This is the senior judgment layer of Gnani's security function and the CISO's right hand on all things compliance and risk looking after every hard regulatory call - how to optimize our internal process to map all compliances and successfully maintain compliant statuses, how to safeguard the organization from all the liabilities, how to read the liability clauses in MSAs, what our DPDP cross-border position is and many more. You will own those calls. You'll run the certification and audit program end-to-end, own the enterprise risk register, lead the client security-questionnaire (ISQ) function, and be the person regulators and enterprise clients can be handed to with confidence.
What you'll own
• Own the certification & audit lifecycle: ISO 27001, ISO 42001, SOC 2 Type 2, PCI DSS, HIPAA, GDPR etc. and the various information security guidelines from the regulatory bodies like RBI, IRDA etc.• Own the enterprise risk register and drive a formal, board-ready risk appetite statement• Lead the client security-questionnaire (ISQ) program: SLAs, the pre-approved answer library, and the strategy to automate it without compromising data protection• Be the authority on hard regulatory questions across DPDP, RBI, IRDAI, GDPR, HIPAA and cross-border transfers - and the go-to for MSA/DPA security & liability reviews alongside Legal/Counsel• Own the policy lifecycle: currency, enforcement, SOPs, KPIs/SLAs, and the evidence that controls operate• Mentor GRC Analysts and interns; turn compliance from ad-hoc heroics into a repeatable, measured program
What we're looking for
• 8-12 years in GRC / information security compliance, with real ownership (not just 'support') of ISO 27001 and SOC 2 programs end-to-end• Demonstrated experience resolving audit non-conformities and client/regulator disputes personally• Strong working command of DPDP Act & Rules, RBI and IRDAI expectations for technology vendors, plus GDPR/HIPAA/PCI• ISO 27001 Lead Implementer/Auditor; SOC 2 and ideally ISO 42001 implementation experience• Excellent written English - your answers go directly to enterprise clients and regulators• Regulated industry (BFSI, insurance, healthcare) or SaaS/AI compliance background
Nice to have
• ISO 27000, ISO 42001 Lead Implementer; privacy certification (DCPP/CIPP/CIPM)• Exposure to CAIQ, SIG, HECVAT frameworks• Experience standing up GRC automation tooling• Prior work with AI/ML or data-heavy platforms
Your first 90 days
• Take full ownership of the certification calendar; resolve the SOC 2 bridge-letter / client-acceptance issue and document the standard playbook for it• Publish a consolidated risk register with the top risks, owners and treatment plans, and a draft risk appetite statement for CISO/board sign-off• Stand up the ISQ program with a defined SLA ( 5 business days for complex questionnaires) and a first version of the answer library• Deliver a 90-day compliance-posture readout to the CISO: what's audit-ready, what's at risk, and the 6-month plan
Why join now
• You will be an early member of a security function being built from the ground up - you shape process and precedent, not inherit a backlog with no context.• High-visibility work with the CISO, Engineering, Legal and Sales - your decisions are felt company-wide within a quarter.• A rare chance to secure a genuinely AI-native platform at a fast-scaling, company, without enterprise bureaucracy.