Dynamic information security leader with extensive experience at BillDesk, specializing in risk assessment and regulatory compliance. Proven track record in developing security policies and incident response strategies, enhancing organizational resilience. Adept at vulnerability assessment and fostering a culture of security awareness, driving significant improvements in security posture.
Overview
17
17
years of professional experience
1
1
Certification
Work History
Deputy Chief Information Security Officer
BillDesk
Mumbai
02.2025 - Current
Help develop and implement the organization's overall information security strategy, ensuring it aligns with business objectives and regulatory requirements.
Provide strategic guidance on security initiatives and support the CISO in decision-making processes.
Assist in the creation and implementation of security policies, standards, and procedures that protect the organization’s information and technology assets.
Ensure that the organization meets industry-specific regulatory compliance requirements (e.g., GDPR, HIPAA, PCI-DSS) and help with audits and assessments.
Ensure that governance frameworks (e.g., NIST, ISO 27001) are followed to provide a structured approach to managing risks.
Work with teams to identify security risks and vulnerabilities, using risk management frameworks to assess their potential impact on the organization.
Assist in creating and implementing risk mitigation strategies for information security threats, including advanced persistent threats, ransomware, insider threats, and more.
Manage security assessments, vulnerability scans, and penetration tests to identify weaknesses and ensure proactive risk management.
Lead or assist in the development and execution of incident response plans, including communication strategies, investigation, containment, and recovery during security breaches.
Work closely with IT, legal, compliance, and communications teams to respond to and resolve security incidents effectively.
Conduct post-incident analyses and develop lessons learned to improve security posture and response mechanisms.
Ensure that security operations are effectively monitored, managed, and optimized across the organization, including network, cloud, endpoints, and application security.
Help evaluate, implement, and manage security tools and technologies, such as SIEM (Security Information and Event Management), firewalls, endpoint protection, and encryption tools.
Collaborate with other departments (e.g., IT, legal, HR, and risk management) to integrate security practices and ensure organizational alignment on security priorities.
Oversee security relationships with third-party vendors and service providers, ensuring they meet the organization’s security requirements and are regularly assessed for compliance and risk.
Develop and promote security awareness programs to ensure that all employees understand their role in maintaining security, reducing human errors and insider threats.
Lead and manage security operations teams, security analysts, incident responders, and other staff under the security division.
Promote the professional development and training of the security team to ensure they stay updated with the latest security trends, threats, and technologies.
Work to embed a security-conscious culture across the organization, ensuring that all employees understand the importance of security.
Ensure that relevant security metrics are tracked and reported to executive leadership and the board of directors, providing them with clear insights into the organization's security posture.
Develop and maintain security dashboards and reporting tools to provide visibility into risk, incident trends, and security performance.
Assist in budgeting for security programs, tools, and personnel, ensuring that resources are allocated effectively to mitigate risk.
Help evaluate and implement cost-effective solutions to enhance security, balancing business needs and security risks.
Deputy Vice President – Infrastructure Risk & SOC
Indusind Bank
Mumbai
10.2022 - Current
Digital managed functions – Infrastructure risk, Cloud security and incident response, Data leakage, Digital risk monitoring and member of risk committee.
Provides direct administration and ownership of SIEM to include configuration, access control, tuning, integration, and continuous improvement activities.
Build and tune custom cases, dashboards, searches, reports on SIEM platform based on cyber security and business needs.
Managing security event supervision: Ensuring that security event supervision and management processes are executed properly.
Defining service improvement plan: Defining and steering the SOC's service improvement plan.
Ensuring compliance with data protection laws (e.g., GDPR, PCI-DSS).
Conducting risk assessments and data protection impact assessments (DPIAs).
Define process documentation & Information security & Cyber Security policy.
Investigate, analyze, and evaluate new technologies and risks.
Developed and implemented strategies to mitigate identified risks.
Created detailed assessment reports with findings, recommendations, and remediation steps.
Actively pursued professional development opportunities to stay updated with the latest security trends and technologies.
Collaborated with cross-functional teams to implement GRC initiatives.
Act as a point of escalation for SIEM and provide guidance and mentoring to associate security engineers/analysts.
Experience in utilizing data analytics and visualization tools to support GRC initiatives.
Responding to data subject access requests (DSARs) and privacy inquiries.
Collaborating with IT and legal teams to ensure data protection.
Keeping up-to-date with evolving data protection regulations.
Conducting data protection training and awareness programs.
Collaborated with cross-functional teams to implement GRC initiatives.
Conducted risk assessments to identify and evaluate potential risks within the organization.
Developed risk mitigation strategies and action plans.
Implemented risk management frameworks and processes.
Collaborated with IT and security teams to address regulatory requirements related to data privacy and security.
Interacted with regulatory agencies and external auditors during compliance assessments and audits.
Data Security Lead
Wipro Technologies - VISA
Bangalore
05.2021 - 09.2022
Define data security & Governance process, procedure, product implementation of Imperva DAM, DLP etc.
Implemented a different set of audit & Security policies to improve the security of company data, including client and patient data.
Strong understanding of governance, risk management, and compliance principles.
Familiarity with regulatory frameworks (e.g., GDPR, HIPAA, SOX).
Knowledge of industry standards and best practices (e.g., ISO 27001, NIST).
Collaborate with business stakeholders to develop and document policies and procedures surrounding Data Governance.
Develop best practices, standards, and methodologies to assist in the implementation and execution of Data Governance model.
Developed and implemented compliance programs to ensure adherence to relevant regulations and standards.
Conducted compliance assessments and audits to identify gaps and areas of improvement.
Collaborated with stakeholders to define compliance policies and procedures.
Senior Info-sec analyst
William Sonoma Inc
Pune
10.2020 - 05.2021
Infrastructure risk assessment.
Rule base review of Infra devices.
Strong knowledge on the compliance requirements and implementing the audit and security controls to adhere to the Audit & Compliance requirements.
Very strong knowledge on creating place holders using Imperva and route the audit data to SOAR platform and SIEM solution for incident management.
Build use cases as business needs and best practices to find the breaches and Incidents (VLAN segregation, Direct DB access, Password Sharing, Off-hour's access etc.).
Strong knowledge on Imperva Data Risk Analytics (Counter Breach), It's ML platform.
Good knowledge on various tools integration (SMTP, AD, SIEM, SNMP & SOAR platforms).
Working with Data protection team (DAM) to protect Unstructured Data and fine tuning the policy as per best practices and trying to be reducing false positive alerts.
Implementing DLP solution in a cluster environment, designing the DLP policies finalizing the SOW for BAU team.
Experience working in environments that leverage virtualization, Web app firewalls- Akamai, content delivery networks, and dynamically generated code.
Protected vulnerable networks following detailed risk assessments.
Guided cross-functional teams in the design, validation, acceptance testing and implementation of secure, networked communications across remote sites for several key clients.
Working on Email security and EDR solution.
Senior Info-sec Manager
Axis Bank Ltd
Mumbai
03.2018 - 10.2019
Maintain risk register to report recurring risk, vulnerabilities, and other security exposures, including misuse of information assets and non-compliance with enterprise security architecture.
Part of incident response and Incident handling and management.
Infrastructure risk assessment.
Implement best practices DAM policies to find the breaches and Incidents (VLAN segregation, Direct DB access, Password Sharing, Off-hour's access etc.).
Strong knowledge on Imperva Data Risk Analytics (Counter Breach), It's ML platform.
Good knowledge on various tools integration (SMTP, AD, SIEM, SNMP & SOAR platforms).
Working with Symantec DLP solution to implement policy for data leakage.
Working with Data protection team (DAM) to protect Unstructured Data and fine tuning the policy as per best practices and trying to be reducing false positive alerts.
Conduct risk assessments in the evaluation and implementation for security solutions, vendors and services.
Protected vulnerable networks following detailed risk assessments.
Guided cross-functional teams in the design, validation, acceptance testing and implementation of secure, networked communications across remote sites for several key clients.
Senior Security Consultant
Capgemini India Pvt Ltd
Mumbai
06.2016 - 03.2018
Drive data security projects to implement controls across IT with a focus on system, application, and database and network security to support Information Security objectives.
Maintain risk register to report recurring risk, vulnerabilities and other security exposures, including misuse of information assets and non-compliance with enterprise security architecture.
Conduct formal risk assessment, treatment and reporting for assets, process and technology.
Identify IS risks and the appropriate controls for software development, day-to-day operations, and remediation of non-compliance.
Supported internal compliance team for ISO27001, PCI-DSS audit & compliance and maintained audit related documents.
Identified and tested vulnerabilities in the areas of information system and network security.
Maintained information security metrics.
Created and tracked investigations to resolution, as well as developed security alert notifications.
Investigate arising incidents caused by malicious activities and identified false positives on Imperva WAF, Imperva DAM and SIEM product.
Ensure that all activities and duties are carried out in full compliance with regulatory requirements, Enterprise-Wide Risk Management Framework and internal Barclays Policies and Policy Standards.
Document all work in accordance with agreed standards, and with re-use in mind.
Undertake impact assessment of change requests against applications / products within domain.
Create/Review component designs & builds to ensure compatibility with the end-to-end system design.
Collaborate and communicate with other team members to build efficient technical solutions.
Manages small to medium engagements, projects, or teams.
Executes on engagement and project criteria, scope management, and risk management.
Responsible for engagement or project documents and deliverables by using standard delivery methodology.
Senior Technical Specialist
Softcell Technologies ltd
Mumbai
10.2015 - 06.2016
To web filtering for User define policy and troubleshooting remotely.
Define Policy, Category Set, and malware analysis with McAfee Web Gateway.
Investigate arising incidents caused by malicious activities, and identified false positives on Imperva WAF.
Evaluate the security of various web apps.
Experience working in environments that leverage virtualization, Web app firewalls, content delivery networks, and dynamically generated code.
Able to determine short term mitigation (WAF rules, signatures, etc.).
Documented security events daily to create a baseline of activity for the client network.
Managing laptop users and create service with McAfee ePo and McAfee client proxy.
Doing POC of various technologies like ATP, WAF and Proxies products and working as a pre-sales and post-sales consultant.
Security Administrator
Wipro Infotech
Mumbai
09.2014 - 06.2015
To web filtering for User define policy and troubleshooting remotely.
Define Policy, Category Set, and Malware analysis with McAfee Web Gateway.
Investigate arising incidents caused by malicious activities, and identified false positives on Imperva WAF.
Evaluate the security of various web apps.
Experience working in environments that leverage virtualization, Web app firewalls, content delivery networks, and dynamically generated code.
Able to determine short term mitigation (WAF rules, signatures, etc.).
Using packet capture and packet analyzer for Troubleshooting of our network as well as analyze the network with TCPDUMP/Wireshark.
Using Qualys for VA scanning.
Deployed and observed IPS sensors and their resulting alerts.
Performed in-depth forensics on workstation hard drives with endpoint security team.
Senior Specialist
HCL Technologies
Mumbai
11.2011 - 09.2014
Worked with various government bodies and BFSI domain (etc State bank of India, CBI and LIC).
To web filtering for User define policy and troubleshooting remotely.
Define Policy, Category Set, and Malware analysis with McAfee Web Gateway.
Investigate arising incidents caused by malicious activities, and identified false positives on IPS.
Using packet capture and packet analyzer for Troubleshooting of our network as well as analyze the network with TCPDUMP/Wireshark.
Deployed and observed IPS sensors and their resulting alerts.
Monitoring, Device Integration, Alert Configuration, Report Configuration & Ad hoc Report.
Co-relation alert rule Configuration on RSA envision as well as Handled Remote locator log Management in RSA envision.
Security Engineer
3i Infotech CSL ltd
Pune
02.2011 - 10.2011
To web filtering for User define policy and troubleshooting remotely.
Define Policy, Category Set, and Malware analysis with Websense.
Investigate arising incidents caused by malicious activities, and identified false positives on IBM ISS.
Using packet capture and packet analyzer for Troubleshooting of our network as well as analyze the network with TCPDUMP/Wireshark.
Using VA scanning with Nessus.
Monitoring, Device Integration, Alert Configuration, Report Configuration & Ad hoc Report.
Co-relation alert rule Configuration on RSA envision as well as Handled Remote locator log management in RSA envision.
Handling NIPS - IBM Proventia and WIPS – Spectra Guard.
Incident Response - Detection, first response, and handling the incidents, participation on Incidence response team.
Administers security policies to control access to systems.
Technical support engineer
Shine Infotrain ltd
Surat
05.2008 - 01.2011
Using squid proxy based on Linux and add/remove URLs for users troubleshooting of issues reported by end user for web filtering.
DHCP, DNS, RAS, ADS, Terminal, RIS, IIS, Print server, IP Sec, NAT, services configure and troubleshoot.
Configure different types of Securities on Windows and Unix platform (user's management and Domain level security).
Skills
Information security management
Risk assessment and management
Regulatory compliance
Incident response planning
Security policy development
Vulnerability assessment
Certification
CISSP | CRISC | CISM | ISO 27001 LA | CEH | AWS | Azure
Director – Information Security | Business Information Security Officer (BISO) at COX AUTOMOTIVE INC.Director – Information Security | Business Information Security Officer (BISO) at COX AUTOMOTIVE INC.