title-image
Turrior - Let work find you
Recruiters get AI-ranked shortlists and automated outreach, filling roles up to 5× faster.
0%
Popularity
0d
Avg. Time to Hire
0h
Recruiter Res. Time
0%
HR Satisfaction
Careers at Athelas
All open opportunities, right here. Explore, apply, grow.
Apply now

Governance, Risk, and Compliance Lead (India)

23 Oct 2025
Bengaluru, Karnataka, India
Verified by Turrior

Content + Source + Freshness • 14 Feb 2026 • 95% confidence

85 / 100

Offer value

Crucial leadership role with significant influence over compliance frameworks in health technology.

  • Lead compliance strategy in an impactful healthcare setting.
  • Strong demand for governance experts in regulated industries.
  • Competitively positioned salary range available.
Pros
  • Senior role with authority over compliance strategy.
  • High relevance to current trends in data privacy.
  • Work in an innovative, mission-driven company.
Cons
  • Pressure associated with compliance and regulatory adherence.
  • Requires continuous education on changing regulations.
  • Possibility of significant responsibility without direct reports.

Who it's for

Senior / Lead • Hybrid or Remote

Good fit
  • Experts in GRC with a passion for healthcare compliance.
  • Senior professionals ready to drive compliance initiatives.
  • Individuals with strong problem-solving capabilities.
Not recommended for
  • Introverts who prefer minimal team interaction.
  • Entry-level compliance candidates.
  • Individuals resisting dynamic workplace environments.

Motivation fit

Desire to safeguard data privacy and compliance standards.Interest in constructing robust governance frameworks.Motivation to lead and mentor within compliance teams.

Key skills

Expertise in GRC frameworks and compliance management.Strong communication and interpersonal skills.Project management and strategic thinking abilities.
Score: 85/100 AI verified analysis

About the job

Location

Bengaluru, India

Employment Type

Full time

Department

Engineering

At Commure, our mission is to simplify healthcare. We have bold ambitions to reimagine the healthcare experience, setting a new standard for how care is delivered and experienced across the industry. Our growing suite of AI solutions spans ambient AI clinical documentation, provider copilots, autonomous coding, revenue cycle management and more — all designed for providers & administrators to focus on what matters most: providing care.

Healthcare is a $4.5 trillion industry with more than $500 billion spent annually on administrative costs, and Commure is at the heart of transforming it. We power over 500,000 clinicians across hundreds of care sites nationwide – more than $10 billion flows through our systems and we support over 100 million patient interactions. With new product launches on the horizon, expansion into additional care segments, and a bold vision to tackle healthcare's most pressing challenges, our ambition is to move from upstart innovator to the industry standard over the next few years.

Commure was recently named to Fortune’s Future 50 list for 2025 and is backed by world-class investors including General Catalyst, Sequoia, Y Combinator, Lux, Human Capital, 8VC, Greenoaks Capital, Elad Gil, and more. Commure has achieved over 300% year-over-year growth for the past two years and this is only the beginning. Healthcare's moment for AI-powered transformation is here, and we're building the technology to power it. Come join us in shaping the future of healthcare.

About the Role

We’re seeking an experienced GRC Lead to drive Commure’s governance, risk, and compliance strategy across our global operations.

In this critical leadership role, you will act as the architect of our compliance framework, owning the end-to-end compliance lifecycle — from policy design and risk assessment to audit coordination and organization-wide awareness.

As the GRC Lead, you’ll work at the intersection of technology, security, and healthcare regulation, ensuring that our products and operations adhere to the highest standards of integrity, data protection, and operational excellence.

Key Responsibilities

Compliance & Governance Leadership

  • Design, implement, and oversee comprehensive IT compliance and governance programs aligned with HIPAA, GDPR, CCPA, and other data privacy regulations.

  • Develop and continuously refine IT security policies, standards, and procedures to balance compliance rigor with operational efficiency.

  • Validate and approve IT processes and activities to ensure conformance with regulatory and organizational mandates.

  • Act as the primary liaison between internal stakeholders, executive leadership, and external auditors on all compliance-related matters.

Risk Management & Assessment

  • Build and maintain a robust risk management framework to proactively identify, assess, and mitigate IT and operational risks.

  • Conduct regular risk assessments, internal audits, and control evaluations to detect vulnerabilities and compliance gaps.

  • Perform physical security audits and validate adherence to standards across facilities and third-party locations.

Audit & Quality Assurance

  • Manage internal and external audit processes, ensuring preparedness, accuracy, and timely resolution of findings.

  • Conduct periodic compliance inspections across organizational and vendor sites to validate adherence to policies.

  • Track, report, and close remediation actions while driving continuous improvement of compliance systems and procedures.

Training & Advisory

  • Design and deliver engaging compliance and security awareness training programs for employees at all levels.

  • Serve as a trusted advisor to leadership and business units on compliance strategy, risk mitigation, and program effectiveness.

  • Prepare comprehensive compliance reports, dashboards, and presentations for executive stakeholders and the Head of Privacy.

Investigation & Remediation

  • Lead or support internal investigations into compliance violations, data incidents, or policy breaches.

  • Develop and implement corrective action plans to address compliance gaps and prevent recurrence.

  • Monitor emerging risks and regulatory changes to ensure proactive compliance readiness.

Required Qualifications

  • Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, Risk Management, or related discipline (Master’s preferred).

  • 5+ years of progressive experience in GRC, IT compliance, cybersecurity assurance, or related governance roles.

  • Deep expertise in HIPAA, GDPR, CCPA, and IT risk management frameworks such as NIST, ISO 27001, and SOC 2.

  • Proven experience in internal audits, risk assessments, and implementing compliance programs in complex or regulated environments.

  • Demonstrated ability in vendor risk management, third-party audits, and compliance oversight.

  • Strong written and verbal communication skills with the ability to simplify complex regulatory concepts for diverse audiences.

Preferred Qualifications

  • Professional certifications such as:

    • CISA (Certified Information Systems Auditor)

    • CISM (Certified Information Security Manager)

    • CISSP (Certified Information Systems Security Professional)

    • ISO 27001 Lead Auditor

    • CRISC (Certified in Risk and Information Systems Control)

    • CHPC (Certified in Healthcare Privacy Compliance)

  • Experience within healthcare technology, digital health, or similarly regulated industries.

  • Proven success in building and scaling GRC programs within high-growth or global organizations.

  • Familiarity with GRC platforms and compliance management tools.

Key Competencies

  • Strategic Leadership: Ability to architect and operationalize GRC programs that safeguard organizational integrity while enabling innovation.

  • Analytical Rigor: Strong diagnostic and problem-solving capabilities with a methodical approach to risk analysis and control design.

  • Ethical Judgment: Unwavering commitment to confidentiality, integrity, and ethical governance.

  • Communication & Influence: Skilled at articulating complex compliance matters to both technical and non-technical audiences.

  • Project Management: Adept at managing multiple concurrent initiatives with precision and accountability.

  • Collaboration & Independence: Strong cross-functional partnership skills, equally effective when leading or working autonomously.

  • Adaptability: Ability to stay ahead of evolving regulatory landscapes, emerging risks, and technology trends.

Commure is committed to creating and fostering a diverse team. We are open to all backgrounds and levels of experience, and believe that great people can always find a place. We are committed to providing reasonable accommodations to all applicants throughout the application process.

Please be aware that all official communication from us will come exclusively from email addresses ending in @getathelas.com, @commure.com or @augmedix.com. Any emails from other domains are not affiliated with our organization.


Employees will act in accordance with the organization’s information security policies, to include but not limited to protecting assets from unauthorized access, disclosure, modification, destruction or interference nor execute particular security processes or activities. Employees will report to the information security office any confirmed or potential events or other risks to the organization. Employees will be required to attest to these requirements upon hire and on an annual basis.

Similar Jobs

End-to-end AI hiring for modern HR teams

Turrior uses artificial intelligence to create job listings, automate candidate screening, conduct video interviews, and apply comprehensive AI scoring — helping companies hire faster, more accurately, and with lower operational costs.

Key benefits:

  • AI-powered job creation and structured job data
  • Intelligent candidate screening and automated shortlisting
  • Video interviews with AI-based answer analysis
  • Comprehensive AI scoring of skills, experience, and role fit
  • Recruitment process automation and reduced time-to-hire

Share job