29 Aug
|
Info Origin
|
Pune
Role Overview
We are looking for a highly experienced Manager – IT & Security to lead and scale our enterprise IT and information security function. This is a strategic as well as hands-on leadership role responsible for building a secure, resilient, and audit-ready technology environment across the organization. The selected candidate will drive IT operations, cybersecurity, compliance, data protection, AI security governance, and customer trust initiatives while leading a growing team.
The role is ideal for a builder-operator who can design systems and processes, strengthen security architecture, manage compliance programs, and support business growth through a strong security posture.
Key Responsibilities
Enterprise IT & Infrastructure
- Own and manage enterprise IT operations including end-user computing, cloud infrastructure, networks, endpoint management, and office IT.
- Design and implement secure, identity-driven architecture using zero-trust principles, conditional access, and device posture enforcement.
- Ensure high availability, performance, resilience, and operational efficiency of internal systems.
- Drive adoption of least-privilege access and cloud security best practices across AWS, Azure, or GCP environments.
Security Strategy & Operations
- Define and execute the organization’s information security strategy aligned with business goals.
- Lead security operations, vulnerability management, patch management, identity governance, monitoring, and incident response.
- Establish threat-informed defense practices and improve detection and response capabilities through automation and AI-driven security operations.
- Manage security incidents, investigations, containment, recovery, and post-incident improvements.
Product & Platform Security
- Partner with engineering teams to embed secure SDLC and DevSecOps practices across the product lifecycle.
- Drive security architecture reviews for authentication, authorization, APIs, cloud-native services, endpoint platforms, and virtualization technologies.
- Implement SAST, DAST, SCA, SBOM, threat modeling, and software supply chain security controls.
Data Protection & Compliance
- Serve as the Data Protection Officer (DPO) and ensure compliance with GDPR, India DPDP Act, and other applicable privacy regulations.
- Define data classification, encryption, DLP, retention, anonymization, and cross-border data transfer policies.
- Lead ISO/IEC 27001, SOC 2 Type II, and other compliance and audit programs, ensuring audit readiness and evidence management.
Customer Trust & Governance
- Represent the organization during customer security reviews, RFP/RFI discussions, audits, and regulatory interactions.
- Own responses to security questionnaires and build a strong customer trust and assurance program.
- Contribute to enterprise sales enablement by reducing security-related deal friction.
Team Leadership
- Lead IT Operations,
Security Engineering, Compliance, and Product Security functions.
- Assess team capabilities, identify gaps, hire strategically, and build a high-performing security organization.
- Promote a strong security culture through awareness programs, phishing simulations, onboarding training, and security champion initiatives.
Required Skills
- Strong expertise in Identity & Access Management (SSO, MFA, IAM, SCIM) .
- Hands-on experience with ZTNA, MDM, Endpoint Security, VDI/Virtualization, and Zero Trust Architecture .
- Solid knowledge of Cloud Security (AWS/Azure/GCP, CSPM, CWPP, IAM, Network Segmentation) .
- Experience with SIEM/SOAR, SOC Operations, Vulnerability Management, Incident Response, and Threat Detection .
- Exposure to AI/LLM Security Governance and AI-driven Security Operations .
- Experience in Secure SDLC, DevSecOps, SAST, DAST, SCA, and SBOM practices .
- Solid understanding of Data Protection, DLP, Encryption, GDPR, and India DPDP Act .
- Experience managing ISO 27001, SOC 2 Type II, Audit, Compliance, and Risk Management programs.
Desired Profile
- 12–15 years of experience across IT infrastructure, cybersecurity, cloud, and security operations roles.
- Proven track record of building and leading security programs in a product company, technology organization, or regulated environment.
- Strong stakeholder management skills with the ability to work with CXOs, customers, auditors, regulators, and cross-functional teams.
- Excellent communication, leadership, decision-making, and crisis management capabilities.
📌 Information Technology Security Manager (Pune)
🏢 Info Origin
📍 Pune