Arcana
Website:
arcana.io
Job details:
About the Role
We are looking for a Senior Compliance Engineer (Bangalore/Coimbatore Location) to own and strengthen Arcana’s security, privacy, and AI compliance programs across our product, engineering, cloud, and business operations.
You will work closely with Security, Engineering, Infrastructure, IT, Legal, People, and business teams to translate compliance requirements into practical controls, maintain continuous audit readiness, and drive certification programs including ISO 27001, SOC 2, and ISO 42001.
What You’ll Do
- Own and continuously improve Arcana’s compliance program across ISO 27001, SOC 2, and ISO 42001, including control design, implementation, operation, and ongoing readiness.
- Support customer and partner assurance activities, including security questionnaires, due diligence requests, control explanations, and evidence coordination.
- Automate evidence collection, control monitoring, recurring reviews, and compliance workflows wherever practical to reduce manual effort and improve audit reliability.
- Maintain clear traceability between policies, risks, controls, technical implementations, evidence, findings, and framework requirements.
- Track regulatory, contractual, customer, and framework changes relevant to Arcana and assess their impact on existing controls and certification scope.
- Support security incidents, exceptions, vendor risk, business continuity, access reviews, change management, and other operational processes where compliance oversight is required.
- Help build a scalable compliance culture where teams understand their control responsibilities and can demonstrate compliance continuously, not only during audits.
What We’re Looking For
- 5-8 years of hands-on experience in information security compliance, GRC, security assurance, or a similar role within a technology product company.
- Direct experience working in SaaS, FinTech, enterprise software, data platforms, or another product-led technology environment. Product-company experience is required.
- Strong hands-on experience with ISO/IEC 27001, including ISMS implementation, risk assessment, control ownership, Statement of Applicability, internal audits, management reviews, corrective actions, and external certification audits.
- Strong hands-on experience with SOC 2, including Trust Services Criteria, control design and testing, evidence management, audit coordination, gap remediation, and Type I / Type II readiness.
- Hands-on experience implementing or operating ISO/IEC 42001 requirements, including AI management systems, AI governance, AI risk management, lifecycle controls, documented responsibilities, and audit readiness.
- Must have directly supported or led certification and attestation cycles for ISO 27001, SOC 2, and ISO 42001, working with external auditors and internal control owners from readiness through closure.
- Relevant certifications such as ISO 27001 Lead Implementer / Lead Auditor, ISO 42001 Lead Implementer / Lead Auditor, CISA, CISM, CRISC, or CISSP.
- Ability to understand technical environments, review control implementation with engineering teams, evaluate evidence quality, and distinguish between documented policy and actual operating effectiveness.
- Strong documentation and communication skills with the ability to write clear policies, standards, control descriptions, risk statements, remediation plans, and audit responses.
- Ability to manage multiple audits, findings, evidence requests, and remediation workstreams with clear ownership, prioritization, and follow-through.
- Strong problem-solving skills and the ability to work independently while partnering effectively with technical and non-technical stakeholders.
Good to Have
- Experience in FinTech, financial technology, analytics, AI-enabled products, or other highly regulated or enterprise-facing SaaS environments.
- Experience with compliance automation or GRC platforms such as Sprinto, Vanta, Drata, Secureframe, or similar tools.
- Familiarity with cloud and engineering environments such as GCP, Kubernetes, CI/CD, IAM, encryption, logging, vulnerability management, and secure software development.
- Experience mapping controls across multiple frameworks such as ISO 27001, SOC 2, ISO 42001, NIST, CIS, GDPR, or customer-specific requirements.
- Experience with third-party risk, customer security reviews, business continuity, privacy, or security risk management.
Click on Apply to know more.