28 Sep
|
Mondee
|
Hyderabad
Information Security Lead
nHyderabad, India | Full-time| 8–9 Years Experience
n
nWork Mode:- WFO
nNotice:- Immediate to 30days
n
nAbout the Role
nWe're looking for a seasoned security leader with 8–9 years of experience to own and scale our enterprise security program. You'll set the strategic direction for information security and cyber risk, build board-level trust in our security posture, and lead a team through a period of rapid growth and technology transformation — including securing the AI systems now central to our product. This role blends governance and strategy with genuine hands-on depth: you'll be as comfortable presenting risk themes to the board as you are stress-testing an LLM for prompt injection.
nWhat You'll Do
nStrategy & Governance
n
n
- Define and drive the organization's information security and cyber risk strategy, aligned with business objectives.
n
- Lead enterprise-wide Information Security Governance, Risk, and Compliance (GRC) initiatives — policy, standards, and control frameworks.
n
- Build board-level visibility into security posture, priorities, governance maturity, and enterprise risk themes.
n
- Ensure alignment with applicable regulations, standards, and audit requirements (ISO 27001, SOC 2, GDPR, PCI-DSS, NIST, CMMC/FedRAMP as applicable).
n
nCloud, Application & Infrastructure Security
n
n
- Own cloud security posture across AWS, Azure, and GCP — including CNAPP, CSPM, and workload protection for cloud-native and containerized environments.
n
- Embed security into the SDLC through DevSecOps practices: SAST/DAST, dependency scanning, and secure code review gates in CI/CD pipelines.
n
- Lead security initiatives spanning cloud, application, infrastructure, and data protection, plus broader cyber resilience.
n
- Own identity and access strategy — least-privilege access, MFA, and privileged access management (PAM).
n
nSecurity Operations & Risk
n
n
- Strengthen security operations through automation,
proactive threat detection (SIEM/XDR), incident response, and vulnerability management.
n
- Own incident response readiness — playbooks, tabletop exercises, and post-incident root-cause reviews.
n
- Lead third-party and vendor risk management, including security assessments of critical vendors and supply-chain risk.
n
nAI & Emerging Technology Security
n
n
- Drive adoption of AI-led security capabilities — AI-driven threat detection, SOC automation, and governance over the organization's own use of AI/LLM tools.
n
- Own security of the AI data pipeline: RAG access controls, vector database permissions, PII redaction in prompts and logs, and keeping customer data out of training and model memorization.
n
- Define least-privilege scoping for non-human identities and AI agents that touch bookings, payments, or PII, with clear tool and function-call boundaries.
n
- Evaluate third-party AI supply-chain risk — security review of model and API vendors, DPAs, and data-flow mapping for every external AI service.
n
- Build AI-specific incident response playbooks covering model misbehavior, AI-assisted social engineering, and deepfake-driven fraud.
n
- Threat-model agent workflows and build evaluation harnesses as part of a secure SDLC for AI features — not one-off checklist reviews.
n
nLeadership & Culture
n
n
- Provide leadership and direction across security functions while enabling business growth and technology transformation.
n
- Partner closely with DevSecOps, Engineering, IT Operations, Cloud, Product, Privacy, Audit, and Business teams.
n
- Foster a solid security culture through awareness, enablement, accountability, and genuine business partnership.
n
nWhat We're Looking For
nExperience & Core Expertise
n
n
- 8–9 years of experience in Information Security / Cybersecurity leadership roles.
n
- Strong track record in security governance, strategy, cyber risk management, and enterprise security operations, with hands-on GRC tooling experience.
n
- Working knowledge of security regulations and frameworks, including ISO 27001, SOC 2, GDPR, PCI-DSS, NIST, and CMMC/FedRAMP where relevant.
n
- Global compliance exposure — comfortable navigating regulatory frameworks across the US, Middle East, India, and Europe.
n
- Proven experience leading cross-functional stakeholders and driving organization-wide security initiatives.
n
- Experience driving security transformation and automation, including hands-on work with monitoring/alerting tools such as Splunk, Datadog, or Azure Sentinel.
n
- Strong stakeholder management skills, with experience presenting to senior leadership and board-level forums.
n
- Experience working in regulated environments with direct exposure to regulatory and audit engagements.
n
nAI Security Depth
n
n
- Hands-on AI red-teaming experience — prompt injection, jailbreak resistance, and data exfiltration through LLM outputs. You should have actually broken models, not just read about it.
n
- Practical understanding of AI regulation, including EU AI Act obligations for high-risk systems, alongside SOC 2, ISO 27001, GDPR, and India's DPDP Act.
n
- Familiarity with CNAPP, cloud-native security, DevSecOps, and modern enterprise security architecture.
n
nNice to Have
n
n
- Prior experience in fintech, insurtech, internet, SaaS, or other large-scale digital organizations.
n
- Relevant certifications such as CISSP, CISM, CCSP, CISA, or ISO 27001 Lead Implementer/Auditor.
n
n
📌 Information Security Manager (Hyderabad)
🏢 Mondee
📍 Hyderabad