Job Description: C-Level Due Diligence Expert / Advisor
Location: India (Remote)
Duration: Ongoing Part-Time
Position Overview
We are seeking an experienced and results-oriented C-level Due Diligence Expert/Advisor to lead due diligence of SaaS product companies around their compliance, privacy, and security initiatives for the company and its
products.
The fractional CISO will work on due diligence projects supporting the acquisition of SaaS companies — many of which run on somewhat dated technology stacks — and will use AI tools, including Anthropic Claude, to accelerate
and standardize how that security due diligence is performed. A core part of the role is building a repeatable, AI-assisted review process that can be run consistently across every target and then re-run periodically after
acquisition.
This is an on-demand, part-time consultant role, ideal for candidates with experience working with U.S.-based, PE-backed SaaS companies. The ideal candidate will have expertise in compliance, data privacy, and cybersecurity
across diverse industries and geographies, and a track record of turning ad hoc diligence work into scalable, AI-assisted, repeatable processes.
Key Responsibilities
• Lead internal compliance audits and ensure adherence to regulatory requirements, including data privacy laws across various jurisdictions.
• Conduct in-depth security due diligence for acquisitions, delivering actionable reports to support decision-making.
• Design and maintain a standardized, AI-assisted security due diligence process — using Claude and other AI tools to review codebases, architecture documentation, policies, and vendor questionnaires from
target SaaS companies, including those running dated or legacy tech stacks.
• Build repeatable assessment templates, checklists, and prompt/workflow libraries that let Claude or similar AI tools consistently surface security gaps, outdated dependencies, weak access controls, and
compliance risks across every acquisition target.
• Collaborate with business, sales, and legal teams to address compliance needs, including HIPAA, GDPR, PCI DSS, and CCPA.
• Coordinate with IT and security teams to design, implement, and manage security policies, audits, and incident management processes.
• Develop and execute cybersecurity strategies for hybrid, on-premise, cloud-based, and legacy SaaS environments.
• Establish the governance around how AI tools are used in the diligence process itself — data handling, access controls, and confidentiality of target company data when it is processed through Claude or other AI platforms.
• Own the ongoing review process for previously acquired companies: re-run the AI-assisted security assessment on a defined cadence post-close, compare results against the original diligence baseline, and
report on remediation progress and emerging risk across the portfolio.
• Continuously refine the AI-assisted review methodology itself — updating templates, prompts, and checklists as new risks, technologies, and target-company patterns are encountered.
• Monitor and address compliance breaches, ensuring root cause analysis and preventive measures.
Act as the primary liaison for audits, assessments, and accreditations conducted by regulatory bodies and external consultants.
• Deliver training and awareness programs to align with regulations and organizational policies.
• Guide cross-functional teams to implement governance controls and meet compliance objectives.
• Provide regular updates to internal stakeholders and leadership on compliance, cybersecurity, and privacy matters, including portfolio-level trends surfaced through the repeatable review process.
Qualifications
• Proven experience in compliance, data privacy, and security risk management with a focus on global and regional regulations.
• Expertise in cybersecurity governance, including network protocols and third-party risk management.
• Knowledge of cloud security, IAM policies, encryption, and monitoring practices, including experience assessing older or legacy SaaS architectures.
• Experience conducting security due diligence and risk assessments for acquisitions, with demonstrated ability to convert one-off assessments into a standardized, reusable methodology.
• Hands-on experience using Anthropic Claude, the Claude API, or comparable AI tools to perform or accelerate real security, compliance, or diligence work — not just familiarity with AI as a concept.
• Ability to design prompts, workflows, and review templates that make an AI-assisted diligence process consistent and repeatable across engagements.
• Experience designing recurring audit or review cadences (e.g., quarterly or semi-annual reassessments) and tracking findings over time.
• Strong communication skills with the ability to train and educate stakeholders on compliance and risk management.
• Demonstrated ability to lead cross-functional teams and drive compliance initiatives.
Preferred Background
• Hands-on experience with regulatory frameworks like GDPR, HIPAA, CCPA, and PCI DSS.
• Experience using Anthropic Claude/Claude API (or similar AI platforms) to review code, documentation, or policies for security and compliance gaps.
• Experience building AI-assisted diligence playbooks, templates, or SOPs used repeatedly across multiple acquisitions or engagements.
• Familiarity with the security and data-handling considerations of using AI tools on confidential target-company information during diligence.
• Leadership in managing ISMS audits, security assurance, and business continuity planning.
• Familiarity with security incident management and governance frameworks.
• Experience with SaaS companies carrying technical debt or legacy infrastructure, and assessing the security implications of that debt during M&A or technology due diligence.