Skima innovation private limited
Posted 3 months ago
Company: Skima AI
Location: Mumbai, India (5 days work from office)
Role Type: Full-Time
About Skima:
AI Skima is a rapidly growing AI SaaS platform designed to revolutionize the recruitment process. We provide enterprise organizations with an intelligent layer that sits on top of their existing HR systems, offering features like semantic screening, automated candidate rediscovery, and omnichannel outreach. Because we handle sensitive candidate data for global enterprisesincluding major healthcare networks and global conglomeratesdata security, privacy, and continuous compliance are core to our business.
Role Overview: We are looking for a highly organized and strategic Governance, Risk, and Compliance (GRC) Specialist to own our day-to-day security posture and act as the bridge between our engineering team and our enterprise clients. In this role, you will not just check compliance boxes; You will leverage our compliance automation platform (Scrut) to maintain our SOC 2 and GDPR posture, while simultaneously taking ownership of enterprise Vendor Risk Assessments (VRAs) to help us close deals faster.
Key Responsibilities:
1. Sales Enablement & Client Trust (External) (not mandatory)
Take primary ownership of completing enterprise security questionnaires, RFPs, and Vendor Risk Assessments (VRAs) accurately and efficiently.
Build and maintain a centralized security knowledge base/Trust Center.
Join prospective client calls to confidently explain about Skima's security controls to external IT and security stakeholders.
Assist in reviewing and negotiating Data Processing Agreements (DPAs) and vendor security exhibits.
2. Continuous Compliance & Automation (Internal)
Oversee daily operations of the compliance automation platform.
Monitor integrations across cloud, MDM, and HR systems to ensure smooth evidence collection.
Investigate and resolve control failures or alerts in collaboration with engineering and DevOps teams.
Ensure adherence to internal policies such as access control, data retention, and backup.
3. Audit & Risk Management
Act as the primary internal project manager for our annual SOC 2 Type II audits, facilitating asynchronous evidence review with our external CPA firm via Scrut.
Lead annual risk assessments, tabletop incident response exercises, and vendor due diligence reviews.
Stay updated on emerging global AI and data privacy regulations (e.g., EU AI Act, GDPR updates) to ensure the Skima platform remains ahead of regulatory curves.
Qualifications & Requirements
Experience: 4 to 6 years of experience in Information Security, IT Audit, or GRC within a modern B2B SaaS (not mandatory) environment.
Compliance Frameworks: Strong foundational knowledge of SOC 2 and GDPR. Experience with ISO 27001 or HIPAA (not mandatory) is a plus.
Automation Tooling: Hands-on experience managing compliance via automation platforms (Scrut, Vanta, Drata, Secureframe, or similar anyone works).
Technical Fluency: Ability to understand and intelligently discuss modern cloud architectures (basic knowledge of any one works) without necessarily needing to write code.
Communication Skills: Excellent technical translation skills. You must be able to clearly articulate complex security concepts to both highly technical auditors and non-technical business stakeholders.
Mindset: A solutions-oriented approach. When a client asks for a specific control we don't have, you know how to propose a valid compensating control rather than just saying no.