Manager - Governance and Compliance (Contractor)
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Manager - Governance and Compliance (Contractor) based in India.
This is a full-time remote leadership role focused on strengthening security, risk, compliance, and AI governance across a globally distributed organization.
You will help shape long-term governance strategies while remaining closely involved in day-to-day execution and operational improvements.
The role combines cybersecurity, regulatory compliance, privacy, AI safety, and technology risk management in a fast-moving environment.
You will establish policies, controls, and security guardrails that protect sensitive information, systems, intellectual property, and client data.
Working across regions and time zones, you will partner with technical and business stakeholders as well as clients, auditors, and external specialists.
The position offers significant influence over security maturity, audit readiness, responsible AI adoption, and operational resilience. A hands-on, proactive mindset is essential, with the opportunity to drive meaningful improvements across both internal operations and client-facing engagements.
Accountabilities:
- Develop, maintain, and enforce security, compliance, risk, privacy, AI governance, and operational policies, standards, processes, and supporting tools in line with business objectives.
- Establish governance frameworks and security guardrails for Generative AI and Machine Learning tools, addressing risks such as IP leakage, shadow AI, unauthorized data ingestion, and unsafe usage.
- Define AI governance and security architecture standards for client-facing projects, ensuring data confidentiality, algorithmic transparency, regulatory alignment, and adherence to client security requirements.
- Conduct AI risk assessments and audits covering prompt injection, training data provenance, bias mitigation, third-party AI capabilities, and emerging AI security risks.
- Serve as a subject matter expert on applicable regulations and provide compliance guidance to clients and internal stakeholders, embedding effective compliance processes into assessments and delivery activities.
- Oversee compliance with global and regional privacy requirements, including India's DPDP Act, GDPR, CCPA, and PDPA, with particular attention to cross-border data transfers.
- Oversee IT infrastructure security, monitoring, maintenance, and adherence to established security best practices.
- Mature the security program through penetration testing, disaster recovery exercises, cloud security posture management, and other proactive security initiatives.
- Integrate DevSecOps and Secure SDLC practices into internal and client development pipelines, including software supply chain security, dependency scanning, and SBOM management.
- Champion Zero Trust security principles, least-privilege access, RBAC, and robust identity and access management practices.
- Lead security and compliance incident response, including severity assessment, resource allocation, containment, and remediation.
- Manage and optimize security technologies such as SIEM, DLP, EDR, vulnerability scanning, endpoint management, Microsoft Sentinel, Microsoft Defender, and development secret-scanning solutions.
- Drive organization-wide security awareness initiatives, including phishing simulations, employee training, AI risk education, and social engineering awareness.
- Lead compliance programs and audits while acting as the primary liaison with external auditors, vCISO providers, and other assurance partners.
- Evaluate emerging technologies and lead strategic initiatives that improve operational efficiency, security maturity, and business agility.
- Manage vendor and technology partner relationships, including contract negotiations, third-party risk assessments, AI vendor evaluations, and service-level oversight.
- Take on additional responsibilities of a similar level as required to support evolving security, compliance, and business priorities.
Requirements:
- 8+ years of experience in senior IT, cybersecurity, security, risk, or compliance roles, including at least 2 years leading technical teams.
- Strong understanding of cloud technologies, with broad familiarity across GCP, AWS, and Azure environments.
- Demonstrated success leading and completing audits against major compliance frameworks such as SOC 2, ISO 27001, and ISO 42001.
- Strong practical knowledge of AI governance, AI safety, privacy within AI pipelines, and LLM threat modeling, including OWASP Top 10 for LLMs.
- Solid knowledge of established security and risk frameworks and methodologies, including MITRE ATT&CK, CIS, NIST, and ISO standards.
- Strong understanding of global and regional data protection requirements, including India's DPDP Act, GDPR, CCPA, PDPA, and cross-border data transfer governance.
- Knowledge of networking, identity and access management, cloud security architecture, and modern security best practices.
- Hands-on familiarity with SIEM, DLP, EDR, vulnerability management, endpoint management, and security monitoring technologies.
- Experience managing departmental budgets, negotiating vendor agreements, conducting third-party assessments, and overseeing external technology partners.
- Excellent written and verbal communication skills, with the ability to translate complex technical and compliance topics for customers, executives, and non-technical stakeholders.
- Strong analytical, problem-solving, prioritization, and time-management abilities, particularly when managing complex cross-functional initiatives simultaneously.
- Proactive and adaptable approach, with the ability to respond effectively to evolving business requirements, unexpected security challenges, and high-priority incidents.
- Collaborative team-player mindset and ability to work effectively with functions including sales, marketing, customer support, product development, and technical teams.
- Willingness to work flexibly across global time zones and contribute with an all-hands-on-deck mentality when required.
- Industry certification in information security or risk management, such as CCSP, CISSP, CISM, or CRISC.
- Bachelor's degree in Computer Science, Information Technology, Information Systems, IT Management, or a related discipline.
Benefits:
- Full-time remote position with the flexibility to work from anywhere in India.
- Opportunity to shape security, risk, compliance, privacy, and AI governance strategies across a global organization.
- High-impact leadership role combining strategic thought leadership with hands-on program execution.
- Exposure to advanced cloud, cybersecurity, AI governance, privacy, and emerging technology initiatives.
- Opportunity to work with global stakeholders, clients, auditors, external security specialists, vendors, and technology partners.
- Scope to strengthen audit readiness, security maturity, responsible AI adoption, and operational resilience.
- Collaborative, inclusive environment that values diverse perspectives, innovation, and continuous improvement.
- Flexibility to support global collaboration and business needs across different regions and time zones.
This role requires you to be in India. If that means relocating or flying in, it is worth checking fares before you commit to a start date.
Compare flights and hotels →Get remote legal jobs like this by email
10 hand-picked jobs, one email a day. No spam, unsubscribe anytime.
Similar for you
Get 10 hand-picked remote jobs like this one in your inbox every morning. One email a day, matched to what you browse. No spam, one-click unsubscribe.
No thanks — continue to the application ↗