Experience: 12-15 years
nWe are looking for a Manager, IT & Security to build, operate, and scale a secure, resilient, and audit-ready technology environment — with equal ownership across enterprise IT and information security.
nKey Responsibilities:
n1. Enterprise IT & Infrastructure Leadership
n
n
- Own and scale global IT operations — end-user computing, networks, cloud infrastructure, and office IT for a distributed workforce.
n
- Dogfood our own product stack (ZTNA, MFA, SSO, MDM, virtualization) as the foundation of internal IT architecture — serving as both a validation environment and a reference implementation for customers.
n
- Design secure, identity-driven enterprise architecture with conditional access, device posture enforcement, and zero-trust segmentation.
n
- Drive adoption of zero-trust and least-privilege models across all infrastructure layers.
n
- Ensure high availability, performance, and resilience of internal systems with defined SLA targets.
n
- Implement cloud security posture management (CSPM) and cloud workload protection (CWPP) across cloud environments.
n
n2.
Security
Strategy & Operations
n
n
- Define and execute the organization's information security strategy, aligned to business objectives and the evolving threat landscape.
n
- Build and lead capabilities across:
n
- Security operations center (SOC) — with AI-augmented monitoring, detection, and response.
n
- Vulnerability management and patching with defined SLA-driven remediation timelines.
n
- Identity and access governance across internal and product environments.
n
- Establish threat-informed defense models aligned to frameworks like MITRE ATT&CK.;
n
- Deploy and evolve AI-native security tooling for automated threat detection, anomaly identification, and intelligent alerting to reduce analyst burden and improve response times.
n
n3. AI & Emerging Technology Security
n
n
- Own the security governance framework for AI/ML usage across the organization — both internal tools and product-embedded capabilities.
n
- Address AI-specific threat vectors including:
n
- LLM-assisted phishing and deepfake-based social engineering.
n
- Prompt injection, data exfiltration via AI tools, and model manipulation risks.
n
- Shadow AI usage and ungoverned adoption of generative AI by employees.
n
- Define acceptable use policies and technical controls for AI tools (e.g., data classification rules for LLM inputs, approved tool lists, access controls for model endpoints).
n
- Evaluate and integrate AI-driven capabilities into the security operations stack — automated triage, behavioral analytics, predictive threat intelligence.
n
- Stay current on regulatory developments related to AI governance and data protection (e.g., EU AI Act, emerging regional frameworks).
n
n4. Product & Platform Security
n
n
- Partner with engineering to embed secure SDLC practices with security gates at each stage of the development lifecycle.
n
- Drive security architecture reviews across the product portfolio, with particular focus on:
n
- Authentication and authorization layers (MFA, SSO, biometric authentication).
n
- ZTNA and VPN / VDI / workspace access components.
n
- MDM and endpoint management services.
n
- Secure OS and USB-based deployment surfaces.
n
- API and cloud-native services.
n
- Implement and mature:
n
- SAST, DAST, SCA, and SBOM practices with automated integration into CI/CD pipelines.
n
- Threat modeling (STRIDE or equivalent) as a standard practice for new features and architecture changes.
n
- Own software supply chain security — dependency integrity,
build pipeline security, and provenance verification.
n
- Act as the internal authority on customer-facing product security posture — particularly critical given that our products are themselves security tools evaluated by CISOs and security teams.
n
n5. Data Protection, Privacy & Security (DPO)
n
n
- Serve as the organization's Data Protection Officer (DPO), with accountability for data privacy compliance across all 12 operating countries.
n
- Define and enforce data classification, data loss prevention (DLP), and encryption strategies (at rest, in transit, and in use) — across products and internal systems.
n
- Partner with product and engineering to embed privacy-by-design principles, particularly for products handling customer identity and access data.
n
- Own data protection impact assessments (DPIAs) for new products, features, and data processing activities.
n
- Ensure alignment between data handling practices and regulatory requirements across all operating geographies (GDPR, India's DPDP Act, and regional data protection laws).
n
- Own data retention, anonymization, and cross-border data transfer policies — including standard contractual clauses (SCCs) and binding corporate rules where required.
n
- Act as the primary point of contact for data protection authorities across jurisdictions.
n
n6. Compliance, Risk & Governance
n
n
- Lead and maintain certifications such as ISO/IEC 27001, SOC 2 Type II, and regional regulatory requirements across operating geographies.
n
- Build audit-ready evidence frameworks — automated where possible — to reduce certification overhead and audit preparation time.
n
- Manage:
n
- Risk assessments (enterprise + product) with quantified risk scoring.
n
- Third-party and vendor risk programs with defined assessment cadence.
n
- Software supply chain risk as part of the broader vendor and dependency risk posture.
n
- Multi-country regulatory interactions and customer security reviews.
n
n7.
Customer
Trust & External Interface
n
n
- Represent the company in security due diligence discussions with enterprise customers (CISOs, CIOs, Risk leaders) — with the understanding that as a security vendor, our own posture is scrutinized to a higher standard.
n
- Own responses to:
n
- Security questionnaires.
n
- RFP/RFI security sections.
n
- Regulatory inquiries.
n
- Build a trust narrative that positions our internal security practices as proof of our product philosophy — we secure ourselves with the same tools we sell.
n
- Contribute to sales enablement by reducing security-related friction in enterprise deal cycles across all 12 operating countries.
n
n8.
Incident
Response & Resilience
n
n
- Define and operationalize incident response and crisis management frameworks with clear escalation paths and communication protocols.
n
- Conduct regular:
n
- Tabletop exercises with cross-functional participation.
n
- Red team / blue team simulations (including AI-augmented adversary simulations).
n
- Ensure alignment between cyber resilience and business continuity / disaster recovery planning.
n
- Define and track incident response metrics — Mean Time to Detect (MTTD), Mean Time to Respond (MTTR), and Mean Time to Recover.
n
n9.
Security
Culture & Awareness
n
n
- Build and run a security awareness program for 300+ employees across multiple countries — including phishing simulations, role-specific training, and onboarding security modules.
n
- Establish a developer security champions program to distribute security ownership across engineering teams — especially critical in a company whose products are security tools.
n
- Foster a culture where security is everyone's responsibility, not a bottleneck or afterthought.
n
n10. Team & Capability Building
n
n
- Inherit and lead an existing team of 10 — 6 in IT Operations and 4 in Security — and grow the function by approximately 20% over the next 12 months (to ~12 people).
n
- Assess current capabilities, identify gaps, and hire strategically to build depth across security engineering, GRC, product security, and data protection.
n
- Structure teams across:
n
- IT Operations
n
- Security Engineering & Operations
n
- GRC, Compliance & Data Protection
n
- Product Security
n
- Customer Trust & Assurance
n
- Establish 24x7 readiness where required for enterprise support, with clear on-call structures and escalation protocols.
n
nExperience:
n
n
- 12–15 years across IT, security, and infrastructure roles, with a progression from hands-on technical work to building and leading teams.
n
- Experience as a Manager / Head of Security / IT / Security Architect in a product company (strong preference for security, identity, or infrastructure product companies) or technology-led enterprise setting.
n
- Strong exposure to regulated industries (BFSI, healthcare, SaaS serving regulated clients).
n
- Track record of building security programs that directly enabled revenue (shortened deal cycles, won enterprise accounts, achieved certifications that unlocked market segments).
n
- Experience operating across multiple geographies and regulatory environments is strongly preferred.
n
nTechnical Depth
n
n
- Identity and access systems (SSO, MFA, IAM, SCIM, directory services, biometric authentication) ideally with experience in organizations that build these products.
n
- Virtualization and secure workspace technologies (VDI, virtual desktops, thin-client architectures).
n
- Endpoint and mobile device security (MDM, device posture, zero-trust network access).
n
- Cloud security CSPM, CWPP, IAM policies, network segmentation across AWS/Azure/GCP.
n
- AI/ML security governance frameworks, LLM risk management, AI-augmented security operations.
n
- Software supply chain security SBOM management, dependency scanning, build integrity.
n
- Secure OS and hardware-rooted security concepts (bootable secure environments, USB-based OS deployment).
n
- Proficiency with modern security tooling (SIEM/SOAR platforms, EDR, vulnerability scanners, cloud-native security tools).
n
nSecurity & Risk
n
n
- Strong grounding in threat modeling, adversary simulation, vulnerability management with SLA-driven remediation, and incident response and crisis management.
n
- Hands-on understanding of adversary behavior, attack paths, and AI-enhanced threat vectors.
n
nCompliance, Governance & Data Protection
n
n
- Deep familiarity with ISO/IEC 27001, SOC 2 Type II.
n
- Data protection regulations across multiple jurisdictions (GDPR, India's DPDP Act, regional equivalents).
n
- DPO responsibilities — data protection impact assessments, breach notification obligations, cross-border transfer mechanisms (SCCs, adequacy decisions).
n
- Emerging AI governance frameworks (EU AI Act and equivalents).
n
📌 Information Technology Security Manager (Pune)
🏢 Accops
📍 Pune