Senior Manager - Information Security
Leena AI · Gurgaon
- Experience7–10 yrs
- SalaryNot disclosed
- Work modeonsite
- Levelexecutive
- Posted11 Sept 2026
About Leena AI
Leena AI is hiring in Gurgaon in technology software. This role looks for around 7+ years of experience.
Skills
- ISO 27001
- SOC 2 Type II
- GDPR
- DPDP
- Information Security Compliance
- Vendor Risk Assessment
- Security Questionnaires
- ISMS
- Control Testing
- Internal Audits
The role
An information security compliance specialist at an enterprise AI software company maintains ISO 27001 and SOC 2 Type II programs, manages GDPR and DPDP compliance, and handles HITRUST readiness. The role also runs vendor risk assessments and security questionnaires for enterprise customers.
Full job description
About Leena AI
Leena AI is a leader in Agentic AI for the enterprise. We are building an iconic company, delivering AI Colleagues that transform back-office functions and accelerate the full promise of Generative AI—unlocking real productivity gains, cutting costs, and delighting employees at scale.
Leena AI provides the most forward-looking, open, and scalable Agentic AI architecture for the enterprise— it empowers CIOs and CTOs to develop, deploy, and manage AI Colleagues for the back office at scale. Built with full governance, compliance, security, and auditability at its core.
Leena AI integrates with 1000+ applications, including SAP, Salesforce, ServiceNow, Workday, and Microsoft Office 365. We are proud to be trusted by 500+ global enterprises and 20 million+ employees, including leading brands such as Nestlé, Puma, Coca-Cola, Sony, and Etihad Airways.
Founded in 2018 and headquartered in New York, Leena AI has secured over $40M in financing from top-tier investors including Greycroft, Bessemer Venture Partners, B Capital, and Y Combinator.
The role
You are the engine room of Leena AI's security compliance program. The Head of Information Security & Compliance owns the program, faces customers, and makes the calls; you run the machine that keeps every commitment true - the evidence, the audits, the questionnaires, the vendors, the trackers. This is a hands-on senior IC role for someone who takes pride in an audit with zero surprises and a questionnaire queue at zero.
What You'll Do
Keep the ISMS audit-ready, every day - evidence collection, control testing, and internal audits across ~10 frameworks; coordinate external auditors and assessors through every surveillance and certification cycle; run the HITRUST readiness workstream under the Head's direction. Answer for our security, in writing - respond to customer security questionnaires (~2/day at quality) across RFPs, vendor-risk reviews, and AI questionnaires; keep the trust portal and standard document set (whitepaper, DPA, TOMs, certifications) current at all times. Run vendor and privacy operations - execute vendor risk assessments, maintain the sub-processor list and DPA notification mechanics, and operate GDPR/DPDP processes with Legal. Track every finding to closure - maintain the vulnerability and audit-findings trackers, chase owners across engineering, report SLA breaches to the Head weekly, and coordinate the pen-test cycle logistics with vendors. Maintain policies and run training - keep the ISMS policy set current and deliver the security awareness program. Report in writing, weekly - done / not done / blocked / need, with dates. This is the non-negotiable working style of the team.
What We're Looking For
7–10 years in information security compliance, in-house at a SaaS/product company - you have personally taken a vendor through full ISO 27001 and SOC 2 Type II cycles as the internal owner, not as an external auditor or consultant. High-volume questionnaire experience: enterprise security questionnaires and RFP security sections have been a core part of your job, and you are fast without being sloppy. Used to chasing engineering teams to closure - evidence, remediation, timelines - with persistence and without needing an escalation for every item. Working fluency in how AI products handle enterprise data - enough to answer AI-questionnaire sections accurately and know when to pull in the Head. Strong on GDPR and DPDP mechanics; CIPM/CIPP, ISO 27701, or DPO exposure a plus. HITRUST or ISO 42001 exposure a plus. Clear, direct communicator in English, comfortable with US customer overlap (EST hours).
How Success Is Measured
Questionnaire turnaround time and quality, with the routine tier handled end-to-end without escalation. Evidence currency: any auditor request answerable within a day, no findings caused by stale or missing evidence. Vendor assessments, sub-processor notifications, and policy reviews completed on calendar, every cycle. Findings trackers accurate and current; SLA breaches surfaced the week they happen, not discovered later.
Why this role is a good move
Full-stack compliance exposure most companies can't offer: ~10 frameworks including HIPAA, HITRUST readiness, and ISO 42001 AI governance from day one. Direct exposure to Fortune-500 customer security processes at an enterprise AI company. A clear #2 seat in a security function being built properly - a dedicated Head above you, real tooling investment, and room to grow as the program scales.
Skills: compliance,iso,information security,security,hitrust