Seasoned Chief Information Security Officer with over 23 years of experience in driving strategic information security initiatives, risk management and compliance programs across diverse industries. Skilled in managing global GRC and cyber security teams, information security budget management and ensuring compliance with regulatory standards. Passionate about fostering a culture of security awareness and continuous improvement, while leveraging cutting edge-technologies to enhance overall organizational resilience.
Overview
19
19
years of professional experience
2004
2004
years of post-secondary education
Work History
Chief Information Security and Privacy Officer
Rakuten India & Rakuten Symphony India
Bangalore, India
11.2019 - 01.2025
Governance, Risk and Compliance
Developed and implemented GRC deliverables tailored to the unique needs of diverse businesses across different regions, ensuring alignment with corporate governance frameworks.
Implemented ISO 27001 Information Security Management System across Rakuten Symphony entities at Dubai, Germany, USA, Japan, Singapore and India.
Implemented ISO 27701 privacy standards for Rakuten India and Rakuten Symphony entities.
Secured SOC 2 Type II attestation for Rakuten India's SaaS products
Ensured PCI-DSS compliance for Rakuten Card and E-commerce divisions spread across Japan, Signapore, USA and Europe.
Developed Business Continuity for technology and pandemic scenarios for numerous Business Units at Rakuten India and Rakuten Symphony India.
Collaborated with CTOs and CIOs to provide risk assessments, threat analysis, and strategic recommendations through detailed reports and KPIs.
Strategic Leadership
Led strategic information security and privacy programme integration across business
Created comprehensive cyber security strategy for Rakuten India and Rakuten Symphony India
Managed an information security budget of $20 million, optimizing resource allocation to enhance security measures and reduce attack surface and vulnerabilities.
Developed Information Security Objectives with IT Security Risks and mitigation strategies
Established enterprise-wide cyber threat intelligence capability
Information Security Program Management
Implemented and oversaw enterprise-wide information security and IT risk management programme
Successfully implemented information security programs such as Shadow IT Management, CASB (DLP), Data Loss Detection (DLD), Third Party Risk Management, Data Privacy program
Cyber Security Defense Department
Providing leadership and direction within Cyber Security Defense Department consisting of Security Operations Center (SOC), Threat Intelligence, Threat Hunting and Application Security team
Managing SOC team consisting of L1, L2, L3 Analysts, Tech Lead and SOC manager (SIEM - Microsoft Sentinel)
Collaborated with internal and external stakeholders to lead global Vulnerability Management processes
Head Cyber Security Defense Operations
Williams Lea Tag
Chennai - Bangalore
06.2018 - 08.2019
Managed large Incident Response Center (IRC) team
Developed Incident Response plan to deal with the Data Breach incident
Monitored security vulnerabilities and hacking threats within WLT's estate
Monitor intelligence sources to identify potential threats/compromises
Managed Cyber Threat Intelligence team
Conducted risk assessment, security audits
Identified issues, risks, opportunities and improvement of policies, processes, procedures and standards
Co-ordinated with client Information Security teams, compliance teams, auditing teams, and regulators
Senior Manager - Cyber Security Engineering
Tata Communications Ltd
Chennai - Bangalore
08.2017 - 06.2018
Managed security with IT to provide technology oversight
Managed team of Architects
Engineered, implemented and monitored security measures
Peer reviewed computer security architecture and cyber security designs
Wrote comprehensive reports
Successfully introduced cloud-security approach/benefits to C-suite management
Network Engineer
Gurgaon
11.2007 - 11.2008
Reported to the Team Manager as individual contributor for implementing/monitoring/supporting security devices and applications for the network
Deployed, configured and supported VPN connections
Planned, configured, established and supported VPN tunnels
Resolved all network security related issues
Network Engineer
Genpact India Pvt. Ltd
Gurgaon
04.2006 - 11.2007
Reported to the Team Manager as individual contributor as well as in the role of Project Lead
Collaborated with Connectivity Leader in UK
Deployed/configured VLANs
Deployed/supported site-to-site VPNs
Education
Master of Commerce - Commerce
Manonmaniam Sundaranar University
Bachelor of Commerce - Commerce
Osmania University
Skills
Governance Risk & Compliance
NIST
ISO 27001
CIS
PCI DSS
SOC 2
Vulnerability Management
Incident Response
Application Security
SIEM - Splunk, MS Sentinel
Information Security Program Management
SOC Operations
Cyber Threat Intelligence
Threat Hunting
Cloud Security
Third Party Risk Management
KPIs & Performance Metrics
DLP
Privacy Assessment & Compliance (GDPR, CCPA)
Languages
English
Hindi
Tamil
Telugu
Kannada
Japanese (L)
Personal Information
Date of birth: 07/19/80
Marital status: Married
Visa status: Japan Business Visit Visa till 2025
Timeline
Chief Information Security and Privacy Officer
Rakuten India & Rakuten Symphony India
11.2019 - 01.2025
Head Cyber Security Defense Operations
Williams Lea Tag
06.2018 - 08.2019
Senior Manager - Cyber Security Engineering
Tata Communications Ltd
08.2017 - 06.2018
Network Engineer
11.2007 - 11.2008
Network Engineer
Genpact India Pvt. Ltd
04.2006 - 11.2007
Bachelor of Commerce - Commerce
Osmania University
Master of Commerce - Commerce
Manonmaniam Sundaranar University
Similar Profiles
CHETAN BAROTHIYACHETAN BAROTHIYA
DevOps Engineer at Rakuten Symphony IndiaDevOps Engineer at Rakuten Symphony India