I am a visionary and results-oriented leader with an illustrious two-decade career, renowned for spearheading successful and holistic Information Security Programs across diverse organizations. My achievements span the domains of Cyber Security Operations, Compliance Management, and IT Infrastructure oversight, underpinned by a steady trajectory of annual accomplishments.
I bring forth a substantial reservoir of practical expertise in safeguarding digital assets across a diverse spectrum of organizations navigating the dynamic multi-cloud landscape, encompassing AWS, Azure, GCP, and Oracle environments. My skillset is deeply rooted in adeptly orchestrating security operations, marked by vigilant real-time monitoring, precise threat detection, comprehensive analysis, and agile incident response strategies.
Deputy General Manager, 01/2021 - Current
Infogain, Noida, India
About Infogain:
Infogain, headquartered in Los Gatos, CA, USA, is a leading business-focused IT services provider that specializes in delivering technology solutions tailored for the High Tech, Retail, and Insurance sectors. With an extensive workforce of approximately 6,500 employees spread across the USA, Europe, the Middle East, India, and Asia Pacific, Infogain stands as a prominent player in the IT services landscape.
Profile Overview:
In my role as the Head Cyber Defense, my primary responsibility is to ensure the protection of Infogain's digital assets and physical resources from the constantly evolving landscape of cyber threats. I am tasked with maintaining an unassailable security posture across 15 strategically positioned global locations, which span a diverse array of group entities including Absolutdata, Infogain, Revel Consulting, NNT, and Silicus.
· Develop and maintain Information Security Policies and standards in alignment with risk appetite, applicable laws, and regulations.
· Developed and executed a comprehensive multi-year cybersecurity strategy, resulting in an impressive advancement from an initial grade B to an exemplary Grade A in the Security Scorecard assessment.
· Develop, track, and control the security services annual operating and capital budgets for purchasing, staffing, and operations.
· Ensure the implementation and enforcement of security controls as stipulated by compliance mandates (ISO27001, SOC2, GDPR, PCI-DSS, HIPAA, CCPA, and PDP).
· Plan and conduct External & Internal security audits, and business processes across the organization in collaboration with the Business Units.
· I serve as a distinguished subject matter expert (SME) in Information Security Management within the context of hybrid environments, utilizing diverse security tools and cloud platforms (AWS, Microsoft Azure/Office 365, Google Cloud Platform, etc.).
· Running Security Operations and providing vigilant oversight across a spectrum of critical domains, including Vulnerability Management, Patch Management, Endpoint Security, Server Security, Application Security, and Network Security.
· Establishment and maintaining an internal Threat-Hunting & Red Teaming capability within the team, enabling proactive evaluation of ongoing threats to the organization.
· Implemented and managing an automated vulnerability assessment program, spanning on-premises and cloud infrastructure, as well as externally accessible web applications.
· Teamed up with a managed security service provider to successfully institute a 24/7 Security Operations Centre (SOC), functioning as a pivotal command center for swift threat recognition and response, leading to minimized disruptions and a proactive approach to risk mitigation.
· Implemented Extended Detection and Response (XDR) solution, fortifying protection against complex cyber threats across diverse attack vectors.
· Orchestrated the deployment of Mobile Device Management (MDM) solutions, ensuring strict policy adherence, robust encryption, and remote data wipe capabilities.
· Strengthened application security through the implementation of a secure development lifecycle, fortifying the organization's foundational security framework.
· Pioneered multiple cyber security initiatives, including the strategic implementation of the Zero Trust paradigm, Multi-Factor Authentication (MFA), simulated ransomware tests, and cyber security tabletop exercises.
· Collaborate extensively with Security partners and Managed Security Service Providers (MSSPs) to conduct and scrutinize routine security assessments of vendors and solutions, encompassing Penetration tests and Vulnerability scans.
· Enhanced awareness on the floor by conducting regular ransomware and phishing simulations, resulting in a significant increase from 28% to 76% in recognizing and guarding against such attacks.
About Absolutdata:
Absolutdata stands as an esteemed consultancy, specializing in analytics and research, recognized for its exceptional expertise. It proudly serves an impressive roster of Fortune 500 clients spanning diverse industries. With a dedicated workforce of 500 professionals, Absolutdata has solidified its reputation as a reliable partner, delivering impactful insights and innovative solutions.
Profile Overview:
In this pivotal capacity, I embraced a dual role as both an Information Security Manager and IT Manager, reporting directly to the CTO/CISO. My unwavering commitment was directed toward ensuring the security and availability of the organization's assets within a hybrid environment. The milestone acquisition of Absolutdata by Infogain in December 2020 marked a transformative phase, elevating our capabilities and expanding the horizons of my roles and responsibilities.
Information Security Manager:
· In the role of an Information Security Manager, I expertly orchestrated the implementation and management of ISO 27001, GDPR, and HIPAA frameworks. This initiative established a resilient IT security roadmap and substantially elevated the organization's security posture. Notable achievements include:
· Established an internal 24x7 Security Operations Center (SOC), leveraging cutting-edge open-source technologies such as ELK, Wazuh, and Security Onion, while also expanding the team's skill set and capabilities.
· Implemented comprehensive vulnerability assessments and penetration testing to evaluate risks and threats across on-premises and cloud assets.
· Pioneered information security and risk management awareness programs, fostering a culture of security awareness within the organization.
· Implemented application security framework to ensure secure software development practices within the organization.
· Assisting the delivery and sales teams in crafting comprehensive responses to information security inquiries.
Information Technology Manager:
· In the role of an IT Manager, I skilfully managed a diverse range of IT infrastructure components, encompassing critical systems such as Windows Active Directory, Database Servers, and Cloud Workloads. Noteworthy accomplishments include:
· Fostered strategic collaboration with other departments, gaining a deep understanding of their technology needs and offering innovative solutions to fulfill those requirements.
· Spearheaded a hybrid IT infrastructure, prioritizing Cloud management and architecture to ensure robust cloud security management and regulatory compliance.
· Seamlessly ensured business continuity during the pandemic-induced transition to remote work by implementing advanced Cyber Security Systems and upholding information security standards.
· Skilfully orchestrated the prosperous migration of cloud services for the Ministry of Housing (Saudi Arabia), consistently upholding security protocols and optimizing resource allocation.
· Attained the esteemed status of an AWS Certified Solution Provider, affirming my profound expertise and industry-wide recognition.
· Managed a comprehensive suite of infrastructure servers and devices, including Windows Active Directory, File Server, Database Server, Print Server, Antivirus Server, Firewall, Switches, VMware Virtualization, IPS, IDS, NDR, Patch Management, DLP, Web Proxy, and more.
· Successfully directed the organization's IT budget, ensuring adherence to financial guidelines and proactively identifying opportunities for cost optimization.
· Collaborated seamlessly with various departments to discern and address their distinct technological requirements, providing tailored solutions to meet their needs.
· Implemented and monitored the Service Help Desk System SDP to expedite issue resolution and enhance user experience.
· Developed and meticulously maintained disaster recovery and business continuity plans, ensuring the organization's IT systems remain resilient and capable of swift recovery from disruptions.
Managed IT operations for Asbsoludata
Managed IT operations for 38 branches across the country) at DLF Pramerica Life Insurance Ltd.
Provided Server & IT Helpdesk support at MINUSTAH (United Nations Peace Keeping Mission in Haiti)