Job Description
Information Security Lead
/n
Hyderabad, India | Full time| 8–9 Years Experience
/n
Work Mode:- WFO
/n
Notice:- Immediate to 30days
/n
About the Role
/n
We're looking for a seasoned security leader with 8–9 years of experience to own and scale our enterprise security program. You'll set the strategic direction for information security and cyber risk, build board-level trust in our security posture, and lead a team through a period of rapid growth and technology transformation — including securing the AI systems now central to our product. This role blends governance and strategy with genuine hands-on depth: you'll be as comfortable presenting risk themes to the board as you are stress-testing an LLM for prompt injection.
/n
What You'll Do
/n
Strategy & Governance
/n
/n
Define and drive the organization's information security and cyber risk strategy, aligned with business objectives.
/n
Lead enterprise-wide Information Security Governance, Risk, and Compliance (GRC) initiatives — policy, standards, and control frameworks.
/n
Build board-level visibility into security posture, priorities, governance maturity, and enterprise risk themes.
/n
Ensure alignment with applicable regulations, standards, and audit requirements (ISO 27001, SOC 2, GDPR, PCI-DSS, NIST, CMMC/FedRAMP as applicable).
/n
/n
Cloud, Application & Infrastructure Security
/n
/n
Own cloud security posture across AWS, Azure, and GCP — including CNAPP, CSPM, and workload protection for cloud-native and containerized settings.
/n
Embed security into the SDLC through DevSecOps practices: SAST/DAST, dependency scanning, and secure code review gates in CI/CD pipelines.
/n
Lead security initiatives spanning cloud, application, infrastructure, and data protection, plus broader cyber resilience.
/n
Own identity and access strategy — least-privilege access, MFA, and privileged access management (PAM).
/n
/n
Security Operations & Risk
/n
/n
Strengthen sec
📌 Information Security Manager Hyderabad (India)
🏢 Mondee
📍 India