Lead - Compliance (Manager - Compliance based on experience)
Qapita
Job Description
About Qapita
Qapita is a leading equity management and fund administration platform serving private companies, investors, and stakeholders across India and Southeast Asia. As we continue to scale, we are strengthening our Information Security & Compliance organization and are looking for an experienced Compliance professional to build and drive our compliance function.
About the Role
This is a high-impact individual contributor role reporting directly to the COO, offering the opportunity to own compliance programs end-to-end and help shape the compliance operating model alongside our incoming CISO.
Key Responsibilities
- Own and manage compliance certifications and audits including SOC 1, SOC 2, and ISO 27001.
- Lead audit readiness, evidence collection, auditor coordination, remediation tracking, and certification renewals.
- Drive compliance with GDPR and India's DPDPA, including DPIAs, data subject requests, consent management, and privacy governance.
- Manage customer security questionnaires, client audits, and Third-Party Risk Management (TPRM) activities.
- Review and support negotiation of security and privacy requirements in customer contracts, MSAs, and DPAs.
- Develop, maintain, and enhance compliance documentation, policies, procedures, incident response plans, and business continuity frameworks.
- Serve as the primary compliance advisor for cross-functional teams including Engineering, Security, Legal, Sales, Customer Success, and Operations.
- Establish scalable compliance processes, governance structures, reporting mechanisms, and compliance tracking frameworks.
Requirements
- 6 to 10 years of experience in Compliance, GRC, Risk Management, Information Security Compliance, or related domains.
- Hands-on experience managing at least one full SOC 2 and/or ISO 27001 audit lifecycle.
- Strong understanding of SOC 1, SOC 2, ISO 27001, GDPR, and DPDPA.
- Experience in a B2B SaaS environment is mandatory; FinTech experience is highly preferred.
- Experience responding to customer security reviews, vendor assessments, and audit requests.
- Ability to work effectively with auditors and multiple business stakeholders.
- Excellent written and verbal communication skills.
- Proven ability to work independently and build structure in a fast-growing environment.
Preferred Qualifications
- Certifications such as CISA, CISM, ISO 27001 Lead Auditor, or ISO 27001 Lead Implementer.
- Experience managing multiple compliance frameworks simultaneously.
- Exposure to privacy and security-related contract reviews in a SaaS organization.
Why Join Us?
- Opportunity to build and shape the compliance function from the ground up.
- High visibility role reporting directly to senior leadership.
- Work closely with the incoming CISO and executive team.
- Be part of a fast-growing SaaS company at the forefront of private market infrastructure.