He/ She will be fully responsible for data security & integrity in the organization consisting of patient data (PII, PHI – Patient Health information, Company data security, Cyber Security & Compliance & IT Audits etc.)
He should have good knowledge about emerging security & compliance requirements for the organization:
- DPDP Act compliance
- IT Act & CERT – In compliance knowledge
- ISO & other industry standards
- NABH Guidelines for Information
IS & Risk Management:
- Access & Identity controls – RBAC, MFA, SSO etc.
- Incident response – Identify & investigate the incident & share the process / procedure to close the gaps & own the solution till incident is closed. Need to share & report all critical incidents like patient data breach in the organization with management & with Govt. Authorities in case it is required as per legal compliance.
- Vendor Risk Management
Audits, Training & Operations:
- Conduct periodic Information security audits for IT Infrastructure comprising Endpoint Security (EDR, Patch Management, Access review management, Application security, Cyber Security, Network Security etc.)
- Training the entire organization staff for cybersecurity awareness, Data compliance awareness & DPDPA awareness.
- Policy creation for the organization, SOPs, Data handling policy, device provisioning & securing remote access to all applications & infrastructure.
Certification required or have good knowledge about below:
- CISA, CISSP, CISM or CompTIA Security+
- Lead Auditor for ISO27001:2025
Experience & Qualification:
- Graduation in IT Security or similar field
- Experience of 7 Years in IT Security & Compliance.
- Robust knowledge of Indian Cyber Laws & DPDP Act & Indian Medical data confidentiality & Security