Enterprise IT & Infrastructure Leadership Own and scale global IT operations — end-user computing, networks, cloud infrastructure, and office IT for a distributed workforce. Dogfood our own product stack (ZTNA, MFA, SSO, MDM, virtualization) as the foundation of internal IT architecture — serving as both a validation setting and a reference implementation for customers. Ensure high availability, performance, and resilience of internal systems with defined SLA targets. Implement cloud security posture management (CSPM) and cloud workload protection (CWPP) across cloud environments. Security Strategy & Operations Define and execute the organization’s information security strategy, aligned to business objectives and the evolving threat landscape. Security operations center (SOC) — with AI-augmented monitoring, detection, and response. Deploy and evolve AI-native security tooling for automated threat detection, anomaly identification, and intelligent alerting to reduce analyst burden and improve response times. AI & Emerging Technology Security Own the security governance framework for AI/ML usage across the organization — both internal tools and product-embedded capabilities. Address AI-specific threat vectors including: LLM-assisted phishing and deepfake-based social engineering. Prompt injection, data exfiltration via AI tools, and model manipulation risks. Shadow AI usage and ungoverned adoption of generative AI by employees. Define acceptable use policies and technical controls for AI tools (e.g., data classification rules for LLM inputs, approved tool lists, access controls for model endpoints). Evaluate and integrate AI-driven capabilities into the security operations stack — automated triage, behavioral analytics, predictive threat intelligence. Stay current on regulatory developments related to AI governance and data protection (e.g., EU AI Act, emerging regional frameworks). Partner with engineering to embed secure SDLC practices with security gates at each stage of the development lifecycle. Secure OS and USB-based deployment surfaces. API and cloud-native services. Own software supply chain security — dependency integrity, build pipeline security, and provenance verification. Data Protection, Privacy & Security (DPO) Serve as the organization’s Data Protection Officer (DPO), with accountability for data privacy compliance across all 12 operating countries. Define and enforce data classification,
data loss prevention (DLP), and encryption strategies (at rest, in transit, and in use) — across products and internal systems. Partner with product and engineering to embed privacy-by-design principles, particularly for products handling customer identity and access data. Own data protection impact assessments (DPIAs) for new products, features, and data processing activities. Ensure alignment between data handling practices and regulatory requirements across all operating geographies (GDPR, India’s DPDP Act, and regional data protection laws). Own data retention, anonymization, and cross-border data transfer policies — including standard contractual clauses (SCCs) and binding corporate rules where required. Act as the primary point of contact for data protection authorities across jurisdictions. Compliance, Risk & Governance Lead and maintain certifications such as ISO/IEC 27001, SOC 2 Type II, and regional regulatory requirements across operating geographies. Risk assessments (enterprise + product) with quantified risk scoring. Third-party and vendor risk programs with defined assessment cadence. Software supply chain risk as part of the broader vendor and dependency risk posture. Multi-country regulatory interactions and customer security reviews. Represent the company in security due diligence discussions with enterprise customers (CISOs, CIOs, Risk leaders) — with the understanding that as a security vendor, our own posture is scrutinized to a higher standard. Regulatory inquiries. Red team / blue team simulations (including AI-augmented adversary simulations). Ensure alignment between cyber resilience and business continuity / disaster recovery planning. Build and run a security awareness program for 300+ employees across multiple countries — including phishing simulations, role-specific training, and onboarding security modules.
Team & Capability Building Inherit and lead an existing team of 10 — 6 in IT Operations and 4 in Security — and grow the function by approximately 20% over the next 12 months (to ~12 people). Assess current capabilities, identify gaps, and hire strategically to build depth across security engineering, GRC, product security, and data protection. IT Operations Security Engineering & Operations GRC, Compliance & Data Protection Establish 24x7 readiness where required for enterprise support, with clear on-call structures and escalation protocols. Experience: ~12–15 years across IT, security, and infrastructure roles, with a progression from hands-on technical work to building and leading teams. ~ Experience as a Manager / Head of Security / IT / Security Architect in a product company (strong preference for security, identity, or infrastructure product companies) or technology-led enterprise setting. ~ Track record of building security programs that directly enabled revenue (shortened deal cycles, won enterprise accounts, achieved certifications that unlocked market segments). ~ Experience operating across multiple geographies and regulatory environments is strongly preferred. Identity and access systems (SSO, MFA, IAM, SCIM, directory services, biometric authentication) ideally with experience in organizations that build these products. Virtualization and secure workspace technologies (VDI, virtual desktops, thin-client architectures). Endpoint and mobile device security (MDM, device posture, zero-trust network access). Cloud security CSPM, CWPP, IAM policies, network segmentation across AWS/Azure/GCP. AI/ML security governance frameworks, LLM risk management, AI-augmented security operations. Software supply chain security SBOM management, dependency scanning, build integrity. Secure OS and hardware-rooted security concepts (bootable secure environments, USB-based OS deployment). Proficiency with modern security tooling (SIEM/SOAR platforms, EDR, vulnerability scanners, cloud-native security tools). Security & Risk Hands-on understanding of adversary behavior, attack paths, and AI-enhanced threat vectors. Compliance, Governance & Data Protection Data protection regulations across multiple jurisdictions (GDPR, India’s DPDP Act, regional equivalents). DPO responsibilities — data protection impact assessments, breach notification obligations, cross-border transfer mechanisms (SCCs, adequacy decisions). Emerging AI governance frameworks (EU AI Act and equivalents).
📌 Information Technology and Security Manager (Pune)
🏢 Accops
📍 Pune