Smith+Nephew

InformationSecurityComplianceAnalyst

Pune, India FULL TIME Remote Friendly
Market Sentiment
HIGH DEMAND

Neural analysis suggests this role is
optimal for Mid candidates.

The Brief

“Information Security Compliance Analyst at Smith+Nephew. Skills: HIPAA Program, Security Compliance, Program Management. Manage annual program activities. Complete annual risk assessments”

What You'll Achieve.

Safeguarding patient data; Strengthening global compliance posture; Deliver the annual program; Maintain the highest standards of security and compliance

Industry & Context.

Problems you'll solve

Sound judgement

Eligibility Requirements

Work from Office – 3 days in a week, UK Shift (12:30 PM IST to 9:30 PM IST)

What They're Looking For.

Must Have

5 years in Information Security, at least 3 years working on Security Compliance programs, At least 2 years in Program or Project Management, Prior experience in deploying and assessing Information Security controls is essential, Prior experience in Program or Project Management is essential

Nice to Have

Bachelor´s degree in Computer Science or related subject preferred, Privacy or Security certifications would be advantageous but are not essential, any HIPAA certification (CHPS, CHSE, CHPSE, CIPP/US), CISA, CISSP, ISO27001 or equivalent, Prior experience of Privacy Law related Security Controls compliance would be very well received, Prior experience using OneTrust, experience in IT Risk Management are optional

What You'll Do.

Manage annual program activities

Complete annual risk assessments

Maintain records in OneTrust

Deliver annual program

Plan program schedule

Manage execution against schedule

Organize stakeholders and external resources

Create and present materials

Organize cadences and report metrics

Plan and scope annual HIPAA Security Risk Assessment

Develop HIPAA SRA testing templates

Support execution of HIPAA SRA

Manage remedial actions from SRA

Perform HIPAA Security Assessments on IT Systems

Track remedial actions

Monitor HIPAA Law for changes

Propose changes to HIPAA Policy

Track and report HIPAA risks

Manage HIPAA records and workflow

How You'll Work.

Team & Collaboration

Work closely with Senior Director of Governance Risk and Compliance; Work with HIPAA Security Officer; Work with HIPAA Privacy Officer; Work with Head of Compliance; Organise stakeholders and external resources; Collaborate with leadership on SRA scope

Communication Scope

Clear communication; Presenting materials to SteerCo

Process & Methodology

Program Management, Project Management

Full Job Description

**Role: Information Security Compliance Analyst** **Location:** Kharadi, Pune **Life Unlimited.** At Smith+Nephew, we design and manufacture technology that takes the limits off living. Are you ready to play a key role in safeguarding patient data and strengthening our global compliance posture. We are looking for an experienced compliance analyst to run the company's annual HIPAA Program, reporting to the Senior Director Governance Risk & Compliance. HIPAA training will be provided for any candidates without direct experience. **What will you be doing?** * In this role you will be supported by the HIPAA Security Officer, HIPAA Privacy Officer and GRC Senior Director, who can provide guidance, additional direction and act as points of escalation HIPAA Program is owned by the Head of Compliance, with strategy directed by a cross-functional Steering Committee. * You will work closely with our Senior Director of Governance Risk and Compliance, the HIPAA Security Officer and the HIPAA Privacy Officer, as well as the Head of Compliance who owns the programme. * You will be managing activities and stakeholders to deliver the annual program. Managing annual program activities, competing annual risk assessments, assessing IT systems, maintaining records in OneTrust and reporting to Leadership. * Through clear communication, structured management and sound judgement, you will help maintain the highest standards of security and compliance across our systems and processes. **What will you need to be successful?** * Bachelor´s degree in Computer Science or related subject preferred. * Certifications: Privacy or Security certifications would be advantageous but are not essential e.g. any HIPAA certification (CHPS, CHSE, CHPSE, CIPP/US), CISA, CISSP, ISO27001 or equivalent. * Work from Office – 3 days in a week in UK Shift (12:30 PM IST to 9:30 PM IST) * Experience: 5 years in Information Security, at least 3 years working on working on Security Compliance programs. * At least 2

Free ATS check

Applying for this Information Security Compliance Analyst role?

Most applicants get filtered before a human reads their resume. See if yours makes the cut.

How to Apply on Workday

  • Workday has a multi-step form — save your progress after every section.
  • "Apply With LinkedIn" can fail or lose data; manual entry is more reliable.
  • Watch for the "Submit for Review" final step — hitting "Save" alone does not submit.
  • Job requisition numbers are useful when following up with HR by email.

ANONYMOUS · UNFILTERED

What do employees actually say about Smith+Nephew?

Real rants from real employees. Read before you apply.

Read Company Rants →