Summary
Overview
Work History
Education
Skills
Websites
Certification
CAREER HIGHLIGHTS
MY TIME
Timeline
Generic
ALMAS KHAN

ALMAS KHAN

Pune,MH

Summary

Cybersecurity and DevSecOps leader with 18+ years of experience spanning Application Security, Governance, Compliance, Risk Management, and AI-driven modernization. Proven expertise in transforming security testing from ad-hoc reviews to a mandatory AppSec governance framework integrated across all releases.

Skilled in leading end-to-end DevSecOps transformations, securely integrating AI-based tools, and developing comprehensive AI governance policies. Experienced in managing 8+ enterprise audits, 70+ NYDFS tests annually, and onboarding 12+ projects into CI/CD pipelines with automated AppSec validation.

Adept at managing and evaluating third-party vendors and contractors , ensuring adherence to SLAs, compliance standards, and delivery performance. Certified CISSP, CEH, ISO 27001 Lead Auditor, with a PG in Data Science & Machine Learning (Purdue University).

Overview

2026
2026
years of professional experience
1
1
Certification

Work History

Information Security Engineer

Western Union
06.2020 - Current

• Transformed organizational AppSec testing from ad-hoc requests to a mandatory release approval process across all projects, integrating security from the development phase.

• Led secure integration of 12+ major business projects into CI/CD pipelines with automated security testing and approval workflows.

• Oversaw 8+ enterprise audits and coordinated 70+ NYDFS compliance tests annually, ensuring complete regulatory alignment.

• Drove AI-enabled modernization by securely integrating AI-based tools into AppSec and governance workflows.

• Developed and authored AI policy, governance documentation, and risk management framework for ethical AI adoption.

• Implemented evidence automation that reduced manual audit preparation time by over 30%.

• Collaborated cross-functionally with 10+ business and engineering teams to align risk, compliance, and AppSec strategies.

• Managed third-party vendors and contractors supporting AppSec, DevSecOps, and audit operations; conducted performance reviews and ensured contractual SLAs were met.
• Collaborated with procurement and governance teams to onboard, review, and optimize vendor security capabilities, achieving improved vendor response and compliance timelines.

Security Architect

Tech Mahindra
01.2018 - 01.2020
  • Led AppSec solutioning and pre-sales support for enterprise/government clients.
  • Worked with business partners to balance requirements, security and risk reduction.
  • Traveled to client sites to perform onsite testing.
  • Translated strategy into solutions and operating models by leading or managing others,

Associate – Information Security

Deutsche Bank, Blackrock
2011 - 01.2018
  • Worked on InfoSec audits, vulnerability assessments, vendor risk governance.
  • Created frameworks by designing and developing technical solutions.
  • Liaised with third parties to respond to security events and understand threat landscape.
  • Strengthened communication skills through regular interactions with others.
  • Worked well in a team setting, providing support and guidance.

Senior Technical Support Officer

HCL, Convergys, BA Continuum
01.2006 - 2011
  • Focused on IDAM, infrastructure security, and technical support.
  • Created user accounts and assigned permissions.

Education

PG Diploma - Data Science & Machine Learning

Purdue University
Pune
01.2022

B.Com. - Commerce

Lucknow University
Lucknow
01.2006

Skills

  • Application security expertise
  • Application security tools
  • Information security certifications
  • Security vulnerability assessment
  • Secure password management
  • Strategic business continuity planning
  • Error resolution in systems
  • Security evaluation proficiency
  • Experience in compliance management
  • Proactive risk assessment
  • Effective operational framework establishment
  • Compliance oversight
  • Security risk evaluation
  • Experience with penetration testing methodologies

Certification

  • CISSP
  • CEH
  • ISO 27001 Lead Auditor
  • ITIL
  • MCP

CAREER HIGHLIGHTS

  • 18+ years across AppSec, DevSecOps, Governance, and Compliance in global environments.
  • Led integration of tools like Checkmarx, Dazz, Xray, ServiceNow – enabling DevSecOps workflows.
  • Owned audit and documentation for PCI-DSS and NYDFS compliance – working with auditors directly.
  • Implemented risk-based AppSec testing strategy for critical/high-risk applications.
  • Certified in CISSP, CEH, ISO 27001 LA; PG in Data Science & ML from Purdue University.
  • Managed and evaluated third-party vendors and security contractors, overseeing performance metrics, compliance adherence, and delivery quality across multiple security domains.

MY TIME

Approximate time allocation across core functional areas: Governance & Compliance, AppSec & CI/CD, Team Coordination, Learning & Development

Timeline

Information Security Engineer

Western Union
06.2020 - Current

Security Architect

Tech Mahindra
01.2018 - 01.2020

Senior Technical Support Officer

HCL, Convergys, BA Continuum
01.2006 - 2011

Associate – Information Security

Deutsche Bank, Blackrock
2011 - 01.2018

PG Diploma - Data Science & Machine Learning

Purdue University

B.Com. - Commerce

Lucknow University
ALMAS KHAN