Information Security Manager / GRC Lead

Flamapp

India

On-site

INR 1,500,000 - 2,100,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Flamapp is building its information security function from the ground up. As our first Information Security Manager / GRC Lead, you will own the compliance programme and work hands-on in Scrut.io to drive ISO 27001:2022 and SOC 2 Type I certification within 3–4 months.

This high-visibility role will help define responsible AI security in practice. You will coordinate evidence collection across Engineering, DevOps, HR, Finance, and Sales, manage audits, and build a security-aware culture for 100+

Qualifications

  • 3–5 years of experience in information security, GRC, or compliance roles.
  • Hands-on experience implementing or maintaining ISO 27001 end-to-end.
  • Solid understanding of SOC 2 Trust Service Criteria and audits.
  • Experience using a GRC platform (Scrut.io, Vanta, Drata, Tugboat Logic, or equivalent).
  • Ability to translate technical security controls into plain-English policies and evidence tasks for non-security teams.
  • Strong project management skills—comfortable owning deadlines, chasing stakeholders, and escalating blockers.
  • Familiarity with cloud security concepts, GCP or AWS, and shared responsibility model.

Responsibilities

  • Drive end-to-end ISO 27001:2022 and SOC 2 implementation across the organization.
  • Own the SoA, risk register, risk treatment plan, and ISMS documentation.
  • Coordinate evidence collection across Engineering, DevOps, HR, Finance, and Sales.
  • Manage internal audit cycles and coordinate with CPA for SOC 2.
  • Track Scrut controls to completion and manage evidence deadlines.
  • Draft, review, and publish ISMS policies (Access Control, Incident Response, Data Classification, etc.).
  • Maintain regulatory registers (CCPA/CPRA) and ensure policy publication in Scrut.
  • Lead security awareness programs and coordinate security training across 100+ employees.

Skills

Information security
GRC
Compliance
Project management
Cloud security
Policy writing

Tools

Scrut.io
Vanta
Drata
Tugboat Logic

Job description

We are building our information security function from the ground up. As our first Information Security Manager / GRC Lead, you will be the operational owner of Flam's entire compliance programme and working hands‑on in Scrut.io to drive ISO 27001:2022 and SOC 2 Type I certification within 3–4 months. This is a high‑impact, high‑visibility role at a company whose core product is AI — meaning you will be helping define what responsible AI security looks like in practice, not just checking boxes.

What You'll Own
ISO 27001 & SOC 2 Implementation
  • Drive end‑to‑end implementation of ISO 27001:2022 across all 88 applicable Annex A controls and SOC 2 Trust Service Criteria, using Scrut.io as the single source of truth
  • Own the Statement of Applicability (SoA), risk register, risk treatment plan, and all ISMS documentation
  • Coordinate evidence collection across Engineering, DevOps, HR, Finance, and Sales — translating control requirements into actionable tasks for each team
  • Manage the internal audit cycle, prepare for Stage 1 and Stage 2 ISO 27001 audits, and coordinate with the external CPA firm for SOC 2
  • Track all 239 Scrut controls to completion, assign owners, and chase evidence deadlines
Policy & Documentation
  • Draft, review, and get management approval for all ISMS policies — Access Control, Incident Response, Data Classification, BCP/DR, Vendor Management, Acceptable Use, and more
  • Maintain the legal and regulatory register covering CCPA/CPRA (California) and applicable federal requirements
  • Ensure all policies are published, acknowledged, and kept current in Scrut
  • Conduct and maintain the organisation's information security risk assessment — identifying threats, scoring likelihood and impact, and producing a risk treatment plan
  • Maintain the risk register in Scrut and present findings at quarterly ISG meetings and annual MRM
Vendor & Third-Party Security
  • Own the vendor security assessment programme — completing questionnaires and reviews for GCP, Modal.com, and all critical SaaS tools
  • Ensure security clauses are present in all vendor contracts and customer MSAs
  • Maintain the third‑party inventory in Scrut with classification and review cadence
Security Awareness & Culture
  • Launch and manage the company‑wide security awareness training programme for 100+ employees — track completion in Scrut
  • Run quarterly phishing simulations and document results
  • Build a security‑first culture — be the person people come to with questions, not the person who sends scary emails
  • Own and maintain the Incident Response Policy and Playbook
  • Coordinate tabletop exercises before audit milestones
  • Monitor and triage security events in collaboration with the DevOps and IT teams
What We're Looking For :
  • 3–5 years of experience in information security, GRC, or compliance roles
  • Hands‑on experience implementing or maintaining ISO 27001 — you have been through at least one certification cycle end‑to‑end
  • Solid understanding of SOC 2 Trust Service Criteria and what auditors look for
  • Experience using a GRC platform (Scrut.io, Vanta, Drata, Tugboat Logic, or equivalent)
  • Ability to translate technical security controls into plain‑English policies and evidence tasks that non‑security teams can execute
  • Strong project management skills — you are comfortable owning deadlines, chasing stakeholders, and escalating blockers
  • Familiarity with cloud security concepts — GCP or AWS — and what 'shared responsibility model' means in practice
Nice to Have
  • ISO 27001 Lead Implementer or Lead Auditor certification (PECB, BSI, or equivalent)
  • CISSP, CISM, or CISA certification
  • Experience with AI/ML product companies or platforms handling sensitive personal data
  • Familiarity with CCPA/CPRA data protection requirements
  • Experience with DPDP Act 2023 (India) — useful given our India operations
  • Prior startup experience — comfortable building programmes with limited resources
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Manager / GRC Lead
Information Security Manager / GRC Lead

Keka Technologies Private Limited • Bengaluru

On-site
INR 1,200,000 - 1,800,000
IT Systems & Network Engineer
IT Systems & Network Engineer

Keka Technologies Private Limited • Bengaluru

On-site
INR 1,000,000 - 1,500,000
IT Systems & Network Engineer
IT Systems & Network Engineer

Flamapp • India

On-site
INR 1,200,000 - 2,400,000
IT Systems & Network Engineer
IT Systems & Network Engineer

Flam • Bengaluru

On-site
INR 900,000 - 1,200,000
GRC Lead / Security Compliance Lead
GRC Lead / Security Compliance Lead

Gnani Innovations Private Limited. • India

On-site
INR 350,000 - 600,000
Governance, Risk and Compliance (GRC) Lead
Governance, Risk and Compliance (GRC) Lead

Money Honey Financial Services • Mumbai

On-site
INR 1,500,000 - 2,000,000
Information Security & Compliance Lead
Information Security & Compliance Lead

Infra360 Solutions Pvt. Ltd. • Haryana

On-site
INR 1,000,000 - 1,500,000
Senior Security GRC & ISO 27001 Manager
Senior Security GRC & ISO 27001 Manager

UST • Thiruvananthapuram

On-site
INR 2,500,000 - 4,500,000
InfoSec Manager
InfoSec Manager

Blankstate • Delhi

On-site
INR 2,500,000 - 4,200,000
Private Health Insurance
Paid Time Off
Work From Home
+1
InfoSec Manager
InfoSec Manager

Blankstate • Dadri

On-site
INR 3,500,000 - 6,500,000
Private Health Insurance
Paid Time Off
Work From Home
+1