Seasoned cybersecurity professional with over a decade of experience in identifying and mitigating cyber threats. Proven ability to manage and direct teams, develop and implement security measures, and ensure compliance with industry standards.
Overview
16
16
years of professional experience
1
1
Certification
Work History
Deputy Vice President (IRM)
Kotak Mahindra Bank Ltd
02.2024 - Current
Managed comprehensive threat intelligence operations, integrating cyber threat analysis, brand monitoring, and dark web surveillance to strengthen the bank's overall security posture.
Optimized threat Intelligence systems and implemented new analysis techniques, significantly reducing false positives by 80% and enhancing detection of advanced and targeted threats.
Managed Threat Hunting initiatives, implementing hypothesis-based, intelligence-based, and situational awareness-based hunting methodologies to proactively identify and mitigate emerging threats.
Engaged in advanced Adversary Infrastructure Hunting, employing techniques such as infrastructure hunting without IOCs, advanced pivoting, and tracking of criminal groups and nation-state actors.
Proactive fingerprinting of Threat Actor controlled infrastructure, such as malware Command and Control (C2) servers, Phishing sites etc. to develop hunt analytics for identifying operational infrastructure before malicious activity occurs.
Led comprehensive security breach investigations, from root cause analysis to impact assessment, coordinating responses to incidents like data leaks and breaches while ensuring thorough reporting to management and regulators.
Working alongside security operations (SOC) to develop and implement Splunk use cases for effective threat detection and incident response.
Mentored and guided team members in technical and functional matters, fostering their development while ensuring the delivery of high-quality, actionable intelligence products.
Manager, Cybersecurity (GSOC)
KPMG Assurance and Consulting Services LLP
05.2021 - 02.2024
Led a team of cybersecurity professionals in developing and executing technical strategies for cloud security posture management and incident response.
Provided technical leadership to the Global Security Operations Group, overseeing the development and implementation of security protocols and processes.
Developed and maintained a threat intelligence program for proactive content fine-tuning and use case development.
Collaborated with cross-functional teams to integrate security considerations into the development and deployment of new systems and applications.
Technical Lead (CRS)
Wipro Technologies Limited
11.2020 - 05.2021
Led the transition of SOC services from an MSS vendor, including project requirements, evaluation, defining roles and responsibilities, and developing solution architecture.
Provided technical leadership for support and maintenance of IBM XGS NIPS and Site Protector, as well as Cisco AAA Infrastructure and IDAM services.
Handled critical security incidents, participated in WAR room activities, and conducted threat-hunting exercises and incident response processes.
Ensured compliance with SLAs and process adherence, reviewing external threat advisories to develop appropriate response strategies.
Led enterprise-wide management of Cisco ISE and its integration with other Cisco security products, automating operational tasks such as endpoints and network device provisioning.
Collaborated with network infrastructure administrators to define and implement AAA policies and configurations.
Developed best practices, created robust documentation, and identified and mitigated operational gaps through knowledge transfer and solution design.
Executive (InfoSec)
Titan Company Limited
08.2013 - 11.2020
Led the incident handling and response program, serving as the point of contact and escalation.
Researched and reviewed external threat advisories, developing custom content based on threat intelligence.
Conducted threat hunting exercises, mock drills, and tabletop exercises to evaluate security controls and response mechanisms.
Performed threat management, threat modeling, and developed use cases for continuous security monitoring.
Created asset and network models, developed correlation rules, and use cases based on different attack scenarios, mapping them with the MITRE ATT&CK framework.
Led organization-wide deployment of NAC aligned with central information security objectives, utilizing Cisco Identity Services Engine, Cisco WLC, switches, and Microsoft Active Directory.
Implemented various authentication protocols for wired and wireless LAN, as well as network device access control.
Conducted endpoints posture assessments and network device profiling.
Managed mobile device access using Cisco ISE and implemented security assessments, hardening, and mitigation strategies for the internal network.
Implemented and managed Trend Micro Deep Security solutions on corporate servers and workloads.
Administered anti-malware solutions and ensured endpoint compliance and security patch management.
Implemented and managed full disk encryption for mobile endpoints.
Handled DLP incidents, alerts, and responses related to data in motion on endpoints.
Conducted architectural improvements, designed solutions, and integrated them as needed.
Engineer (CS)
Aurum Soft Systems Limited
08.2011 - 04.2013
Managed IT infrastructure, providing technical support and maintaining IT assets and networks.
Worked as system and network administrator, ensuring information and data security.
Supported new projects with a focus on IT infrastructure.
Apprenticeship / On Job Trainee
HCL Infosystems Limited
09.2008 - 08.2011
Completed diploma apprenticeship, specializing in master image preparation and disk duplication.
Trained as an assembly line lead, producing and repairing PCs and servers.
Education
Bachelor of Arts - Economics
Kumaun University
Nainital
Engineering Diploma - Information Technology
Government Polytechnic Collage
Dwarahat
Skills
Threat Intelligence
Incident Response
Threat Hunting
Cloud Security
NAC Implementation
Endpoint and Server Security
Privileged Access Management
Configuration Change Auditing
Network Security Assessment
Team Management
Accomplishments
Earned "Rising Star" for consistently exceeding expectations and delivering innovative solutions. at KPMG.
Awarded "CRS High Flyer" for leading the resolution of a critical Cisco Identity Services issue, saving the client a critical service downtime. at Wipro Technologies.
Honored as "Trail Blazer" for establishing state-of-the-art IT infrastructure and enhancing overall enterprise security posture. at Titan Company Ltd
Certification
Certified Hacking Forensic Investigator, EC Council - 2021-07
IBM Resilient SOAR Foundations, IBM - 2021-03
CyberArk Certified Trustee, CyberArk - 2021-02
Certified Ethical Hacker (CEHv10), EC Council - 2020-10
Languages
Hindi
Bilingual or Proficient (C2)
English
Bilingual or Proficient (C2)
Timeline
Deputy Vice President (IRM)
Kotak Mahindra Bank Ltd
02.2024 - Current
Manager, Cybersecurity (GSOC)
KPMG Assurance and Consulting Services LLP
05.2021 - 02.2024
Technical Lead (CRS)
Wipro Technologies Limited
11.2020 - 05.2021
Executive (InfoSec)
Titan Company Limited
08.2013 - 11.2020
Engineer (CS)
Aurum Soft Systems Limited
08.2011 - 04.2013
Apprenticeship / On Job Trainee
HCL Infosystems Limited
09.2008 - 08.2011
Certified Hacking Forensic Investigator, EC Council - 2021-07
IBM Resilient SOAR Foundations, IBM - 2021-03
CyberArk Certified Trustee, CyberArk - 2021-02
Certified Ethical Hacker (CEHv10), EC Council - 2020-10
Bachelor of Arts - Economics
Kumaun University
Engineering Diploma - Information Technology
Government Polytechnic Collage
Similar Profiles
NALINI NUPURNALINI NUPUR
Manager in Corporate Banking, Operations) at Kotak Mahindra BankManager in Corporate Banking, Operations) at Kotak Mahindra Bank