Hevo Data
About this role
Hevo sells a no code data pipeline platform used by more than 2,000 companies including Cult.fit, Postman and ThoughtSpot, funded with $42 million from Sequoia India, Qualgro and Chiratae. This role owns the company's entire security compliance posture. That means running SOC 2 Type II, ISO 27001 and GDPR certifications end to end across audit cycles, evidence collection and remediation, and being the primary contact for external auditors and customer security review teams. It is not a paperwork job: the posting puts equal weight on security engineering, asking you to design and improve controls across cloud infrastructure, access management and the software development lifecycle, and to embed compliance requirements into CI/CD pipelines and infrastructure as code with the DevOps team. The stated ambition is making compliance a continuous, automated practice rather than a point in time scramble before each audit.
Who this is for
What the posting requires:
- 5 to 8 years of experience in security engineering, information security or a compliance focused role.
What the work actually looks like, which is where this posting is unusually detailed:
Compliance programme ownership:
- Own and manage Hevo's compliance certifications end to end, including SOC 2 Type II, ISO 27001, GDPR and other applicable frameworks, across audit cycles, evidence collection and remediation.
- Lead internal readiness assessments and gap analyses, and drive remediation roadmaps with Engineering and Infrastructure.
- Act as primary point of contact for external auditors, certification bodies and customer security review teams.
- Respond to customer security questionnaires, due diligence requests and vendor assessments.
Security engineering and controls:
- Design, implement and continuously improve security controls across cloud infrastructure, access management, data handling and the software development lifecycle.
- Work with DevOps and Engineering to embed security and compliance requirements into CI/CD pipelines, infrastructure as code and deployment practice.
- Conduct security risk assessments, vulnerability reviews and internal audits, prioritising findings and driving resolution to deadlines.
- Define and enforce policies on data classification, access control, encryption, logging, monitoring and incident response.
Policy and governance:
- Develop and operationalise security policies, standards and procedures aligned to industry frameworks.
- Build and run a compliance awareness and training programme across the company.
- Establish continuous compliance monitoring using GRC tooling and automation.
- Report compliance metrics, audit findings and risk posture to leadership on a regular cadence.
Cross functional work:
- Assess compliance implications of new features and infrastructure changes early with Product and Engineering.
- Work with Legal and Finance on contractual obligations, data processing agreements and regional regulatory requirements.
- Support Sales and Customer Success on enterprise security reviews for security sensitive deals.
Location and working pattern: Bengaluru. Office days are not stated.
Honest fit guidance: this sits deliberately at the intersection of security engineering and compliance, and the posting calls it high visibility. If you are a pure penetration tester or a pure GRC analyst, only half the role will fit. It suits someone who can both write the policy and change the pipeline that enforces it.
- 5 to 8 years of experience in security engineering, information security or a compliance focused role.
What the work actually looks like, which is where this posting is unusually detailed:
Compliance programme ownership:
- Own and manage Hevo's compliance certifications end to end, including SOC 2 Type II, ISO 27001, GDPR and other applicable frameworks, across audit cycles, evidence collection and remediation.
- Lead internal readiness assessments and gap analyses, and drive remediation roadmaps with Engineering and Infrastructure.
- Act as primary point of contact for external auditors, certification bodies and customer security review teams.
- Respond to customer security questionnaires, due diligence requests and vendor assessments.
Security engineering and controls:
- Design, implement and continuously improve security controls across cloud infrastructure, access management, data handling and the software development lifecycle.
- Work with DevOps and Engineering to embed security and compliance requirements into CI/CD pipelines, infrastructure as code and deployment practice.
- Conduct security risk assessments, vulnerability reviews and internal audits, prioritising findings and driving resolution to deadlines.
- Define and enforce policies on data classification, access control, encryption, logging, monitoring and incident response.
Policy and governance:
- Develop and operationalise security policies, standards and procedures aligned to industry frameworks.
- Build and run a compliance awareness and training programme across the company.
- Establish continuous compliance monitoring using GRC tooling and automation.
- Report compliance metrics, audit findings and risk posture to leadership on a regular cadence.
Cross functional work:
- Assess compliance implications of new features and infrastructure changes early with Product and Engineering.
- Work with Legal and Finance on contractual obligations, data processing agreements and regional regulatory requirements.
- Support Sales and Customer Success on enterprise security reviews for security sensitive deals.
Location and working pattern: Bengaluru. Office days are not stated.
Honest fit guidance: this sits deliberately at the intersection of security engineering and compliance, and the posting calls it high visibility. If you are a pure penetration tester or a pure GRC analyst, only half the role will fit. It suits someone who can both write the policy and change the pipeline that enforces it.
Apply on company site
Opens jobs.lever.co, the employer's own application page. Applying is always free.