12 Sep
|
Exto
|
Madhya Pradesh
12 Sep
Exto
Madhya Pradesh
Job Type: Full-time
Location: Remote — IndiaEmployment Type: Full-timeShift Time: US Time ZoneReports to: CEOAbout ExtoExto is a growing SaaS technology company serving complex, mission-critical construction and infrastructure environments. As we continue to scale our platform, customers, and enterprise relationships, maintaining strong security, compliance, and operational controls is critical to our business.We are looking for an experienced Security & Compliance Lead to take ownership of Exto's information security and compliance programs, including SOC 2 Type II, VAPT, security policies, controls, audits, remediation, and ongoing compliance monitoring.This is a highly hands-on and independent role. The successful candidate will work directly with the CEO while partnering closely with Product, Engineering, DevOps/Infrastructure, IT, Operations, HR, and other stakeholders.The RoleThe Security & Compliance Lead will be responsible for ensuring that Exto maintains the policies, controls, processes, evidence, and technical practices required to meet our security and compliance obligations.You will own the day-to-day management of Exto's compliance programs and serve as the primary internal point of contact for auditors, penetration testing providers, security vendors, and other external compliance stakeholders.This role requires someone who has personally managed SOC 2 Type II and security assessment programs before and understands how to translate compliance requirements into practical processes that engineering and business teams can follow.You should be comfortable working independently, identifying gaps, driving corrective actions, and holding stakeholders accountable for completing compliance requirements.Key ResponsibilitiesSOC 2 Type II & Compliance Program ManagementOwn and manage Exto's SOC 2 Type II compliance program from readiness through audit completion and ongoing monitoring.Coordinate directly with external auditors and compliance partners.Maintain the company's SOC 2 control framework, policies, procedures, risk register, evidence repository, and compliance calendar.Coordinate evidence collection across Engineering, Product, DevOps, HR, Operations, Finance, and other teams.Ensure controls are operating consistently throughout the SOC 2 observation period.Identify control gaps and drive remediation plans to completion.Prepare the organization for annual audits, surveillance activities, customer security reviews, and related assessments.Monitor changes to the business, systems, infrastructure, or organizational structure that may impact existing controls.VAPT & Vulnerability ManagementOwn and coordinate Vulnerability Assessment and Penetration Testing activities.Work with external VAPT providers to define scope, schedule testing, review findings, and manage remediation.Work directly with Engineering and DevOps teams to prioritize vulnerabilities based on severity and business risk.Track findings through remediation and verification.Maintain documented vulnerability management and remediation processes.Ensure critical and high-risk vulnerabilities are addressed within defined remediation timelines.Coordinate periodic internal vulnerability reviews and security assessments.Security Governance & PoliciesDevelop, maintain, and enforce information security policies, standards, procedures, and controls.Establish clear security and compliance processes appropriate for a growing SaaS organization.Ensure policies are practical,
understandable, and consistently followed by employees.Maintain areas such as:Access managementUser provisioning and deprovisioningPrivileged accessPassword and MFA requirementsChange managementSecure software developmentVulnerability managementIncident responseBusiness continuity and disaster recoveryVendor managementData retention and deletionSecurity awareness and trainingRisk managementAsset managementBackup and recoveryLogging and monitoringProduct & Engineering SecurityPartner closely with Product, Engineering, and DevOps to ensure security and compliance requirements are incorporated into Exto's technology environment and software development lifecycle.Responsibilities may include:Reviewing security implications of new product features, architecture changes, and infrastructure decisions.Supporting secure software development practices.Ensuring appropriate controls exist across Exto's development and production environments.Working with engineering teams to implement and maintain controls involving platforms such as:Microsoft AzureGitHubSnykCI/CD environmentsCloud infrastructureIdentity and access management systemsMonitoring and logging platformsReviewing access permissions and privileged accounts.Supporting dependency, vulnerability, and source-code security processes.Ensuring security findings from tools such as Snyk and other scanners are appropriately prioritized and remediated.Helping establish security requirements and checkpoints within the software development lifecycle.Continuous ComplianceCompliance should not exist only during audit periods.The Security & Compliance Lead will establish processes that allow Exto to maintain continuous compliance throughout the year.This includes:Periodic access reviewsSecurity control testingEvidence collectionEmployee compliance trainingVendor security reviewsVulnerability remediation trackingPolicy reviewsRisk assessmentsBackup and recovery testingIncident response exercisesBusiness continuity testingMonitoring compliance deadlines and certificationsYou will proactively identify upcoming compliance requirements and ensure the appropriate teams are prepared.Audit & Customer Security SupportServe as the primary internal coordinator for SOC 2 auditors and external security assessors.Respond to auditor requests and coordinate internal stakeholders.Support customer security questionnaires and enterprise security reviews when required.Help Sales and Customer teams respond accurately to security and compliance questions.Maintain organized documentation and evidence that can be reused during customer assessments.Ensure statements regarding Exto's security posture and certifications are accurate and supportable.Risk ManagementMaintain Exto's security and compliance risk register.Conduct periodic risk assessments.Identify risks associated with systems, vendors, infrastructure, processes,
and new initiatives.Recommend risk mitigation strategies.Escalate material security or compliance risks directly to the CEO.Track remediation commitments and ensure owners complete agreed actions.What We Are Looking ForWe are specifically looking for someone who has done this before and can independently manage the function rather than requiring extensive direction.Required ExperienceApproximately 5+ years of experience in information security, cybersecurity, GRC, compliance, or related roles.Direct hands-on experience managing or leading SOC 2 Type II readiness and audit programs.Experience coordinating with external auditors.Experience managing VAPT or penetration testing programs.Experience working with engineering and DevOps teams in a SaaS or cloud-based environment.Strong understanding of security controls, risk management, and evidence-based audits.Familiarity with cloud security, preferably Microsoft Azure.Experience working with GitHub or similar source-code management environments.Experience with vulnerability management platforms such as Snyk or similar tools.Understanding of secure SDLC practices.Ability to create practical policies, controls, and operating procedures.Strong project-management and follow-through skills.Excellent written and verbal English communication skills.Strongly PreferredPrevious experience working for a B2B SaaS company.Experience independently owning compliance at a startup or scale-up.Experience supporting enterprise customers with security questionnaires or security assessments.Familiarity with frameworks such as:SOC 2ISO 27001NIST Cybersecurity FrameworkCIS ControlsOWASPGDPR and privacy-related requirementsExperience with compliance automation/GRC platforms such as Vanta, Drata, Secureframe, Sprinto, or similar.Experience reviewing third-party/vendor security risks.Relevant certifications such as CISA, CISM, CISSP, ISO 27001 Lead Implementer/Auditor, CRISC, or equivalent are advantageous but not mandatory.What Success Looks LikeWithin this role, success means that:Exto successfully maintains SOC 2 Type II compliance.Audits are well organized and completed with minimal disruption to the organization.Compliance evidence is continuously maintained rather than collected at the last minute.VAPT findings are properly prioritized, tracked, remediated, and closed.Security policies and controls are clearly documented and consistently followed.Engineering teams have defined security expectations within their development processes.Azure, GitHub, Snyk, and other critical systems are configured and governed according to appropriate security practices.Access reviews, risk assessments, vulnerability reviews, and other recurring controls happen on schedule.Compliance gaps are proactively identified before they become audit findings.Leadership has clear visibility into the company's security posture, risks, remediation activities, and upcoming compliance obligations.Working StyleThis role is ideal for someone who is:Highly independent and self-directed.Comfortable operating in a startup setting.Hands-on rather than purely advisory.Comfortable challenging teams when security or compliance requirements are not being followed.Able to balance security requirements with practical business and engineering realities.Comfortable working directly with senior leadership.Capable of communicating technical security issues in clear business terms.This person will report directly to the CEO and will have the authority and responsibility to work across departments to ensure Exto's security and compliance requirements are understood and consistently implemented.
📌 Security & Compliance Lead (Madhya Pradesh)
🏢 Exto
📍 Madhya Pradesh