Information Security Manager (Hyderabad)

Information Security Manager (Hyderabad)

27 Sep
|
Mondee
|
Hyderabad

27 Sep

Mondee

Hyderabad

Information Security Lead

Hyderabad, India | Full-time| 8–9 Years Experience

Work Mode:- WFO

Notice:- Immediate to 30days

About the Role

We're looking for a seasoned security leader with 8–9 years of experience to own and scale our enterprise security program. You'll set the strategic direction for information security and cyber risk, build board-level trust in our security posture, and lead a team through a period of rapid growth and technology transformation — including securing the AI systems now central to our product. This role blends governance and strategy with genuine hands-on depth: you'll be as comfortable presenting risk themes to the board as you are stress-testing an LLM for prompt injection.

What You'll Do

Strategy & Governance

- Define and drive the organization's information security and cyber risk strategy, aligned with business objectives.
- Lead enterprise-wide Information Security Governance, Risk, and Compliance (GRC) initiatives — policy, standards, and control frameworks.
- Build board-level visibility into security posture, priorities, governance maturity, and enterprise risk themes.
- Ensure alignment with applicable regulations, standards, and audit requirements (ISO 27001, SOC 2, GDPR, PCI-DSS, NIST, CMMC/FedRAMP as applicable).

Cloud, Application & Infrastructure Security

- Own cloud security posture across AWS, Azure, and GCP — including CNAPP, CSPM, and workload protection for cloud-native and containerized environments.
- Embed security into the SDLC through DevSecOps practices: SAST/DAST, dependency scanning, and secure code review gates in CI/CD pipelines.
- Lead security initiatives spanning cloud, application, infrastructure, and data protection, plus broader cyber resilience.
- Own identity and access strategy — least-privilege access, MFA, and privileged access management (PAM).

Security Operations & Risk

- Strengthen security operations through automation,



proactive threat detection (SIEM/XDR), incident response, and vulnerability management.
- Own incident response readiness — playbooks, tabletop exercises, and post-incident root-cause reviews.
- Lead third-party and vendor risk management, including security assessments of critical vendors and supply-chain risk.

AI & Emerging Technology Security

- Drive adoption of AI-led security capabilities — AI-driven threat detection, SOC automation, and governance over the organization's own use of AI/LLM tools.
- Own security of the AI data pipeline: RAG access controls, vector database permissions, PII redaction in prompts and logs, and keeping customer data out of training and model memorization.
- Define least-privilege scoping for non-human identities and AI agents that touch bookings, payments, or PII, with explicit tool and function-call boundaries.
- Evaluate third-party AI supply-chain risk — security review of model and API vendors, DPAs, and data-flow mapping for every external AI service.
- Build AI-specific incident response playbooks covering model misbehavior, AI-assisted social engineering, and deepfake-driven fraud.
- Threat-model agent workflows and build evaluation harnesses as part of a secure SDLC for AI features — not one-off checklist reviews.

Leadership & Culture

- Provide leadership and direction across security functions while enabling business growth and technology transformation.
- Partner closely with DevSecOps, Engineering, IT Operations, Cloud, Product, Privacy, Audit, and Business teams.




- Foster a strong security culture through awareness, enablement, accountability, and genuine business partnership.

What We're Looking For Experience & Core Expertise

- 8–9 years of experience in Information Security / Cybersecurity leadership roles.
- Strong track record in security governance, strategy, cyber risk management, and enterprise security operations, with hands-on GRC tooling experience.
- Working knowledge of security regulations and frameworks, including ISO 27001, SOC 2, GDPR, PCI-DSS, NIST, and CMMC/FedRAMP where relevant.
- Global compliance exposure — comfortable navigating regulatory frameworks across the US, Middle East, India, and Europe.
- Proven experience leading cross-functional stakeholders and driving organization-wide security initiatives.
- Experience driving security transformation and automation, including hands-on work with monitoring/alerting tools such as Splunk, Datadog, or Azure Sentinel.
- Strong stakeholder management skills, with experience presenting to senior leadership and board-level forums.
- Experience working in regulated environments with direct exposure to regulatory and audit engagements.

AI Security Depth

- Hands-on AI red-teaming experience — prompt injection, jailbreak resistance, and data exfiltration through LLM outputs. You should have actually broken models, not just read about it.
- Practical understanding of AI regulation, including EU AI Act obligations for high-risk systems, alongside SOC 2, ISO 27001, GDPR, and India's DPDP Act.
- Familiarity with CNAPP, cloud-native security, DevSecOps, and modern enterprise security architecture.

Nice to Have

- Prior experience in fintech, insurtech, internet, SaaS, or other large-scale digital organizations.
- Relevant certifications such as CISSP, CISM, CCSP, CISA, or ISO 27001 Lead Implementer/Auditor.

📌 Information Security Manager (Hyderabad)
🏢 Mondee
📍 Hyderabad

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: information security manager (hyderabad) / hyderabad

Subscribe to this job alert:

Get the latest job offers by email for: information security manager (hyderabad) / hyderabad