📢 New: get today's jobs on our WhatsApp Channel
Jobiglo

No results.

This job is no longer available

This job expired on 29/08/2026. It no longer accepts applications.

Information Security Lead – GRC (ISO 27001, SOC2, HIPAA)

Eplanet Global · Karachi

Senior 🇬🇧 English
ISO 27001 SOC 2 HIPAA network security application security ONC Health IT Certification §170.315

Job description

About the role

We are seeking an experienced Information Security Lead (GRC) to drive our Governance, Risk, and Compliance program. The role will work closely with Engineering, DevOps, Legal, Product and executive teams to ensure the organization meets ISO 27001, SOC 2, HIPAA and healthcare security standards.

Key responsibilities

  • Lead GRC initiatives, including ISO 27001 and SOC 2 implementation, audit readiness and certification.
  • Manage HIPAA compliance and ONC Health IT Certification §170.315 security criteria.
  • Oversee Vulnerability Assessment & Penetration Testing (VAPT) activities and remediation tracking.
  • Define, implement and maintain security policies, standards, procedures and controls.
  • Coordinate audits, collect evidence, plan remediation and produce compliance reports.
  • Develop and execute risk mitigation strategies across people, process and technology.
  • Partner with Legal to draft, review and manage Business Associate Agreements (BAAs) with cloud vendors and AI/LLM subprocessors.
  • Collaborate with Engineering and Infrastructure to improve cloud, application and network security posture.
  • Monitor security compliance metrics and report regularly to leadership.

Required profile

  • Proven experience as a Lead Implementer or Lead Auditor for ISO 27001 and SOC 2.
  • Strong knowledge of HIPAA compliance and healthcare security requirements.
  • Hands‑on experience managing VAPT activities.
  • Experience with cloud, network and application security.
  • Deep understanding of GRC frameworks.
  • Track record handling audits, evidence collection, remediation and reporting.
  • Excellent communication and stakeholder management skills.
  • Ability to define and execute risk mitigation, compensating controls and residual risk acceptance.
  • Working knowledge of ONC Health IT Certification §170.315 security criteria.
  • Experience collaborating with Legal on BAA drafting and management.

Required skills

  • ISO 27001
  • SOC 2
  • HIPAA
  • Vulnerability Assessment & Penetration Testing (VAPT)
  • Cloud security
  • Network security
  • Application security
  • GRC frameworks
  • ONC Health IT Certification §170.315

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec Eplanet Global.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.

Why are you reporting this job?

Thank you for your report. We will review this job.

A question about this job?

Ask it here: you will get the full job summary by e-mail, right away.

💬 Chat with us on Telegram

Published 3 months ago

20 views · 0 interested

Boost your chances

Upload your CV — we will match you with relevant openings.

Analyzing your CV...

Eplanet Global

Karachi