← Browse all jobs

M

Information Security Manager

Mondee · India

FULL TIME

Job Description

Information Security Lead

Hyderabad, India | Full-time| 8–9 Years Experience

Work Mode:- WFO

Notice:- Immediate to 30days

About the Role

We're looking for a seasoned security leader with 8–9 years of experience to own and scale our enterprise security program. You'll set the strategic direction for information security and cyber risk, build board-level trust in our security posture, and lead a team through a period of rapid growth and technology transformation — including securing the AI systems now central to our product. This role blends governance and strategy with genuine hands-on depth: you'll be as comfortable presenting risk themes to the board as you are stress-testing an LLM for prompt injection.

What You'll Do

Strategy & Governance

  • Define and drive the organization's information security and cyber risk strategy, aligned with business objectives.
  • Lead enterprise-wide Information Security Governance, Risk, and Compliance (GRC) initiatives — policy, standards, and control frameworks.
  • Build board-level visibility into security posture, priorities, governance maturity, and enterprise risk themes.
  • Ensure alignment with applicable regulations, standards, and audit requirements (ISO 27001, SOC 2, GDPR, PCI-DSS, NIST, CMMC/FedRAMP as applicable).

Cloud, Application & Infrastructure Security

  • Own cloud security posture across AWS, Azure, and GCP — including CNAPP, CSPM, and workload protection for cloud-native and containerized environments.
  • Embed security into the SDLC through DevSecOps practices: SAST/DAST, dependency scanning, and secure code review gates in CI/CD pipelines.
  • Lead security initiatives spanning cloud, application, infrastructure, and data protection, plus broader cyber resilience.
  • Own identity and access strategy — least-privilege access, MFA, and privileged access management (PAM).

Security Operations & Risk

  • Strengthen security operations through automation, proactive threat detection (SIEM/XDR), incident response, and vulnerability management.
  • Own incident response readiness — playbooks, tabletop exercises, and post-incident root-cause reviews.
  • Lead third-party and vendor risk management, including security assessments of critical vendors and supply-chain risk.

AI & Emerging Technology Security

  • Drive adoption of AI-led security capabilities — AI-driven threat detection, SOC automation, and governance over the organization's own use of AI/LLM tools.
  • Own security of the AI data pipeline: RAG access controls, vector database permissions, PII redaction in prompts and logs, and keeping customer data out of training and model memorization.
  • Define least-privilege scoping for non-human identities and AI agents that touch bookings, payments, or PII, with clear tool and function-call boundaries.
  • Evaluate third-party AI supply-chain risk — security review of model and API vendors, DPAs, and data-flow mapping for every external AI service.
  • Build AI-specific incident response playbooks covering model misbehavior, AI-assisted social engineering, and deepfake-driven fraud.
  • Threat-model agent workflows and build evaluation harnesses as part of a secure SDLC for AI features — not one-off checklist reviews.

Leadership & Culture

  • Provide leadership and direction across security functions while enabling business growth and technology transformation.
  • Partner closely with DevSecOps, Engineering, IT Operations, Cloud, Product, Privacy, Audit, and Business teams.
  • Foster a strong security culture through awareness, enablement, accountability, and genuine business partnership.

What We're Looking For

Experience & Core Expertise

  • 8–9 years of experience in Information Security / Cybersecurity leadership roles.
  • Strong track record in security governance, strategy, cyber risk management, and enterprise security operations, with hands-on GRC tooling experience.
  • Working knowledge of security regulations and frameworks, including ISO 27001, SOC 2, GDPR, PCI-DSS, NIST, and CMMC/FedRAMP where relevant.
  • Global compliance exposure — comfortable navigating regulatory frameworks across the US, Middle East, India, and Europe.
  • Proven experience leading cross-functional stakeholders and driving organization-wide security initiatives.
  • Experience driving security transformation and automation, including hands-on work with monitoring/alerting tools such as Splunk, Datadog, or Azure Sentinel.
  • Strong stakeholder management skills, with experience presenting to senior leadership and board-level forums.
  • Experience working in regulated environments with direct exposure to regulatory and audit engagements.

AI Security Depth

  • Hands-on AI red-teaming experience — prompt injection, jailbreak resistance, and data exfiltration through LLM outputs. You should have actually broken models, not just read about it.
  • Practical understanding of AI regulation, including EU AI Act obligations for high-risk systems, alongside SOC 2, ISO 27001, GDPR, and India's DPDP Act.
  • Familiarity with CNAPP, cloud-native security, DevSecOps, and modern enterprise security architecture.

Nice to Have

  • Prior experience in fintech, insurtech, internet, SaaS, or other large-scale digital organizations.
  • Relevant certifications such as CISSP, CISM, CCSP, CISA, or ISO 27001 Lead Implementer/Auditor.

Details

CompanyMondee
LocationIndia
TypeFULL TIME
Nichegeneral

Similar Jobs

L

IT - OT Security

Lonza

U

Warehouse Worker - Seasonal

United Parcel Service

U

Seasonal Package Handler

United Parcel Service

U

Warehouse Worker - Package Handler

United Parcel Service

U

Seasonal Warehouse Worker

United Parcel Service