Bengaluru, Karnataka, India
Sales persons, with due respect, please keep away - NO CONNECT and PITCH tactics š I'm a digital transformative security leader who thrives in building & sustaining highly agile Cyber Security function. Having built my career with many reputed MNCs in cyber security, data privacy, business continuity & corporate security domains over 20+ years, I've gained leadership experience in running integrated global security programs. I've proven track record of setting up, leading and delivering business-aligned security programs. My techno-leadership expertise helps companies to optimize their security posture with an integrated cyber security program compliant with legal & regulatory requirements. I'm passionate about driving culture change that unlocks the value of cyber security in digital transformation journey by deriving ROI and deliver security value-add to business. Competencies: ⢠Set up Cyber Security function ground up in MNCs aligning with business goals ⢠Strategy, Vision, Roadmap & Execution ⢠Engaging C-suite on business case presentation, building consensus, advisory and coaching on optimal security posture. ⢠Cyber Security Governance, Risk & Compliance (GRC) for ISO 27001 ISMS, GDPR, PCI-DSS, SSAE 18 & NIST ⢠Enterprise Risk Mgmt | TPRM ⢠Cloud Security | IAM | DLP | AI Risks ⢠Security Culture | Awareness ⢠Incident Mgmt ⢠Security Metrics & Dashboard ⢠Honors 2025: LinkedIn Cybersecurity Face 2025, CyberFrat | Leadership Excellence Award, CXO Junction 2024: LinkedIn Top Voice - GRC, Risk Management & Information Security | Influencer Titan in Cybersecurity, CF100 | Cyber Security Leadership Excellence Award, CXO Junction Top 50 Creators Cyber Security - LinkedIn - Worldwide, Favikon | Cyber Champions 2024 - InfoSec Train 2023: LinkedIn Top Voice - Cyber Security & Security Awareness | Top 50 Global Thought Leader and Influencer on Risk Mgmt 2023, 2024, Cyber Security 2023, 2024, Thinkers360 2022: Top 50 B2B Thought Leader and Influencer to Work with 2023 APAC, Thinkers360 2021: Key Opinion Leader - Risk Mgmt, Onalytica 2020: Top 50 Global Thought Leaders and Influencers on Risk Mgmt | Cyber Security | Privacy | Culture, Thinkers360 2019: CISO of the Year 2018, 2019, 2020: CISO Top 100 Influencers 2018: - Indywood IT Excellence Award - Next100 Award - Big 50 CISO Award - Global Goodwill Ambassador ⢠Aspiring knowledge altruist ⢠Published Author: - Career Excellence (Vol I & II), Atlantic Publishers, New Delhi - Cyber Crimes - A Primer on Internet Threats & Email Abuses, Viva Books, New Delhi https://rb.gy/q4u0qm
- I believe in learning and sharing knowledge through speaking opportunities in professional security conferences, academic institutions and in-house corporate events. - I avail these speaking engagements in my personal capacity and as such all views I express are personal and do not reflect my employers'. - I'm selective in my choice of events where I'm invited to speak and my services, in the spirit of giving back to my industry/society are pro bono. A few of the notable events where I was a featured Speaker / Moderator / Host: 1. Center of Excellence for Innovation, Incubation and Entrepreneurship, GITAM University, Bangalore - Jan 2019 - Topic: "Importance of Stringent Cyber Security Measures for SMEs". 2. Big Cyber Security Show and Awards, The Leela Mumbai - Sep 2018 - Panel Moderator on "Cyber Hygiene in Today's Threatscape" with panelists from leading companies. - Fireside chat host on "Insider Threat Management Program". 3. REVA Academy for Corporate Excellence (RACE), REVA University, Bangalore - Sep 2018 & Feb 2019 - Topic: "Building a Successful Cyber Security Career" 4. Overseas Security Advisory Council (OSAC) Meet, Vivanta by Taj, Bangalore - Aug 2018 - Topic: "Physical Security Meets Cyber Security - Convergence is the Way Forward" 5. National Privacy Summit, ISC2 Bangalore Chapter, Radisson, Bangalore - Aug 2018 - Topic: "Building a Culture of Privacy" 6. In-house Talk at Concentrix, Bangalore - Aug 2017 - Topic: "Building an Enterprise Information Security Program" 7. Institute for Development and Research in Banking Technology (IDRBT), Hyderabad - 2013, 2014, 2015 - Addressed sessions on Cyber Fraud / Cyber Crimes / Cyber Risks & Threats to participants for 3 consecutive years. 8. Overseas Security Advisory Council (OSAC) Meet, Microsoft Campus, Hyderabad - 2006 - Delivered a talk on "Understanding Cyber Crimes"
I was part of the global Cyber Security Governance, Risk and Compliance function. Key Accomplishments in Cyber Security GRC role: Risk Management ⢠As part of GRC operations revamp plan, improved existing processes for operational efficiency ⢠Managed global projects for security risk assessments performed by US and Europe regions with focus on closure within agreed upon TAT ⢠Established Risk Management governance for ASEAN entities and regimented Vendor Risk Assessment process ⢠Revised Information Security controls as part of Architecture Review Board review ⢠Jointly strategized on global application repository data clean-up campaign and achieved targeted results ⢠Integrated System Risk Assessment process into Architecture Review Board; Achieved streamlined process and single point security validation experience for business units saving time and effort ⢠Contributed significantly to the 360-degree Project Health Assessment program as Security CoE by partnering with other CoEs like Engineering, Quality, Documentation, Agile, etc to provide single window review of projects saving time & effort for business units. š This project received global recognition as it was awarded V-up Accomplishment Award by the CEO. ⢠Worked closely with HQ counterparts to select and test features of GRC automation tool Policy Governance ⢠Reviewed and revised of Global Security Standards and coordination with US and Europe regions Security Culture Initiatives ⢠Automated monthly Security induction sessions for contractors into video-based training saving 5 man-hours every month. This project won global CEO recognition in the form of V-up Accomplishment Award for FY22. š ⢠Ideated and started Security Awareness monthly Mailers & Newsletters to foster 'Security First' culture. This is widely appreciated by leadership for promoting security awareness. ⢠Key contribution to adapt and introduce Information Security Annual eLearning Refresher for staff
Hired as Dy General Manager with a mandate to set up BISO function initially for Marketing and Sales Dept. My role progressively expanded to cover many other key departments to promote Nissan Cyber Security Program adoption, policy enforcement, security advisory, security culture building and evangelize security best practices. š Received peer recognition via High Five Award in 2020
Leadership role in promoting security value-add through engagements with Business Groups/Functions across Indian Subcontinent (ISC) ⢠Recruited to establish Business Engagement function for InfoSec to all Business Groups/Departments across Indian Subcontinent region. ⢠Serve as Regional Security Business Partner to businesses and establish relationship with key business stakeholders to engage them actively on security matters and drive compliance to InfoSec Management Framework - policies, procedures, guidelines & standards. Key Achievements: ⢠Established CISO presence across ISC region among key BGs/Depts and self as SPOC for InfoSec matters and promote compliance to security policies, standards and best practices through Business Engagement meetings. ⢠Created mindshare among employees and key business leaders about importance of cyber security by serving as SPOC for security and compliance related matters. ⢠Collaborated with other relevant CISO teams to improve security posture on specific projects as required. ⢠Promoted positive security culture among employees within ISC through various security awareness initiatives - introduced new hire induction, promoted compliance to online IS awareness trainings, envisioned & launched cyber security daily news roundup ā collate real-world news/insights, populate & e-publish, etc ⢠Built CISO Ambassador Network across ISC to serve as last mile effective delivery of security messages to staff ⢠Actively engage with BG/Functions in Indian Subcontinent to drive compliance to Philips Security Policies, Standards & Best Practices through Deployment activities. ⢠Partner with businesses and handhold them in implementing/facilitating security initiatives as per goals. ⢠Reach out to business leadership teams to introduce CISO organization priorities, assess maturity levels, provide advisory to improve security posture and report status.
Reported to CEO Leadership role in driving Information Security program for ISGN covering US and India. - Lead Governance, Risk & Compliance programs for ISO 27001:2013 ISMS and SSAE 16 Audit - Successfully cleared ISO 27001 ISMS CAV Assessment by BSI & SSAE 16 by KPMG - Drive Business Continuity Program covering SaaS applications, shared services & IT function - Envision and strategize key security initiatives to improve information security posture enterprise-wide - Lead policy governance program covering Information Security, Infrastructure Security, Application Security, Data Privacy, Business Continuity - develop, maintain and publish security policies, procedures, standards, guidelines and ensure enforcement - Perform ongoing Risk Assessments, Control Effectiveness Tests highlight risks to IS Steering Committee, provide mitigation solutions and track them for closure - Run Vulnerability Assessment & Penetration Testing (VAPT) Program through SMEs for key applications and IT network and ensure timely closure - Drive Security Awareness, Education and Training programs on various security topics - policies, risks, threats, etc and advocate adoption of best practices to protect sensitive data - Draft periodic awareness emails on security best practices, policy updates and handle security & BCP emergency/crisis communication across the company - Oversee submission of information security, business continuity-related inputs for RFIs, RFPs to existing and potential clients - Review security-related clauses on Master Service Agreements, Vendor Contracts and other legal documentation - Liaison with internal and external stakeholders - clients, regulators for security audits, assessments & reviews and provide inputs as necessary, track audit findings and ensure timely closure. - Investigate security incidents and preform root cause analysis, reporting, put in place measures to avoid recurrence - Prepare Security Dashboards with KRI metrics for management reporting