Summary
Overview
Work History
Education
Skills
Certification
Security Research & Community Experience
Timeline
Generic
Sangeeta Yadav

Sangeeta Yadav

Principal Cybersecurity
Gurgaon,HR

Summary

Cybersecurity and security architecture leader with 14+ years shaping enterprise security across global technology, regulated fintech and industrial environments. Operates at enterprise leadership level across three strategic pillars — enterprise security architecture, cyber risk governance and secure-by-design transformation. Proven in translating cybersecurity strategy into scalable architecture and governance frameworks across cloud, digital and OT environments. Led enterprise programmes across eGRC, third-party risk, vulnerability management and security assurance, with trusted advisory to senior leadership on technology risk and architecture decisions.

Overview

10
10
Certifications
15
15
years of professional experience

Work History

Virtual CISO / Cybersecurity Advisor

Craw Security
03.2025 - Current
  • Deliver [number]% of remediation priorities through executive reporting, stakeholder alignment, and roadmap updates.
  • Assess [number] security gaps weekly across architecture, governance, and operational controls.
  • Advise client leaders on cybersecurity strategy aligned with business objectives and security transformation priorities.
  • Strengthen governance with security policies, standards, accountability models, and executive reporting.
  • Guide organisations on enterprise security architecture, cloud security architecture, and application security architecture.
  • Translate cybersecurity risk into clear business impact, exposure, and executive-level recommendations.
  • Develop pragmatic remediation roadmaps for maturity, compliance, vulnerability management, and cloud security priorities.

Principal CyberSecurity

BHP Billiton
05.2022 - 03.2025
  • Advanced critical vulnerabilities by ~97% (2,856 to ~90) through Secure SDLC and GitLab-based DevSecOps controls.
  • Drove AWS cloud security posture, CSPM, architecture reviews, threat modelling, and risk assessments to eliminate critical cloud findings.
  • Strengthened enterprise security governance with risk-based standards, security controls, automation, and remediation oversight.
  • Led enterprise security architecture and security-by-design initiatives across engineering, infrastructure, and platform environments.
  • Partnered with senior leaders and cross-functional stakeholders to communicate cyber risk, architecture decisions, remediation priorities, and business impact.
  • Built security awareness and engagement initiatives reaching 1,000+ participants, while mentoring professionals across cloud security, AppSec, and threat modelling.

Information Security Manager

ADDX PTE Ltd
08.2019 - 05.2022
  • Built cybersecurity strategy, roadmap, and governance for a fintech environment from the ground up.
  • Owned enterprise security architecture across applications, networks, platforms, and AWS, embedding security requirements into solution design and Secure SDLC.
  • Established AWS cloud security posture management, strengthening IAM, access controls, architecture standards, vulnerability management, and cloud risk oversight.
  • Implemented real-time threat detection, WAF controls, and SIEM capabilities to strengthen monitoring, incident response, and application-layer protection.
  • Led security design reviews, threat modelling, architecture risk assessments, VA/PT, and application, API, and blockchain security, defining preventive and compensating controls.
  • Maintained 99.9% availability of security monitoring services across AWS and internal platforms.

Security Program Manager

Microsoft Pvt Ltd
12.2018 - 08.2019
  • Designed third-party security assessment framework; led Threat Modelling, Secure Code Review, and
    Penetration Testing for mission-critical enterprise software. Introduced ML-based static analysis and
    data-driven risk scoring to improve detection and prioritisation at programme scale.
  • Drove lean process transformation and automation across the Third-Party Software Security programme,
    materially reducing manual triage overhead and serving as lead Cyber Security Consultant to enterprise
    clients on business-critical application risk.

Information Security Architect

Zeotap India Pvt Ltd Global Role
11.2017 - 12.2018
  • Designed and governed secure application and network architecture, strengthening IAM, access controls and overall security posture through threat modelling, security design reviews, AWS security automation and platform hardening.
  • Led incident response, post-incident analysis, disaster recovery drills and enterprise security assessments, improving resilience, recovery readiness and risk visibility for stakeholders.

Security Consultant

E&Y
04.2017 - 10.2017
  • Defined and standardized security evaluation procedures across diverse IT products, including mobile devices, thick clients, network equipment and operating systems, improving consistency and quality of security assessments.
  • Advised on cloud security, IAM and security architecture, designing risk-based controls aligned with business, customer and regulatory requirements.

Security Analyst

SAP Labs India
07.2015 - 03.2017
  • Performed manual and automated source-code reviews, VA/PT, and security assessments for SAP On-Device, On-Demand, and On-Premise products.
  • Translated threat intelligence and OSINT findings into concise reports and briefings for technical and non-technical stakeholders. Supported security analysis by aligning findings to corporate standards and presenting risks in clear, decision-ready language.

InfoSec Consultant

Bytecode Cyber Security
07.2011 - 08.2013
  • Conducted web application, thick-client, network security testing and vulnerability assessments, including manual penetration testing.
  • Delivered Network Security and Application Security training to team members on security tools, methodologies and manual penetration-testing techniques.

Education

Master of Technology - Information Security and Management

Delhi Technical University
India
05-2015

Bachelor of Technology - Computer Science Engineering

Kurukshetra University
India
05-2011

Skills

Enterprise security architecture

Cloud security architecture

Application security architecture

Threat modelling

Security design reviews

Cybersecurity strategy

Security governance

Security policies & standards

Security maturity assessments

Executive reporting

Stakeholder management

Architecture risk assessment

Cloud security posture management

Identity & access management

Third-party risk management

Security program metrics

Certification

Certified Information Systems Security Professional (CISSP)

Security Research & Community Experience

Part-time Cobalt community pentester, Part-time Synack platform Pentester

Timeline

Virtual CISO / Cybersecurity Advisor

Craw Security
03.2025 - Current

Principal CyberSecurity

BHP Billiton
05.2022 - 03.2025

Information Security Manager

ADDX PTE Ltd
08.2019 - 05.2022

Security Program Manager

Microsoft Pvt Ltd
12.2018 - 08.2019

Information Security Architect

Zeotap India Pvt Ltd Global Role
11.2017 - 12.2018

Security Consultant

E&Y
04.2017 - 10.2017

Security Analyst

SAP Labs India
07.2015 - 03.2017

InfoSec Consultant

Bytecode Cyber Security
07.2011 - 08.2013

Bachelor of Technology - Computer Science Engineering

Kurukshetra University

Master of Technology - Information Security and Management

Delhi Technical University
Sangeeta YadavPrincipal Cybersecurity