Head of Information Security & Compliance

Leena AI
Leena AI

IT, Compliance / Regulatory

Gurugram, Haryana, India

Posted on Aug 28, 2026
About Leena AI

Leena AI is a leader in Agentic AI for the enterprise. We are building an iconic company, delivering AI Colleagues that transform back-office functions and accelerate the full promise of Generative AI—unlocking real productivity gains, cutting costs, and delighting employees at scale.

Leena AI provides the most forward-looking, open, and scalable Agentic AI architecture for the enterprise— it empowers CIOs and CTOs to develop, deploy, and manage AI Colleagues for the back office at scale. Built with full governance, compliance, security, and auditability at its core.

Leena AI integrates with 1000+ applications, including SAP, Salesforce, ServiceNow, Workday, and Microsoft Office 365. We are proud to be trusted by 500+ global enterprises and 20 million+ employees, including leading brands such as Nestlé, Puma, Coca-Cola, Sony, and Etihad Airways.

Founded in 2018 and headquartered in New York, Leena AI has secured over $40M in financing from top-tier investors including Greycroft, Bessemer Venture Partners, B Capital, and Y Combinator.

Leena AI builds agentic AI for employee experience, deployed inside some of the world's largest enterprises across the US, Europe, and APAC. Our customers' security and compliance teams hold us to Fortune-500 standards - and passing that bar is a core part of how we win. We maintain SOC 1 Type 2, SOC 2 Type II, ISO 27001/27701/27017/27018, HIPAA, and GDPR programs, with HITRUST and ISO 42001 (AI management).

Role Overview

You will be Leena AI's named security leader: the designated Security Official and ISMS owner listed on our trust center and in customer agreements, reporting to the CTO with a quarterly readout to the management. This is a builder-operator role, not a delegate-and-review role - you'll drive cross-department security controls and processes yourself, backed by executive authority, a compliance manager you will hire and manage, and security engineering capacity in the platform team.

What You'll Own

  • The ISMS and every attestation — Own SOC 1/2, the ISO 27001 family, HIPAA, and upcoming HITRUST and ISO 42001 programs. Manage the audit calendar, evidence discipline, auditor relationships, and closure of findings.
  • Customer trust, in the room — Lead security review calls with enterprise buyers and their CISOs, audit walkthroughs, and strategic security workstreams on enterprise deals alongside the CTO.
  • Risk & incident response — Own the corporate risk register, incident response process, business continuity, and disaster recovery posture.
  • Third-party & privacy governance — Own vendor risk, sub-processor management, DPA obligations, and the privacy program with Legal across GDPR, DPDP, and CCPA. Stay ahead of regulatory changes before customers ask.
  • Vulnerability remediation governance — Establish and enforce company-wide remediation SLAs with Engineering and drive overdue or high-risk findings to closure.
  • AI governance — Own the controls and documentation for how our AI products handle enterprise data, including inference, retention, training boundaries, and tenancy. Lead the organization toward ISO 42001 certification.
  • Offensive security & technical assurance — Own penetration testing and red-team programs, including scoping, vendor selection, cadence, and remediation. Set cloud security posture standards across our AWS multi-region deployments and direct security-engineering execution within the Platform team.
  • The team — Hire and manage a Senior Manager of Information Security & Compliance. Provide dotted-line leadership to security engineering within Platform/DevOps and manage consultant, MSSP, and penetration-testing vendor relationships.

What We're Looking For

  • 10–15 years of experience in information security/GRC, with at least 3 years in a leadership role at a SaaS vendor selling to US or European enterprises. You have been on the vendor side — not consulting to or auditing SaaS companies.
  • Direct ownership of ISO 27001 and SOC 2 Type II — you have personally led these programs, sat across from auditors, managed evidence, and driven findings through closure. HITRUST or FedRAMP experience is a strong plus.
  • Strong AI/LLM security and data-governance expertise — you can explain to an enterprise buyer how an AI product handles their data across inference, retention, training boundaries, and tenancy, and defend the controls behind it. Experience with ISO 42001, NIST AI RMF, or the EU AI Act is a strong plus.
  • Enterprise customer credibility — you can walk a Fortune 500 CISO through architecture, controls, and AI security posture and hold your ground under detailed questioning.
  • Strong execution and an IC mindset — you’re comfortable writing the policy, building the tracker, working through evidence, and chasing the engineer yourself when that's what it takes to get closure.
  • Privacy expertise — strong working knowledge of GDPR, DPDP, and CCPA. CIPP/CIPM or equivalent practical depth is preferred.
  • Cloud security fluency — working knowledge of AWS security and modern security tooling including EDR, SIEM/XDR, WAF, and CSPM. You don’t need to operate every tool yourself, but you should be able to set standards and direct technical execution.
  • Strong communication skills — fluent English and comfortable working with US-based customers and teams, with required overlap during US hours, including EST.

Why This Role Is a Good Move

  • Whole-program ownership — Direct access to the CTO and CEO. You are the security leadership, not a layer inside it.
  • Real enforcement authority — Engineering remediation SLAs and accountability are explicitly part of the role, not implied.
  • Build the team — Your first hire is the Senior Manager of Information Security & Compliance who will run the program day to day.
  • Lead enterprise AI governance — Get a front-row seat to ISO 42001, AI questionnaires, model-safety reviews, and the security controls shaping enterprise AI adoption.
  • Influence revenue — Work directly with enterprise customers and CISOs and play a meaningful role in strategic deals.

Skills: risk,compliance,iso,information security,security,soc,enterprise