
Manager – Governance and Compliance
Posted 3 days ago

Posted 3 days ago
This is a fully remote position, open to applicants in India.
• Lead the organization's strategic direction in Security, Risk & Compliance, and AI Governance.
• Oversee and implement security initiatives, AI governance frameworks, and compliance obligations.
• Create and uphold policies, standards, processes, and tools aimed at cyber readiness, regulatory compliance, AI governance, and operational excellence.
• Set and enforce acceptable-use policies and security protocols for Generative AI and Machine Learning applications.
• Define standards for AI governance and security architecture in client-facing projects.
• Perform AI risk assessments and audits addressing prompt injection, training data origins, bias mitigation, and third-party AI functionalities.
• Offer compliance consulting and expertise to clients.
• Integrate compliance processes into assessments and coordinate internal or partner execution.
• Ensure adherence to privacy regulations and manage international data transfers.
• Supervise IT infrastructure security, monitoring, and upkeep.
• Enhance the security program through penetration testing, disaster recovery drills, and CSPM.
• Incorporate DevSecOps and Secure SDLC methodologies, including dependency scanning and SBOM management.
• Implement Zero Trust architecture, least privilege access, and RBAC.
• Lead incident response activities, including severity assessment, resource allocation, and threat management.
• Manage SIEM, DLP, EDR, vulnerability scanning, endpoint management, ticketing systems, Microsoft Sentinel, Microsoft Defender, and secret scanning tools.
• Foster a security culture through phishing simulations, employee awareness initiatives, and AI-risk training.
• Direct compliance programs and audits; act as the liaison with auditors and vCISO providers.
• Assess new technologies and spearhead strategic digital projects.
• Oversee vendor and technology partner relationships, negotiate contracts, perform third-party risk evaluations, and monitor service quality.
• Execute other tasks of similar nature and responsibility.
• 8+ years of experience in a Senior IT, Security, or Compliance capacity.
• Minimum of 2 years in a leadership role managing a technical team.
• Knowledge and experience with cloud technologies.
• General familiarity with GCP, AWS, and Azure.
• Proven success in leading and achieving SOC 2, ISO 27001, and ISO 42001 audits.
• Strong grasp of AI governance frameworks, AI safety, data privacy in AI workflows, and LLM threat modeling.
• Practical experience with MITRE ATT&CK, CIS, NIST, ISO, and related standards.
• Awareness of global and regional data protection regulations, including the India DPDP Act, GDPR, CCPA, and PDPA.
• Understanding of networking, identity access protocols, and cloud security best practices.
• Exceptional written and oral communication skills.
• Strong analytical and problem-solving capabilities.
• Effective time management skills.
• Ability to collaborate across teams and adapt to changing business requirements.
• Experience in developing and managing departmental budgets and negotiating with vendors.
• Relevant industry certification(s) in Information Security, such as CCSP, CISSP, or CISM, or in Risk Management, such as CRISC.
• B.S. in Computer Science, Information Technology, Information Systems, or IT Management.
• Full-time remote work opportunity from any location in India.
• Flexible working hours to accommodate global collaboration and business requirements.
• An inclusive and diverse workplace.
• Equal opportunity employment.
TAG IMF
Neogen Corporation
Parexel
Stone & Company
Get handpicked remote jobs straight to your inbox weekly.