Security Manager

Accops

Pune District

On-site

INR 1,400,000 - 2,100,000

Full time

7 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Accops, a security-focused enterprise, seeks a Manager, IT & Security to build and scale a secure, audit-ready tech environment across a distributed workforce. You will own IT operations, security strategy, and data protection, driving a zero-trust architecture and AI-driven defenses in a product‑led organization.

You will lead SOC, vulnerability management, and governance programs across multiple geographies, ensuring compliance with GDPR, DPDP, and regional laws while partnering with

Qualifications

  • 12–15 years across IT, security, and infrastructure roles.
  • Experience as a Manager / Head of Security / IT in a product or technology environment.
  • Experience across multiple geographies and regulatory environments.
  • Strong governance, risk management, and compliance background.

Responsibilities

  • Lead IT operations, security, and data protection across a global distributed workforce.
  • Implement zero-trust, CSPM, CWPP, and AI-driven security tooling.
  • Oversee SOC operations, vulnerability management, and incident response.
  • Partner with engineering on secure SDLC and product security reviews.
  • Ensure GDPR, DPDP and cross-border data transfer compliance.
  • Build enterprise security capability across 12+ countries and establish 24x7 readiness.

Skills

IT operations
Security engineering
GRC
Data protection
Cloud security
AI governance
Threat modeling
Incident response
Security architecture
Identity & access governance

Tools

SIEM/SOAR
EDR
Vulnerability scanners
SBOM tooling
Cloud-native security tools

Job description

We are looking for a Manager, IT & Security to build, operate, and scale a secure, resilient, and audit-ready technology environment — with equal ownership across enterprise IT and information security.

Key Responsibilities:
  • Own and scale global IT operations — end-user computing, networks, cloud infrastructure, and office IT for a distributed workforce.
  • Dogfood our own product stack (ZTNA, MFA, SSO, MDM, virtualization) as the foundation of internal IT architecture — serving as both a validation environment and a reference implementation for customers.
  • Design secure, identity-driven enterprise architecture with conditional access, device posture enforcement, and zero-trust segmentation.
  • Drive adoption of zero-trust and least-privilege models across all infrastructure layers.
  • Ensure high availability, performance, and resilience of internal systems with defined SLA targets.
  • Implement cloud security posture management (CSPM) and cloud workload protection (CWPP) across cloud environments.
2. Security Strategy & Operations
  • Define and execute the organization’s information security strategy, aligned to business objectives and the evolving threat landscape.
  • Build and lead capabilities across:
  • Security operations center (SOC) — with AI-augmented monitoring, detection, and response.
  • Vulnerability management and patching with defined SLA-driven remediation timelines.
  • Identity and access governance across internal and product environments.
  • Establish threat-informed defense models aligned to frameworks like MITRE ATT&CK.
  • Deploy and evolve AI-native security tooling for automated threat detection, anomaly identification, and intelligent alerting to reduce analyst burden and improve response times.
  • Own the security governance framework for AI/ML usage across the organization — both internal tools and product-embedded capabilities.
  • Address AI-specific threat vectors including:
  • LLM-assisted phishing and deepfake-based social engineering.
  • Prompt injection, data exfiltration via AI tools, and model manipulation risks.
  • Shadow AI usage and ungoverned adoption of generative AI by employees.
  • Define acceptable use policies and technical controls for AI tools (e.g., data classification rules for LLM inputs, approved tool lists, access controls for model endpoints).
  • Evaluate and integrate AI-driven capabilities into the security operations stack — automated triage, behavioral analytics, predictive threat intelligence.
  • Stay current on regulatory developments related to AI governance and data protection (e.g., EU AI Act, emerging regional frameworks).
4. Product & Platform Security
  • Partner with engineering to embed secure SDLC practices with security gates at each stage of the development lifecycle.
  • Drive security architecture reviews across the product portfolio, with particular focus on:
  • Authentication and authorization layers (MFA, SSO, biometric authentication).
  • ZTNA and VPN / VDI / workspace access components.
  • MDM and endpoint management services.
  • Secure OS and USB-based deployment surfaces.
  • API and cloud-native services.
  • Implement and mature:
  • SAST, DAST, SCA, and SBOM practices with automated integration into CI/CD pipelines.
  • Threat modeling (STRIDE or equivalent) as a standard practice for new features and architecture changes.
  • Own software supply chain security — dependency integrity, build pipeline security, and provenance verification.
  • Act as the internal authority on customer-facing product security posture — particularly critical given that our products are themselves security tools evaluated by CISOs and security teams.
5. Data Protection, Privacy & Security (DPO)
  • Serve as the organization’s Data Protection Officer (DPO), with accountability for data privacy compliance across all 12 operating countries.
  • Define and enforce data classification, data loss prevention (DLP), and encryption strategies (at rest, in transit, and in use) — across products and internal systems.
  • Partner with product and engineering to embed privacy-by-design principles, particularly for products handling customer identity and access data.
  • Own data protection impact assessments (DPIAs) for new products, features, and data processing activities.
  • Ensure alignment between data handling practices and regulatory requirements across all operating geographies (GDPR, India’s DPDP Act, and regional data protection laws).
  • Own data retention, anonymization, and cross-border data transfer policies — including standard contractual clauses (SCCs) and binding corporate rules where required.
  • Act as the primary point of contact for data protection authorities across jurisdictions.
  • Lead and maintain certifications such as ISO/IEC 27001, SOC 2 Type II, and regional regulatory requirements across operating geographies.
  • Build audit-ready evidence frameworks — automated where possible — to reduce certification overhead and audit preparation time.
  • Manage:
  • Risk assessments (enterprise + product) with quantified risk scoring.
  • Third-party and vendor risk programs with defined assessment cadence.
  • Software supply chain risk as part of the broader vendor and dependency risk posture.
  • Multi-country regulatory interactions and customer security reviews.
7. Customer Trust & External Interface
  • Represent the company in security due diligence discussions with enterprise customers (CISOs, CIOs, Risk leaders) — with the understanding that as a security vendor, our own posture is scrutinized to a higher standard.
  • Own responses to:
  • RFP/RFI security sections.
  • Regulatory inquiries.
  • Build a trust narrative that positions our internal security practices as proof of our product philosophy — we secure ourselves with the same tools we sell.
  • Contribute to sales enablement by reducing security-related friction in enterprise deal cycles across all 12 operating countries.
  • Define and operationalize incident response and crisis management frameworks with clear escalation paths and communication protocols.
  • Conduct regular:
  • Tabletop exercises with cross-functional participation.
  • Red team / blue team simulations (including AI-augmented adversary simulations).
  • Ensure alignment between cyber resilience and business continuity / disaster recovery planning.
  • Define and track incident response metrics — Mean Time to Detect (MTTD), Mean Time to Respond (MTTR), and Mean Time to Recover.
9. Security Culture & Awareness
  • Build and run a security awareness program for 300+ employees across multiple countries — including phishing simulations, role‑specific training, and onboarding security modules.
  • Establish a developer security champions program to distribute security ownership across engineering teams — especially critical in a company whose products are security tools.
  • Foster a culture where security is everyone’s responsibility, not a bottleneck or afterthought.
10. Team & Capability Building
  • Inherit and lead an existing team of 10 — 6 in IT Operations and 4 in Security — and grow the function by approximately 20% over the next 12 months (to ~12 people).
  • Assess current capabilities, identify gaps, and hire strategically to build depth across security engineering, GRC, product security, and data protection.
  • Structure teams across:
  • IT Operations
  • Security Engineering & Operations
  • GRC, Compliance & Data Protection
  • Product Security
  • Customer Trust & Assurance
  • Establish 24x7 readiness where required for enterprise support, with clear on‑call structures and escalation protocols.
Experience:
  • 12–15 years across IT, security, and infrastructure roles, with a progression from hands‑on technical work to building and leading teams.
  • Experience as a Manager / Head of Security / IT / Security Architect in a product company (strong preference for security, identity, or infrastructure product companies) or technology‑led enterprise environment.
  • Strong exposure to regulated industries (BFSI, healthcare, SaaS serving regulated clients).
  • Track record of building security programs that directly enabled revenue (shortened deal cycles, won enterprise accounts, achieved certifications that unlocked market segments).
  • Experience operating across multiple geographies and regulatory environments is strongly preferred.
Technical Depth
  • Identity and access systems (SSO, MFA, IAM, SCIM, directory services, biometric authentication) ideally with experience in organizations that build these products.
  • Virtualization and secure workspace technologies (VDI, virtual desktops, thin‑client architectures).
  • Endpoint and mobile device security (MDM, device posture, zero‑trust network access).
  • Cloud security CSPM, CWPP, IAM policies, network segmentation across AWS/Azure/GCP.
  • AI/ML security governance frameworks, LLM risk management, AI‑augmented security operations.
  • Software supply chain security SBOM management, dependency scanning, build integrity.
  • Secure OS and hardware‑rooted security concepts (bootable secure environments, USB‑based OS deployment).
  • Proficiency with modern security tooling (SIEM/SOAR platforms, EDR, vulnerability scanners, cloud‑native security tools).
Security & Risk
  • Strong grounding in threat modeling, adversary simulation, vulnerability management with SLA‑driven remediation, and incident response and crisis management.
  • Hands‑on understanding of adversary behavior, attack paths, and AI‑enhanced threat vectors.
Compliance, Governance & Data Protection
  • Deep familiarity with ISO/IEC 27001, SOC 2 Type II.
  • Data protection regulations across multiple jurisdictions (GDPR, India’s DPDP Act, regional equivalents).
  • DPO responsibilities — data protection impact assessments, breach notification obligations, cross‑border transfer mechanisms (SCCs, adequacy decisions).
  • Emerging AI governance frameworks (EU AI Act and equivalents).
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Security Manager
Information Security Manager

Mondee • Hyderabad

On-site
INR 3,500,000 - 7,000,000
Security Engineering Manager
Security Engineering Manager

SmartStream • India

On-site
INR 4,000,000 - 6,000,000
Senior Product Security Engineer
Senior Product Security Engineer

Whatfix • Bengaluru

On-site
INR 4,200,000 - 7,000,000
Security Engineering Manager
Security Engineering Manager

Smartstream Limited • Bengaluru

On-site
INR 4,000,000 - 7,000,000
Principal Engineer- Info Sec
Principal Engineer- Info Sec

Acuity Analytics • Maharashtra

On-site
INR 1,500,000 - 2,100,000
Opening For Cybersecurity GRC & Compliance (Media, Telco & Healthcare)
Opening For Cybersecurity GRC & Compliance (Media, Telco & Healthcare)

Staffing Services • Bengaluru

On-site
INR 2,500,000 - 5,000,000
Information Security Manager
Information Security Manager

SaaS Labs, Inc • India

On-site
INR 4,000,000 - 7,000,000
Principal Engineer- Information security
Principal Engineer- Information security

Acuity Analytics • Pune District, Gurugram District, Bengaluru

On-site
INR 1,800,000 - 2,600,000
Senior Product Security Engineer
Senior Product Security Engineer

Whatfix Inc. • Bengaluru

On-site
INR 2,500,000 - 4,500,000
Sr Lead - IT Risk & GRC
Sr Lead - IT Risk & GRC

Star Union Dai-ichi Life Insurance Company Limited • Navi Mumbai

On-site
INR 1,500,000 - 2,500,000