JobRaahGet matched free

Jobs

Lead - Information Security & Compliance

Gocomet · Bangalore · India · On-site

Pay: INR 2,000,000 – 3,000,000 a year

Posted Oct 9, 2026

Apply with JobRaah

Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.

Job Title: Lead - Information Security & Compliance Experience Level: 4-7 years Company Overview GoComet is a world-leading freight intelligence and supply chain visibility SaaS platform, helping global enterprises optimize their supply chains. We are built on a foundation of trust and security, and maintaining the integrity of our systems and customer data is paramount. We are looking for an experienced security leader to own our information security, compliance, customer trust, and governance programs while supervising organizational IT operations. Position Summary We are seeking a proactive Lead - Information Security & Compliance to own our security strategy, ISO 27001 and SOC 2 programs, internal security audits, policies, risk management, SOP adherence, and responses to customer security requirements. The role also provides governance and oversight for organizational IT operations. This is a security-first, hands-on ownership role for someone with 4-7 years of relevant experience who can establish controls, implement and maintain ISO 27001 and SOC 2 requirements, drive audit readiness, and ensure security SOPs are documented, understood, and consistently followed. You will be the primary security contact for auditors and enterprise customers, coordinate remediation across teams, and supervise the IT operations professional responsible for day-to-day employee support and administration. Key Responsibilities 1. Information Security, Risk & Compliance Leadership (ISO 27001 / SOC 2) Own the design, implementation, operation, and continuous improvement of the Information Security Management System (ISMS), ISO 27001 controls, and SOC 2 control environment, including control ownership, evidence, and ongoing readiness. Plan and lead internal security audits, ISO 27001 and SOC 2 assessments, surveillance and external audits; coordinate auditors, evidence collection, corrective actions, and timely closure of findings. Maintain the security risk register and drive periodic risk assessments, control testing, gap analyses, remediation plans, exception reviews, and leadership reporting across business, product, infrastructure, and vendors. Own and maintain security policies, standards, SOPs, registers, and supporting documentation; assign control owners, train relevant teams, monitor adherence, and follow up on deviations so processes work in practice, not just on paper. Own the security incident response framework, escalation and communication procedures, incident coordination, root-cause reviews, corrective actions, and periodic readiness exercises with engineering and IT teams. Run vendor and third-party security due diligence, periodic reviews, contractual control tracking, and remediation follow-up in coordination with procurement and business owners. Own business continuity and disaster recovery governance: coordinate BCP/DR plans, RTO/RPO definitions, tabletop and recovery exercises, backup assurance, documented…