
Job Description
Ovii's Interpretation of the Role
Ema seeks a Security & Compliance Lead to own the company’s security posture and compliance programs across cloud, AI/ML, and enterprise client environments. The role reports to the Head of Engineering and partners with infrastructure, product, and customer‑facing teams to drive SOC 2, PCI DSS, FedRAMP and emerging AI regulatory initiatives.
Role Snapshot
- Lead security & compliance strategy for an AI‑first platform
- Own SOC 2, PCI DSS, FedRAMP and related certification programs
- Define cloud and API security architecture on GCP & Azure
- Build DevSecOps pipelines and embed security into AI/ML workflows
- Engage with enterprise CISOs, auditors and client security teams
- Drive vulnerability management, incident response and zero‑trust design
- Cultivate a security‑aware engineering culture
Must-Have Requirements
- Security engineering
- Compliance frameworks (SOC 2, PCI DSS, FedRAMP, ISO 27001)
- Cloud security (GCP, Azure, IAM, network security)
- DevSecOps tooling (SAST/DAST, CSPM, SIEM, secrets management)
- Incident response & vulnerability management
- Zero‑trust design
- API security
- security engineering
- compliance program ownership
Nice-to-Have Signals
- HIPAA compliance experience
- GDPR compliance experience
- AI/ML security (model pipelines, data governance)
- AI governance frameworks (NIST AI RMF, EU AI Act)
- Security certifications (CISSP, CISM, CCSP, Lead Auditor)
- WAF expertise (Cloudflare, Akamai)
- Exposure to enterprise identity providers
- On‑prem/air‑gapped deployment security
- AI/ML security
- HIPAA/GDPR compliance
- CISSP
- CISM
- CCSP
- Lead Auditor
Work Setup
- Location: Bengaluru, India
- Work mode: ONSITE
- Employment type: Full-Time
Eligibility Gates
- Visa sponsorship: unknown
Not Specified in JD
- Visa sponsorship
- Salary range
- Remote eligibility
- Education requirement
- Required certifications
What You'll Likely Work On
- Serve as the primary liaison for customer InfoSec teams, CISOs and auditors during security reviews and due‑diligence cycles
- Own end‑to‑end compliance programs (SOC 2 Type II, PCI DSS, FedRAMP, ISO 27001/27701/27017/42001, DORA, UK Cyber Essentials Plus, HIPAA, GDPR)
- Define and enforce security perimeters across cloud infrastructure, APIs, network segmentation and access controls
- Partner with Infrastructure to harden production, implement zero‑trust and secure multi‑tenant or air‑gapped deployments
- Run vulnerability management, penetration testing and incident‑response programs, handling the full incident lifecycle
- Select, evaluate and operate security tooling such as SIEM, CSPM, SAST/DAST, secrets management and runtime protection
- Pioneer DevSecOps for an AI‑first org, embedding security gates into CI/CD and protecting model pipelines and training data
- Collaborate with Sales Engineering and Customer Success to answer security questionnaires, design customer‑specific architectures and present the security story to technical and executive audiences
Good Fit If You Have
- Experience working directly with enterprise client security teams, CISOs and auditors
- Familiarity with AI governance frameworks (NIST AI RMF, EU AI Act, ISO 42001)
- Prior experience building security programs at high‑growth startups
- Relevant certifications such as CISSP, CISM, CCSP or Lead Auditor
Skills
- Security engineering
- Compliance frameworks (SOC 2, PCI DSS, FedRAMP, ISO 27001)
- Cloud security (GCP, Azure, IAM, network segmentation)
- DevSecOps tooling (SAST/DAST, CSPM, SIEM, secrets management)
- AI/ML system security and model risk management
- Incident response & vulnerability management
- Zero‑trust network design
- Written & verbal stakeholder communication