Live opening · Posted 23 hours ago

Security & Compliance Lead

Exto · India (Remote)
Linkedin No
You are 23 hours behind. JobBeeper subscribers saw this role while it was still new.

At a glance

The key details from the original listing.

Posted 23 hours ago
CompanyExto
LocationIndia (Remote)
Work modeNo
SourceLinkedin
Listed23 hours ago

Your early-applicant advantage

Live timing from JobBeeper.

Live data
6 min from Linkedin publishing this role to us finding it
8 min median time from a role going live to a subscriber being told
6 hours subscribers had this role before this page existed
16,917 roles found in the last 24 hours — the newest are not on this site yet
Start your free trial →

About the role

Description supplied by the original job listing.

Location: Remote — India
Employment Type: Full-time
Shift Time: US Time Zone
Reports to: CEO
About Exto
Exto is a growing SaaS technology company serving complex, mission-critical construction and infrastructure environments. As we continue to scale our platform, customers, and enterprise relationships, maintaining strong security, compliance, and operational controls is critical to our business.
We are looking for an experienced Security & Compliance Lead to take ownership of Exto's information security and compliance programs, including SOC 2 Type II, VAPT, security policies, controls, audits, remediation, and ongoing compliance monitoring.
This is a highly hands-on and independent role. The successful candidate will work directly with the CEO while partnering closely with Product, Engineering, DevOps/Infrastructure, IT, Operations, HR, and other stakeholders.
The Role
The Security & Compliance Lead will be responsible for ensuring that Exto maintains the policies, controls, processes, evidence, and technical practices required to meet our security and compliance obligations.
You will own the day-to-day management of Exto's compliance programs and serve as the primary internal point of contact for auditors, penetration testing providers, security vendors, and other external compliance stakeholders.
This role requires someone who has personally managed SOC 2 Type II and security assessment programs before and understands how to translate compliance requirements into practical processes that engineering and business teams can follow.
You should be comfortable working independently, identifying gaps, driving corrective actions, and holding stakeholders accountable for completing compliance requirements.
Key Responsibilities
SOC 2 Type II & Compliance Program Management
Own and manage Exto's SOC 2 Type II compliance program from readiness through audit completion and ongoing monitoring.
Coordinate directly with external auditors and compliance partners.
Maintain the company's SOC 2 control framework, policies, procedures, risk register, evidence repository, and compliance calendar.
Coordinate evidence collection across Engineering, Product, DevOps, HR, Operations, Finance, and other teams.
Ensure controls are operating consistently throughout the SOC 2 observation period.
Identify control gaps and drive remediation plans to completion.
Prepare the organization for annual audits, surveillance activities, customer security reviews, and related assessments.
Monitor changes to the business, systems, infrastructure, or organizational structure that may impact existing controls.
VAPT & Vulnerability Management
Own and coordinate Vulnerability Assessment and Penetration Testing activities.
Work with external VAPT providers to define scope, schedule testing, review findings, and manage remediation.
Work directly with Engineering and DevOps teams to prioritize vulnerabilities based on severity and business risk.
Track findings through remediation and verification.
Maintain documented vulnerability management and remediation processes.
Ensure critical and high-risk vulnerabilities are addressed within defined remediation timelines.
Coordinate periodic internal vulnerability reviews and security assessments.
Security Governance & Policies
Develop, maintain, and enforce information security policies, standards, procedures, and controls.
Establish clear security and compliance processes appropriate for a growing SaaS organization.
Ensure policies are practical, understandable, and consistently followed by employees.
Maintain areas such as:
Access management
User provisioning and deprovisioning
Privileged access
Password and MFA requirements
Change management
Secure software development
Vulnerability management
Incident response
Business continuity and disaster recovery
Vendor management
Data retention and deletion
Security awareness and training
Risk management
Asset management
Backup and recovery
Logging and monitoring
Product & Engineering Security
Partner closely with Product, Engineering, and DevOps to ensure security and compliance requirements are incorporated into Exto's technology environment and software development lifecycle.
Responsibilities may include:
Reviewing security implications of new product features, architecture changes, and infrastructure decisions.
Supporting secure software development practices.
Ensuring appropriate controls exist across Exto's development and production environments.
Working with engineering teams to implement and maintain controls involving platforms such as:
Microsoft Azure
GitHub
Snyk
CI/CD environments
Cloud infrastructure
Identity and access management systems
Monitoring and logging platforms
Reviewing access permissions and privileged accounts.
Supporting dependency, vulnerability, and source-code security processes.
Ensuring security findings from tools such as Snyk and other scanners are appropriately prioritized and remediated.
Helping establish security requirements and checkpoints within the software development lifecycle.
Continuous Compliance
Compliance should not exist only during audit periods.
The Security & Compliance Lead will establish processes that allow Exto to maintain continuous compliance throughout the year.
This includes:
Periodic access reviews
Security control testing
Evidence collection
Employee compliance training
Vendor security reviews
Vulnerability remediation tracking
Policy reviews
Risk assessments
Backup and recovery testing
Incident response exercises
Business continuity testing
Monitoring compliance deadlines and certifications
You will proactively identify upcoming compliance requirements and ensure the appropriate teams are prepared.
Audit & Customer Security Support
Serve as the primary internal coordinator for SOC 2 auditors and external security assessors.
Respond to auditor requests and coordinate internal stakeholders.
Support customer security questionnaires and enterprise security reviews when required.
Help Sales and Customer teams respond accurately to security and compliance questions.
Maintain organized documentation and evidence that can be reused during customer assessments.
Ensure statements regarding Exto's security posture and certifications are accurate and supportable.
Risk Management
Maintain Exto's security and compliance risk register.
Conduct periodic risk assessments.
Identify risks associated with systems, vendors, infrastructure, processes, and new initiatives.
Recommend risk mitigation strategies.
Escalate material security or compliance risks directly to the CEO.
Track remediation commitments and ensure owners complete agreed actions.
What We Are Looking For
We are specifically looking for someone who has done this before and can independently manage the function rather than requiring extensive direction.
Required Experience
Approximately 5+ years of experience in information security, cybersecurity, GRC, compliance, or related roles.
Direct hands-on experience managing or leading SOC 2 Type II readiness and audit programs.
Experience coordinating with external auditors.
Experience managing VAPT or penetration testing programs.
Experience working with engineering and DevOps teams in a SaaS or cloud-based environment.
Strong understanding of s

Work arrangement
No

Get JobBeeper Mobile App

Never miss a job opening! Get instant job alerts on your phone.

Subscribers see fresh openings within minutes. Download the JobBeeper App on Google Play to get real-time push notifications and apply before anyone else.

⚡ Instant Push Alerts 🎯 Tailored Filters 🚀 Direct Employer Links
GET IT ON Google Play

More openings worth a look

Recently tracked roles with full details and direct application links.

6 roles
Good roles move before most people even see them. Tell JobBeeper what you want and get fresh matches delivered in minutes.
Start your free trial →
⚡ Get fresh job alerts 📱 Get App