Job Summary:
We are seeking a meticulous and highly skilled Compliance Analyst to join our team in Delhi. This role is crucial for ensuring our organizational practices strictly adhere to a multitude of regulatory frameworks including ISO 27001, SOC (specify type, e.g., SOC 2), GDPR, PCI DSS, HIPAA, and other relevant regional, national, and international standards. The Compliance Analyst will be responsible for conducting internal audits, managing compliance documentation, assessing third-party risks, and preparing comprehensive responses to RFIs/RFPs, contributing significantly to our robust compliance posture.
Key Responsibilities:
Regulatory Frameworks:
- Align and meticulously maintain organizational practices in accordance with a broad spectrum of regulatory frameworks, including ISO 27001, SOC (specify type, e.g., SOC 2), GDPR, and other relevant regional, national, and international standards.
- Conduct regular and thorough internal audits to assess and ensure ongoing compliance with multiple regulatory frameworks and internal policies, identifying areas for improvement.
Compliance Documentation and Reporting:
- Develop, meticulously maintain, and update comprehensive compliance records, certifications, and audit reports.
- Generate clear, concise, and accurate compliance reports for internal leadership, external auditors, and other stakeholders as required.
Third-Party Risk Management:
- Assess and continuously monitor the compliance of third-party vendors and service providers with relevant regulatory and organizational standards.
- Conduct thorough risk evaluations and implement robust vendor due diligence processes to identify and mitigate potential compliance risks.
PCI DSS and HIPAA Compliance:
- Ensure the organization's ongoing compliance with Payment Card Industry Data Security Standard (PCI DSS) through regular audits, development and maintenance of relevant policies, and performance of gap analyses.
- Implement and monitor effective security controls to protect cardholder data, ensuring adherence to PCI DSS requirements.
- Develop, implement, and maintain HIPAA compliance programs, with a strong focus on ensuring the confidentiality, integrity, and availability of Protected Health Information (PHI).
- Ensure strict adherence to risk mitigation strategies related to PHI.
RFI/RFP Management:
- Prepare and submit accurate and comprehensive responses to Requests for Information (RFIs) and Requests for Proposal (RFPs), ensuring complete alignment with PCI DSS, HIPAA, and other applicable organizational policies and standards.
- Maintain a well-organized and up-to-date repository of all compliance documentation to facilitate efficient and accurate responses to customer and stakeholder inquiries.
- Develop and implement internal compliance policies and procedures.
- Stay updated on evolving regulatory requirements and industry best practices.
- Provide guidance and training to internal teams on compliance matters.
Required Skills and Qualifications:
- 3-6 years of experience in a dedicated compliance or audit role.
- Demonstrated experience aligning organizational practices with ISO 27001, SOC (specify type, e.g., SOC 2), and GDPR.
- Proven experience in conducting internal audits and assessing compliance with multiple regulatory frameworks.
- Strong ability to develop, maintain, and update comprehensive compliance records, certifications, and audit reports.
- Experience in third-party risk management, including vendor assessment and due diligence processes.
- In-depth knowledge and hands-on experience ensuring PCI DSS compliance, including audits, policy development, and control implementation.
- Solid experience in developing, implementing, and maintaining HIPAA compliance programs, with a focus on PHI.
- Proven ability to prepare accurate and comprehensive responses to RFIs and RFPs related to security and compliance.
- Excellent written and verbal communication skills, with the ability to convey complex compliance concepts clearly.
- Strong analytical and problem-solving skills, with meticulous attention to detail.
Didn’t find the job appropriate? Report this Job