06 Aug
|
GTMfund
|
Bengaluru
We're looking for a hands-on Security Lead to own and drive our security strategy, compliance, and cloud security initiatives while partnering closely with Engineering, Product, and Leadership.
Responsibilities Own the organisation's security strategy across Governance, Risk & Compliance (GRC), cloud security, and enterprise security.
Lead and maintain SOC 2 Type II and/or HITRUST compliance programs with continuous audit readiness.
Design and implement security architecture for cloud-native environments on AWS, Azure, or GCP.
Build and improve security controls covering IAM, secrets management, network security, and Secure SDLC.
Perform risk assessments and provide business-focused security recommendations.
Establish security policies, governance frameworks, incident response processes, and security documentation.
Drive AI/LLM security initiatives, including AI governance, risk assessment, and responsible AI adoption.
Partner with Product, Engineering, Customer Success, and Sales teams on enterprise security reviews and customer security questionnaires.
Evaluate and manage external security vendors, penetration testing partners, and compliance consultants.
Continuously improve the organisation's security posture across products and infrastructure.
Requirements 7+ years of experience in Information Security.
Experience working in regulated industries such as Healthcare, Financial Services,
or Government.
Strong hands-on experience with SOC 2 Type II and/or HITRUST compliance.
Deep expertise in Governance, Risk & Compliance (GRC).
Experience designing cloud security architecture on AWS, Azure, or GCP.
Robust understanding of IAM, Secure SDLC, Infrastructure Security, Network Security, and Security Architecture.
Experience assessing and securing AI/LLM-based applications or AI-powered products.
Ability to independently own and drive security initiatives in an Individual Contributor role.
Excellent stakeholder management and communication skills.
Good To
Have CISSP, CISM, CCSP, or equivalent certifications.
Experience with AI Agent Security or Autonomous AI Systems.
Exposure to HL7 FHIR or healthcare interoperability standards.
Experience in high-growth SaaS or startup environments.
Knowledge of multi-tenant SaaS security architectures.
Experience supporting enterprise customer security assessments and trust reviews.
Experience building security awareness and training programs.
Skills: Cloud Security, Cyber Security, y Security Architecture, Information Security, Governance Risk and Compliance (GRC), SOC 2 HITRUST IAM, Secure SDLC, AWS, Azure, e GCP, AI Security, ity LLM Security, Risk Assessment, Incident Response, Enterprise Security Compliance, DevSecOps.
📌 Security Lead (Bengaluru)
🏢 GTMfund
📍 Bengaluru