24 Sep
|
CitiusTech
|
Pune
Role summary:
Drive project-level information security governance across all client engagements and ensure adherence to EPIC requirements, contractual security obligations, healthcare regulatory requirements, data privacy mandates, internal control frameworks and confidentiality & security policies.
Key Responsibilities:
1. Project Security Governance & Facilitation
- Conduct detailed governance reviews for newly onboarded and existing projects.
- Facilitate structured security assessment workshops with project leadership teams.
- Gain comprehensive understanding of: Project scope and service delivery model, Data processing activities, PHI, PII, confidential information handling, EPIC nuances, Cloud-hosted environments, Artificial Intelligence / GenAI use cases, Third-party and subcontractor involvement.
2. Contractual and Regulatory Compliance Oversight
- Review project compliance against: Client contractual information security requirements, EPIC requirements, Data Privacy and Data Protection requirements, HIPAA/HITECH obligations, GDPR, DPDPA, and applicable privacy regulations, Client-specific confidentiality and security obligations, Internal confidentiality and security policy requirements .
- Interpret security obligations from client agreements and translate them into actionable project-level controls and monitor adherence to all obligations.
- Identify contractual compliance gaps and ensure remediation planning.
3. Security Risk Assessment and Gap Analysis
- Evaluate project implementation against organizational security policies and standards.
- Conduct comprehensive security gap assessments.
- Identify: Information security risks, Data privacy risks, EPIC & Client contractual non-compliance risks, Regulatory non-compliance risks, Operational security control deficiencies.
- Document findings and provide practical recommendations.
- Present risk exposure and remediation plans to management and stakeholders.
- Monitor implementation of remediation plans adherence to timelines.
4. Audit Management
- Plan and conduct internal project and account audits. Raise non-conformances and observations and track timely implementation of corrective and preventive actions.
- Support external audits and client assessments as required.
5. Third-Party and Subcontractor Governance
- Conduct security due diligence reviews and subcontractor risk assessments.
- Validate compliance with contractual and security obligations.
- Track remediation of identified third-party risks.
Experience & Skills
- 78 years in GRC
- Hands-on experience in Internal and external audits, Information Security governance, risk assessment.
- Robust understanding of regulatory requirements
- Good stakeholder management and documentation skills
Key competencies:
- In-depth audit interviewing and documentation
- Risk identification, articulation and reporting
- Strong communication skills – verbal and written
- Willingness to work as per US timings – afternoons and late evenings IST
- Strong documentation, stakeholder management and reporting
- Good technical understanding of security controls
- Good understanding of EPIC, HIPAA and other regulatory compliances
📌 Information Security Engineer (Pune)
🏢 CitiusTech
📍 Pune