Live opening · Posted 11 days ago

Head of Information - Security and IT

1Buy.AI · Delhi
Instahyre 6-10 yrs
You are 11 days behind. JobBeeper subscribers saw this role while it was still new.

At a glance

The key details from the original listing.

Posted 11 days ago
Company1Buy.AI
LocationDelhi
Experience6-10 yrs
SourceInstahyre
Listed11 days ago

Your early-applicant advantage

Live timing from JobBeeper.

Live data
0 min from Instahyre publishing this role to us finding it
22 min median time from a role going live to a subscriber being told
6 hours subscribers had this role before this page existed
16,030 roles found in the last 24 hours — the newest are not on this site yet
Start your free trial →

About the role

Description supplied by the original job listing.

As the Head of Information Security & IT, you will own the company's security posture, cloud infrastructure, DevSecOps practices, and internal IT operations. This is a hands-on + strategic leadership role, where you will build security and IT systems from scratch in an AI-first B2B SaaS environment.
The candidate will have responsibilities across the following functions:
Security and Compliance (SOC 2 ISO 27001):
Drive SOC 2 Type 2 certification end-to-end (policies, controls, audit readiness).
Ensure compliance with ISO 27001 GDPR, and DPDP Act.
Define security policies, access controls, incident response, and data governance.
Act as SPOC for auditors, client security reviews, and due diligence.
DevSecOps and Application Security:
Implement SAST/DAST tools (SonarQube, Snyk, OWASP, etc. )
Integrate security into CI/CD pipelines (GitHub, Jenkins).
Own vulnerability management and remediation tracking.
Conduct penetration testing and security code reviews.
Cloud Security and AWS Management:
Manage AWS infrastructure (IAM, VPC, S3 KMS, CloudTrail, GuardDuty).
Enforce least privilege access and encryption standards.
Implement Infrastructure-as-Code security (Terraform/CloudFormation).
Manage cloud cost optimisation and disaster recovery planning.
Network and Endpoint Security:
Design and manage network security architecture (WAF, VPN, DDoS protection).
Implement zero-trust security models.
Monitor network traffic and threat detection systems.
Manage endpoint security (MDM, EDR).
IT Operations and Vendor Management:
Manage Google Workspace and internal IT systems.
Implement SIEM tools (Splunk or equivalent) for monitoring and alerts.
Oversee vendor risk management and security compliance.
Handle IT operations (onboarding, access control, hardware, licenses).
Requirements:
6-12 years in Information Security / IT / DevSecOps.
Experience leading SOC 2 Type 2 / ISO 27001 compliance.
Strong expertise in AWS cloud and security architecture.
Hands-on experience with DevSecOps and CI/CD security integration.
Experience managing SaaS tools, vendors, and IT operations.
Strong understanding of network security and zero-trust architecture.
Good to Have:
Experience with Scrut, Vanta, and Drata.
Exposure to SIEM tools (Splunk, Datadog).
Certifications like CISSP, CISM, CCSP, AWS Security.
Startup experience (building systems from scratch).
Exposure to the B2B SaaS/supply chain domain.

Experience
6-10 yrs

Get JobBeeper Mobile App

Never miss a job opening! Get instant job alerts on your phone.

Subscribers see fresh openings within minutes. Download the JobBeeper App on Google Play to get real-time push notifications and apply before anyone else.

⚡ Instant Push Alerts 🎯 Tailored Filters 🚀 Direct Employer Links
GET IT ON Google Play

More openings worth a look

Recently tracked roles with full details and direct application links.

6 roles
Good roles move before most people even see them. Tell JobBeeper what you want and get fresh matches delivered in minutes.
Start your free trial →
⚡ Get fresh job alerts 📱 Get App