🎁 Before you apply, rehearse this interview. Create your free WorkMundi account and get an Interview Training on HelpsYouSpeak — no cost, no card. I want my training →
Job Description: Position Overview: As a GRC and AI Governance Lead at LeadSquared, you will assist the Information Security Compliance Manager in executing and maintaining the organizations information security, data privacy, and AI governance compliance program. The role will support day-to-day compliance operations across ISO 27001, SOC 2, HIPAA, privacy regulations such as GDPR, CCPA and DPDP, and emerging AI governance requirements including ISO/IEC 42001. The ideal candidate will have hands-on experience in compliance operations, internal audits, risk assessments, control monitoring, customer RFI responses, policy documentation, evidence management, and cross-functional coordination. This role is expected to support the Compliance Manager in implementing, monitoring, and continuously improving security and AI governance policies, procedures, controls, dashboards, and audit readiness activities. Key Responsibilities: Compliance Management: Develop and maintain a working understanding of ISO 27001, SOC 2, HIPAA, ISO/IEC 42001, GDPR, CCPA, DPDP and other applicable security, privacy, and AI governance requirements. Assist the Compliance Manager in planning, tracking, and coordinating compliance activities across information security, privacy, and AI governance programs. Support internal audits, control testing, evidence collection, and periodic assessments to identify compliance gaps and improvement areas. Create and maintain compliance dashboards, trackers, audit evidence repositories, and monthly compliance health updates for review by the Compliance Manager and Top Management. Good understanding of regulatory requirements like GDPR, CCPA, DPDP etc. Assist in establishing and maintaining an Artificial Intelligence Management System aligned with ISO/IEC 42001, covering AI policy, roles and responsibilities, AI risk assessment, impact assessment, lifecycle controls, monitoring, documentation, and continual improvement. Support AI governance activities, including maintaining an inventory of AI use cases, assessing responsible AI risks such as bias, transparency, explainability, data privacy, security, human oversight, misuse, and third-party AI dependency risks. Policy and Procedure Development: Create, update, and maintain information security, privacy, and AI governance policies, procedures, standards, guidelines, templates, and control documents in alignment with organizational requirements and applicable frameworks. Assist in communicating policies and procedures across the organization and tracking adoption, exceptions, acknowledgements, and remediation actions. Draft and maintain AI governance artefacts such as responsible AI policy, AI acceptable use guidelines, AI risk assessment templates, AI impact assessment checklists, human oversight requirements, and AI vendor due diligence questionnaires. Risk Assessment and Management: Perform and document security, privacy, third-party, cloud, SDLC, DevOps, and AI-related risk assessments under the guidance of the Compliance Manager. Track risk mitigation plans, owners, due dates, residual risks, management approvals, exceptions, and closure evidence. Have a good understanding of OWASP top 10 cloud security, web application security, and DevOps security risks Have a good understanding on SDLC workflow and its infosec requirements from and ISO27001 standard perspective Support AI risk management across the AI lifecycle, including use case intake, data assessment, model/tool evaluation, testing, deployment review, monitoring, change management, and retirement/decommissioning controls. Training and Awareness: Support training and awareness programs to educate employees about information security, privacy, responsible AI usage, AI acceptable use, and compliance requirements. Knowledge of phishing simulations is a plus Incident Response and Management: Assist in maintaining incident response procedures for security, privacy, and AI-related incidents, including prompt reporting, triage, documentation, RCA/CAPA tracking, and closure. Coordinate with relevant stakeholders during incidents and support evidence collection, compliance notifications, post-incident reviews, and implementation tracking of corrective actions. Vendor and Third-Party Risk Management: Evaluate the security, privacy, and AI governance practices of third-party vendors and partners to ensure they meet applicable compliance, customer, and organizational requirements. Manage vendor risk assessments, due diligence questionnaires, audit evidence requests, AI tool assessments, and remediation follow-ups under the supervision of the Compliance Manager. Reporting and Documentation: Prepare compliance reports, audit status updates, AI governance trackers, control health summaries, and evidence packs for internal stakeholders, customer audits, and external assessments as applicable. Maintain comprehensive documentation of security controls, privacy .