Lead Security GRC Analyst

About Providence

Providence, one of the US’s largest not-for-profit healthcare systems, is committed to high quality, compassionate healthcare for all. Driven by the belief that health is a human right and the vision, ‘Health for a better world’, Providence and its 121,000 caregivers strive to provide everyone access to affordable quality care and services.

Providence has a network of 51 hospitals, 1,000+ care clinics, senior services, supportive housing, and other health and educational services in the US.

Providence India is bringing to fruition the transformational shift of the healthcare ecosystem to Health 2.0. The India center will have focused efforts around healthcare technology and innovation, and play a vital role in driving digital transformation of health systems for improved patient outcomes and experiences, caregiver efficiency, and running the business of Providence at scale.


Why Us?

  • Best In-class Benefits
  • Inclusive Leadership
  • Reimagining Healthcare
  • Competitive Pay
  • Supportive Reporting Relation

Position Summary

We are seeking a highly motivated Cybersecurity GRC Specialist with 6–9 years of experience in Governance, Risk, Compliance, Privacy, and Information Security programs. The ideal candidate will have hands-on expertise in SOC 2 Type II, ISO 27001/27002, HITRUST CSF, HIPAA Security and Privacy requirements, and GDPR compliance. The role will be responsible for driving compliance initiatives, risk assessments, audit readiness, policy governance, privacy compliance, and continuous improvement of the organization’s security and compliance posture.

 

Key Responsibilities

Governance & Compliance

  • Lead and support compliance programs aligned to SOC 2 Type II, ISO 27001/27002, HITRUST CSF, HIPAA Security and Privacy Rules, GDPR, and applicable global privacy regulations.
  • Conduct compliance gap assessments and maturity evaluations.
  • Develop, review, and maintain cybersecurity policies, standards, procedures, and guidelines.
  • Drive remediation efforts for audit findings and compliance gaps.

Risk Management

  • Perform enterprise security risk assessments and third-party/vendor risk assessments.
  • Maintain risk registers and track mitigation activities through closure.
  • Facilitate risk treatment plans with business and technology stakeholders.
  • Support control design reviews and risk-based decision-making.

Audit & Certification Support

  • Coordinate internal and external audits and assessments.
  • Provide auditors with evidence, documentation, control narratives, and framework mappings.
  • Support certification and attestation activities for ISO 27001, HITRUST, and SOC 2 engagements.
  • Track audit observations, corrective actions, and management responses through closure.

Privacy & Regulatory Compliance

  • Support HIPAA Security and Privacy compliance initiatives.
  • Assist with GDPR obligations, including Data Protection Impact Assessments, privacy risk assessments, data retention and classification requirements, and third-party privacy reviews.
  • Partner with Legal, Privacy, Security, Technology, and business teams on regulatory and compliance matters.

Providence’s vision to create ‘Health for a Better World’ aids us to provide a fair and equitable workplace for all in our employment, whether temporary, part-time or full time, and to promote individuality and diversity of thought and background, and acknowledge its role in the organization’s success. This makes us committed towards equal employment opportunities, regardless of race, religion or belief, color, ancestry, disability, marital status, gender, sexual orientation, age, nationality, ethnic origin, pregnancy, or related needs, mental or sensory disability, HIV Status, or any other category protected by applicable law. In furtherance to our mission in building a more inclusive and equitable environment, we shall, from time to time, undertake programs to assist, uplift and empower underrepresented groups including but not limited to Women, PWD (Persons with Disabilities), LGTBQ+ (Lesbian, Gay, Transgender, Bisexual or Queer), Veterans and others. We strive to address all forms of discrimination or harassment and provide a safe and confidential process to report any misconduct.

Contact our Integrity hotline also, read our Code of Conduct.