Security & Compliance Lead
Job Description
ABOUT PLAYPOWER LABS PlayPower Labs builds software for leading EdTech companies that serve millions of learners. We help our clients solve hard product and engineering problems so they can deliver better learner experiences through advanced technology, thoughtful design, and reliable execution. We’ve been fully remote since before COVID and plan to stay remote. We are US-based, with a development center in Gandhinagar, India. WHAT WE BELIEVE - We believe technology is a force multiplier for education.
- Great software can make learning more engaging, effective, personalized, and accessible for millions of learners worldwide. The future of education will be shaped by advanced online learning, AI, and education data, and we want to help build that future.
- Education data combined with AI is opening up new ways to create adaptive, personalized learning experiences.
- Build practical security controls around auth, access, secrets, data privacy, infrastructure, and deployments.
- Create safe usage guidelines for AI tools, agents, MCP servers, tool calling, and automation workflows.
- Run vulnerability management, security reviews, risk assessments, and incident response planning.
- Drive compliance readiness for frameworks like SOC 2, ISO 27001, GDPR, or similar.
- Help teams handle sensitive data properly, especially when using AI tools and third-party platforms.
- Train the team on secure development, AI safety, privacy basics, and common attack patterns.
- Bring a startup mindset: fast decisions, clear ownership, practical fixes, and no security theater.
- Good understanding of OWASP, cloud security, IAM, secrets management, vulnerability scanning, CI/CD security, and incident response.
- Strong working knowledge of the HIPAA Privacy, Security, and Breach Notification Rules.
- Familiarity with compliance frameworks like SOC 2, ISO 27001, GDPR, or similar.
- AI-native mindset: you understand the risks around AI tools, agents, MCPs, data leakage, permissions, and prompt/tool misuse.
- Product-minded, practical, calm under pressure, and allergic to pointless bureaucracy.
- You’ve worked on AI governance, agent security, MCP security, or LLM data privacy.
- You can automate security checks, compliance evidence, access reviews, or vendor reviews.
- You’ve taken a company through SOC 2 or ISO 27001 successfully.
How to Stand Out
- Highlight your hands‑on experience with ISO 27001, SOC 2, and GDPR compliance frameworks; include a one‑page “Compliance Dashboard” in your resume that shows specific controls you designed, audit outcomes, and any certifications you led (e.g., achieving SOC 2 Type II in under 6 months).
- Build a concise portfolio of security artefacts—red‑team/blue‑team exercise reports, risk‑assessment matrices, or automated policy‑as‑code scripts (Terraform, Ansible, or CloudFormation). Host them on a private GitHub repo and share the link in your application, ensuring each file includes a brief context note (project scope, tools used, impact).
- Demonstrate remote‑first collaboration skills: in your cover letter, cite at least two instances where you led security reviews across distributed teams (e.g., US product managers + India dev center) using tools like Confluence, Jira, and Slack. Mention your preferred time‑zone overlap strategy (e.g., 2‑hour core window 4 PM–6 PM IST) and how you ensured timely issue triage.
- Prepare for scenario‑based interview questions by rehearsing a “Live Threat‑Model Walkthrough.” Choose a recent EdTech feature (e.g., AI‑driven recommendation engine), outline the data flow, identify top‑3 threats, and propose mitigations using OWASP‑ASVS and cloud‑native controls (IAM, KMS, WAF). Bring a slide deck or whiteboard sketch to the virtual interview.
- When discussing compensation, reference the Indian remote market for senior security leadership (₹30‑40 LPA base + 15‑20 % performance bonus) and align it with Playpower’s “cost‑of‑living‑adjusted” policy. Ask for a clear breakdown of equity or profit‑share components, and be ready to negotiate a quarterly security‑milestone bonus tied to audit pass rates.
This is a remote position listed on WFA Digital, the platform for professionals who work from anywhere. Browse more remote jobs across all categories.