Posted on: 22/09/2026
About Leena AI :
Leena AI is a leader in Agentic AI for the enterprise. We are building an iconic company, delivering AI Colleagues that transform back-office functions and accelerate the full promise of Generative AI - unlocking real productivity gains, cutting costs, and delighting employees at scale.
The role :
You are the engine room of Leena AI's security compliance program. The Head of Information Security & Compliance owns the program, faces customers, and makes the calls; you run the machine that keeps every commitment true - the evidence, the audits, the questionnaires, the vendors, the trackers.
What You'll Do :
- Keep the ISMS audit-ready, every day - evidence collection, control testing, and internal audits across ~10 frameworks; coordinate external auditors and assessors through every surveillance and certification cycle; run the HITRUST readiness workstream under the Head's direction.
- Answer for our security, in writing - respond to customer security questionnaires (~2/day at quality) across RFPs, vendor-risk reviews, and AI questionnaires; keep the trust portal and standard document set (whitepaper, DPA, TOMs, certifications) current at all times.
- Run vendor and privacy operations - execute vendor risk assessments, maintain the sub-processor list and DPA notification mechanics, and operate GDPR/DPDP processes with Legal.
- Track every finding to closure - maintain the vulnerability and audit-findings trackers, chase owners across engineering, report SLA breaches to the Head weekly, and coordinate the pen-test cycle logistics with vendors.
- Maintain policies and run training - keep the ISMS policy set current and deliver the security awareness program.
- Report in writing, weekly - done / not done / blocked / need, with dates.
What We're Looking For :
- 7 - 10 years in information security compliance, in-house at a SaaS/product company - you have personally taken a vendor through full ISO 27001 and SOC 2 Type II cycles as the internal owner, not as an external auditor or consultant.
- High-volume questionnaire experience : enterprise security questionnaires and RFP security sections have been a core part of your job, and you are fast without being sloppy.
- Used to chasing engineering teams to closure - evidence, remediation, timelines - with persistence and without needing an escalation for every item.
- Working fluency in how AI products handle enterprise data - enough to answer AI-questionnaire sections accurately and know when to pull in the Head.
- Strong on GDPR and DPDP mechanics; CIPM/CIPP, ISO 27701, or DPO exposure a plus.
- HITRUST or ISO 42001 exposure a plus.
- Clear, direct communicator in English, comfortable with US customer overlap (EST hours).
How Success Is Measured :
- Questionnaire turnaround time and quality, with the routine tier handled end-to-end without escalation.
- Evidence currency : any auditor request answerable within a day, no findings caused by stale or missing evidence.
- Vendor assessments, sub-processor notifications, and policy reviews completed on calendar, every cycle.
- Findings trackers accurate and current; SLA breaches surfaced the week they happen, not discovered later.
Why this role is a good move :
- Full-stack compliance exposure most companies can't offer : ~10 frameworks including HIPAA, HITRUST readiness, and ISO 42001 AI governance from day one.
- Direct exposure to Fortune-500 customer security processes at an enterprise AI company.
- A clear #2 seat in a security function being built properly - a dedicated Head above you, real tooling investment, and room to grow as the program scales.
Skills :
- Compliance, ISO, Information Security, Security, HITRUST
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
IT Security
Job Code
1673526