19 Aug
|
LeadSquared
|
Bengaluru
19 Aug
LeadSquared
Bengaluru
:
Position Overview: As a GRC and AI Governance Lead at LeadSquared, you will assist the Information Security Compliance Manager in executing and maintaining the organization’s information security, data privacy, and AI governance compliance program. The role will support day-to-day compliance operations across ISO 27001, SOC 2, HIPAA, privacy regulations such as GDPR, CCPA and DPDP, and emerging AI governance requirements including ISO/IEC 42001. The ideal candidate will have hands-on experience in compliance operations, internal audits, risk assessments, control monitoring, customer RFI responses, policy documentation, evidence management, and cross-functional coordination.
This role is expected to support the Compliance Manager in implementing, monitoring, and continuously improving security and AI governance policies, procedures, controls, dashboards, and audit readiness activities.
Key Responsibilities:
Compliance Management:
- Develop and maintain a working understanding of ISO 27001, SOC 2, HIPAA, ISO/IEC 42001, GDPR, CCPA, DPDP and other applicable security, privacy, and AI governance requirements.
- Assist the Compliance Manager in planning, tracking, and coordinating compliance activities across information security, privacy, and AI governance programs.
- Support internal audits, control testing, evidence collection, and periodic assessments to identify compliance gaps and improvement areas.
- Create and maintain compliance dashboards, trackers, audit evidence repositories, and monthly compliance health updates for review by the Compliance Manager and Top Management.
- Good understanding of regulatory requirements like GDPR, CCPA, DPDP etc.
- Assist in establishing and maintaining an Artificial Intelligence Management System aligned with ISO/IEC 42001, covering AI policy, roles and responsibilities, AI risk assessment, impact assessment, lifecycle controls, monitoring, documentation, and continual improvement.
- Support AI governance activities, including maintaining an inventory of AI use cases, assessing responsible AI risks such as bias, transparency, explainability, data privacy, security, human oversight, misuse, and third-party AI dependency risks.
Policy and Procedure Development:
- Create, update, and maintain information security, privacy, and AI governance policies, procedures, standards, guidelines, templates, and control documents in alignment with organizational requirements and applicable frameworks.
- Assist in communicating policies and procedures across the organization and tracking adoption, exceptions, acknowledgements, and remediation actions.
- Draft and maintain AI governance artefacts such as responsible AI policy, AI acceptable use guidelines, AI risk assessment templates, AI impact assessment checklists, human oversight requirements, and AI vendor due diligence questionnaires.
Risk Assessment and Management:
- Perform and document security, privacy, third-party, cloud, SDLC, DevOps, and AI-related risk assessments under the guidance of the Compliance Manager.
- Track risk mitigation plans, owners, due dates, residual risks, management approvals,
exceptions, and closure evidence.
- Have a good understanding of OWASP top 10 cloud security, web application security, and DevOps security risks
- Have a good understanding on SDLC workflow and its infosec requirements from and ISO27001 standard perspective
- Support AI risk management across the AI lifecycle, including use case intake, data assessment, model/tool evaluation, testing, deployment review, monitoring, change management, and retirement/decommissioning controls.
Training and Awareness:
- Support training and awareness programs to educate employees about information security, privacy, responsible AI usage, AI acceptable use, and compliance requirements.
- Knowledge of phishing simulations is a plus
Incident Response and Management:
- Assist in maintaining incident response procedures for security, privacy, and AI-related incidents, including prompt reporting, triage, documentation, RCA/CAPA tracking, and closure.
- Coordinate with relevant stakeholders during incidents and support evidence collection, compliance notifications, post-incident reviews, and implementation tracking of corrective actions.
Vendor and Third-Party Risk Management:
- Evaluate the security, privacy, and AI governance practices of third-party vendors and partners to ensure they meet applicable compliance, customer, and organizational requirements.
- Manage vendor risk assessments, due diligence questionnaires, audit evidence requests, AI tool assessments, and remediation follow-ups under the supervision of the Compliance Manager.
Reporting and Documentation:
- Prepare compliance reports, audit status updates, AI governance trackers, control health summaries, and evidence packs for internal stakeholders, customer audits, and external assessments as applicable.
- Maintain comprehensive documentation of security controls, privacy controls, AI governance controls, risks, exceptions, audit evidence, management approvals, and compliance activities.
Continuous Improvement:
- Stay up-to-date with industry trends, emerging threats, regulatory changes, AI governance expectations, responsible AI practices, and standards including ISO/IEC 42001.
- Support continuous improvement initiatives to enhance LeadSquared’s security posture, compliance maturity, audit readiness, and AI governance framework.
Handling Customer’s InfoSec queries:
- Respond to customer RFIs, security questionnaires, AI governance questionnaires, privacy assessments, and information security related queries with support from relevant internal stakeholders.
- Streamline the RFI response process, maintain standard response repositories, track response ETA, and ensure timely closure of customer compliance queries.
- Engage in client meetings and discussions related to information security, privacy, compliance, and responsible AI practices at LeadSquared and provide relevant inputs as applicable under the guidance of the Compliance Manager.
Compliance Automation
- Experience in working with GRC and compliance automation tools such as Sprinto, AuditBoard, Drata, or equivalent platforms to streamline audit activities, control monitoring, risk assessments, employee awareness, vendor management, evidence collection, and compliance dashboards.
AI Governance and ISO/IEC 42001 Support
- Assist in implementing, maintaining, and improving ISO/IEC 42001 aligned AI governance processes, documentation, and control monitoring.
- Maintain AI use case inventories, AI risk registers, AI vendor assessments, AI impact assessments, and responsible AI evidence repositories.
- Work with product, engineering, security, legal, privacy, and compliance teams to assess AI systems for data privacy, security, fairness, explainability, accountability, human oversight, lifecycle monitoring, and regulatory alignment.
- Support reviews of AI-enabled features, employee AI tool usage, third-party AI services, and customer-facing AI governance queries.
Qualifications:
- Bachelor's degree in Information Security, Computer Science, or a related field. A Master's degree in Cyber Security is a plus.
- At least 5–7 years of relevant experience in information security compliance, audit support, risk management, GRC operations, privacy compliance, or AI governance support.
- Experience in auditing and risk assessment of SDLC and DevOps functions is a must
- Solid working knowledge of ISO 27001, SOC 2, HIPAA, and privacy regulations; exposure to ISO/IEC 42001, AI governance, responsible AI, or AI risk management is highly desirable.
- Professional certifications such as ISO 27001 Lead Auditor/Implementer, CISA, CISM, CISSP, ISO/IEC 42001 Foundation/Lead Implementer, AI governance, privacy, or equivalent certifications are desirable.
- Must have worked on Risk assessment and audits of AWS infrastructure for a product/solution
- Excellent communication, coordination, documentation, stakeholder management, and follow-up skills, with the ability to support the Compliance Manager across multiple parallel compliance activities.
- Must have conducted at least 1 SoC2 Type1 and Type 2 internal audits and represented the organization in SoC2, HIPAA external audits
- Understanding of AI governance concepts such as AI lifecycle management, AI risk assessment, AI impact assessment, data quality, model/tool monitoring, bias and fairness considerations, explainability, transparency, accountability, human oversight, and third-party AI risk is preferred.
- Experience in responding to customer RFIs on information security, privacy, compliance, and AI governance is a must.
- Strong analytical and problem-solving abilities.
- Ability to work collaboratively with cross-functional teams including Security, IT, Engineering, Product, Legal, Privacy, HR, Customer Success, and external auditors.
📌 Lead - GRC and AI Governance (Bengaluru)
🏢 LeadSquared
📍 Bengaluru