Lead - Cybersecurity Audit & Assurance

Freshworks
Chennai,Posted 1 March 2026

Job Description

<p>The Lead GRC Cybersecurity professional will own and drive governance, risk, and compliance<br> programs across Freshworks. This role partners closely with engineering, cloud operations,<br> product, legal, and business teams to ensure regulatory, customer, and certification<br> requirements are met at scale. The role also serves as a primary interface with external auditors<br> and internal stakeholders while strengthening security assurance across cloud, Kubernetes, and<br> AI-driven systems.</p><p><strong>Roles &amp; Responsibilities</strong></p><p><br> <strong>Governance and Compliance</strong><br> • Lead and manage compliance programs for ISO 27001, SOC, PCI DSS, and Cyber Essentials<br> • Own end to end audit lifecycle including planning, evidence readiness, walkthroughs, and<br> closure<br> • Interpret control requirements and translate them into practical, scalable processes<br> • Maintain compliance documentation, policies, risk registers, and control narratives<br> Audit and Stakeholder Management<br> • Act as the primary point of contact for external auditors and certification bodies<br> • Coordinate cross functional teams for timely evidence collection and validation<br> • Provide clear, concise, and executive ready compliance reports and dashboards<br> • Drive continuous improvement based on audit findings and risk assessments</p><p><strong>Risk Management</strong><br> • Identify, assess, and track cybersecurity and technology risks across cloud and product<br> environments. Facilitate risk reviews with business and technical leadership<br> • Ensure risk treatment plans are practical, tracked, and aligned with business priorities</p><p><strong>Cloud, Platform, and AI Security</strong><br> • Demonstrate strong understanding of cloud concepts and shared responsibility models<br> • Work closely with engineering teams on security controls for cloud and Kubernetes<br> environments<br> • Understand AI security fundamentals, including LLM architectures, data risks, prompt injection,<br> and model misuse<br> • Support governance and risk frameworks for AI-enabled features and platforms</p><p><br> <strong>Communication and Leadership</strong><br> • Enable strong interdepartment collaboration across security, engineering, legal, IT, and<br> compliance<br> • Mentor and guide junior GRC team members<br> • Represent the GRC function with confidence to senior leadership and customers</p> <ul><li>8 to 15 years of experience in cybersecurity GRC roles</li><li>Strong experience in report writing and executive level communication</li><li>Proven experience interfacing with auditors and regulators</li><li>Hands on experience managing ISO 27001, SOC 2, and PCI audits</li><li>Strong understanding of cloud security principles and Kubernetes environments</li><li>Working knowledge of AI security concepts, LLM risks, and governance considerations</li><li>Ability to drive evidence collection across distributed and global teams</li><li>Preferred Qualifications</li><li>Prior experience in SaaS or cloud native organizations</li><li>Certifications such as CISA, ISO 27001 Lead Implementer or Auditor, CISSP, or CISM</li></ul><p>Preferred Qualifications</p><ul><li>Prior experience in SaaS or cloud native organizations</li><li>Certifications such as CISA, ISO 27001 Lead Implementer or Auditor, CISSP, or CISM</li></ul> <p>What Success Looks Like in This Role</p><ul><li>Proactively own and manage Certification cycles</li><li>Strong audit readiness culture across engineering and business teams</li><li>Clear visibility of risk posture for leadership</li><li>Scalable and future-ready GRC programs aligned with cloud and AI adoption</li></ul><div sr-tagline=""></div><p>At Freshworks, we have fostered an environment that enables everyone to find their true potential, purpose, and passion, welcoming colleagues of all backgrounds, genders, sexual orientations, religions, and ethnicities. We are committed to providing equal opportunity and believe that d ... (truncated, view full listing at source)