Head of Security and IT
Execo · Pune District, Maharashtra, India
Apply & track with Apply EdgeJob DescriptionLead security and IT for the whole company. You are the single owner of both, for every entity in seven countries (US, UK, Singapore, Kenya, Philippines, India, South Africa), reporting to the COO and leading a team of five in India, the Philippines, and Kenya.Set the security strategy and stand behind it with clients. You own SOC 2 Type II, the annual audit and penetration test, incident response with the General Counsel, and the security answers in every RFP and client audit we face.Own every policy and process document across security and IT. Write them, keep them current and version controlled; run the training and phishing simulations that make people follow them, with completion reported by country.Set the global standard for identity and access and enforce it everywhere. Google Workspace, Microsoft 365, zero trust in Chrome Enterprise Premium, and best-practice for Administrator management.Own the company's position on AI. Which models are approved for which data, enforced through access controls, including the AI features that switch on inside software we already own.Run IT as a 24/7 service across seven countries. The Jira queue and its service levels, HR to IT automation so leavers lose access on their last day, and assets from purchase to disposal.Own the cost of every subscription we hold. Build and run the cost model with Finance: what we pay, which entity and team it belongs to, what each renewal should cost, and where we are paying for seats nobody uses. You bring the savings, not just the invoices.Lead and develop the team. Shift rota covering US, European, and Asian hours, a deputy who can hold the queue, continuity and disaster recovery plans tested per entity, and monthly reporting to the COO on service, risk, compliance, and spend.RequirementsHas been the accountable owner of security and IT for a company or a large division, with eight or more years in the field, three of them leading a team across more than one country.Deep Google Workspace administration at organisation level, plus Microsoft 365 and Entra ID, and hands on zero trust (Chrome Enterprise Premium, BeyondCorp, Zscaler, or Cloudflare Access).Has taken a company through SOC 2 Type II in Vanta, Drata, or Sprinto, and wrote the policies and procedures rather than inheriting them.Has scoped penetration tests, run phishing programmes, and written and tested continuity plans.Has owned a software subscription budget alongside Finance: tracking spend, allocating cost to entities and teams, negotiating renewals, and removing seats. Be ready to quote what you saved and how.Has represented a company to client security teams: questionnaires, audits, and RFPs.Has run a service desk to service levels across time zones, ideally Jira, building automation across functions to provide a seamless user experience.Desirable: ISO 27001; GDPR, PDPA, DPDP, POPIA; CISSP, CISM, or CCSP; scripting in Apps Script, Python, or PowerShell.