Principal Governance Risk & Compliance Analyst

About Providence

Providence, one of the US’s largest not-for-profit healthcare systems, is committed to high quality, compassionate healthcare for all. Driven by the belief that health is a human right and the vision, ‘Health for a better world’, Providence and its 121,000 caregivers strive to provide everyone access to affordable quality care and services.

Providence has a network of 51 hospitals, 1,000+ care clinics, senior services, supportive housing, and other health and educational services in the US.

Providence India is bringing to fruition the transformational shift of the healthcare ecosystem to Health 2.0. The India center will have focused efforts around healthcare technology and innovation, and play a vital role in driving digital transformation of health systems for improved patient outcomes and experiences, caregiver efficiency, and running the business of Providence at scale.


Why Us?

  • Best In-class Benefits
  • Inclusive Leadership
  • Reimagining Healthcare
  • Competitive Pay
  • Supportive Reporting Relation

Job Description

GRC Consultant – Cyber Governance, Risk & Compliance

Location: Hyderabad, India  |  Experience: 12–15+ Years  |  Role Level: Principal Consultant / GRC Consultant

Role Summary

We are seeking an experienced Governance, Risk & Compliance (GRC) Consultant to lead enterprise cybersecurity governance, risk management, compliance, audit, and assurance initiatives. The role will drive the development and maturity of cyber governance frameworks, strengthen risk management practices, support regulatory and certification requirements, and provide strategic guidance to leadership on cyber risk and compliance matters.

Key Responsibilities

  • Lead enterprise Cyber Governance, Risk Management, Compliance, and Assurance programs.
  • Develop and maintain cybersecurity policies, standards, procedures, and control frameworks.
  • Conduct enterprise risk assessments, cyber risk analysis, and risk treatment planning.
  • Drive implementation and continuous improvement of governance and control frameworks.
  • Support internal and external audits, regulatory assessments, and certification initiatives.
  • Establish risk and compliance reporting mechanisms for executive leadership and key stakeholders.
  • Monitor compliance with industry regulations, contractual obligations, and security standards.
  • Partner with technology, security, legal, privacy, and business teams to address risk and compliance requirements.
  • Facilitate control testing, gap assessments, remediation tracking, and compliance reviews.
  • Provide strategic guidance on cyber risk posture, governance priorities, and regulatory obligations.
  • Lead third-party risk management, vendor assessments, and security due diligence activities.
  • Mentor teams and promote a strong culture of governance, accountability, and risk awareness.

Required Qualifications

  • 12–15+ years of experience in Cybersecurity Governance, Risk Management, Compliance, Audit, or related disciplines.
  • Experience establishing, managing, or maturing enterprise GRC programs.
  • Strong understanding of cybersecurity governance models, risk management methodologies, and compliance frameworks.
  • Demonstrated experience supporting large-scale audits, certifications, and regulatory assessments.
  • Experience developing policies, standards, control frameworks, and executive reporting dashboards.
  • Strong knowledge of ISO 27001, NIST CSF, HITRUST CSF, SOC 2 Type II, HIPAA, and other industry frameworks.
  • Experience conducting risk assessments, compliance reviews, and control effectiveness evaluations.
  • Proven ability to influence and engage senior business and technology stakeholders.
  • Strong consulting, leadership, communication, and stakeholder management skills.
  • Experience managing cross-functional compliance and assurance initiatives.

Preferred Certifications

CISM, CRISC, CISA, ISO 27001 Lead Auditor / Lead Implementer, HITRUST CCSFP preferred, and CISSP preferred.

Key Competencies

Cyber Governance & Policy Management, Enterprise Risk Management, Regulatory Compliance & Audit Management, Security Control Frameworks, Third-Party Risk Management, Executive Reporting & Metrics, Assurance & Control Testing, Stakeholder Management & Consulting, Strategic Planning & Leadership, and Risk-Based Decision Making.

Providence’s vision to create ‘Health for a Better World’ aids us to provide a fair and equitable workplace for all in our employment, whether temporary, part-time or full time, and to promote individuality and diversity of thought and background, and acknowledge its role in the organization’s success. This makes us committed towards equal employment opportunities, regardless of race, religion or belief, color, ancestry, disability, marital status, gender, sexual orientation, age, nationality, ethnic origin, pregnancy, or related needs, mental or sensory disability, HIV Status, or any other category protected by applicable law. In furtherance to our mission in building a more inclusive and equitable environment, we shall, from time to time, undertake programs to assist, uplift and empower underrepresented groups including but not limited to Women, PWD (Persons with Disabilities), LGTBQ+ (Lesbian, Gay, Transgender, Bisexual or Queer), Veterans and others. We strive to address all forms of discrimination or harassment and provide a safe and confidential process to report any misconduct.

Contact our Integrity hotline also, read our Code of Conduct.