Skip to content

Lead - Information Security & Compliance

GocometBangalore, KA, IndiaOctober 9, 2026
On-site
Full-time
GRC
Management

Job Title: Lead - Information Security & Compliance

Experience Level: 4-7 years

Company Overview

GoComet is a world-leading freight intelligence and supply chain visibility SaaS platform, helping global enterprises optimize their supply chains. We are built on a foundation of trust and security, and maintaining the integrity of our systems and customer data is paramount. We are looking for an experienced security leader to own our information security, compliance, customer trust, and governance programs while supervising organizational IT operations.

Position Summary

We are seeking a proactive Lead - Information Security & Compliance to own our security strategy, ISO 27001 and SOC 2 programs, internal security audits, policies, risk management, SOP adherence, and responses to customer security requirements. The role also provides governance and oversight for organizational IT operations.

This is a security-first, hands-on ownership role for someone with 4-7 years of relevant experience who can establish controls, implement and maintain ISO 27001 and SOC 2 requirements, drive audit readiness, and ensure security SOPs are documented, understood, and consistently followed. You will be the primary security contact for auditors and enterprise customers, coordinate remediation across teams, and supervise the IT operations professional responsible for day-to-day employee support and administration.

Key Responsibilities

1. Information Security, Risk & Compliance Leadership (ISO 27001 / SOC 2)

  • Own the design, implementation, operation, and continuous improvement of the Information Security Management System (ISMS), ISO 27001 controls, and SOC 2 control environment, including control ownership, evidence, and ongoing readiness.
  • Plan and lead internal security audits, ISO 27001 and SOC 2 assessments, surveillance and external audits; coordinate auditors, evidence collection, corrective actions, and timely closure of findings.
  • Maintain the security risk register and drive periodic risk assessments, control testing, gap analyses, remediation plans, exception reviews, and leadership reporting across business, product, infrastructure, and vendors.
  • Own and maintain security policies, standards, SOPs, registers, and supporting documentation; assign control owners, train relevant teams, monitor adherence, and follow up on deviations so processes work in practice, not just on paper.
  • Own the security incident response framework, escalation and communication procedures, incident coordination, root-cause reviews, corrective actions, and periodic readiness exercises with engineering and IT teams.
  • Run vendor and third-party security due diligence, periodic reviews, contractual control tracking, and remediation follow-up in coordination with procurement and business owners.
  • Own business continuity and disaster recovery governance: coordinate BCP/DR plans, RTO/RPO definitions, tabletop and recovery exercises, backup assurance, documented outcomes, and remediation with technical owners.
  • Coordinate vulnerability assessments, penetration testing, security reviews, and remediation tracking with engineering and infrastructure owners; prioritize findings by risk and preserve audit-ready evidence of closure.
  • Build and deliver role-appropriate security awareness, phishing readiness, policy communication, onboarding training, and regular reinforcement of secure practices across the organization.

2. Organizational IT Governance & Supervision

  • Supervise the IT operations owner responsible for employee support, hardware, software, and connectivity; define service expectations, review recurring issues, and intervene for security-sensitive escalations.
  • Establish and monitor IT SOPs for employee onboarding/offboarding, account provisioning, access approvals, timely deprovisioning, periodic access reviews, and asset recovery; ensure the IT owner executes and records these controls.
  • Govern security configuration and access controls for Google Workspace/Microsoft 365, identity and SSO, MFA, endpoint management/MDM, and other core tools; review the IT owner's implementation and exception handling.
  • Hold IT accountable for accurate device, software, license, and subscription inventories, endpoint compliance, lifecycle processes, and evidence of control execution.
  • Review IT procurement and new-tool onboarding for security, data protection, access, and vendor risk; supervise implementation rather than personally handling routine procurement or device deployment.
  • Provide security oversight of AWS/GCP or other cloud environments, including identity and access, configuration baselines, logging, backup, vulnerability exposure, and remediation with engineering or infrastructure teams.

3. Customer Security Assurance & Trust

  • Serve as the accountable security and compliance point of contact for customers, prospects, auditors, and internal business stakeholders.
  • Own timely, accurate responses to customer security questionnaires, due diligence, RFP security sections, security evidence requests, and follow-up clarifications; coordinate verified inputs with technical and business teams.
  • Lead customer security reviews and calls, partnering with Sales, Customer Success, Legal, and Engineering to explain controls, address risks, and track any agreed security commitments to closure.
  • Own the accuracy and currency of customer-facing security documentation, approved audit reports and certifications, trust materials, and standard assurance responses, sharing sensitive evidence appropriately.

Qualifications & Experience

Required (Must-Haves):

  • Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or a related field, or equivalent practical experience.
  • 4-7 years of relevant experience with a strong primary focus on information security governance, compliance, risk, audits, and security program ownership; IT operations oversight experience is sufficient.
  • Demonstrated ownership of ISO 27001 implementation/maintenance and SOC 2 readiness or audit cycles, including ISMS operation, control mapping, evidence collection, internal audits, and corrective-action management.
  • Strong practical knowledge of ISMS, security risk assessments, access management, asset controls, incident response, vendor risk, vulnerability management, BCP/DR, and policies/SOP implementation and monitoring.
  • Ability to supervise an IT operations professional and govern organizational IT controls, identity and endpoint security, employee access lifecycle, asset management, and escalations without being the primary helpdesk operator.
  • Excellent written and verbal communication skills, including independently handling customer security questionnaires, enterprise security reviews, auditor interactions, and clear executive updates.
  • Strong security documentation, control-evidence management, audit project management, process discipline, and cross-functional follow-through.
  • An ownership-driven leader who can translate security requirements into operational controls, monitor adherence, close gaps, and independently drive multiple audit, customer, and internal security priorities.

Preferred (Nice-to-Haves):

  • Security qualifications such as CISM, CISSP, ISO 27001 Lead Implementer/Lead Auditor, or comparable hands-on audit and implementation experience.
  • Practical understanding of cloud security controls and shared-responsibility models in AWS, Azure, or GCP.
  • Familiarity with privacy and data-protection obligations, such as GDPR or CCPA, and enterprise customer contractual security requirements.
  • Exposure to security tooling such as SIEM, EDR, vulnerability scanners, GRC/audit evidence platforms, and security monitoring workflows.
  • Experience supporting security/compliance programs and customer security reviews in a B2B SaaS or enterprise-facing environment.
  • Experience supervising an IT owner or junior team members, coordinating security initiatives across engineering and business teams, and holding control owners accountable.

Job Details

Salary

₹2,000,000 – ₹3,000,000/yr

Experience

Management

Tools & Tech

AWS
Azure
GCP

Preferred Certs

CISM
CISSP