12 Aug
|
Saas Labs
|
Bengaluru
12 Aug
Saas Labs
Bengaluru
What you'll do
Own and continuously improve our security and compliance programs, including SOC 2 Type II, ISO 27001, GDPR, HIPAA, PCI DSS, CSA STAR, and other relevant frameworks.
Lead external audits from planning through remediation while ensuring continuous compliance.
Manage enterprise security reviews, customer questionnaires, RFP security responses, and Trust Center content to support enterprise sales.
Review customer DPAs, security addendums, and vendor contracts in partnership with Legal.
Build and manage our third-party risk and vendor security program.
Define and operationalize our AI governance framework, including AI security controls, model provider assessments, data handling, and customer AI commitments.
Lead security incident response, including investigation, containment, customer communication, regulatory notifications, and post-incident reviews.
Drive cloud security across AWS and GCP by improving IAM, least privilege, vulnerability management, configuration security, and infrastructure hardening.
Own security awareness programs, access reviews, organizational security policies, and risk management processes.
Partner closely with Engineering, Product, Sales, Customer Success, and People Operations to embed security into every stage of the business.
What we're looking for
8+ years of experience in Information Security, Cybersecurity, or Governance, Risk & Compliance,
with at least 2 years owning a security program end-to-end.
Solid experience implementing and managing security frameworks.
Experience leading external audits, driving remediation, and maintaining compliance certifications.
Deep understanding of cloud security across AWS and/or GCP, including IAM, network security, vulnerability management, and security best practices.
Experience managing customer security reviews, security questionnaires, and enterprise compliance requests.
Strong understanding of vendor risk management, privacy, and data protection obligations.
Excellent written communication skills with the ability to explain complex security concepts to customers, auditors, and executive stakeholders.
Ability to work independently, prioritize effectively, and make pragmatic security decisions in a fast-moving environment.
Edges that help
CISSP, CISM, CISA, ISO 27001 Lead Auditor, or similar security certifications.
Experience in a high-growth B2B SaaS company serving enterprise customers.
Experience building AI governance, responsible AI, or AI security programs.
Familiarity with customer contract negotiations, DPAs, and enterprise procurement processes.
Experience supporting security initiatives across global engineering organizations.
Own and maintain our Trust Center content.
📌 Information Security Manager (Bengaluru)
🏢 Saas Labs
📍 Bengaluru