAA.

Requirements

What do you bring to the table?

· Experience:

  • Minimum of 8+ years of progressive experience in Information Security GRC, with a focus on risk management, compliance, and governance.
  • Proven, hands-on experience driving and maintaining ISO 27001 certification programs.
  • Deep practical knowledge and experience of implementing security controls ensuring compliance in a technical, cloud-centric environment.
  • Strong technical competency in Cloud Security (AWS, Azure, or GCP) and related cloud-native security services.
  • Education: Bachelor's degree in IT, Computer Science or related field.
  • Certifications (One or more highly preferred):
  • CISSP (Certified Information Systems Security Professional)
  • CISA (Certified Information Systems Auditor)
  • ISO 27001 Lead Implementer/Auditor
  • CCSK (Certificate of Cloud Security Knowledge) or equivalent Cloud-specific security certification (e.g., AWS Certified Security, Azure Security Engineer).
  • Hands-on experience with NIST 800-53 compliance frameworks is required.

Soft Skills

  • Proficiency in written and verbal communication skills with the ability to translate complex security and compliance requirements / controls into clear actionable
  • Strong project management and organizational skills to handle multiple, simultaneous audit and compliance initiatives.
  • A collaborative and proactive mindset, with the ability to influence and lead cross-functional teams without direct authority.

Benefits

  • Flexible Work & Time Off - Embrace hybrid work models and enjoy the freedom of unlimited paid time off to support work-life balance.
  • Health & Well-being - Access comprehensive group medical and life insurance coverage, along with a 24/7 Employee Assistance Program (EAP) for mental health and wellness support.
  • Growth & Learning - Fuel your professional journey with continuous learning and development programs designed to help you upskill and grow.
  • Engaging & Fun Work Culture - Experience a vibrant workplace with team events, celebrations, and engaging activities that make every workday enjoyable.
  • & Many More...
From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Workable (global search)'s own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Workable (global search)'s form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Workable (global search)'s answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.