About the Role
OrthoFX, a high-growth US-based healthcare tech company, is hiring a Compliance Analyst to support our information security audit and risk management program. You'll work across ISO 27001, SOC 2 Type 2, and HIPAA frameworks — conducting internal audits, supporting external audits, and helping us stay ahead of evolving compliance requirements.
This is a compliance/audit-focused GRC role — not a penetration testing, red-team, or offensive security position.
What You'll Do
- Support internal and external audits across ISO 27001, HIPAA, SOC 2 Type 2, and customer assessments
- Conduct technical and non-technical information security assessments
- Participate in risk assessments and document findings in the GRC system
- Assist in vendor/third-party risk assessments (using tools like ServiceNow)
- Track audit actions, findings, and remediation to closure
- Collaborate with IT, Network, and Cloud teams on security assessments
- Maintain and update compliance policies, procedures,
and dashboards
- Review controls across access management, change management, patch management, and vulnerability remediation
What You Bring
- Bachelor's degree in IT, Cybersecurity, or related field
- 1–3 years of hands-on experience in Information Security Audits or Compliance (not general IT, not financial/AML compliance)
- Working knowledge of ISO 27001, SOC 2, HIPAA — GDPR/NIST familiarity a plus
- Exposure to GRC or ITSM tools (ServiceNow, Jira, Drata, Sprinto, Vanta, or similar)
- Strong documentation and audit-reporting skills
- Certifications like ISO 27001 LI/LA or CISA are a plus, not mandatory
Why OrthoFX
- High-growth US-based healthcare tech company
- Work on products that directly touch patient lives
- Cooperative, transparent, inclusive culture
- Real room to grow as the company scales
📌 Compliance Analyst – ISO 27001 / SOC 2 / HIPAA (Kochi)
🏢 OrthoFX
📍 Kochi