Seasoned information security professional with 19 years of experience in developing and implementing robust cybersecurity strategies. Skilled in managing security operations, leading cross-functional teams, and driving security compliance and risk mitigation initiatives. Adept at leveraging the latest security technologies and best practices to protect critical organizational assets.
Overview
19
19
years of professional experience
11
11
Certification
Work History
Vice President - Information Security
BNY
12.2020 - Current
Conducted and documented regular audits for critical business service applications and horizontal processes identifying IT internal control weakness and developing remediation plans
Performed risk assessments, aligning security policies with regulatory requirements to strengthen the organization's audit-readiness
Prepared detailed reports on audit findings for executive leadership , ensuring clarity in compliance status and recommendations for improved control measures
Collaborated with cross-functional teams to enforce information security policies, enhancing compliance with industry standards
Led compliance framework audits, resulting in reduction in compliance incidents. Conducted in-depth risk assessments, identifying control gaps and remediating vulnerabilities.
Cultivated strong relationships with key stakeholders, including vendors, regulators, and community leaders to promote collaboration and long-term success.
Established a culture of continuous improvement, fostering innovation and driving sustainable growth across the organization.
Demonstrated proficient leadership skills to motivate employees and build competent teams.
Collaborated with senior management to develop strategic initiatives and long term goals.
Negotiated high-value contracts that maximized profitability while mitigating risks for the organization.
Managed financial planning and budgeting processes, ensuring fiscal responsibility and maximizing return on investments.
Senior Manager - Information Security
Virtusa Consulting Services
01.2020 - 12.2020
Plan and conduct audit for all High Security Accounts (ISO27001 and NIST 800-53 standard)
Performing audits on regular frequency for identifying gaps and their effective mitigation by engagement
Perform technical risk assessments for critical accounts and projects categorized as High Security Accounts
Identify IT internal control weaknesses in processes by performing Risk Assessment and document the findings
Registering all risks identified in available risk registers and following up till closure
Preparation of reports/deliverables/status updates/audit committee presentations
Perform security assessments on the new Work From Home amendments
Establish and develop functional requirement including operationalization of audit programs and testing of audit module in Service Now GRC application
Attention to detail and mentor young interns and analysts within the practice
Contribute to knowledge management sessions within the practice
Identify and escalate potential business opportunities for the firm on existing client engagements
Provided strong leadership to enhance team productivity and morale.
Senior Manager - Information Security
HCL Technologies Limited
05.2019 - 10.2019
Second line of defence for identifying and managing the Information Security related risks in engagement
Review MSA / SOW for contractual commitment
Validation of controls: Enhanced Compliance Assessments ECA performed with ISO27001 baseline and contractual controls from MSA
Performing audits on regular frequency for identifying gaps and their effective mitigation by engagement
Registering all risks identified in available Risk Registers and following-up till closure
Regulatory and Audit coordination, organizing meetings with regulators and external auditors, identifying and tracking outstanding regulatory and audit commitments, oversight on controls over regulatory reporting
Ensure compliance with internal policies (audit methodology and risk management) and regulatory requirements
Maintain documentation required and as agreed for security assessments, audits and internal control testing
Evaluate the efficiency of controls and improve them to keep account healthier
Lead Consultant- Information Security
Wipro Limited
03.2014 - 05.2019
Conceptualizing, formulating, updating and implementing company-wide information security policies & procedures
Assessing and implementing Information and Communications Technology (ICT) / Information Security (IS) Governance best practices, recommendations and Industry Information Security (IS) requirements
Identifying threats, risks and vulnerabilities from emerging security violations
Ensuring fulfilment of legal and contractual information security / privacy mandates and directing responses to network or system intrusions
Performing technical risk evaluation of hardware and software installed in systems & networks
Testing installed systems to ensure protection strategies are properly implemented and working as intended
Executing & testing risk treatment plans / controls to verify and address risks in an effective & efficient manner
Supporting control owners to mitigate risks and improve their controls
Fostered user security awareness; responded to information security incidents
Planning and implementing business continuity plans, disaster recovery plans, risk mitigation plan, and crisis management as per ISO 23001 guidelines
Coordinating for internal/external audits; steering internal audits as per the corporate security policy
Closing critical loopholes, maximizing security options, and staying ahead of current risks
Delivering leadership guidance and training to information systems security personnel
Received Certificate of Excellence Award for displaying outstanding performance at workplace and for showcasing dedication, handwork, competence and commitment in 2016
Recipient of Global Infrastructure Services Award-The Willingness to Outwork and Outlearn Makes All Difference in 2017
Achieved 7/7 in Customer Satisfaction Survey results for 2 consecutive years in 2015 and 2016
Attained Net Promoter Score of 10/10 for 2 consecutive years in 2015 and 2016
Contributed in cyber security practice
Successfully conducted assessments independently to evaluate that GLOBE IS/IT controls are effective & efficient and reduce risks at an acceptable level for the organization
Worked with different towers to develop plan comprising business continuity strategy, infrastructure & critical resources of plan
Reduced data loss or unauthorized access with an estimated annual savings through planning and implementing business process and technical controls
Acted as a member of core IS team set-up to provide strategic direction and operationalize Information Security function
IT Senior Security Specialist
Objectwin Technology India Pvt Ltd
08.2013 - 03.2014
Conducted technical risk evaluation of hardware & software installed in systems & networks
Performed security audits as well as vulnerability assessment on globe servers
Evaluated risk treatment plans, controlled mitigations, and reported results to management & stakeholders
Designed & governed Security Management framework and led SOX SAS70 & security compliance efforts to reduce business risk
Supported a team of business continuity coordinators within key business units to implement a business continuity methodology consisting of business impact analysis, plan development, exercises and on-going plan maintenance
Delivered consistent success in protecting organization's computers, networks and data against threats, such as security breaches, computer viruses or attacks by cybercriminals
Gained exposure in various aspects of cyber security including computer network attack, computer network defence, computer network reconnaissance, cyber forensics, and cyber intelligence collection and analysis
Team Leader-Service Delivery / Technical Support
Emirates NBD
01.2008 - 04.2012
System Engineer
KPMG
07.2006 - 09.2007
Technical Support Engineer
Jesuma Computers
03.2005 - 05.2006
Technical Support Engineer
Slash Support
06.2004 - 01.2005
Technical Support Help Desk Engineer - HP Project
Sutherland Technologies Limited
03.2004 - 05.2004
Education
EPGDBM - Business Management
Symbiosis
01.2018
MBA - Systems
Vinayaka Mission
01.2011
B.Sc. - Mathematics
Madras University
01.2002
Skills
Information Security Consulting
IS Audits
Cyber Risk Management
Governance, Risk and Compliance
Project Management
Operational & Strategic Planning
Data Privacy
Vulnerability Assessment & Management
Business Continuity & Disaster Recovery
Team Management
Vendor Risk Management
Cloud Security
Certification
NPTEL Certification on Information Security conducted by IIT Madras
Certified Lead Implementer Professional (CLIP) for BS10012:2017 - PIMS including GDPR
CRisP - Certified Risk Professional
Certified Ethical Hacker (CEH)
EC Council Certified Security Analyst (ECSA)
ISO27001 IRCA Lead Auditor
COBIT 5 Foundation
Cisco Certified Network Associate
Microsoft Certified System Administrator
ITIL Version 3
Languages
English
Tamil
Training
PMP (Project Management Professional)
ELP - Emerging Leaders Program
Negotiation Skills
CHFI - Certified Hacking Forensic Investigator
Personal Information
Location Preference: South India
Date of Birth: 03/29/81
Timeline
Vice President - Information Security
BNY
12.2020 - Current
Senior Manager - Information Security
Virtusa Consulting Services
01.2020 - 12.2020
Senior Manager - Information Security
HCL Technologies Limited
05.2019 - 10.2019
Lead Consultant- Information Security
Wipro Limited
03.2014 - 05.2019
IT Senior Security Specialist
Objectwin Technology India Pvt Ltd
08.2013 - 03.2014
Team Leader-Service Delivery / Technical Support
Emirates NBD
01.2008 - 04.2012
System Engineer
KPMG
07.2006 - 09.2007
Technical Support Engineer
Jesuma Computers
03.2005 - 05.2006
Technical Support Engineer
Slash Support
06.2004 - 01.2005
Technical Support Help Desk Engineer - HP Project
Sutherland Technologies Limited
03.2004 - 05.2004
MBA - Systems
Vinayaka Mission
B.Sc. - Mathematics
Madras University
NPTEL Certification on Information Security conducted by IIT Madras
Certified Lead Implementer Professional (CLIP) for BS10012:2017 - PIMS including GDPR
CRisP - Certified Risk Professional
Certified Ethical Hacker (CEH)
EC Council Certified Security Analyst (ECSA)
ISO27001 IRCA Lead Auditor
COBIT 5 Foundation
Cisco Certified Network Associate
Microsoft Certified System Administrator
ITIL Version 3
EPGDBM - Business Management
Symbiosis
Similar Profiles
Allison MoschettaAllison Moschetta
Associate, Business Planning and Analysis II at BNYAssociate, Business Planning and Analysis II at BNY