Summary
Overview
Work History
Education
Skills
Timeline
SeniorSoftwareEngineer
Mukund Shrimali

Mukund Shrimali

Bengaluru

Summary

Proven security leader with over a decade of experience driving enterprise-wide security programs across e-commerce, fintech, banking, and healthcare. Skilled at aligning security with business goals, leading compliance initiatives (ISO 27001, PCI-DSS, DPDP), and building high-performing security teams. Expertise in cloud security, application security, and SOC operations, with a track record of enabling secure digital transformation and preparing organizations for IPO readiness. Adept at stakeholder engagement with regulators, enterprise customers, and leadership teams to build trust and deliver security-driven business value.

Overview

13
13
years of professional experience

Work History

Manager - Information Security

Flipkart Internet Pvt Ltd
06.2021 - Current

Internal transition from Myntra; leading Information Security for Myntra under Flipkart's central InfoSec team


  • Lead Information security program aligning with enterprise security strategy and compliance requirements.
  • Implemented enterprise-wide security architecture for web and mobile applications, enhancing resilience and regulatory compliance.
  • Oversaw PCI-DSS and ISO 27001 audits; engaged directly with auditors to ensure successful certifications.
  • Regularly brief CISO and senior leadership on emerging threats, residual risk posture, and mitigation strategies.
  • Managed and implemented the organization-wide Incident Management program, including incident detection, escalation, response, and post-incident review processes to strengthen resilience.
  • Established automated vulnerability assessment processes to improve efficiency and reduce risk exposure.
  • Mentor and manage AppSec team, embedding secure coding practices through quarterly training and awareness sessions.
  • Partnered with engineering and IT teams to conduct risk assessments for new technology adoption.
  • Directed implementation of WAF, Bot Management, and EDR across 5,000+ VMs, ensuring advanced threat protection.
  • Deployed CSPM, consistently maintaining >90% compliance score across cloud infrastructure.
  • Orchestrated Database Activity Monitoring solution for compliance and data security.
  • Led the enterprise-wide AuthNZ initiative, integrating 128+ services handling PII into a centralized platform.
  • Mentored Security Assurance team and engaged leadership on risk reduction strategies.
  • Partnered with business stakeholders to ensure security was a key enabler in product delivery.

Application Security Manager

Goddard Technical Solutions Pvt Ltd
02.2020 - 06.2021
  • Managed application security suite, bridging management and Tech Leads, while driving compliance and client satisfaction.
  • Crafted API/Mobile/AWS Secure Configuration Guidelines for robust security standards.
  • Implemented infrastructure hardening for AWS, containers, and assets.
  • Led diverse security assessments including Web App, API, Network, and Mobile Penetration Testing.
  • Conducted Architecture Reviews, managed Bug Bounty Program, and automated security through Jenkins (CI/CD) for Avail finance.

Security lead

Happiest Minds Technologies
11.2016 - 02.2020
  • Managed security testing projects across BFSI, e-commerce, and healthcare, aligning assessments with OWASP and compliance requirements.
  • Built and led a 4-member security team, fostering growth and operational excellence.
  • Partnered with sales and delivery teams to drive pre-sales security engagements.

Cyber Security consultant

Cigital Asia
12.2014 - 10.2016
  • Transitioned from intern to permanent position at Iviz Security, specializing in web and mobile app vulnerability scanning according to OWASP and SANS standards.
  • Reviewed penetration testing reports, conducted assessments for diverse clients including top banks and IT firms in India, and communicated findings and remediation strategies. Skilled in identifying business-level threats.

Information Security Trainer

Meclosys Information Services
05.2012 - 12.2013
  • Delivered CEH and cybersecurity training for corporate teams and law enforcement.
  • Partnered with cybercrime city police for specialized awareness workshops.

Education

Diploma Computer Engineering -

VPMP Polytechnic, Technical Education Board

Skills

  • Security Leadership & Governance: Enterprise-wide program management, IPO readiness, policy & standards, security audits & certifications (ISO 27001, PCI, DPDP)
  • Technical Expertise: Cloud security (Azure, CSPM), application security, DevSecOps, OWASP, security architecture, risk frameworks, incident response, BC/DR planning
  • Business Integration: Secure product development, risk-informed decision making, creating security value propositions, RFP security response
  • Operational Excellence: SOC oversight, vulnerability management, WAF/BOT management, threat detection & response, vendor management
  • Stakeholder Engagement: Customer security assurance, regulatory discussions, executive presentations, industry networking
  • People Development: Mentoring and leading diverse global teams, security awareness, cross-functional collaboration

Timeline

Manager - Information Security

Flipkart Internet Pvt Ltd
06.2021 - Current

Application Security Manager

Goddard Technical Solutions Pvt Ltd
02.2020 - 06.2021

Security lead

Happiest Minds Technologies
11.2016 - 02.2020

Cyber Security consultant

Cigital Asia
12.2014 - 10.2016

Information Security Trainer

Meclosys Information Services
05.2012 - 12.2013

Diploma Computer Engineering -

VPMP Polytechnic, Technical Education Board
Mukund Shrimali