Skip to content

Head of Information Security

Yanolja Cloud Solution Pvt. Ltd.Surat, GJ, IndiaSeptember 9, 2026
On-site
Full-time
Leadership
Executive

Job Description – Information Security Lead

Organizational Overview

Yanolja Cloud Solution Pvt. Ltd. (YCS) is a global end-to-end hospitality technology provider specializing in solutions for small and medium-sized accommodation businesses.

With more than 400+ team members and 20+ years of experience, YCS currently serves 40,000+ customers across 170+ countries, with 50+ supported languages in our software and a 24/7 support network.

We have local teams across 15+ countries, including India, Thailand, Indonesia, Philippines, Sri Lanka, South Africa, Tanzania, Uganda, USA, Mexico, and counting.

Position Overview

We are looking for an experienced Information Security Lead with a minimum of 10 years of professional experience in cybersecurity and information security to lead and strengthen the security posture of YCS's SaaS products, applications, APIs, cloud infrastructure, internal systems, and customer data.

This is a senior technical leadership role requiring a strong combination of application security, API security, AWS/cloud security, incident response, vulnerability management, security architecture, DevSecOps, and security governance.

The ideal candidate will be capable of independently investigating complex security incidents, challenging technical architecture, working closely with engineering teams, establishing security standards, and driving security vulnerabilities and risks through remediation and closure.

This is not intended to be a purely governance, audit, or SOC-monitoring role. The candidate is expected to remain technically hands-on while providing security leadership across the organization.

Key Responsibilities

1. Information Security Ownership

  • Own and continuously improve the overall information security posture of the organization.
  • Establish security priorities based on business risk, customer impact, and technical exposure.
  • Develop and maintain the organization's security roadmap in collaboration with the CTO and engineering leadership.
  • Act as the primary technical security authority for product, application, API, cloud, and infrastructure security matters.
  • Define security standards, controls, procedures, and technical guidelines.
  • Track security risks and ensure identified issues are driven to closure.

2. Application & API Security

  • Lead security reviews of web applications, APIs, backend services, integrations, and customer-facing platforms.
  • Identify and address vulnerabilities including broken authentication, broken authorization, IDOR/BOLA, injection vulnerabilities, XSS, sensitive data exposure, insecure API endpoints, security misconfigurations, weak session management, and improper tenant isolation.
  • Ensure applications follow OWASP Top 10 and OWASP API Security best practices.
  • Review authentication and authorization mechanisms including OAuth 2.0, JWT, access tokens, refresh tokens, API keys, service-to-service authentication, and RBAC.
  • Review the security of third-party and partner APIs.
  • Work directly with engineering teams to remediate security weaknesses.

3. Multi-Tenant SaaS Security

  • Review and strengthen security controls for multi-tenant SaaS applications.
  • Ensure proper logical separation of customer and tenant data.
  • Validate tenant-level authorization controls across APIs, services, databases, and administrative functions.
  • Identify risks that could allow one customer or hotel to access another customer's information.
  • Review authorization architecture for internal systems, customer applications, and third-party integrations.
  • Ensure sensitive operations have appropriate access controls and audit trails.

4. Cloud & AWS Security

  • Own security reviews of AWS infrastructure and cloud architecture.
  • Review and improve IAM users, roles and policies, privileged access, security groups, VPC and network architecture, S3 permissions, databases, secrets management, encryption, cloud logging, key management, and publicly exposed services.
  • Identify excessive permissions and privilege-escalation risks.
  • Establish least-privilege access across AWS environments.
  • Review cloud architecture before deployment of critical systems.
  • Work closely with DevOps and infrastructure teams to remediate cloud security findings.
  • Ensure appropriate monitoring and alerting using AWS security services and centralized monitoring platforms.

5. Security Incident Response & Investigation

  • Lead investigation of security incidents including suspected customer-data leakage, unauthorized access, credential compromise, malware infections, API misuse, suspicious login activity, cloud compromise, insider threats, and endpoint compromise.
  • Determine incident scope, timeline, root cause, impact, and attack path.
  • Coordinate containment, eradication, recovery, and post-incident remediation.
  • Perform or coordinate forensic analysis across application, database, API, AWS, endpoint, authentication, and network logs.
  • Maintain appropriate evidence and incident documentation.
  • Conduct post-incident reviews and ensure corrective actions are completed.
  • Develop and maintain incident-response playbooks and escalation procedures.

6. Vulnerability Management

  • Own the organization's vulnerability-management program.
  • Establish processes for vulnerability identification, prioritization, remediation, verification, and closure.
  • Manage vulnerabilities identified through penetration testing, SAST, DAST, Software Composition Analysis, cloud-security scans, infrastructure scans, container scans, and security assessments.
  • Prioritize vulnerabilities based on severity, exploitability, internet exposure, customer impact, data sensitivity, and business risk.
  • Define vulnerability-remediation SLAs and escalate overdue critical and high-risk vulnerabilities.
  • Validate security fixes before closing findings.
  • Identify recurring vulnerability patterns and drive systemic improvements.

7. Secure SDLC & DevSecOps

  • Establish and mature Secure SDLC practices.
  • Work with engineering leadership to embed security throughout product development.
  • Participate in architecture and design reviews for critical features.
  • Perform threat modeling for high-risk systems and functionality.
  • Define security requirements before development begins.
  • Integrate automated security controls into CI/CD pipelines, including SAST, DAST, dependency scanning, secret scanning, container scanning, and Infrastructure-as-Code scanning.
  • Establish secure coding guidelines.
  • Conduct security-focused code reviews when required.
  • Help engineering teams understand security vulnerabilities and remediation techniques.
  • Ensure security becomes an engineering responsibility rather than an end-stage compliance activity.

8. Security Architecture

  • Conduct security architecture reviews for new products, major product changes, cloud architecture, APIs, third-party integrations, authentication systems, payment integrations, and customer-data workflows.
  • Identify security threats during design rather than after production deployment.
  • Recommend preventive, detective, and corrective controls.
  • Review trust boundaries, access flows, privilege models, and data flows.
  • Ensure security architecture supports scalability without compromising tenant or customer isolation.

9. Identity & Access Management

  • Establish and review identity and access-management controls.
  • Ensure implementation of least privilege, MFA, RBAC, privileged-access management, Joiner-Mover-Leaver processes, and periodic access reviews.
  • Review privileged user and administrator activity.
  • Identify shared, dormant, unnecessary, or excessive accounts.
  • Review service accounts, API credentials, tokens, and machine identities.
  • Ensure credentials are securely generated, stored, distributed, rotated, and revoked.

10. Security Logging, Monitoring & Detection

  • Define security logging requirements for applications and infrastructure.
  • Ensure appropriate logging across APIs, applications, databases, authentication systems, AWS, network infrastructure, and endpoints.
  • Define critical security events that require monitoring.
  • Improve SIEM detection and alerting capabilities.
  • Develop use cases for detecting suspicious behavior.
  • Review alerts and reduce unnecessary false positives.
  • Ensure critical security logs are appropriately retained and protected from unauthorized modification.

11. Data Security & Privacy

  • Ensure sensitive customer and business data is appropriately protected.
  • Review encryption at rest and in transit, data masking, tokenization, data retention, data-access controls, backup security, and secrets management.
  • Ensure sensitive information is not unnecessarily logged.
  • Review how customer information is shared with partners, vendors, OTAs, and external systems.
  • Investigate suspected data-leakage incidents and determine whether exposure occurred internally or externally.
  • Recommend controls to minimize unnecessary collection and exposure of sensitive information.

12. Third-Party & Vendor Security

  • Lead technical security assessments for third-party vendors and integrations.
  • Review security considerations before onboarding technology vendors.
  • Assess external API integrations and data-sharing mechanisms.
  • Evaluate authentication, authorization, API-key handling, data encryption, credential distribution, and vendor security posture.
  • Track and remediate third-party security risks.
  • Participate in security discussions with enterprise customers and technology partners where required.

13. Penetration Testing & Security Assessments

  • Define scope and objectives for external and internal penetration-testing exercises.
  • Coordinate with penetration-testing vendors.
  • Review findings critically rather than accepting scanner or vendor results at face value.
  • Validate exploitability and business impact.
  • Ensure remediation and retesting are completed.
  • Perform targeted technical security assessments internally when required.

14. Security Governance & Compliance

  • Support security programs aligned with frameworks such as ISO 27001, SOC 2, PCI DSS where applicable, GDPR, and relevant privacy and security regulations.
  • Maintain security policies, standards, procedures, and technical controls.
  • Support internal and external audits.
  • Maintain security risk registers.
  • Track audit findings, penetration-testing findings, exceptions, and remediation commitments.
  • Ensure technical controls operate effectively and are not implemented only for audit purposes.

15. Security Metrics & Reporting

Develop and periodically report meaningful security metrics including:

  • Critical and high-risk vulnerabilities
  • Vulnerability-aging trends
  • Vulnerability SLA compliance
  • Mean Time to Detect security incidents
  • Mean Time to Contain incidents
  • Mean Time to Remediate vulnerabilities
  • Recurring vulnerability trends
  • Cloud security posture
  • Security incidents by severity
  • Security coverage across critical applications
  • Secure SDLC adoption
  • Penetration-testing closure rate
  • Open security risks
  • Privileged-access review status
  • Security-control maturity

Present major security risks, business impact, and recommendations to senior leadership in clear business language.

Leadership Responsibilities

  • Provide technical leadership to security analysts, engineers, and other security team members.
  • Mentor junior and mid-level security professionals.
  • Review the quality of security investigations and assessments.
  • Establish security-review standards for the team.
  • Coordinate across Engineering, DevOps, Infrastructure, QA, Product, IT, Compliance, and management.
  • Challenge technical decisions constructively where material security risks exist.
  • Drive accountability without creating unnecessary friction between Security and Engineering.

Required Experience

  • Minimum 10 years of professional experience in Cybersecurity / Information Security.
  • Significant hands-on experience across several of the following areas:
    • Application Security
    • API Security
    • Cloud Security
    • Incident Response
    • Vulnerability Management
    • Security Architecture
    • Penetration Testing
    • DevSecOps
  • Strong experience securing SaaS applications.
  • Strong understanding of web and API security.
  • Strong knowledge of OWASP Top 10 and OWASP API Security Top 10.
  • Hands-on experience with AWS cloud environments.
  • Experience investigating real-world security incidents.
  • Strong understanding of authentication, authorization, access control, and identity management.
  • Experience working closely with Engineering and DevOps teams.
  • Experience reviewing penetration-testing findings and driving remediation.
  • Experience analyzing security logs across application, cloud, database, endpoint, and infrastructure layers.
  • Good understanding of network-security concepts.
  • Experience with SIEM, EDR, vulnerability-management, WAF, and application-security tools.

Technical Skills

Candidates should have strong practical knowledge of:

  • AWS Security
  • IAM and least privilege
  • Web application security
  • REST API security
  • OAuth 2.0
  • JWT
  • API-key security
  • Authentication and authorization
  • RBAC
  • Multi-tenant architecture security
  • Linux and Windows security
  • TCP/IP and network-security fundamentals
  • Firewalls and WAF
  • TLS and certificates
  • Encryption
  • Secrets management
  • Database security
  • Logging and monitoring
  • SIEM
  • EDR
  • Vulnerability scanners
  • SAST / DAST
  • Software Composition Analysis
  • Docker / container security
  • CI/CD security

Knowledge of Node.js, React, microservices, Kubernetes, or similar modern application stacks from a security perspective will be an advantage.

Preferred Certifications

Certifications are desirable but will not substitute for practical experience.

Relevant certifications may include:

  • CISSP
  • CISM
  • OSCP
  • CCSP
  • AWS Certified Security – Specialty
  • GIAC certifications
  • CEH
  • ISO 27001 Lead Implementer / Lead Auditor

Education

Bachelor's or Master's degree in:

  • Computer Science
  • Information Technology
  • Cybersecurity
  • Information Security
  • Engineering

or equivalent professional experience.

Key Behavioral Competencies

The successful candidate should demonstrate:

  • Strong analytical and investigative ability.
  • High level of technical curiosity.
  • Ability to investigate issues independently.
  • Strong ownership and accountability.
  • Ability to challenge assumptions using technical evidence.
  • Good judgment during high-severity security incidents.
  • Ability to distinguish theoretical risk from genuine business risk.
  • Ability to communicate complex security issues to non-security stakeholders.
  • Strong documentation skills.
  • Ability to collaborate effectively with developers.
  • Ability to influence technical teams without relying solely on authority.
  • Strong attention to detail.
  • Continuous learning mindset.

What We Do Not Want

This position is not intended for someone whose experience is primarily limited to:

  • Reviewing dashboards and forwarding SOC alerts.
  • Audit documentation only.
  • ISO / compliance coordination without technical depth.
  • Running vulnerability scanners without understanding the findings.
  • Managing penetration-testing vendors without being capable of technically challenging their findings.
  • Creating policies without understanding the systems being protected.

The successful candidate must be capable of personally investigating and understanding complex technical security issues.

Key Success Measures

Within the role, the Information Security Lead will be expected to demonstrate measurable improvement in:

  • Reduction of critical and high-risk vulnerabilities.
  • Faster remediation of security findings.
  • Reduction of recurring security weaknesses.
  • Better application and API authorization controls.
  • Improved AWS security posture.
  • Improved security logging and incident visibility.
  • Effective investigation and containment of security incidents.
  • Improved Secure SDLC adoption.
  • Better security architecture reviews before production deployment.
  • Reduction in credential and secrets-management risks.
  • Improved vulnerability and penetration-test closure rates.
  • Stronger collaboration between Security and Engineering.

Experience

Minimum: 10 years

Preferred: 10–15 years of relevant cybersecurity experience, including significant hands-on technical security responsibilities.

Reporting Structure

Reports To: CTO / CISO / Head of Technology

Works Closely With: Engineering Leadership, Software Development, DevOps, Cloud Infrastructure, IT, QA, Product, Compliance, Internal Audit, and Senior Management.

Designation

Information Security Lead

Depending on the candidate's level of experience and organizational responsibilities, equivalent titles may include:

  • Lead – Information Security
  • Cybersecurity Lead
  • Lead – Product & Cloud Security
  • Senior Manager – Information Security
  • Senior Manager – Cybersecurity

Job Details

Salary

₹2,000,000 – ₹2,400,000/yr

Experience

Executive

Tools & Tech

AWS
Docker
Kubernetes
Linux
Node.js
React
S3
Windows

Preferred Certs

AWS Security Specialty
CCSP
CEH
CISM
CISSP
OSCP