Information Security Manager
Rapido
About the Company
Founded in 2015, Rapido is India’s leading multi-modal mobility platform. What began with bike taxis has rapidly evolved to include auto-rickshaws, cab-hailing, and peer-to-peer deliveries. Today, Rapido commands a dominant 70% market share in bike taxis, 40% in auto rides, and holds the second-largest position in the cab segment with a 22% share—establishing us as the overall market leader in ride-hailing. With over 4 million rides completed daily and more than 2 billion rides served to date, Rapido operates in 200+ cities and is aggressively expanding toward a presence in 500 cities. In 2024, we proudly achieved unicorn status with a valuation of $1.1 billion. Driven by technology and innovation, we’re expanding into new categories while remaining committed to improving last-mile connectivity and empowering livelihoods at scale.
About the Role
We are looking for an experienced, hands-on Information Security Manager to lead security operations, governance, risk management, incident response, and security transformation across the organization.
This role combines security leadership, technical depth, operational ownership, and stakeholder management. The candidate will help define and execute the security roadmap while ensuring security controls across Identity, Endpoint, Cloud, Network, SaaS, and Data Protection are effectively implemented and operated.
The ideal candidate should be comfortable working with senior leadership while remaining technically engaged with security architecture, implementation, incidents, and operational improvements.
Key Responsibilities
Security Strategy & Leadership
- Define and execute security priorities and roadmap aligned with business and technology objectives.
- Advise leadership on security risks, incidents, control gaps, and remediation priorities.
- Establish security KPIs, KRIs, SLAs, and maturity targets.
- Drive security-by-design across IT, Engineering, Cloud, SaaS, and enterprise technology initiatives.
- Balance security requirements with business velocity, scalability, user experience, and risk.
Security Operations & Implementation
Lead implementation and operational maturity across:
- EDR / XDR
- SIEM / SOC
- IAM / PAM
- MDM / UEM
- DLP & Data Protection
- Vulnerability Management
- Cloud & Network Security
- Email & SaaS Security
- Security Monitoring & Alerting
Partner with IT, Engineering, Platform, and Cloud teams to ensure security controls are scalable, measurable, and operationally effective.
Drive automation across security monitoring, access governance, vulnerability management, compliance, and reporting.
Incident Response & Problem Management
- Lead response to major security incidents and operational escalations.
- Own incident severity, escalation, communication, containment, remediation, and recovery processes.
- Coordinate investigations across Security, Engineering, IT, HR, Legal, Compliance, and external partners.
- Lead Root Cause Analysis (RCA) and ensure corrective and preventive actions are implemented.
- Identify recurring security issues and drive long-term remediation rather than temporary fixes.
Governance, Risk & Compliance
- Maintain visibility of organizational security risks, exceptions, control gaps, and remediation commitments.
- Drive security risk assessments for infrastructure, applications, SaaS platforms, vendors, and technology initiatives.
- Support audit and compliance programs including ISO 27001, SOC 2, NIST, and CIS Controls.
- Maintain security policies, standards, SOPs, incident playbooks, and operational runbooks.
- Ensure audit and security findings have clear ownership and closure timelines.
Security Metrics & Executive Reporting
Develop leadership-level dashboards and reporting covering:
- Security incidents and trends
- MTTD / MTTR
- Vulnerability ageing and remediation
- Patch and endpoint compliance
- Identity and privileged-access risks
- Security control coverage
- SIEM/SOC effectiveness
- Audit findings and risk remediation
- Security project delivery and SLA adherence
Translate technical findings into clear business risk, impact, priority, and recommended actions.
Team & Stakeholder Leadership
- Lead, mentor, and develop security engineers and analysts.
- Establish clear ownership, accountability, and operational standards.
- Partner with Engineering, IT, Platform, Cloud, HR, Legal, Compliance, and business teams.
- Manage security vendors, SOC providers, implementation partners, and technology vendors.
- Drive cross-functional security initiatives and ensure timely delivery of security programs.
Required Skills & Experience
- 8–12 years of experience in Information Security, Security Operations, IT Security, Cloud Security, or related areas.
- Experience leading security teams, programs, and cross-functional initiatives.
- Strong knowledge of:
- Security Operations & Incident Response
- SIEM / SOC
- EDR / XDR
- IAM / PAM
- Vulnerability Management
- Endpoint & Network Security
- Cloud & SaaS Security
- MDM / UEM
- DLP & Data Protection
- Experience implementing and operating enterprise security technologies.
- Working knowledge of ISO 27001, NIST, CIS Controls, and SOC 2.
- Experience with GCP, AWS, or Azure environments.
- Strong RCA, troubleshooting, risk assessment, and problem-solving capabilities.
- Strong executive communication and stakeholder management skills.
- Ability to lead effectively during high-pressure security incidents.
Preferred Qualifications
- Bachelor’s degree in Computer Science, Information Security, Engineering, or related field.
- Certifications such as CISSP, CISM, CCSP, ISO 27001 Lead Implementer/Auditor, Security+, or CEH are advantageous.
- Experience working in fast-paced, high-growth technology organizations.
What We’re Looking For
A security leader who:
- Owns outcomes, not just recommendations.
- Can operate across strategy, governance, architecture, and execution.
- Has sufficient technical depth to work effectively with Engineering and Infrastructure teams.
- Can translate technical risks into business impact for leadership.
- Builds scalable security controls without creating unnecessary business friction.
- Drives automation, continuous improvement, and measurable risk reduction.
- Builds strong teams and creates clear accountability.
What You'll Get at Rapido
- Get the opportunity to design and build security systems at enterprise scale, not just manage existing tools.
- Work across Cloud, Identity, Endpoint, Network, SaaS, SIEM/SOC, EDR/XDR, IAM/PAM, and Data Protection.
- Work with millions of security events, logs, alerts, and telemetry signals across endpoints, identities, networks, SaaS platforms, and cloud workloads.
- Build smarter detection, monitoring, alerting, and incident response pipelines with a strong focus on automation.
- Solve real-world security engineering problems and take solutions from design → implementation → production → operations.
- Work closely with Engineering, Platform, Cloud, IT, and leadership to build security into Rapido’s technology ecosystem.
- Get the freedom to experiment, automate, improve, and build rather than being limited to traditional security operations.
- Build and mentor a strong security team while helping shape how security scales at Rapido.