Open Network For Digital Commerce (ONDC)
Website:
ondc.org
Job details:
About ONDC
ONDC (Open Network for Digital Commerce) is a Government of India initiative under the Department for Promotion of Industry and Internal Trade (DPIIT). Operating as a Digital Public Infrastructure, ONDC is building an open, interoperable network that decentralises digital commerce and enables seamless participation for buyers, sellers, and service providers across categories — from retail and food to mobility and financial services.
As the network scales across categories and geographies, ensuring the security, trust, and compliance of the platform becomes central to ONDC's mission.
Role Overview
The Manager – Information Security will be a key member of the Technology team, responsible for establishing and managing ONDC's information security framework. This role will own ISO 27001 certification, drive security operations, and lead audit management for the organisation — reporting directly to the SVP – Technology.
The ideal candidate brings deep experience in information security operations and compliance, has led ISO audit and certification cycles, and can work effectively in a fast-moving, mission-driven environment.
Key Responsibilities
ISO Certification & Compliance
- Own the end-to-end ISO 27001 ISMS implementation and certification lifecycle — from gap assessment to certification and ongoing surveillance
- Coordinate with certification bodies and internal stakeholders to ensure audit readiness at all times
- Track and close non-conformities; maintain audit documentation and corrective action plans
- Ensure compliance with applicable regulations including IT Act, DPDP Act, and CERT-In advisories
Security Operations
- Manage day-to-day information security operations — threat monitoring, incident response, and vulnerability management
- Administer security tools including SIEM, endpoint protection, WAF, IAM, and DLP solutions
- Define and enforce security baselines across cloud infrastructure and API layers supporting the ONDC platform
- Embed security practices into the development lifecycle in collaboration with engineering teams (DevSecOps)
Risk Management & Governance
- Conduct periodic risk assessments and maintain an up-to-date risk register with mitigation plans
- Develop, review, and maintain information security policies, standards, and procedures
- Carry out security assessments for third-party vendors and network participants
- Report security metrics and risk posture to the SVP – Technology and senior leadership on a regular basis
Audit Management
- Plan and execute internal security audits across systems, processes, and integrations
- Liaise with external auditors and regulatory bodies to facilitate smooth audit execution
- Maintain comprehensive audit trails and evidence repositories for compliance purposes
- Prepare management review inputs and support leadership reporting on security posture
Candidate Profile
Essential
- 10-15 years of experience in information security, with hands-on ownership of ISO 27001 implementation and audit cycles
- Demonstrated experience in security operations — SOC management, incident response, and vulnerability management
- Strong understanding of cloud security (AWS / GCP / Azure) and API security principles
- Relevant certifications: ISO 27001 Lead Implementer or Lead Auditor, CISSP, or CISM
- Good communication and stakeholder management skills — able to engage technical teams and senior leadership equally
What ONDC Offers
- An opportunity to build and lead the information security function for one of India's most significant Digital Public Infrastructure initiatives
- Work at the intersection of technology, compliance, and public impact at national scale
- A collaborative, mission-driven team working on problems with genuine national significance
Click on Apply to know more.