Mumbai, Maharashtra, India
ISO/IEC 42001:2023 | CISSP-ISSAP | GCHQ-CIPR | CRISC | CISSP | ECSA | CEH | RHCE | RHCSA As an accomplished CISO with extensive experience and abilities in IS&IT strategy and management, I possess a broad range of knowledge and talent that will allow me to contribute toward the success of your company. My expertise lies in successfully coordinating full-cycle organizational IS processes, including IS strategy, Implementations, Data Privacy Protection, Secure Architecture and Design. For over 15 years, I have excelled in Implementing ISMS and Designing Information Security from scratch, demonstrating a keen ability to anticipate management and business needs and consistently identify optimal balance between IS and Business requirements to achieve and exceed goals. Additionally, my proven talents in networking, communication, negotiation and general business acumen positions me to make a significant contribution to the company. My current role as a Group CISO for Tata Power includes overall implementation of IS for three clusters including both IT & OT. My Previous role in Zebpay as a CISO includes implementing and governing the overall IS program according to MAS and ensuring that BlockChain Infra is secure and audited throughout. Previously my role in HDFC life diversifies in HDFC Life group and it’s two subsidiaries- HDFC Pension Management and HDFC International Life & RE. As a deputy Group Chief Information Security Officer for HDFC Life and CISO for HDFC Pension Management and HDFC International Life & RE, My role here includes the management of operations & administration of various IT security devices, solutions, technologies and processes deployed to enhance the security posture for HDFC Life Group. At the same time ensuring continuous monitoring, implementation and sustenance of requirements for ISO, IRDAI, PFRDA and DFSA. In my previous role as a Head of Cyber Security Operations and Governance, Risk, Compliance (GRC) at Ares India for Ares Management Corporation, I was responsible for providing visionary leadership to a team and help build Cyber security and GRC practice for Ares India. In my previous role as a Chief Information Security Officer (CISO) at DSP Mutual Fund (Formerly DSP BlackRock), I have been into leadership role to establish IS and Governance practice for the fund house with AUM of approx. 75K Cr as of September 2019. My role here spans strategizing the new strategies pertaining to IS and accordingly implement to support the vision of the organization.
As a Group CISO, my role is diversified into Renewables, Power Transmission & Distribution and Generation. This includes managing Information and OT security for Solar Implementation, Power Grid, EV charging stations and overall portfolio of Tata Power Group including its subsidiaries.
As the advisory board member, my role is to help them to strategise their cybersecurity program for the BlockChain and NFT tokens. The role emphasises on providing current knowledge, critical thinking and analysis to increase the confidence of the decision-makers who represent the company. Assist them in developing secure product and identify best practices in BlockChain Services, NFT Tokens and VDAs.
As an advisory board member, my role is to help and mentor C3ihub - IIT Kanpur to develop Cybersecurity Maturity Model Framework for the Power and Energy sector. As part of the mentorship, I’ll be collaborating with IIT Kanpur on this project supported by NCIIPC and Ministry of Power
ZebPay is one the India’s oldest and largest crypto exchange headquartered in Singapore and offices in India, Australia and US. Compliance: - Monetary Authority of Singapore (MAS) - Crypto Exchange Rating (CER) Framework Initiatives: - Threat Modelling on BlockChain Network - BlockChain audit - Risk Governance - Bug Bounty Program Responsibilities: 1. Leadership & Executive Engagement: Define the CISO’s charter and focus areas comprising policy, process and technology controls that would act as foundation for taking risk based decisions on design, tool and spends both within and beyond cyber security. 2. Engage with business heads and team leads through an OKR and KPI driven approach with a mix of technology and commercial sense. 3. Product Security: Evolve a culture of SSDLC to build and operate a product security testing and automation function aligned to DevSecOps philosophy with automation and developer empathy as its core constructs. 4. Platform Security: Work in synergy with infrastructure and product engineering teams to define baseline security configuration, build continuous visibility for detecting misconfigurations, vulnerabilities and mature remediation practices. 5. Contribute in maturing modern infrastructure delivery (IAC) and modern software supply chain (CICD / DevOps) practices. 6. Threat and Vulnerability Management: Detect, triage and operate remediation operations for mis-configurations and vulnerabilities across product, platform and identity plane as per defined SLA. 7. Security Operations: Set the foundation for creating incident response operations to guard against security breaches through a mixture of inhouse operations and a managed services model 8. GRC: Operate and evolve lean GRC (governance, risk, compliance) structure with regular cadence with leaders 9. Control Effectiveness & Audit Readiness: Owning success of technology controls, create an internal mechanism of audit readiness, demonstrating compliance to external auditors.
My role in HDFC life diversifies in HDFC Life group and it’s two subsidiaries- HDFC Pension Management and HDFC International Life & Dubai RE. Chief Information Security Officer for HDFC Pension Management and HDFC International Life & RE. My role here includes the management of operations & administration of various IT security devices, solutions, technologies and processes deployed to enhance the security posture for HDFC Life, HDFC Pension and HDFC LifeRe, At the same time , ensuring continuous monitoring, implementation and sustenance of requirements for ISO 27001 certification, PCI DSS & other regulatory requirements on Information & Cyber Security mandated by IRDAI, NCIPC, Cert-In, DFSA, etc Job Responsibilities: • Develop strategy & roadmap to strengthen Information security posture along with Group CISO • Develop & publish dashboard to measure security posture based on security metrics • Identify & analyze pain areas in existing security operations / architecture & implement improvements • Implement and manage requirements of ISO 27001 certification and security & regulatory frameworks mandated by IRDAI, NCIPC, Cert-In etc. • Establish & implement a cyber security and cyber crisis management strategy & plan • Ensure the coverage and effectiveness of security operations and deployed solutions • Measure, manage & report – availability, performance, capacity, risks & SLAs from business perspective • Ensure compliance with organization IT policy, audit & regulatory requirements • Identification, investigation and resolution of security incidents & breaches • Develop & operate a 24x7 security incident management and emergency response team • Vendor management with a focus on building and monitoring partner ecosystem • Plan and execute quarterly \ annual disaster recovery and Business Continuity drills • Software compliance management