Job Description
Position Description
As the Manager - Governance and Compliance (Contractor), you will play a pivotal role in helping to drive the organization’s comprehensive, long-term strategy for Security, Risk & Compliance, and AI Governance functions in alignment with global business objectives. This is a full time remote role where you can work from anywhere in India. The core goal of this position is to safeguard the company against internal and external threats, ensure a constant state of audit readiness, and enforce strict AI safety and governance standards. This position requires an individual who possesses thought leadership in their areas of expertise, the ability to communicate the vision, and hands-on involvement with a start-up mentality. You will be responsible for the day to day management and execution of the organization’s security programs, AI governance frameworks, and applicable compliance requirements, while collaborating closely with teams and stakeholders across different regions and time zones. The role requires flexibility in working hours to support global collaboration and business needs.
Job Responsibilities
- Develop and maintain policies, standards, processes, and tools that ensure cyber readiness, regulatory compliance, AI governance, and operational excellence in alignment with business goals.
- Establish, rollout, and enforce acceptable use policies and security guardrails for Generative AI and Machine Learning tools across internal operations to prevent IP leakage, shadow AI, and unauthorized data ingestion.
- Define and enforce AI governance and security architecture standards for client-facing projects and deliverables,
ensuring client data confidentiality, algorithmic transparency, and compliance with client security requirements.
- Conduct regular AI risk assessments and audits covering prompt injection, training data provenance, bias mitigation, and third-party SaaS/vendor AI features.
- Act as the company’s subject matter expert on industry regulations and provide compliance consulting and guidance to clients. You'll also design and embed compliance processes into assessments, ensuring they’re executed effectively — whether handled in-house or through trusted partners.
- Ensure full compliance with relevant global and regional privacy regulations (including India's DPDP Act, GDPR, CCPA, PDPA) and manage requirements for cross-border data transfers between remote/offshore delivery centers and global client jurisdictions.
- Uphold Internal Security Standards: Oversee Ollion’s IT’s infrastructure ensuring systems are secure, monitored, and maintained according to best practices.
- Mature the company's security program through proactive exercises, including annual penetration testing, disaster recovery simulations, and CSPM.
- Integrate DevSecOps and Secure SDLC practices into internal and client build pipelines, ensuring software supply chain security, dependency scanning,
and Software Bill of Materials (SBOM) management.
- Oversee the development, implementation, and enforcement of security policies and procedures, championing a Zero Trust architecture based on the principle of least privilege and Role-Based Access Control (RBAC).
- Lead the incident response process, determining severity, assigning resources, and ensuring swift containment of Security and compliance threats.
- Hands-on experience with security tools such as SIEM, DLP, endpoint detection and response (EDR), and vulnerability scanning.
- Proficiency with endpoint management solutions (e.g., Intune MDM, ManageEngine RMM) and ticketing systems (e.g., Freshservice).
- Manage and optimize security tools, including SIEM (Microsoft Sentinel), the Microsoft Defender suite, and secret scanning solutions for development environments.
- Drive company-wide security culture, phishing simulations, and employee awareness programs, including training on AI-driven risks and social engineering threats.
- Lead and manage all compliance programs and audits.
- Act as the primary liaison with external partners, including auditors and virtual CISO (vCISO) providers.
- Evaluate emerging technologies and lead strategic digital initiatives to enhance operational efficiency and business agility.
- Manage relationships with external vendors and technology partners; negotiate contracts, conduct third-party risk assessments (including vendor AI evaluations), and ensure service levels are met.
- Undertake any other duties of a similar level and responsibility as may be required from time to time.
📌 Manager - Governance and Compliance (Contractor) (Pune)
🏢 Ollion
📍 Pune