Security & Compliance Lead
full-time
lead
Posted 18 hours ago
About this role
ABOUT EMA
Ema is the Universal Agentic Control Plane for the enterprise. Our platform enables organizations to deploy AI Employees that automate complex workflows across HR, Customer Support, Sales, Finance, and more — powered by EmaFusion™ (a patented mixture-of-experts layer), GWE™ (our agentic orchestration engine), and the Enterprise Context Graph.
We work with the world's largest enterprises — from Fortune 500 firms to fast-scaling tech companies — across industries that demand the highest standards of security, privacy, and regulatory compliance. Our Trust Center (trust.ema.ai http://trust.ema.ai) reflects our commitment: SOC 2 Type II, HIPAA, GDPR, and a security-first architecture that supports on-prem and air-gapped deployments.
THE ROLE
We are looking for a Security & Compliance Lead to own Ema's entire security and compliance posture — both internal and customer-facing. This is a critical, high-visibility role that sits at the intersection of enterprise compliance, cloud infrastructure security, and the rapidly evolving landscape of AI/ML-driven development.
You will report directly to the Head of Engineering and serve as the single point of accountability for how Ema secures its platform, earns customer trust, and stays ahead of regulatory requirements in the agentic AI space. You will work closely with our Infrastructure team, Product Engineering, and directly with the InfoSec teams, CISOs, and compliance officers of our global enterprise clients.
WHAT YOU WILL DO
COMPLIANCE & REGULATORY LEADERSHIP
- Serve as the primary point of contact for customer InfoSec teams and CISOs during security reviews, vendor assessments, and due diligence cycles.
- Have high ownership in building and maintaining the security posture of the organization. Play a critical role in hiring and mentoring folks.
- Own and drive SOC 2 Type II, PCI DSS, FedRAMP, ISO 27001/27701/27017/42001, DORA and UK Cyber Essentials Plus, HIPAA and GDPR compliance programs end-to-end — from gap analysis through audit readiness and certification maintenance.
- Build and maintain Ema's compliance documentation, evidence repositories, and control frameworks. Keep our Trust Center (trust.ema.ai http://trust.ema.ai) current and credible.
- Navigate the emerging regulatory landscape for AI/ML systems — including AI governance frameworks, model risk management expectations, and data residency requirements across global markets.
SECURITY POSTURE & ARCHITECTURE
- Define and enforce Ema's internal and external security perimeters — covering cloud infrastructure, application security, API security, network segmentation, and access controls.
- Work closely with the Infrastructure team to harden production environments, implement zero-trust principles, and ensure secure multi-tenant and air-gapped deployment architectures.
- Establish and run vulnerability management, penetration testing, and incident response programs. Own the security incident lifecycle from detection through post-mortem.
- Evaluate and implement security tooling: SIEM, CSPM, SAST/DAST, secrets management, and runtime protection.
- Strong understanding of WAF. Expertise on Cloudflare, Akamai etc .. is beneficial.
- Exposure to enterprise security layers → workspace, identity providers.
DEVSECOPS & AI-NATIVE SDLC
- Pioneer the DevSecOps practice for an AI-first engineering org — embedding security into CI/CD pipelines, code review workflows, and deployment gates.
- Innovate on the SDLC for the age of AI-driven development: define guardrails for AI-generated code, secure model pipelines, protect training data integrity, and establish provenance tracking for agentic workflows.
- Secure the ML/Agentic stack specifically — model serving infrastructure, prompt injection defenses, agent-to-agent trust boundaries, and data exfiltration prevention in LLM-powered systems.
- Champion a security-aware engineering culture through training, threat modeling workshops, and lightweight governance that accelerates rather than blocks delivery.
ENTERPRISE CLIENT ENGAGEMENT
- Partner with Sales Engineering and Customer Success to support enterprise deals — completing security questionnaires, participating in client CISO reviews, and designing customer-specific security architectures.
- Work with global enterprise clients across regulated industries (financial services, healthcare, government) to meet their security and compliance requirements.
- Translate complex compliance requirements into engineering work, and communicate Ema's security story with clarity and confidence to technical and executive audiences.
WHAT WE LOOK FOR
- 8+ years of experience in security engineering, compliance, or DevSecOps — with at least 3 years in a lead or senior IC role owning compliance programs.
- Deep, hands-on experience with SOC 2 Type II, PCI DSS, and FedRAMP. Experience with HIPAA and GDPR is strongly preferred.
- S
Similar Jobs
Related searches:
On-site Jobs
Lead Jobs
On-site Lead Jobs
Lead AI InfrastructureLead NLP & Language AILead AI Safety & SecurityLead AI Agents & RAGLead Machine LearningLead Healthcare AI
AI Jobs in Bangalore
AI Infrastructure in BangaloreNLP & Language AI in BangaloreAI Safety & Security in BangaloreAI Agents & RAG in BangaloreMachine Learning in BangaloreHealthcare AI in Bangalore
securityllmhealthcareagentsmlopscloud
Get jobs like this delivered weekly
Free AI jobs newsletter. No spam.