
Lead, Information Security & Data Privacy Office
Augnito
Posted 2026-05-26
Corporate & Support
Job Description
Ovii's Interpretation of the Role
Lead the Information Security and Data Privacy Office for a health‑tech AI company, shaping privacy, security and legal compliance programs across a global SaaS platform.
Role Snapshot
- Privacy and security governance lead
- Legal compliance champion for healthcare SaaS
- Primary SPOC for audits, regulators and customers
- Owner of ISMS, ISO 27001/42001 and SOC 2 readiness
- Cross‑functional liaison with engineering, IT and legal
Must-Have Requirements
- Law degree (LLB/LLM)
- 5+ years data privacy, legal compliance or information security governance experience
- Hands‑on knowledge of GDPR, HIPAA, India DPDP, UAE/ KSA PDPL
- Experience managing audits, risk assessments and regulatory reviews
- data privacy
- legal compliance
- information security governance
- Law degree (LLB or LLM)
- Law degree (LLB/LLM) mandatory
- Location: Bengaluru, India
Nice-to-Have Signals
- CIPP certification
- ISO 27001 Lead Auditor/Implementer
- ISO 42001 certification
- CISM certification
- GDPR Practitioner certification
- CIPM certification
- HCISPP certification
- healthcare SaaS or technology environment
- CIPP
- ISO 42001
- CISM
- GDPR Practitioner
- CIPM
- HCISPP
Work Setup
- Location: Bengaluru, India
- Work mode: ONSITE
- Employment type: Full-Time
Not Specified in JD
- Visa sponsorship
- Salary range
- Remote eligibility
- Notice period
- Travel
- Security clearance
- Coding test
- Portfolio
- GitHub
- Writing sample
- Cover letter
What You'll Likely Work On
- Lead compliance programs for GDPR, HIPAA, regional health‑privacy laws and SOC 2
- Maintain RoPA, data‑retention, consent and cross‑border transfer documentation
- Conduct DPIAs/PIAs, manage data‑subject‑rights requests and breach response processes
- Design, implement and maintain the ISMS, ensuring ISO 27001/42001 and SOC 2 readiness
- Run risk assessments, internal audits, corrective‑action tracking and compliance reviews
- Partner with Engineering and IT on cloud security, access controls and security best practices
- Draft and negotiate SaaS agreements, NDAs, licensing contracts and IP filings
- Serve as the central point of contact for customer privacy reviews, auditor queries and regulator engagements
- Create and deliver privacy and information‑security awareness training across the organization
Good Fit If You Have
- Experience handling privacy audits and regulator inquiries in a health‑tech environment
- Strong communication skills for cross‑functional and external stakeholder engagement
- Ability to translate legal requirements into practical security and privacy controls
Skills
- Law degree (LLB/LLM)
- Global privacy regulations (GDPR, HIPAA, India DPDP, UAE/ KSA PDPL)
- ISMS frameworks (ISO 27001, ISO 42001, SOC 2)
- Privacy Impact Assessments (DPIA/PIA)
- Data Subject Rights handling
- Audit and risk assessment management
- Contract drafting & negotiation
- Cloud security & access control basics
- Security awareness & training programs
- Regulatory liaison & stakeholder management