Search by job, company or skills

Senior Security & Compliance Lead Certifications & GRC

  • Posted 5 hours ago
  • Be among the first 10 applicants

Job Description

Position: Senior Security & Compliance Lead Certifications & GRC

Location:Hyderabad (8:00 PM -5:00 AM IST)

Work Type: Full-Time

Experience: 10+ Years

PETADATA is looking for a Senior Security & Compliance Lead Certifications & GRC with strong experience in cybersecurity, risk management, compliance frameworks, and enterprise security solutions.

Roles & Responsibilities

Security Certifications & Compliance Program

  • Own the organization's security certification roadmap, determining which certifications and attestations are required and prioritizing them based on business, customer, and market requirements.
  • Lead certification programs such as SOC 2 Type I, SOC 2 Type II, ISO 27001, and, where applicable, ISO 27017/27018, GDPR/privacy, HIPAA, PCI DSS, or CSA STAR.
  • Manage certifications end to end, including gap assessments, control design, control implementation, evidence collection, auditor selection, audit coordination, remediation, and certification.
  • Establish and maintain an Information Security Management System (ISMS), including security policies, standards, procedures, and supporting documentation.
  • Develop a unified control framework that can map controls across multiple security and compliance standards and deployment models.

Cloud & On-Premise Security

  • Build and maintain the compliance posture for a multi-tenant cloud platform, including tenant isolation, data segregation, shared infrastructure controls, and cloud-provider responsibilities.
  • Develop security and compliance requirements for on-premise and customer-deployed environments, including secure deployment, hardening, documentation, and customer audit support.
  • Establish and maintain a clear shared-responsibility model across cloud and customer-managed deployments.
  • Map security controls across cloud environments such as AWS, GCP, and Azure and ensure appropriate security responsibilities are documented and implemented.

Security Engineering & Risk Management

  • Partner with Engineering and Architecture teams to ensure security controls are designed into the platform, rather than added after development.
  • Drive implementation of controls covering encryption, access control, secrets management, logging and auditing, tenant isolation, and secure SDLC practices.
  • Establish and manage vulnerability management, penetration testing, and security review processes, ensuring findings are tracked through remediation and closure.
  • Conduct security risk assessments and manage third-party and vendor security risks.
  • Work closely with technical teams to identify security gaps and develop practical remediation plans.

Security Operations & Business Continuity

  • Establish and maintain incident response, business continuity, and disaster recovery plans, including regular testing and validation.
  • Develop and deliver security awareness training and promote a security-first culture across the organization.
  • Monitor security and compliance controls continuously and coordinate remediation when gaps are identified.
  • Manage ongoing surveillance audits, recertification activities, and compliance monitoring as the organization, platform, and team evolve.

Customer Trust & Audit Management

  • Own the organization's customer security and trust program, responding to security questionnaires, RFP security sections, vendor assessments, and customer audit requests.
  • Maintain security and compliance documentation through a centralized trust/compliance portal.
  • Work directly with customers to explain security controls, compliance posture, shared responsibilities, and deployment-specific requirements.
  • Serve as the primary point of contact for auditors, customers, engineers, and executive stakeholders on security and compliance matters.
  • Translate complex security requirements into clear policies, evidence, documentation, and actionable recommendations.

Note: Should be able to work independently and work in USA time zones

Required Qualifications & Skills

  • 8+ years in information security, GRC, or security compliance.
  • Hands-on experience leading SOC 2 and/or ISO 27001 certifications end to end.
  • Strong knowledge of SaaS security, multi-tenant environments, cloud security, IAM, encryption, and audit logging.
  • Experience with AWS, GCP, or Azure and cloud shared responsibility.
  • Experience with on-premise/customer-deployed software security and compliance.
  • Strong understanding of risk management, control frameworks, ISMS, audits, and continuous compliance.
  • Knowledge of GDPR, CCPA, and other relevant privacy requirements.
  • Experience with vulnerability management, penetration testing, incident response, and vendor risk management.
  • Strong security documentation and audit evidence management skills.
  • Excellent communication skills with auditors, engineers, customers, and executives.
  • Highly self-directed, with the ability to build and manage a security program independently.
  • Preferred: CISSP, CISA, CISM, CCSP, ISO 27001 Lead Implementer/Auditor, and experience with HIPAA, PCI DSS, NIST, FedRAMP, Vanta, Drata, or DevSecOps.

Education

Bachelor s degree in Computer Science, Information Technology, Engineering, or a related field.

Candidates are required to attend Phone/video calls and in-person interviews. After the Selection, the candidate (He/She) should undergo all background checks on Education and Experience.

Please email your resume to [Confidential Information]

After carefully reviewing your experience and skills, one of our HR team members will contact you on the next steps

More Info

Job Type:
Industry:
Employment Type:

Job ID: 153788125

Beware of Scammers

We don’t charge money for job offers