An application made for this job — a tailored resume and cover letter that speak straight to the posting.
Hotelecia is seeking a Senior Manager for Infrastructure and Security Operations to lead the Security Operations Centre and drive vulnerability remediation across IT infrastructure and applications.
The role requires strong knowledge of OWASP/STRIDE, experience with security tooling, and governance across security programs. Reporting and collaboration with senior management are key aspects of this position.
PMLI15507
Information Technology
23-Apr-2026
Lead and manage Security Operations Centre and Knowledge of OWASP/ STRIDE Concepts.
Required experience in IT Infrastructure & application domain and broad understanding of infrastructure technologies like OS (Windows & Non-windows), DB, Middleware, Network devices.
Responsibility is reviewing Web & App vulnerabilities like SAST & DAST, data from multiple sources (i.e., External/Internal penetration testing) assist in providing support and resolution for vulnerability remediation to application team.
Maintain Security tool compliance like Security scanner, AV & SIEM.
Actively investigate the latest in security vulnerabilities, advisories, incidents, and provide insights (sources like, Microsoft, Oracle, IBM, Red hat etc.).
Maintain Security patching for Servers, DB, Middleware, Endpoints & Networks device.
Responsible for integration servers in SIEM.
Manage Web Application Firewalls (WAF) to protect web applications from common threats (e.g., SQL injection, cross-site scripting, and DDoS attacks).
Maintain documentation for security controls, incident response, and WAF policies.
Management reporting (daily / weekly / monthly) with remediation plans, progress, and issues.
Familiar with cyber security concepts and industry-best practices.
Responsible for the organization's information security program, providing guidance to key members and the team. This involves working closely with senior management and the three lines of defense in defining objectives for information security, while also building relationships and goodwill.
Manage organization-wide information security governance processes and lead information security planning processes to establish an inclusive and comprehensive information security program with support from the IT teams.
Establish annual and long-range security and compliance goals, define security strategies, metrics, reporting mechanisms, and program services, and create maturity models and a roadmap for continual program improvements.
Ensure information security solutions are successfully implemented by the service providers and system integration partners, operating effectively and being monitored.
Lead, develop, and maintain regulatory compliance & policies/standards. Set and manage the strategic development and tactical implementation of compliance plans. Develop actions and plans with Business/IT executives to address and remediate compliance gaps. Manage the execution of plans and actions for the business.
Understand the risks to the organization beyond the traditional IT risks and be able to articulate how the IT controls fit within the framework of the business.
Develop and implement effective and reasonable policies and practices to secure protected and sensitive data, ensuring information security and compliance with relevant legislation and legal interpretation.
Develop, implement, and administer technical security standards, as well as a suite of security services and tools to address and mitigate security risks in collaboration with vendors, suppliers, and service providers. Provide direction and guidance in assessing and evaluating information security risks and monitor compliance with security standards and appropriate policies.