Senior/Lead - Infosec

Job type: Full Time · Department: Security & Compliance · Work type: On-Site

Bengaluru, Karnataka, India

About us:

The global hiring revolution is shaping a future where talent can thrive everywhere, driving innovation and progress on a global scale.

Multiplier is at the forefront of this change. By removing barriers and simplifying global hiring, we’re creating a level playing field where businesses and individuals – (like you) – can compete, grow, and succeed, regardless of geography.

Multiplier empowers companies to hire, onboard, manage, and pay talent in 150+ countries, quickly and compliantly. Our mission is to build a world without limits, where ambitious businesses can look beyond borders to build their global dream teams. Our unified employment platform, complete with world-class EOR, AOR and Global Payroll products, means it has never been easier to seize the global hiring opportunity.  

We’re backed by some of the best in the business, (Sequoia, DST, and Tiger Global), are led by industry-leading experts, scaling fast, and seeking brilliant like-minded enthusiasts to join our team. The future is borderless. Let’s build it together.

What’s the opportunity?

Multiplier is building a function that has never existed here before: someone who owns compliance and personally works inside the cloud environment that compliance governs, rather than splitting the two across separate people. This role covers global compliance frameworks including ISO 27001, SOC 2, GDPR, and DPDPA, alongside internal financial controls and statutory audits (ITGC/ITAC) across EOR and advisory. You will drive GRC automation and continuous compliance, and you will also be the one who logs into AWS and GCP to validate controls yourself, not someone who hands that work to an engineering team.

A key focus area will also include leveraging AI-driven controls and analytics to enhance control and process violation detection, compliance monitoring, and risk intelligence across the enterprise.

What you'll do:

  • Strong interpersonal and stakeholder management skills to collaborate with executive and audit teams to align business, finance, and security goals

  • Develop and execute cybersecurity governance, strategy, and operational procedures for group companies.

  • Oversee technical risk, compliance, and data security, especially for applicable compliances

  • Strategize readiness and execute IT statutory audits, including Internal Financial Controls (IFC), IT General Controls (ITGC), and IT Application Controls (ITAC).

  • Ensure adherance to Cybersecurity Framework, SOC 2, GDPR, ISO 27001, NIST, CIS, and DPDPA, among others.

  • Drive all GRC initiatives for information security and data privacy in the enterprise on the cloud and on-premises.

  • Drive continuous automation and improvement for audit readiness, technical documentation, and regulatory response

  • Conduct comprehensive Third Party Risk Assessments focused on information security and privacy risks, including vendor security posture evaluation, contractual security obligations, and ongoing monitoring of third-party controls

  • Performed SAR, Data Localisation and Tokenisation audits.

  • Performed user entitlement review, ITSM audits.

  • Define strategies and lead initiatives to automate Governance, Risk, and Compliance (GRC) processes, driving continuous compliance across all regulatory and statutory mandates

  • Establish and oversee AI security frameworks, ensuring compliance with security and data privacy requirements.

  • Implementation of SOC 1 and SOC 2 audit processes, including key dependencies and limitations regarding reliance on external SOC reports for control assurance

Core Competencies / Must Haves

  • Genuine hands-on comfort working inside cloud environments, not just reviewing documentation about them

  • Compliance as a core identity, not a side function to a technical specialty or a checklist exercise

  • GRC automation and continuous compliance

  • SOC 2, GDPR, and ISO 27001 enablement

  • Risk management and audit readiness

  • Data privacy, data governance, and data protection

  • Third Party Risk Assessment

  • Execution rigor and strategic planning


Qualifications:

  • ISO 27001, CISA/CISM, Privacy Certifications

  • Working on cloud environment (AWS, GCP etc)

  • Hands on experience in Enterprise security tool like DLP, IDS-IPS, Network security tools

  • Demonstrated Ai literacy in understanding data processing, security, and responsible Ai use.

Equal Employment Opportunity:

Multiplier is an equal opportunity employer: we value diversity. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.

Made with