Back to jobs
1
Hiring company100ms

Verified today

Security and Compliance Lead – AI Agents

Bengaluru, India Full-time On-site

About the role

Security and Compliance Lead – AI Agents (Healthcare) – 100ms is building AI agents to automate patient access workflows in U.S. healthcare. The role leads HIPAA compliance, SOC 2 certification, and enterprise security, building policies, tooling, and a security culture from scratch. The candidate will partner with engineering, product, legal, and customer success to embed secure-by-design principles, manage risk, and drive audit readiness. The position requires deep knowledge of HIPAA, HITECH, SOC 2, cloud security, and GRC platforms, and experience in a startup environment. The role is on-site in Bengaluru, India, with a hybrid schedule of three onsite days per week.

What you’ll do

  • Own and operationalise 100ms’s security posture, regulatory compliance, and privacy framework.
  • Design and maintain HIPAA compliance covering Privacy, Security, and Breach Notification Rules.
  • Lead SOC 2 Type II, HITRUST CSF, and customer security assessments.
  • Define and enforce security architecture across cloud, application, and AI agent pipelines.
  • Manage vulnerability scanning, patching, and penetration testing schedules.
  • Develop and run Security Incident Response Plan with tabletop exercises and on-call rotation.
  • Drive security awareness training, phishing simulations, and quarterly compliance reporting.
  • Embed secure-by-design principles into SDLC and collaborate on DevSecOps practices.

What you’ll bring

  • 5+ years in information security or compliance, with 2+ years in U.S. healthcare data.
  • Deep knowledge of HIPAA, HITECH, SOC 2, and cloud-native compliance.
  • Proven experience building compliance programs from zero to one in a startup.

Nice to have

  • CISSP, CISM, HCISPP, CCSP, or HITRUST CCSFP certifications.
  • Experience with AI/LLM security considerations (prompt injection, data leakage).
  • Familiarity with FDA SaMD or CMS interoperability standards (FHIR, HL7).
  • Background in penetration testing or application security.

Skills

HIPAA compliance program design and implementation.SOC 2 Type II and HITRUST certification leadership.Cloud security architecture (AWS/GCP/Azure) and IAM.DevSecOps practices: CI/CD pipeline security, secrets management.GRC platform management (Sprinto, Vanta, Drata).Risk assessment and incident response planning.AI/LLM security: prompt injection defenses, PHI handling.

Benefits

  • Competitive salary ₹50–80 LPA and significant ESOP grant.
  • Comprehensive health insurance for employee and family.
  • Flexible work arrangements and direct access to founders.
  • On-site collaboration with a high-growth startup culture.