Lead - Governance, Risk & Compliance (Bengaluru)

Lead - Governance, Risk & Compliance (Bengaluru)

13 Aug
|
Flam
|
Bengaluru

13 Aug

Flam

Bengaluru

Role
We are building our information security function from the ground up. As our first Information Security Manager / GRC Lead, you will be the operational owner of Flam's entire compliance programme and working hands-on in Scrut.io to drive ISO 27001:2022 and SOC 2 Type I certification within 3–4 months. This is a high-impact, high-visibility role at a company whose core product is AI — meaning you will be helping define what responsible AI security looks like in practice, not just checking boxes.

What You'll Own
ISO 27001 & SOC 2 Implementation
• Drive end-to-end implementation of ISO 27001:2022 across all 88 applicable Annex A controls and SOC 2 Trust Service Criteria, using Scrut.io as the single source of truth
• Own the Statement of Applicability (SoA), risk register, risk treatment plan, and all ISMS documentation
• Coordinate evidence collection across Engineering, DevOps, HR, Finance, and Sales — translating control requirements into actionable tasks for each team
• Manage the internal audit cycle, prepare for Stage 1 and Stage 2 ISO 27001 audits,



and coordinate with the external CPA firm for SOC 2
• Track all 239 Scrut controls to completion, assign owners, and chase evidence deadlines

Policy & Documentation
• Draft, review, and get management approval for all ISMS policies — Access Control, Incident Response, Data Classification, BCP/DR, Vendor Management, Acceptable Use, and more
• Maintain the legal and regulatory register covering CCPA/CPRA (California) and applicable federal requirements
• Ensure all policies are published, acknowledged, and kept current in Scrut

Risk Management
• Conduct and maintain the organisation's information security risk assessment — identifying threats, scoring likelihood and impact, and producing a risk treatment plan
• Maintain the risk register in Scrut and present findings at quarterly ISG meetings and annual
Management Review Meetings (MRM)
• Conduct Data Protection Impact Assessments (DPIAs) for current product features

📌 Lead - Governance, Risk & Compliance (Bengaluru)
🏢 Flam
📍 Bengaluru

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: lead - governance, risk & compliance (bengaluru) / bengaluru

Subscribe to this job alert:

Get the latest job offers by email for: lead - governance, risk & compliance (bengaluru) / bengaluru