Information Security Engineer (Mumbai)

Information Security Engineer (Mumbai)

24 Sep
|
CitiusTech
|
Mumbai

24 Sep

CitiusTech

Mumbai

Role summary:

Drive project-level information security governance across all client engagements and ensure adherence to EPIC requirements, contractual security obligations, healthcare regulatory requirements, data privacy mandates, internal control frameworks and confidentiality & security policies.

Key Responsibilities:

1. Project Security Governance & Facilitation

- Conduct detailed governance reviews for newly onboarded and existing projects.
- Facilitate structured security assessment workshops with project leadership teams.
- Gain comprehensive understanding of: Project scope and service delivery model, Data processing activities, PHI, PII, confidential information handling, EPIC nuances, Cloud-hosted environments, Artificial Intelligence / GenAI use cases, Third-party and subcontractor involvement.

2. Contractual and Regulatory Compliance Oversight

- Review project compliance against: Client contractual information security requirements, EPIC requirements, Data Privacy and Data Protection requirements, HIPAA/HITECH obligations, GDPR, DPDPA, and applicable privacy regulations, Client-specific confidentiality and security obligations, Internal confidentiality and security policy requirements .
- Interpret security obligations from client agreements and translate them into actionable project-level controls and monitor adherence to all obligations.
- Identify contractual compliance gaps and ensure remediation planning.

3. Security Risk Assessment and Gap Analysis

- Evaluate project implementation against organizational security policies and standards.
- Conduct comprehensive security gap assessments.




- Identify: Information security risks, Data privacy risks, EPIC & Client contractual non-compliance risks, Regulatory non-compliance risks, Operational security control deficiencies.
- Document findings and provide practical recommendations.
- Present risk exposure and remediation plans to management and stakeholders.
- Monitor implementation of remediation plans adherence to timelines.

4. Audit Management

- Plan and conduct internal project and account audits. Raise non-conformances and observations and track timely implementation of corrective and preventive actions.
- Support external audits and client assessments as required.

5. Third-Party and Subcontractor Governance

- Conduct security due diligence reviews and subcontractor risk assessments.
- Validate compliance with contractual and security obligations.
- Track remediation of identified third-party risks.

Experience & Skills

- 78 years in GRC
- Hands-on experience in Internal and external audits, Information Security governance, risk assessment.
- Strong understanding of regulatory requirements
- Good stakeholder management and documentation skills

Key competencies:

- In-depth audit interviewing and documentation
- Risk identification, articulation and reporting
- Strong communication skills – verbal and written
- Willingness to work as per US timings – afternoons and late evenings IST
- Strong documentation, stakeholder management and reporting
- Good technical understanding of security controls
- Valuable understanding of EPIC, HIPAA and other regulatory compliances

📌 Information Security Engineer (Mumbai)
🏢 CitiusTech
📍 Mumbai

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: information security engineer (mumbai) / mumbai

Subscribe to this job alert:

Get the latest job offers by email for: information security engineer (mumbai) / mumbai