About Gurucul
Gurucul is a recognized leader in AI-powered SecOps and Insider Risk Management — named a Leader in the 2025 Gartner® Magic Quadrant™ for SIEM, built on more than a decade of pioneering Behavioral AI, and now shipping an expanding line of agentic AI that is changing how security teams detect, investigate, and respond. We protect some of the most complex environments in the world and hold ourselves to the highest standards of security, compliance, and trust.
Role Summary
The Information Security Officer (ISO) will own and lead Gurucul’s global Security, Risk, and Compliance program, operating primarily from India. This is a senior leadership role with broad authority across internal security operations, audit and compliance frameworks, third-party risk management, and strategic certification initiatives including ISO 42001, FedRAMP, SOC 2 Type 2, and ISO 27001. The ISO will also serve as a Field CISO, engaging directly with enterprise customers and prospects to build trust, support sales cycles, and represent Gurucul’s security posture externally.
Key Responsibilities
Security, Risk and Compliance Program
- Own and operate Gurucul’s enterprise security program including policy, standards, and controls
- Lead all compliance certifications and audits including SOC 2 Type 2, ISO 27001, and customer-specific requirements
- Manage third-party and vendor risk assessments, security questionnaires, and procurement reviews
- Oversee the certificate lifecycle management program and IT security infrastructure
- Drive security awareness training and monthly communications for all employees
- Maintain and test the business continuity and incident response plans
- Manage the risk register and report program status to executive leadership and the board as required
ISO 42001 and AI Governance
- Lead Gurucul’s initiative to achieve ISO 42001 certification, establishing an AI Management System (AIMS) aligned to the standard
- Define and implement AI risk assessment and governance policies covering Gurucul’s AI-powered product portfolio
- Ensure AI lifecycle practices including development, deployment, and monitoring meet ISO 42001 requirements
- Collaborate with Product and Engineering to embed responsible AI principles and controls into the SDLC
- Position Gurucul’s ISO 42001 compliance as a competitive differentiator with enterprise and regulated-industry customers
FedRAMP Authorization
- Own and drive Gurucul’s FedRAMP authorization roadmap, targeting FedRAMP Moderate or High as appropriate
- Coordinate with a Third Party Assessment Organization (3PAO) to complete the System Security Plan (SSP) and security assessment
- Manage the Plan of Action and Milestones (POA&M;) and continuous monitoring obligations post-authorization
- Work with Engineering and SaaS Operations to implement NIST SP 800-53 controls required for FedRAMP compliance
- Support federal sales pursuits by serving as the authoritative resource on Gurucul’s FedRAMP status and roadmap
- Coordinate with Carahsoft and federal channel partners on compliance requirements for government go-to-market
Field CISO
- Serve as a trusted security advisor to enterprise customers and prospects across all verticals
- Participate in pre-sales engagements to address CISO-level security and compliance questions
- Complete customer security questionnaires, vendor assessments, and due diligence requests (e.g., SIG, CAIQ)
- Support contract negotiations involving data processing agreements, DPAs, and security obligations
- Present Gurucul’s security posture, certifications, and compliance roadmap at executive briefings and industry events
- Act as a credible peer to customer security leadership, building trust and accelerating deal cycles
Cross-Functional Leadership
- Partner with Product, Engineering, and SaaS Operations to embed security into the software development lifecycle
- Collaborate with Legal and Contracts on DPA negotiations, regulatory inquiries, and customer security obligations
- Support analyst relations and RFI/RFP responses requiring security and compliance content
- Work closely with the India-based technology and support teams to ensure operational security standards are met
Required Qualifications
- 10+ years of experience in information security with at least 4 years in a leadership role
- Demonstrated experience running SOC 2 Type 2, ISO 27001, or equivalent compliance programs end to end
- Deep knowledge of security frameworks including NIST CSF, NIST SP 800-53, ISO 27001, and CIS Controls
- Experience working with enterprise SaaS or cloud-based technology companies
- Familiarity with UEBA, SIEM, and insider risk technologies
- Solid executive presence and ability to communicate security risk to non-technical audiences
- Experience working with US-based enterprise and federal customers from an India delivery model
Preferred Qualifications (Nice-to-Have)
- CISSP, CISM, or equivalent certification
- Prior experience as a CISO or Deputy CISO in a mid-market SaaS product organization
- Hands-on experience with FedRAMP authorization processes including SSP development, 3PAO coordination, and POA&M; management
- Hands-on experience with ISO 42001 or AI governance frameworks
- Experience supporting enterprise sales cycles in a Field CISO or customer-facing security role
- Experience managing AWS or multi-cloud security controls in a FedRAMP-authorized environment
- Working knowledge of GDPR, HIPAA, CMMC, and other global data privacy and regulatory frameworks
Equal Opportunity Employer
Gurucul Solutions, LLC is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees.
To apply:
Please send resumes to
[email protected] for consideration.
📌 Information Security Officer (India)
🏢 Gurucul
📍 India