Velsera Logo

Velsera

Principal GRC, Specialist

Reposted Yesterday
Be an Early Applicant
Pune, Maharashtra
Mid level
Pune, Maharashtra
Mid level
The role involves developing and maintaining governance policies, conducting risk assessments, ensuring compliance, training staff, and managing vendor risk.
The summary above was generated by AI

Medicine moves too slow. At Velsera, we are changing that.
 
Velsera was formed in 2023 through the shared vision of Seven Bridges and Pierian, with a mission to accelerate the discovery, development, and delivery of life-changing insights.
 
Velsera provides software and professional services for:
AI-powered multimodal data harmonization and analytics for drug discovery and development
IVD development, validation, and regulatory approval
Clinical NGS interpretation, reporting, and adoption
 
With our headquarters in Boston, MA, we are growing and expanding our teams located in different countries!

What will you do?

Governance and Policy Development    

- Develop, implement, and maintain governance policies, SOPs, and related documentation. 

- Ensure all policies align with industry standards (e.g., FedRAMP, NIST SP 800-53, ISO 27001 family, and HIPAA). 

- Monitor policy effectiveness and recommend updates based on organizational changes or regulatory updates. 

 

Risk Management    

- Conduct risk assessments to identify vulnerabilities, threats, and compliance gaps. 

- Collaborate with cross-functional teams to design and implement remediation strategies. 

- Maintain risk registers and monitor mitigation efforts. 

 

Compliance Oversight    

- Support the organization in achieving and maintaining FedRAMP certification. 

- Manage periodic audits, security assessments, and readiness activities for compliance frameworks. 

- Track and report on compliance metrics, audit findings, and resolution status. 

 

Training and Awareness    

- Develop and deliver training programs to enhance employee understanding of compliance policies and procedures. 

- Act as a point of contact for compliance-related queries within the organization. 

 

Incident Response and Reporting    

- Support incident response processes to ensure effective investigation and reporting of compliance-related incidents. 

- Collaborate with stakeholders to implement corrective actions and prevent recurrence. 

Vendor and Third-Party Risk Management    

- Assess third-party vendors for compliance with organizational policies and standards. 

- Ensure contracts include appropriate compliance requirements. 

 

What do you bring to the table?

Education & Experience    

- Bachelor's degree in Information Technology, Cybersecurity, Risk Management, or related field (Master’s preferred). 

- 3+ years of experience in governance, risk, and compliance roles, with specific experience in FedRAMP compliance. 

 

Knowledge & Skills    

- Strong understanding of FedRAMP, NIST SP 800-53, ISO 27001, and other relevant frameworks. 

- Experience in drafting policies, procedures, and SOPs. 

- Familiarity with GRC tools and platforms (e.g., Archer, ServiceNow GRC). 

- Excellent communication and documentation skills. 

- Analytical mindset with attention to detail. 

 

Certifications (Preferred)    

- Certified Information Systems Security Professional (CISSP) 

- Certified Information Systems Auditor (CISA) 

- Certified Information Security Manager (CISM) 

- ISO 27001 Lead or Internal auditor

Our Core Values

People first. We create collaborative and supportive environments by operating with respect and flexibility to promote mental, emotional and physical health. We practice empathy by treating others the way they want to be treated and assuming positive intent. We are proud of our inclusive diverse team and humble ourselves to learn about and build our connection with each other.

Patient focused. We act with swift determination without sacrificing our expectations of quality. We are driven by providing exceptional solutions for our customers to positively impact patient lives. Considering what is at stake, we challenge ourselves to develop the best solution, not just the easy one. 

Integrity. We hold ourselves accountable and strive for transparent communication to build trust amongst ourselves and our customers. We take ownership of our results as we know what we do matters and collectively we will change the healthcare industry. We are thoughtful and intentional with every customer interaction understanding the overall impact on human health. 

Curious. We ask questions and actively listen in order to learn and continuously improve. We embrace change and the opportunities it presents to make each other better. We strive to be on the cutting edge of science and technology innovation by encouraging creativity. 

Impactful. We take our social responsibility with the seriousness it deserves and hold ourselves to a high standard. We improve our sustainability by encouraging discussion and taking action as it relates to our natural, social and economic resource footprint. We are devoted to our humanitarian mission and look for new ways to make the world a better place. 

Velsera is an Equal Opportunity Employer:
Velsera is proud to be an equal opportunity employer committed to providing employment opportunity regardless of sex, race, creed, colour, gender, religion, marital status, domestic partner status, age, national origin or ancestry.

Top Skills

Archer
Fedramp
Iso 27001
Nist Sp 800-53
Servicenow Grc

Similar Jobs

Yesterday
Hybrid
3 Locations
Mid level
Mid level
Big Data • Fintech • Information Technology • Business Intelligence • Financial Services • Cybersecurity • Big Data Analytics
Perform audits on IT and cybersecurity controls, develop risk-based audit plans, analyze control environments, and document audit findings and reports.
Top Skills: Auditboard Ops AuditBmc RemedyCisCobitCsfIsoNist 800.53Sailpoint IiqSplunk
Yesterday
Hybrid
Mumbai, Maharashtra, IND
Senior level
Senior level
Financial Services
The Tech Risk and Controls Lead will mitigate tech risks, enhance compliance, and provide guidance to technology process owners in risk management.
Top Skills: Data SecurityInformation SecurityRisk Management FrameworksTechnology Risk Management
5 Days Ago
Pune, Maharashtra, IND
Senior level
Senior level
Healthtech • Logistics • Pharmaceutical
The role involves designing and implementing information security solutions, addressing security issues, and collaborating with other architects to enhance enterprise security architecture.
Top Skills: Anti-VirusApplication ArchitectureCobitCybersecurityEdrEmail Security GatewayFirewallHTML/CSSIdentity And Access ManagementIso 27001/27002ItilJavaScriptMicrosoft Azure Security TechnologiesNetwork Solutions And SystemsNistPci)ProxiesPythonSecurity Standards (SoxSIEMSoarSoftware Development Life Cycle (Sdlc)SQLVpn Ids/Ips

What you need to know about the Pune Tech Scene

Once a far-out concept, AI is now a tangible force reshaping industries and economies worldwide. While its adoption will automate some roles, AI has created more jobs than it has displaced, with an expected 97 million new roles to be created in the coming years. This is especially true in cities like Pune, which is emerging as a hub for companies eager to leverage this technology to develop solutions that simplify and improve lives in sectors such as education, healthcare, finance, e-commerce and more.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account