

Cybersecurity and DevSecOps leader with 18+ years of experience spanning Application Security, Governance, Compliance, Risk Management, and AI-driven modernization. Proven expertise in transforming security testing from ad-hoc reviews to a mandatory AppSec governance framework integrated across all releases.
Skilled in leading end-to-end DevSecOps transformations, securely integrating AI-based tools, and developing comprehensive AI governance policies. Experienced in managing 8+ enterprise audits, 70+ NYDFS tests annually, and onboarding 12+ projects into CI/CD pipelines with automated AppSec validation.
Adept at managing and evaluating third-party vendors and contractors , ensuring adherence to SLAs, compliance standards, and delivery performance. Certified CISSP, CEH, ISO 27001 Lead Auditor, with a PG in Data Science & Machine Learning (Purdue University).
• Transformed organizational AppSec testing from ad-hoc requests to a mandatory release approval process across all projects, integrating security from the development phase.
• Led secure integration of 12+ major business projects into CI/CD pipelines with automated security testing and approval workflows.
• Oversaw 8+ enterprise audits and coordinated 70+ NYDFS compliance tests annually, ensuring complete regulatory alignment.
• Drove AI-enabled modernization by securely integrating AI-based tools into AppSec and governance workflows.
• Developed and authored AI policy, governance documentation, and risk management framework for ethical AI adoption.
• Implemented evidence automation that reduced manual audit preparation time by over 30%.
• Collaborated cross-functionally with 10+ business and engineering teams to align risk, compliance, and AppSec strategies.
• Managed third-party vendors and contractors supporting AppSec, DevSecOps, and audit operations; conducted performance reviews and ensured contractual SLAs were met.
• Collaborated with procurement and governance teams to onboard, review, and optimize vendor security capabilities, achieving improved vendor response and compliance timelines.