Ovii Job Board

Lead, Information Security & Data Privacy Office

Augnito

Bengaluru, India • Onsite - Bengaluru, India • Full-Time • 5+ years

Posted 2026-05-26 Corporate & Support

Apply on employer site

Job Description

Ovii's Interpretation of the Role

Lead the Information Security and Data Privacy Office for a health‑tech AI company, shaping privacy, security and legal compliance programs across a global SaaS platform.

Role Snapshot

  • Privacy and security governance lead
  • Legal compliance champion for healthcare SaaS
  • Primary SPOC for audits, regulators and customers
  • Owner of ISMS, ISO 27001/42001 and SOC 2 readiness
  • Cross‑functional liaison with engineering, IT and legal

Must-Have Requirements

  • Law degree (LLB/LLM)
  • 5+ years data privacy, legal compliance or information security governance experience
  • Hands‑on knowledge of GDPR, HIPAA, India DPDP, UAE/ KSA PDPL
  • Experience managing audits, risk assessments and regulatory reviews
  • data privacy
  • legal compliance
  • information security governance
  • Law degree (LLB or LLM)
  • Law degree (LLB/LLM) mandatory
  • Location: Bengaluru, India

Nice-to-Have Signals

  • CIPP certification
  • ISO 27001 Lead Auditor/Implementer
  • ISO 42001 certification
  • CISM certification
  • GDPR Practitioner certification
  • CIPM certification
  • HCISPP certification
  • healthcare SaaS or technology environment
  • CIPP
  • ISO 42001
  • CISM
  • GDPR Practitioner
  • CIPM
  • HCISPP

Work Setup

  • Location: Bengaluru, India
  • Work mode: ONSITE
  • Employment type: Full-Time

Not Specified in JD

  • Visa sponsorship
  • Salary range
  • Remote eligibility
  • Notice period
  • Travel
  • Security clearance
  • Coding test
  • Portfolio
  • GitHub
  • Writing sample
  • Cover letter

What You'll Likely Work On

  • Lead compliance programs for GDPR, HIPAA, regional health‑privacy laws and SOC 2
  • Maintain RoPA, data‑retention, consent and cross‑border transfer documentation
  • Conduct DPIAs/PIAs, manage data‑subject‑rights requests and breach response processes
  • Design, implement and maintain the ISMS, ensuring ISO 27001/42001 and SOC 2 readiness
  • Run risk assessments, internal audits, corrective‑action tracking and compliance reviews
  • Partner with Engineering and IT on cloud security, access controls and security best practices
  • Draft and negotiate SaaS agreements, NDAs, licensing contracts and IP filings
  • Serve as the central point of contact for customer privacy reviews, auditor queries and regulator engagements
  • Create and deliver privacy and information‑security awareness training across the organization

Good Fit If You Have

  • Experience handling privacy audits and regulator inquiries in a health‑tech environment
  • Strong communication skills for cross‑functional and external stakeholder engagement
  • Ability to translate legal requirements into practical security and privacy controls

Skills

  • Law degree (LLB/LLM)
  • Global privacy regulations (GDPR, HIPAA, India DPDP, UAE/ KSA PDPL)
  • ISMS frameworks (ISO 27001, ISO 42001, SOC 2)
  • Privacy Impact Assessments (DPIA/PIA)
  • Data Subject Rights handling
  • Audit and risk assessment management
  • Contract drafting & negotiation
  • Cloud security & access control basics
  • Security awareness & training programs
  • Regulatory liaison & stakeholder management