IT Risk Management Specialist Needed

Job ID: 39314294

Budget: ₹37,500 – ₹75,000 INR

Seeking Risk Management - Freelancer to be based out in Bangalore, Hebbal office.

Aster Digital Health is the digital transformation arm of Aster DM Healthcare, leading innovation across our hospitals, clinics, labs, pharmacies, and virtual care platforms. We are actively reshaping how healthcare is delivered by leveraging technology to improve access, efficiency, and patient experience.
We are currently seeking expert support to develop a robust risk management framework and policies tailored to our operational landscape.
We are interested in exploring a 3-month collaboration with your team, ideally commencing at the earliest convenience. Our goal is to engage experienced professionals who can work closely with our internal stakeholders to:
Objective: The IT Risk and Audit Management, to be responsible for overseeing and managing the IT risk management and audit functions. This role to involve identifying, assessing, and mitigating IT risks, as well as ensuring compliance with regulatory requirements and internal policies. To have a strong background in IT risk management, audit, and compliance, with excellent analytical and problem-solving skills.
Key actionables:
• Develop and implement IT risk management strategies and frameworks.
• Conduct regular IT risk assessments and audits to identify potential risks and vulnerabilities.
• Monitor and report on IT risk exposure and mitigation efforts.
• Ensure compliance with relevant regulatory requirements and internal policies.
• Collaborate with IT and business teams to develop and implement risk mitigation plans.
• Provide guidance and support to IT and business units on risk management and compliance matters.
• Prepare and present reports on IT risk and audit findings to senior management.
• Stay up-to-date with industry trends and best practices in IT risk management and audit.
• Plan and lead the engagements with various certification bodies including cyber insurance, legal, ISO/HIPAA exercises etc.
• Ensure the Documentation and architectural change such as DR/BCP plans and drills are maintained with respect to Risk and Audit committee requirements
• Act as a central authority to manage all approvals of access to data, servers, and VPN based services.
Should a formal agency collaboration not be feasible within our timeframe, we are open to engaging your experts on a freelance or contract basis.
Please let us know your availability for a brief call to discuss this opportunity further. We are happy to provide additional details to help assess the scope and potential engagement model.
Looking forward to hearing from you.

Regards,
Jessie