Position: Senior Security & Compliance Lead Certifications & GRC
Location:Hyderabad (8:00 PM -5:00 AM IST)
Work Type: Full-Time
Experience: 10+ Years
PETADATA is looking for a Senior Security & Compliance Lead Certifications & GRC with strong experience in cybersecurity, risk management, compliance frameworks, and enterprise security solutions.
Roles & Responsibilities
Security Certifications & Compliance Program
- Own the organization's security certification roadmap, determining which certifications and attestations are required and prioritizing them based on business, customer, and market requirements.
- Lead certification programs such as SOC 2 Type I, SOC 2 Type II, ISO 27001, and, where applicable, ISO 27017/27018, GDPR/privacy, HIPAA, PCI DSS, or CSA STAR.
- Manage certifications end to end, including gap assessments, control design, control implementation, evidence collection, auditor selection, audit coordination, remediation, and certification.
- Establish and maintain an Information Security Management System (ISMS), including security policies, standards, procedures, and supporting documentation.
- Develop a unified control framework that can map controls across multiple security and compliance standards and deployment models.
Cloud & On-Premise Security
- Build and maintain the compliance posture for a multi-tenant cloud platform, including tenant isolation, data segregation, shared infrastructure controls, and cloud-provider responsibilities.
- Develop security and compliance requirements for on-premise and customer-deployed environments, including secure deployment, hardening, documentation, and customer audit support.
- Establish and maintain a clear shared-responsibility model across cloud and customer-managed deployments.
- Map security controls across cloud environments such as AWS, GCP, and Azure and ensure appropriate security responsibilities are documented and implemented.
Security Engineering & Risk Management
- Partner with Engineering and Architecture teams to ensure security controls are designed into the platform, rather than added after development.
- Drive implementation of controls covering encryption, access control, secrets management, logging and auditing, tenant isolation, and secure SDLC practices.
- Establish and manage vulnerability management, penetration testing, and security review processes, ensuring findings are tracked through remediation and closure.
- Conduct security risk assessments and manage third-party and vendor security risks.
- Work closely with technical teams to identify security gaps and develop practical remediation plans.
Security Operations & Business Continuity
- Establish and maintain incident response, business continuity, and disaster recovery plans, including regular testing and validation.
- Develop and deliver security awareness training and promote a security-first culture across the organization.
- Monitor security and compliance controls continuously and coordinate remediation when gaps are identified.
- Manage ongoing surveillance audits, recertification activities, and compliance monitoring as the organization, platform, and team evolve.
Customer Trust & Audit Management
- Own the organization's customer security and trust program, responding to security questionnaires, RFP security sections, vendor assessments, and customer audit requests.
- Maintain security and compliance documentation through a centralized trust/compliance portal.
- Work directly with customers to explain security controls, compliance posture, shared responsibilities, and deployment-specific requirements.
- Serve as the primary point of contact for auditors, customers, engineers, and executive stakeholders on security and compliance matters.
- Translate complex security requirements into transparent policies, evidence, documentation, and actionable recommendations.
Note: Should be able to work independently and work in USA time zones
Required Qualifications & Skills
- 8+ years in information security, GRC, or security compliance.
- Hands-on experience leading SOC 2 and/or ISO 27001 certifications end to end.
- Strong knowledge of SaaS security, multi-tenant environments, cloud security, IAM, encryption, and audit logging.
- Experience with AWS, GCP, or Azure and cloud shared responsibility.
- Experience with on-premise/customer-deployed software security and compliance.
- Strong understanding of risk management, control frameworks, ISMS, audits, and continuous compliance.
- Knowledge of GDPR, CCPA, and other relevant privacy requirements.
- Experience with vulnerability management, penetration testing, incident response, and vendor risk management.
- Strong security documentation and audit evidence management skills.
- Excellent communication skills with auditors, engineers, customers, and executives.
- Highly self-directed, with the ability to build and manage a security program independently.
- Preferred: CISSP, CISA, CISM, CCSP, ISO 27001 Lead Implementer/Auditor, and experience with HIPAA, PCI DSS, NIST, FedRAMP, Vanta, Drata, or DevSecOps.
Education
Bachelor s degree in Computer Science, Information Technology, Engineering, or a related field.
Candidates are required to attend Phone/video calls and in-person interviews. After the Selection, the candidate (He/She) should undergo all background checks on Education and Experience.
Please email your resume to
[email protected]
After carefully reviewing your experience and skills, one of our HR team members will contact you on the next steps
📌 enior Security & Compliance Lead – Certifications & GRC (Hyderabad)
🏢 PETADATA
📍 Hyderabad