19 Sep
|
Infoedge
|
India
About Info Edge India Ltd.
InfoEdge’s mission is to create world-class platforms that transform lives by continuously innovating. Our products and services are built keeping our customers in mind. We always delight our customers by delivering superior value through enhanced offerings on the internet and other platforms. Through our continuous investment across various businesses, especially in cutting-edge technology, machine learning and artificial intelligence (AI), we have built a robust system that constantly increases our predictive powers on customer behaviour, and optimizes and improves our systems. Our various teams tirelessly work together to solve problems, innovate, and create something to empower our customers.
At Info
Edge, people are our core competitive advantage and we will continue doing all that is needed to attract and retain the best available talent.
Business: IT Team (Central Function)
Role: SVP – Information Security will lead the organization's enterprise cybersecurity strategy, governance, operations, risk management, compliance, and security transformation initiatives across all
Info Edge internet businesses. The role requires a technology-first leader capable of securing large-scale consumer internet platforms while enabling innovation through cloud, open-source technologies, DevSecOps, and AI adoption.
Key Responsibilities:
Security Leadership & Strategy
Define and implement the enterprise-wide cybersecurity strategy aligned with business objectives and risk appetite.
Establish and drive a security-first culture across Product, Engineering, Infrastructure, Data, and Business functions.
Develop multi-year security roadmaps covering security architecture, governance, security operations, cloud security,
data protection, and AI security.
Present cybersecurity posture, risk assessments, and strategic recommendations to executive leadership and board stakeholders.
Spearhead cyber resilience and security transformation programs across all business verticals.
Build and lead high-performing Information Security teams across Security Engineering, Application Security, Security Operations, GRC, and Security Architecture.
Develop future leaders, strengthen organizational capabilities, and build a high-performance security organization.
Partner closely with Product, Engineering, Infrastructure, Data, and Business leadership teams.
Application Security & Product Security
Establish Secure Software Development Lifecycle (SSDLC) and DevSecOps practices across engineering teams.
Embed security controls into CI/CD pipelines and modern software delivery processes.
Drive application security initiatives (including SAST, DAST, IAST, SCA, API Security, Mobile Security, Container Security
Testing, Penetration Testing, Red Team Exercises, etc.).
Conduct architecture reviews and threat modeling for business-critical applications.
Drive security awareness and secure coding standards among development teams.
Security Operations, Incident Response & SOC
Build and mature a modern 24x7 Security Operations Center (SOC).
Lead incident detection, response, threat hunting, threat intelligence, and cyber defense operations.
Develop and maintain incident response playbooks (including ransomware, malware, insider threats, web application attacks, cloud security incidents, data breaches, etc.).
Lead cyber crisis management and forensic investigations.
Implement SOAR-based automation to improve detection and response effectiveness.
Conduct red-team, blue-team, and purple-team exercises.
Cloud Security
Define cloud security strategy for AWS, Azure, GCP, and hybrid-cloud environments.
Implement cloud-native security controls (including Kubernetes, Containers, Serverless, Data Platforms, AI Platforms,
etc.).
Drive cloud security initiatives (including CSPM, CWPP, CIEM, Container Security, etc.).
Secure cloud environments supporting modern application platforms and enterprise workloads.
Network & Infrastructure Security
Define and govern network security architecture.
Oversee enterprise network security controls (including Next-Generation Firewalls, IDS/IPS, Web Application Firewalls
(WAF), DDoS Protection, Zero Trust Network Architecture, VPN & Remote Access Security, Network Segmentation,
etc.) and ensure protection of internet-facing applications operating at scale.
Qualifications & Experience
Bachelor's or Master’s Degree in Computer Science, Information Technology, Engineering, or a related discipline.
Professional certifications preferred CISSP, CISM, CCSP, CRISC, GIAC, AWS/Azure Security Certifications.
15–20+ years of progressive experience in Information Security/Cyber Security, including a minimum of 5+ years leading enterprise-wide security organizations.
Experience securing large-scale internet businesses,
consumer platforms, digital products, and cloud-native environments.
Strong exposure to DevSecOps, Open Source Technologies, Security Automation, and internet-scale platforms.
Proven experience building and leading Application Security, Cloud Security, SOC, and Security Engineering functions.
Demonstrated experience handling major cyber incidents, crisis management, and enterprise security transformation initiatives.
Security Leadership
Build and lead high-performing Information Security teams across Security Engineering, Application Security, Security
Operations, GRC, and Security Architecture.
Develop future leaders and foster a collaborative, security-first culture.
Partner closely with Product, Engineering, Infrastructure, Data, and Business leadership teams.
Technical Competencies
Robust understanding of modern application architectures, microservices, APIs, containers, Kubernetes, and cloud platforms.
Excellent stakeholder management and executive communication capabilities.
Experience managing security programs within high-growth technology organizations.
Exposure to privacy, regulatory compliance, and data protection programs.
Demonstrated experience in AI Security and emerging cybersecurity technologies.
Cyber Security Domains: Application Security, Cloud Security, Security Operations, SOC Management, Incident Response,
Threat Intelligence, Vulnerability Management, Endpoint Security, IAM/PAM, Data Security, Network Security, Security
Architecture, and AI Security.
Technology & Platform Expertise: AWS, Azure, GCP, Kubernetes, Docker, Terraform, Infrastructure as Code, DevSecOps
Toolchains, CI/CD Platforms, API Security, SIEM & SOAR Platforms, EDR/XDR Solutions, and Threat Intelligence Platforms.
Open Source Security Tools Exposure: Experience with modern application security, software supply chain security,
vulnerability management, container security, secrets management, SIEM, and open-source security tooling (e.g., OWASP Suite,
SonarQube, Snyk, Trivy, OWASP ZAP, Wazuh, Suricata, OpenSearch, Falco, Keycloak, HashiCorp Vault, OpenSSF Frameworks,
etc.).
Leadership Competencies: Strategic Thinking and Vision, Business Acumen, Executive Presence and Stakeholder Management,
Strong Leadership and Team Building, Analytical and Risk-Based Decision Making, Ability to Influence Cross-Functional Teams,
Crisis Management and Incident Leadership, Innovation Mindset with Focus on Emerging Technologies, Strong Communication
& Presentation Skills, and Continuous Learning and Technology Curiosity.
📌 Senior Vice President - Information Security (India)
🏢 Infoedge
📍 India