Job Title: Senior Director-Product & Information Security
Location: Bangalore
Job Type: Full Time, Hybrid
Immediate joiners or notice period less than 15days are needed
This Role:
The Senior Director - Product & Information Security at LogixHealth will lead the efforts to ensure the organization and our partners are as secure as possible. This role will help ensure that security is always front and center across all our products, systems, platforms and tools within our ever growing environment. This role will work with a globally distributed team of engineers working in our fast-paced environment.
Key Responsibilities:
- Own and lead end-to-end Product/Application Security, Cloud & Data Center Security, and IT Security for a US HealthTech organization
- Provide strategic and operational leadership for the Security Operations Center (SOC), including detection, monitoring, incident response, escalation, and reporting
- Establish and govern secure SDLC practices across all applications, including threat modeling, SAST, DAST, dependency scanning, penetration testing, and remediation tracking
- Own security architecture and controls across cloud platforms, hybrid infrastructure, and on-prem data centers, ensuring strong identity, network, and data protection
- Partner closely with Product, Engineering, IT, and Platform teams to embed security-by-design without slowing product delivery or impacting patient/user experience
- Define, implement, and enforce information security governance, policies, standards, and procedures aligned with healthcare regulatory requirements
- Ensure continuous compliance and audit readiness for HIPAA, SOC 2, HITRUST (preferred), ISO 27001, and other applicable US healthcare regulations
- Lead incident response and crisis management, including tabletop exercises, breach simulations, regulatory notifications, and post-incident reviews
- Oversee vulnerability management, risk assessments, security testing, and remediation across applications, infrastructure, endpoints, and third-party vendors
- Drive security automation across SOC operations, compliance reporting, control monitoring, and alerting to improve speed, accuracy, and scale
- Build and maintain strong risk management and reporting frameworks, providing clear visibility into security posture, key risks, and mitigation progress to executive leadership
- Foster a strong security-first culture through ongoing awareness programs, phishing simulations, workshops, and targeted training for technical and non-technical teams
- Lead, mentor, and scale a high-performing security, compliance, and SOC team, ensuring clear accountability, skill development, and succession planning
- Manage relationships with security vendors, MSSPs, auditors, regulators, and external partners, ensuring SLA adherence and cost-effective outcomes
- Act as a trusted advisor to executive leadership on security risks, regulatory exposure, and business trade-offs in a healthcare environment
Qualifications:
The following requirements are representative of the knowledge, skills, and/or ability required to perform this job successfully. Reasonable accommodation may be made to enable individuals with disabilities to perform the duties.
Required:
- 12+ years of progressive experience across Product/Application Security, Cloud/Infrastructure Security, and SOC operations, with at least 3+ years in a senior leadership capacity
- Demonstrated experience owning or leading a SOC function, including incident response, threat detection, security monitoring, and operational governance
- Proven ability to define and execute cybersecurity strategy, roadmap, and long-term security vision
- Strong balance of strategic leadership and hands-on execution, with the ability to drive both direction and delivery
- Proven expertise in Application Security, including Penetration Testing, Secure SDLC, DevSecOps, vulnerability management, and secure architecture principles
- Deep expertise in cloud security controls across AWS, Azure, and GCP, including container and Kubernetes security
- Strong experience in security governance, compliance, and risk management, including ISO 27001 / ISO 2700x, SOC 2, GDPR, HIPAA, HITRUST, and audit readiness
- Demonstrated experience embedding security controls and best practices into engineering workflows and driving adoption across development teams
- Proven ability to work cross-functionally with Engineering, DevOps, Legal, Compliance, Risk, and business stakeholders
- Strong ability to communicate and influence executives, auditors, regulators, and cross-functional leadership teams
- Excellent analytical, problem-solving, and people leadership skills, with a strong bias toward ownership, accountability, and measurable outcomes