Senior Security & Compliance Lead – Certifications & GRC

PETADATA

Hyderabad

On-site

INR 400,000 - 700,000

Full time

5 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

PETADATA is seeking a Senior Security & Compliance Lead to own the security certification program and drive governance across cloud and on-prem environments. You will coordinate with engineering and auditing teams to ensure robust controls, evidence, and remediation for audits.

The role requires 10+ years of security, GRC, and compliance experience, with expertise in SOC 2 and ISO 27001, cloud security, and risk management. Hybrid work model and USA time zone alignment may apply.

Qualifications

  • Bachelor's degree in Computer Science, Information Technology, Engineering, or a related field.
  • 10+ years of experience in information security, GRC, or security compliance.
  • Hands-on experience leading SOC 2 and/or ISO 27001 certifications end to end.
  • Strong knowledge of SaaS security, multi-tenant environments, cloud security, IAM, encryption, and audit logging.
  • Experience with AWS, GCP, or Azure and cloud shared responsibility.
  • Experience with on-premise/customer-deployed software security and compliance.
  • Strong understanding of risk management, control frameworks, ISMS, audits, and continuous compliance.
  • Knowledge of GDPR, CCPA, and other relevant privacy requirements.
  • Experience with vulnerability management, penetration testing, incident response, and vendor risk management.

Responsibilities

  • Own the organization's security certification roadmap and prioritize certifications.
  • Lead certification programs such as SOC 2 Type I/II, ISO 27001, and related standards.
  • Manage end-to-end certification activities: gaps, controls, evidence, auditors, remediation.
  • Establish and maintain an ISMS with policies, standards, and procedures.
  • Develop a unified control framework mapping controls across standards.

Skills

SOC 2 Certification
ISO 27001
GRC Compliance
Cloud Security (AWS/GCP/Azure)
Risk Management
Audit & Evidence Management

Education

Bachelor's degree in CS/IT/Engineering

Tools

AWS
GCP
Azure
ISMS

Job description

Position: Senior Security & Compliance Lead Certifications & GRC

Location: Hyderabad (8:00 PM -5:00 AM IST)

Work Type: Full-Time

Experience: 10+ Years

PETADATA is looking for a Senior Security & Compliance Lead Certifications & GRC with strong experience in cybersecurity, risk management, compliance frameworks, and enterprise security solutions.

Roles & Responsibilities
Security Certifications & Compliance Program
  • Own the organization's security certification roadmap, determining which certifications and attestations are required and prioritizing them based on business, customer, and market requirements.
  • Lead certification programs such as SOC 2 Type I, SOC 2 Type II, ISO 27001, and, where applicable, ISO 27017/27018, GDPR/privacy, HIPAA, PCI DSS, or CSA STAR.
  • Manage certifications end to end, including gap assessments, control design, control implementation, evidence collection, auditor selection, audit coordination, remediation, and certification.
  • Establish and maintain an Information Security Management System (ISMS), including security policies, standards, procedures, and supporting documentation.
  • Develop a unified control framework that can map controls across multiple security and compliance standards and deployment models.
Cloud & On-Premise Security
  • Build and maintain the compliance posture for a multi-tenant cloud platform, including tenant isolation, data segregation, shared infrastructure controls, and cloud-provider responsibilities.
  • Develop security and compliance requirements for on-premise and customer-deployed environments, including secure deployment, hardening, documentation, and customer audit support.
  • Establish and maintain a clear shared-responsibility model across cloud and customer-managed deployments.
  • Map security controls across cloud environments such as AWS, GCP, and Azure and ensure appropriate security responsibilities are documented and implemented.
Security Engineering & Risk Management
  • Partner with Engineering and Architecture teams to ensure security controls are designed into the platform, rather than added after development.
  • Drive implementation of controls covering encryption, access control, secrets management, logging and auditing, tenant isolation, and secure SDLC practices.
  • Establish and manage vulnerability management, penetration testing, and security review processes, ensuring findings are tracked through remediation and closure.
  • Conduct security risk assessments and manage third-party and vendor security risks.
  • Work closely with technical teams to identify security gaps and develop practical remediation plans.
Security Operations & Business Continuity
  • Establish and maintain incident response, business continuity, and disaster recovery plans, including regular testing and validation.
  • Develop and deliver security awareness training and promote a security-first culture across the organization.
  • Monitor security and compliance controls continuously and coordinate remediation when gaps are identified.
  • Manage ongoing surveillance audits, recertification activities, and compliance monitoring as the organization, platform, and team evolve.
Customer Trust & Audit Management
  • Own the organization's customer security and trust program, responding to security questionnaires, RFP security sections, vendor assessments, and customer audit requests.
  • Maintain security and compliance documentation through a centralized trust/compliance portal.
  • Work directly with customers to explain security controls, compliance posture, shared responsibilities, and deployment-specific requirements.
  • Serve as the primary point of contact for auditors, customers, engineers, and executive stakeholders on security and compliance matters.
  • Translate complex security requirements into clear policies, evidence, documentation, and actionable recommendations.

Note: Should be able to work independently and work in USA time zones

Required Qualifications & Skills
  • 8+ years in information security, GRC, or security compliance.
  • Hands-on experience leading SOC 2 and/or ISO 27001 certifications end to end.
  • Strong knowledge of SaaS security, multi-tenant environments, cloud security, IAM, encryption, and audit logging.
  • Experience with AWS, GCP, or Azure and cloud shared responsibility.
  • Experience with on-premise/customer-deployed software security and compliance.
  • Strong understanding of risk management, control frameworks, ISMS, audits, and continuous compliance.
  • Knowledge of GDPR, CCPA, and other relevant privacy requirements.
  • Experience with vulnerability management, penetration testing, incident response, and vendor risk management.
  • Strong security documentation and audit evidence management skills.
  • Excellent communication skills with auditors, engineers, customers, and executives.
  • Highly self-directed, with the ability to build and manage a security program independently.
  • Preferred: CISSP, CISA, CISM, CCSP, ISO 27001 Lead Implementer/Auditor, and experience with HIPAA, PCI DSS, NIST, FedRAMP, Vanta, Drata, or DevSecOps.
Education

Bachelor s degree in Computer Science, Information Technology, Engineering, or a related field.

Candidates are required to attend Phone/video calls and in-person interviews. After the Selection, the candidate (He/She) should undergo all background checks on Education and Experience.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security and Compliance Lead
Security and Compliance Lead

Quadrant Technologies • Hyderabad

On-site
INR 2,400,000 - 4,000,000
GRC Specialist
GRC Specialist

NopalCyber • Hyderabad

On-site
INR 800,000 - 1,200,000
Senior GRC Analyst
Senior GRC Analyst

3M HEALTHCARE • Hyderabad

On-site
INR 1,500,000 - 2,200,000
Info/Security - Analyst
Info/Security - Analyst

Ascendion Engineering • Hyderabad

Hybrid
INR 2,500,000 - 3,800,000
Senior Analyst GRC (Cyber Security)
Senior Analyst GRC (Cyber Security)

Quarks Technosoft • Hyderabad

On-site
INR 1,200,000 - 2,200,000
Senior / Principal GRC Analyst
Senior / Principal GRC Analyst

Altera • Bengaluru

On-site
INR 3,000,000 - 4,500,000
Senior GRC Analyst
Senior GRC Analyst

Exotel Techcom Pvt Ltd • Bengaluru

On-site
INR 800,000 - 1,400,000
Senior / Principal GRC Analyst
Senior / Principal GRC Analyst

844 Altera Semiconductor Technology India Pvt. Ltd. • Bengaluru

On-site
INR 2,000,000 - 3,000,000
Cybersecurity GRC Analyst
Cybersecurity GRC Analyst

Powerbridge • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Health insurance
Long-term benefit savings plan
Professional development opportunities
Product GRC Consultant
Product GRC Consultant

CyRAACS™ • Bengaluru

On-site
INR 600,000 - 1,200,000