He/ She will be fully responsible for data security & integrity in the organization consisting of patient data (PII, PHI – Patient Health information, Company data security, Cyber Security & Compliance & IT Audits etc.)
He should have positive knowledge about emerging security & compliance requirements for the organization:
DPDP Act compliance
IT Act & CERT – In compliance knowledge
ISO & other industry standards
NABH Guidelines for Information
IS & Risk Management:
Access & Identity controls – RBAC, MFA, SSO etc.
Incident response – Identify & investigate the incident & share the process / procedure to close the gaps & own the solution till incident is closed. Need to share & report all critical incidents like patient data breach in the organization with management & with Govt. Authorities in case it is required as per legal compliance.
Vendor Risk Management
Audits, Training & Operations:
Conduct periodic Information security audits for IT Infrastructure comprising Endpoint Security (EDR, Patch Management, Access review management, Application security, Cyber Security, Network Security etc.)
Training the entire organization staff for cybersecurity awareness, Data compliance awareness & DPDPA awareness.
Policy creation for the organization, SOPs, Data handling policy, device provisioning & securing remote access to all applications & infrastructure.
Certification required or have valuable knowledge about below:
CISA, CISSP, CISM or CompTIA Security+
Lead Auditor for ISO27001:2025
Experience & Qualification:
Graduation in IT Security or similar field
Experience of 7 Years in IT Security & Compliance.
Robust knowledge of Indian Cyber Laws & DPDP Act & Indian Medical data confidentiality & Security