Deskripsi Pekerjaan
Are you a strategic security leader with deep expertise in healthcare compliance? We are looking for a Security & Compliance Lead to drive Governance, Risk, and Compliance (GRC) initiatives for a prominent US healthcare group. This high-impact contract role, based in Kuala Lumpur, is critical to ensuring the organization meets rigorous HIPAA standards and maintains an exceptional security posture.
As the Security & Compliance Lead, you will be the primary architect of the company's compliance framework. You will own and manage the end-to-end GRC strategy, including policy development, risk assessment, and control validation. Your expertise in HIPAA will be instrumental in achieving and maintaining full readiness for US healthcare regulations. You will lead cloud security initiatives across major platforms (AWS, Azure, GCP), managing cloud controls, data protection strategies, and incident response plans tailored for a healthcare environment.
A critical component of this role is Vendor Risk Management (VRM). You will develop and execute a rigorous VRM program to assess, monitor, and mitigate risks associated with third-party vendors and partners. Furthermore, you will ensure the organization is perpetually audit-ready by maintaining a comprehensive evidence library and coordinating internal and external audits (SOC 2, HITRUST, ISO 27001).
This is a unique opportunity to take a leadership position in a fast-paced environment where your work directly contributes to the safety and security of sensitive health information. The ideal candidate is a collaborative leader who can communicate complex compliance requirements to technical and non-technical stakeholders alike. If you are passionate about healthcare compliance and ready to make a tangible impact, we encourage you to apply.
This is a contract / temporary position offering a premium rate commensurate with the seniority and specialized nature of the role. You will enjoy the autonomy to shape the compliance landscape while working alongside a world-class team dedicated to healthcare innovation.
Tanggung Jawab
- Develop, implement, and maintain the corporate GRC strategy, frameworks, and policies aligned with HIPAA, HITRUST, and NIST standards.
- Lead HIPAA readiness assessments and remediation efforts to ensure compliance across all business units and technology platforms.
- Manage Cloud Security Posture Management (CSPM) and enforce cloud controls for AWS/Azure environments.
- Oversee the Vendor Risk Management (VRM) lifecycle, including due diligence, ongoing monitoring, and contract reviews.
- Prepare and coordinate internal and external audit engagements (SOC 2, ISO 27001, HITRUST).
- Conduct risk assessments, gap analyses, and drive the remediation of identified findings.
- Develop and deliver security awareness training and communication programs tailored to healthcare regulatory requirements.
- Report on compliance status and risk exposure to senior leadership and key stakeholders.
Kualifikasi
- Bachelor’s degree in Information Security, Computer Science, or a related field. Master’s degree preferred.
- Minimum 8 years of experience in information security, with at least 5 years focused on GRC and compliance.
- Deep subject matter expertise in HIPAA regulations and US healthcare compliance requirements.
- Professional certifications such as CISSP, CISM, CRISC, CISA, or CHIS.
- Strong experience with cloud security controls and architectures in AWS, Azure, or GCP.
- Proven track record of managing vendor risk assessments and third-party security programs.
- Excellent communication, leadership, and stakeholder management skills.
- Experience in conducting audits (SOC 2, HITRUST, PCI-DSS) is a strong advantage.