Ovii Job Board

Security & Compliance Lead

Ema

Bengaluru, India • Onsite - Bengaluru, India • Full-Time • 8+ years

Posted 2026-04-29 Tech & Engg

Apply on employer site

Job Description

Ovii's Interpretation of the Role

Ema seeks a Security & Compliance Lead to own the company’s security posture and compliance programs across cloud, AI/ML, and enterprise client environments. The role reports to the Head of Engineering and partners with infrastructure, product, and customer‑facing teams to drive SOC 2, PCI DSS, FedRAMP and emerging AI regulatory initiatives.

Role Snapshot

  • Lead security & compliance strategy for an AI‑first platform
  • Own SOC 2, PCI DSS, FedRAMP and related certification programs
  • Define cloud and API security architecture on GCP & Azure
  • Build DevSecOps pipelines and embed security into AI/ML workflows
  • Engage with enterprise CISOs, auditors and client security teams
  • Drive vulnerability management, incident response and zero‑trust design
  • Cultivate a security‑aware engineering culture

Must-Have Requirements

  • Security engineering
  • Compliance frameworks (SOC 2, PCI DSS, FedRAMP, ISO 27001)
  • Cloud security (GCP, Azure, IAM, network security)
  • DevSecOps tooling (SAST/DAST, CSPM, SIEM, secrets management)
  • Incident response & vulnerability management
  • Zero‑trust design
  • API security
  • security engineering
  • compliance program ownership

Nice-to-Have Signals

  • HIPAA compliance experience
  • GDPR compliance experience
  • AI/ML security (model pipelines, data governance)
  • AI governance frameworks (NIST AI RMF, EU AI Act)
  • Security certifications (CISSP, CISM, CCSP, Lead Auditor)
  • WAF expertise (Cloudflare, Akamai)
  • Exposure to enterprise identity providers
  • On‑prem/air‑gapped deployment security
  • AI/ML security
  • HIPAA/GDPR compliance
  • CISSP
  • CISM
  • CCSP
  • Lead Auditor

Work Setup

  • Location: Bengaluru, India
  • Work mode: ONSITE
  • Employment type: Full-Time

Eligibility Gates

  • Visa sponsorship: unknown

Not Specified in JD

  • Visa sponsorship
  • Salary range
  • Remote eligibility
  • Education requirement
  • Required certifications

What You'll Likely Work On

  • Serve as the primary liaison for customer InfoSec teams, CISOs and auditors during security reviews and due‑diligence cycles
  • Own end‑to‑end compliance programs (SOC 2 Type II, PCI DSS, FedRAMP, ISO 27001/27701/27017/42001, DORA, UK Cyber Essentials Plus, HIPAA, GDPR)
  • Define and enforce security perimeters across cloud infrastructure, APIs, network segmentation and access controls
  • Partner with Infrastructure to harden production, implement zero‑trust and secure multi‑tenant or air‑gapped deployments
  • Run vulnerability management, penetration testing and incident‑response programs, handling the full incident lifecycle
  • Select, evaluate and operate security tooling such as SIEM, CSPM, SAST/DAST, secrets management and runtime protection
  • Pioneer DevSecOps for an AI‑first org, embedding security gates into CI/CD and protecting model pipelines and training data
  • Collaborate with Sales Engineering and Customer Success to answer security questionnaires, design customer‑specific architectures and present the security story to technical and executive audiences

Good Fit If You Have

  • Experience working directly with enterprise client security teams, CISOs and auditors
  • Familiarity with AI governance frameworks (NIST AI RMF, EU AI Act, ISO 42001)
  • Prior experience building security programs at high‑growth startups
  • Relevant certifications such as CISSP, CISM, CCSP or Lead Auditor

Skills

  • Security engineering
  • Compliance frameworks (SOC 2, PCI DSS, FedRAMP, ISO 27001)
  • Cloud security (GCP, Azure, IAM, network segmentation)
  • DevSecOps tooling (SAST/DAST, CSPM, SIEM, secrets management)
  • AI/ML system security and model risk management
  • Incident response & vulnerability management
  • Zero‑trust network design
  • Written & verbal stakeholder communication