โšก New

Security & Compliance Lead

Exto

RemoteFull-timeMid LevelRemote

Job Description

Location: Remote โ€” India

Employment Type: Full-time

Shift Time: US Time Zone

Reports to: CEO


About Exto

Exto is a growing SaaS technology company serving complex, mission-critical construction and infrastructure environments. As we continue to scale our platform, customers, and enterprise relationships, maintaining strong security, compliance, and operational controls is critical to our business.

We are looking for an experienced Security & Compliance Lead to take ownership of Exto's information security and compliance programs, including SOC 2 Type II, VAPT, security policies, controls, audits, remediation, and ongoing compliance monitoring.

This is a highly hands-on and independent role. The successful candidate will work directly with the CEO while partnering closely with Product, Engineering, DevOps/Infrastructure, IT, Operations, HR, and other stakeholders.


The Role

The Security & Compliance Lead will be responsible for ensuring that Exto maintains the policies, controls, processes, evidence, and technical practices required to meet our security and compliance obligations.

You will own the day-to-day management of Exto's compliance programs and serve as the primary internal point of contact for auditors, penetration testing providers, security vendors, and other external compliance stakeholders.

This role requires someone who has personally managed SOC 2 Type II and security assessment programs before and understands how to translate compliance requirements into practical processes that engineering and business teams can follow.

You should be comfortable working independently, identifying gaps, driving corrective actions, and holding stakeholders accountable for completing compliance requirements.


Key Responsibilities

SOC 2 Type II & Compliance Program Management

  • Own and manage Exto's SOC 2 Type II compliance program from readiness through audit completion and ongoing monitoring.
  • Coordinate directly with external auditors and compliance partners.
  • Maintain the company's SOC 2 control framework, policies, procedures, risk register, evidence repository, and compliance calendar.
  • Coordinate evidence collection across Engineering, Product, DevOps, HR, Operations, Finance, and other teams.
  • Ensure controls are operating consistently throughout the SOC 2 observation period.
  • Identify control gaps and drive remediation plans to completion.
  • Prepare the organization for annual audits, surveillance activities, customer security reviews, and related assessments.
  • Monitor changes to the business, systems, infrastructure, or organizational structure that may impact existing controls.


VAPT & Vulnerability Management

  • Own and coordinate Vulnerability Assessment and Penetration Testing activities.
  • Work with external VAPT providers to define scope, schedule testing, review findings, and manage remediation.
  • Work directly with Engineering and DevOps teams to prioritize vulnerabilities based on severity and business risk.
  • Track findings through remediation and verification.
  • Maintain documented vulnerability management and remediation processes.
  • Ensure critical and high-risk vulnerabilities are addressed within defined remediation timelines.
  • Coordinate periodic internal vulnerability reviews and security assessments.


Security Governance & Policies

  • Develop, maintain, and enforce information security policies, standards, procedures, and controls.
  • Establish clear security and compliance processes appropriate for a growing SaaS organization.
  • Ensure policies are practical, understandable, and consistently followed by employees.
  • Maintain areas such as:
  • Access management
  • User provisioning and deprovisioning
  • Privileged access
  • Password and MFA requirements
  • Change management
  • Secure software development
  • Vulnerability management
  • Incident response
  • Business continuity and disaster recovery
  • Vendor management
  • Data retention and deletion
  • Security awareness and training
  • Risk management
  • Asset management
  • Backup and recovery
  • Logging and monitoring


Product & Engineering Security

Partner closely with Product, Engineering, and DevOps to ensure security and compliance requirements are incorporated into Exto's technology environment and software development lifecycle.

Responsibilities may include:

  • Reviewing security implications of new product features, architecture changes, and infrastructure decisions.
  • Supporting secure software development practices.
  • Ensuring appropriate controls exist across Exto's development and production environments.
  • Working with engineering teams to implement and maintain controls involving platforms such as:
  • Microsoft Azure
  • GitHub
  • Snyk
  • CI/CD environments
  • Cloud infrastructure
  • Identity and access management systems
  • Monitoring and logging platforms
  • Reviewing access permissions and privileged accounts.
  • Supporting dependency, vulnerability, and source-code security processes.
  • Ensuring security findings from tools such as Snyk and other scanners are appropriately prioritized and remediated.
  • Helping establish security requirements and checkpoints within the software development lifecycle.


Continuous Compliance

Compliance should not exist only during audit periods.

The Security & Compliance Lead will establish processes that allow Exto to maintain continuous compliance throughout the year.

This includes:

  • Periodic access reviews
  • Security control testing
  • Evidence collection
  • Employee compliance training
  • Vendor security reviews
  • Vulnerability remediation tracking
  • Policy reviews
  • Risk assessments
  • Backup and recovery testing
  • Incident response exercises
  • Business continuity testing
  • Monitoring compliance deadlines and certifications

You will proactively identify upcoming compliance requirements and ensure the appropriate teams are prepared.


Audit & Customer Security Support

  • Serve as the primary internal coordinator for SOC 2 auditors and external security assessors.
  • Respond to auditor requests and coordinate internal stakeholders.
  • Support customer security questionnaires and enterprise security reviews when required.
  • Help Sales and Customer teams respond accurately to security and compliance questions.
  • Maintain organized documentation and evidence that can be reused during customer assessments.
  • Ensure statements regarding Exto's security posture and certifications are accurate and supportable.


Risk Management

  • Maintain Exto's security and compliance risk register.
  • Conduct periodic risk assessments.
  • Identify risks associated with systems, vendors, infrastructure, processes, and new initiatives.
  • Recommend risk mitigation strategies.
  • Escalate material security or compliance risks directly to the CEO.
  • Track remediation commitments and ensure owners complete agreed actions.


What We Are Looking For

We are specifically looking for someone who has done this before and can independently manage the function rather than requiring extensive direction.


Required Experience

  • Approximately 5+ years of experience in information security, cybersecurity, GRC, compliance, or related roles.
  • Direct hands-on experience managing or leading SOC 2 Type II readiness and audit programs.
  • Experience coordinating with external auditors.
  • Experience managing VAPT or penetration testing programs.
  • Experience working with engineering and DevOps teams in a SaaS or cloud-based environment.
  • Strong understanding of security controls, risk management, and evidence-based audits.
  • Familiarity with cloud security, preferably Microsoft Azure.
  • Experience working with GitHub or similar source-code management environments.
  • Experience with vulnerability management platforms such as Snyk or similar tools.
  • Understanding of secure SDLC practices.
  • Ability to create practical policies, controls, and operating procedures.
  • Strong project-management and follow-through skills.
  • Excellent written and verbal English communication skills.


Strongly Preferred

  • Previous experience working for a B2B SaaS company.
  • Experience independently owning compliance at a startup or scale-up.
  • Experience supporting enterprise customers with security questionnaires or security assessments.
  • Familiarity with frameworks such as:
  • SOC 2
  • ISO 27001
  • NIST Cybersecurity Framework
  • CIS Controls
  • OWASP
  • GDPR and privacy-related requirements
  • Experience with compliance automation/GRC platforms such as Vanta, Drata, Secureframe, Sprinto, or similar.
  • Experience reviewing third-party/vendor security risks.
  • Relevant certifications such as CISA, CISM, CISSP, ISO 27001 Lead Implementer/Auditor, CRISC, or equivalent are advantageous but not mandatory.


What Success Looks Like

Within this role, success means that:

  • Exto successfully maintains SOC 2 Type II compliance.
  • Audits are well organized and completed with minimal disruption to the organization.
  • Compliance evidence is continuously maintained rather than collected at the last minute.
  • VAPT findings are properly prioritized, tracked, remediated, and closed.
  • Security policies and controls are clearly documented and consistently followed.
  • Engineering teams have defined security expectations within their development processes.
  • Azure, GitHub, Snyk, and other critical systems are configured and governed according to appropriate security practices.
  • Access reviews, risk assessments, vulnerability reviews, and other recurring controls happen on schedule.
  • Compliance gaps are proactively identified before they become audit findings.
  • Leadership has clear visibility into the company's security posture, risks, remediation activities, and upcoming compliance obligations.


Working Style

This role is ideal for someone who is:

  • Highly independent and self-directed.
  • Comfortable operating in a startup environment.
  • Hands-on rather than purely advisory.
  • Comfortable challenging teams when security or compliance requirements are not being followed.
  • Able to balance security requirements with practical business and engineering realities.
  • Comfortable working directly with senior leadership.
  • Capable of communicating technical security issues in clear business terms.

This person will report directly to the CEO and will have the authority and responsibility to work across departments to ensure Exto's security and compliance requirements are understood and consistently implemented.

Posted Today

Related Jobs

Related Searches

Apply Now