Senior Manager - Information Security

Quiet Capital

Gurugram District

On-site

INR 1,500,000 - 2,100,000

Full time

7 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Leena AI is seeking a senior security compliance leader to own and advance the information security program. You will ensure audit readiness, respond to high‑volume security questionnaires, and oversee vendor risk and privacy operations for a global enterprise AI platform.

You will drive remediation, maintain policies, and deliver regular written updates to leadership. This role requires strong GDPR/DPDP expertise, ISO/HITRUST exposure, and English communication across a US client base.

Qualifications

  • 7–10 years in information security compliance.
  • Experience leading ISO 27001 and SOC 2 Type II cycles as internal owner.
  • Strong experience with enterprise security questionnaires (RFPs).
  • Deep knowledge of GDPR/DPDP, HIPAA, and AI governance concepts.

Responsibilities

  • Keep ISMS audit‑ready daily: evidence, testing, internal audits across ~10 frameworks; coordinate with external auditors.
  • Respond to security questionnaires in writing (~2/day) across RFPs and vendor reviews; maintain trust portal and standard documents.
  • Manage vendor/privacy operations: vendor risk assessments, sub‑processor lists, DPA notifications, GDPR/DPDP processes with Legal.
  • Track findings to closure: maintain trackers, chase owners, report SLA breaches, coordinate pen‑test logistics.
  • Maintain policies and deliver security awareness training; report weekly on progress.
  • Communicate clearly in English with US customer overlap (EST hours).

Skills

ISO 27001
SOC 2 Type II
GDPR/DPDP
HITRUST
ISO 27701
DPO exposure
CIPM/CIPP
Vendor risk
Security questionnaires
English fluency

Job description

About Leena AI

Leena AI is a leader in Agentic AI for the enterprise. We are building an iconic company, delivering AI Colleagues that transform back‑office functions and accelerate the full promise of Generative AI—unlocking real productivity gains, cutting costs, and delighting employees at scale.

Leena AI provides the most forward‑looking, open, and scalable Agentic AI architecture for the enterprise— it empowers CIOs and CTOs to develop, deploy, and manage AI Colleagues for the back office at scale. Built with full governance, compliance, security, and auditability at its core.

Leena AI integrates with 1000+ applications, including SAP, Salesforce, ServiceNow, Workday, and Microsoft Office 365. We are proud to be trusted by 500+ global enterprises and 20 million+ employees, including leading brands such as Nestlé, Puma, Coca‑Cola, Sony, and Etihad Airways.

Founded in 2018 and headquartered in New York, Leena AI has secured over $40M in financing from top‑tier investors including Greycroft, Bessemer Venture Partners, B Capital, and Y Combinator.

The role

You are the engine room of Leena AI's security compliance program. The Head of Information Security & Compliance owns the program, faces customers, and makes the calls; you run the machine that keeps every commitment true - the evidence, the audits, the questionnaires, the vendors, the trackers. This is a hands‑on senior IC role for someone who takes pride in an audit with zero surprises and a questionnaire queue at zero.

What You'll Do
  • Keep the ISMS audit‑ready, every day - evidence collection, control testing, and internal audits across ~10 frameworks; coordinate external auditors and assessors through every surveillance and certification cycle; run the HITRUST readiness workstream under the Head's direction.
  • Answer for our security, in writing - respond to customer security questionnaires (~2/day at quality) across RFPs, vendor-risk reviews, and AI questionnaires; keep the trust portal and standard document set (whitepaper, DPA, TOMs, certifications) current at all times.
  • Run vendor and privacy operations - execute vendor risk assessments, maintain the sub‑processor list and DPA notification mechanics, and operate GDPR/DPDP processes with Legal.
  • Track every finding to closure - maintain the vulnerability and audit‑findings trackers, chase owners across engineering, report SLA breaches to the Head weekly, and coordinate the pen‑test cycle logistics with vendors.
  • Maintain policies and run training - keep the ISMS policy set current and deliver the security awareness program.
  • Report in writing, weekly - done / not done / blocked / need, with dates. This is the non‑negotiable working style of the team.
What We're Looking For
  • 7–10 years in information security compliance, in‑house at a SaaS/product company - you have personally taken a vendor through full ISO 27001 and SOC 2 Type II cycles as the internal owner, not as an external auditor or consultant.
  • High‑volume questionnaire experience: enterprise security questionnaires and RFP security sections have been a core part of your job, and you are fast without being sloppy.
  • Used to chasing engineering teams to closure - evidence, remediation, timelines - with persistence and without needing an escalation for every item.
  • Working fluency in how AI products handle enterprise data - enough to answer AI‑questionnaire sections accurately and know when to pull in the Head.
  • Strong on GDPR and DPDP mechanics; CIPM/CIPP, ISO 27701, or DPO exposure a plus. HITRUST or ISO 42001 exposure a plus.
  • Clear, direct communicator in English, comfortable with US customer overlap (EST hours).
How Success Is Measured
  • Questionnaire turnaround time and quality, with the routine tier handled end‑to‑end without escalation.
  • Evidence currency: any auditor request answerable within a day, no findings caused by stale or missing evidence.
  • Vendor assessments, sub‑processor notifications, and policy reviews completed on calendar, every cycle.
  • Findings trackers accurate and current; SLA breaches surfaced the week they happen, not discovered later.
Why this role is a good move
  • Full‑stack compliance exposure most companies can't offer: ~10 frameworks including HIPAA, HITRUST readiness, and ISO 42001 AI governance from day one.
  • Direct exposure to Fortune‑500 customer security processes at an enterprise AI company.
  • A clear #2 seat in a security function being built properly - a dedicated Head above you, real tooling investment, and room to grow as the program scales.

Skills: compliance,iso,information security,security,hitrust

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Manager - Information Security
Senior Manager - Information Security

Leena AI • Gurugram District

On-site
INR 3,000,000 - 6,000,000
Head of Information Security & Compliance
Head of Information Security & Compliance

Leena AI • Gurugram District

On-site
INR 3,500,000 - 7,500,000
Engineering Manager - DevOps
Engineering Manager - DevOps

Leena AI • Gurugram District

On-site
INR 4,000,000 - 7,000,000
AI Security Architect
AI Security Architect

TE Connectivity • Bengaluru

Hybrid
INR 2,800,000 - 4,800,000
GRC Lead / Security Compliance Lead
GRC Lead / Security Compliance Lead

Gnani Innovations Private Limited. • India

On-site
INR 350,000 - 600,000
Engineering Manager - DevOps
Engineering Manager - DevOps

Quiet Capital • Gurugram District

On-site
INR 3,000,000 - 6,000,000
Information Security Manager
Information Security Manager

Focaloid Technologies • Ernakulam

On-site
INR 1,200,000 - 1,900,000
Security Architect (Bangalore, India)
Security Architect (Bangalore, India)

AiPrise • Bengaluru

On-site
INR 4,000,000 - 6,000,000
Security Engineer ( AI Compliance & Offensive Security )
Security Engineer ( AI Compliance & Offensive Security )

Dreamcast • Jaipur

On-site
INR 1,800,000 - 2,400,000
Security & Compliance Engineer Intern
Security & Compliance Engineer Intern

AI Prof • Hyderabad

On-site
INR 1,500,000 - 2,100,000