Location Name: Pune Corporate Office - Mantri
Job Purpose
Your job is to make sure our SaaS platform is secure, audit-ready, and certifiable without slowing the company down. You'll design and run our information security and compliance programs end-to-end—turning chaos into controls, and controls into certifications customers actually care about.
In a SaaS startup, security is revenue insurance. This role directly impacts:
- Enterprise deal velocity
- Customer trust & retention
- Long-term company valuation
You won't be a back-office function. You'll be a strategic enabler.
Duties And Responsibilities
A- Minimum required Accountabilities for this role
- Security & Compliance Ownership
- Own the InfoSec and compliance roadmap for the company
- Define and maintain policies, standards, and controls (practical, not academic)
- Act as the single point of accountability for audits and certifications
- Certifications & Frameworks (Core Mandate)
You Will Lead Certification Efforts End-to-end, Including
- ISO 27001 (ISMS design, implementation, audits)
- SOC 2 Type I & II
- GDPR, DPDP (India), and customer-driven security questionnaires
- Prepare evidence, manage auditors, close gaps—no outsourcing responsibility
- Risk, Controls & Security Governance
- Conduct risk assessments and threat modeling for SaaS architecture
- Translate risks into prioritized, business-aligned controls
- Own vendor risk management and third-party security reviews
- Engineering & Product Partnership
- Work directly with Engineering, DevOps, and Product teams
- Embed security into SDLC, CI/CD, cloud infrastructure, and data flows
- Push for automation over manual controls wherever possible
- Incident & Response Readiness
- Define and maintain incident response, BCP, and DR plans
- Lead tabletop exercises and post-incident reviews
- Ensure real preparedness—not just documented plans
- Customer & Sales Enablement
- Support enterprise sales with security narratives and compliance evidence
- Respond to customer security assessments and due-diligence reviews
- Act as a credibility multiplier, not a bottleneck
B- Additional Accountabilities Pertaining To The Role
Leadership Expectations
- Think systems-first, not tool-first.
- Bias for automation and simplicity.
- Calm under pressure; decisive during incidents.
- Business-aware: understands how infra decisions affect revenue, customers, and growth.
- Comfortable pushing back on bad ideas—even from senior stakeholders.
Major Challenges
- Core certifications achieved and renewed with minimal audit friction
- Security controls embedded into engineering workflows
- Reduced sales friction due to faster, confident compliance responses
- Clear risk posture that leadership actually understands
- No security theater—only controls that work
Required Qualifications And Experience
- Qualifications
- Post Graduates with relevant sales experience of 6-8 years (also graduates with experience of 8-10 years may apply)
- Work Experience
- Relevant sales experience in managing large sales channels in multiple market environments
- Prior & relevant experience in the Financial Services Industry would be an added advantage.
- Demonstrated success & achievement orientation.
- Excellent communication skills.
- Strong bias for action & driving results in a high performance environment.
- Demonstrated ability to lead from the front.
- Excellent relationship skills.
- Strong analytical skills to drive channel performance and drive profitability.
- Exceptionally high motivational levels and needs to be a self-starter.
Must-Have
- 5–10+ years in InfoSec, GRC, or compliance roles (SaaS or cloud-native preferred)
- Proven ownership of ISO 27001 and/or SOC 2 certifications
- Strong understanding of:
o Cloud security (AWS / Azure / GCP)
o SaaS architecture & multi-tenant systems
o Data protection & privacy regulations
- Ability to write clear, audit-grade documentation that engineers don't hate
- Comfortable pushing back on leadership when risk is real
Nice-to-Have (Big Plus)
- Experience in early-stage or scaling SaaS startups
- Automation mindset (GRC tools, evidence pipelines, scripts)
- Certifications like ISO 27001 LA, CISA, CISSP, or similar
- Experience dealing with global customers and enterprise procurement teams