Information Security Lead

Yanolja Cloud Solution

Yanolja Cloud Solution Pvt. Ltd. (YCS) is a global end-to-end hospitality technology provider specializing in solutions for small and medium-sized accommodation businesses.

With more than 400+ team members and 20+ years of experience, YCS currently serves 40,000+ customers across 170+ countries, with 50+ supported languages in our software and a 24/7 support network.

We have local teams across 15+ countries, including India, Thailand, Indonesia, Philippines, Sri Lanka, South Africa, Tanzania, Uganda, USA, Mexico, and counting.

Position Overview

We are looking for an experienced Information Security Lead with a minimum of 10 years of professional experience in cybersecurity and information security to lead and strengthen the security posture of YCS's SaaS products, applications, APIs, cloud infrastructure, internal systems, and customer data.

This is a senior technical leadership role requiring a strong combination of application security, API security, AWS/cloud security, incident response, vulnerability management, security architecture, DevSecOps, and security governance.

The ideal candidate will be capable of independently investigating complex security incidents, challenging technical architecture, working closely with engineering teams, establishing security standards, and driving security vulnerabilities and risks through remediation and closure.

This is not intended to be a purely governance, audit, or SOC-monitoring role. The candidate is expected to remain technically hands-on while providing security leadership across the organization.


Required Experience

  • Minimum 10 years of professional experience in Cybersecurity / Information Security.
  • Significant hands-on experience across several of the following areas:
  • Application Security
  • API Security
  • Cloud Security
  • Incident Response
  • Vulnerability Management
  • Security Architecture
  • Penetration Testing
  • DevSecOps
  • Strong experience securing SaaS applications.
  • Strong understanding of web and API security.
  • Strong knowledge of OWASP Top 10 and OWASP API Security Top 10.
  • Hands-on experience with AWS cloud environments.
  • Experience investigating real-world security incidents.
  • Strong understanding of authentication, authorization, access control, and identity management.
  • Experience working closely with Engineering and DevOps teams.
  • Experience reviewing penetration-testing findings and driving remediation.
  • Experience analyzing security logs across application, cloud, database, endpoint, and infrastructure layers.
  • Good understanding of network-security concepts.
  • Experience with SIEM, EDR, vulnerability-management, WAF, and application-security tools.


Technical Skills

Candidates should have strong practical knowledge of:

  • AWS Security
  • IAM and least privilege
  • Web application security
  • REST API security
  • OAuth 2.0
  • JWT
  • API-key security
  • Authentication and authorization
  • RBAC
  • Multi-tenant architecture security
  • Linux and Windows security
  • TCP/IP and network-security fundamentals
  • Firewalls and WAF
  • TLS and certificates
  • Encryption
  • Secrets management
  • Database security
  • Logging and monitoring
  • SIEM
  • EDR
  • Vulnerability scanners
  • SAST / DAST
  • Software Composition Analysis
  • Docker / container security
  • CI/CD security


Knowledge of Node.js, React, microservices, Kubernetes, or similar modern application stacks from a security perspective will be an advantage.

Preferred Certifications

Certifications are desirable but will not substitute for practical experience.

Relevant certifications may include:

  • CISSP
  • CISM
  • OSCP
  • CCSP
  • AWS Certified Security – Specialty
  • GIAC certifications
  • CEH
  • ISO 27001 Lead Implementer / Lead Auditor

Education

Bachelor's or Master's degree in:

  • Computer Science
  • Information Technology
  • Cybersecurity
  • Information Security
  • Engineering

or equivalent professional experience.

Key Behavioral Competencies

The successful candidate should demonstrate:

  • Strong analytical and investigative ability.
  • High level of technical curiosity.
  • Ability to investigate issues independently.
  • Strong ownership and accountability.
  • Ability to challenge assumptions using technical evidence.
  • Good judgment during high-severity security incidents.
  • Ability to distinguish theoretical risk from genuine business risk.
  • Ability to communicate complex security issues to non-security stakeholders.
  • Strong documentation skills.
  • Ability to collaborate effectively with developers.
  • Ability to influence technical teams without relying solely on authority.
  • Strong attention to detail.
  • Continuous learning mindset.

What We Do Not Want

This position is not intended for someone whose experience is primarily limited to:

  • Reviewing dashboards and forwarding SOC alerts.
  • Audit documentation only.
  • ISO / compliance coordination without technical depth.
  • Running vulnerability scanners without understanding the findings.
  • Managing penetration-testing vendors without being capable of technically challenging their findings.
  • Creating policies without understanding the systems being protected.

The successful candidate must be capable of personally investigating and understanding complex technical security issues.

Key Success Measures

Within the role, the Information Security Lead will be expected to demonstrate measurable improvement in:

  • Reduction of critical and high-risk vulnerabilities.
  • Faster remediation of security findings.
  • Reduction of recurring security weaknesses.
  • Better application and API authorization controls.
  • Improved AWS security posture.
  • Improved security logging and incident visibility.
  • Effective investigation and containment of security incidents.
  • Improved Secure SDLC adoption.
  • Better security architecture reviews before production deployment.
  • Reduction in credential and secrets-management risks.
  • Improved vulnerability and penetration-test closure rates.
  • Stronger collaboration between Security and Engineering.

Experience

Minimum: 10 years

Preferred: 10–15 years of relevant cybersecurity experience, including significant hands-on technical security responsibilities.

Reporting Structure

Reports To: CTO / CISO / Head of Technology

Works Closely With: Engineering Leadership, Software Development, DevOps, Cloud Infrastructure, IT, QA, Product, Compliance, Internal Audit, and Senior Management.

Designation

Information Security Lead

Depending on the candidate's level of experience and organizational responsibilities, equivalent titles may include:

  • Lead – Information Security
  • Cybersecurity Lead
  • Lead – Product & Cloud Security
  • Senior Manager – Information Security
  • Senior Manager – Cybersecurity


How to apply

To apply for this job you need to authorize on our website. If you don't have an account yet, please register.