About the Role
OrthoFX, a high-growth US-based healthcare tech company, is hiring a Compliance Analyst to support our information security audit and risk management program. You'll work across ISO 27001, SOC 2 Type 2, and HIPAA frameworks — conducting internal audits, supporting external audits, and helping us stay ahead of evolving compliance requirements.
This is a compliance/audit-focused GRC role — not a penetration testing, red-team, or offensive security position.
What You'll Do
Support internal and external audits across ISO 27001, HIPAA, SOC 2 Type 2, and customer assessments
Conduct technical and non-technical information security assessments
Participate in risk assessments and document findings in the GRC system
Assist in vendor/third-party risk assessments (using tools like ServiceNow)
Track audit actions, findings, and remediation to closure
Collaborate with IT, Network, and Cloud teams on security assessments
Maintain and update compliance policies, procedures,
and dashboards
Review controls across access management, change management, patch management, and vulnerability remediation
What You Bring
Bachelor's degree in IT, Cybersecurity, or related field
1–3 years of hands-on experience in Information Security Audits or Compliance (not general IT, not financial/AML compliance)
Working knowledge of ISO 27001, SOC 2, HIPAA — GDPR/NIST familiarity a plus
Exposure to GRC or ITSM tools (ServiceNow, Jira, Drata, Sprinto, Vanta, or similar)
Strong documentation and audit-reporting skills
Certifications like ISO 27001 LI/LA or CISA are a plus, not mandatory
Why OrthoFX
High-growth US-based healthcare tech company
Work on products that directly touch patient lives
Team-oriented, transparent, inclusive culture
Real room to grow as the company scales
📌 Compliance Analyst – ISO 27001 / SOC 2 / HIPAA (Kochi)
🏢 OrthoFX
📍 Kochi