Cybersecurity leader with ~20 years of experience building and scaling security functions across e-commerce, financial services, and telecom. Currently heading AI & Product Security at Poshmark India - driving AI security governance, product security frameworks, application security posture, and enterprise IT security across a global platform. Deep expertise across the full security stack: LLM/GenAI security, threat modeling, ASPM, API & mobile security, DevSecOps, cloud security, and vendor risk management. Known for embedding security into product development lifecycles, leading high-performing global teams, and translating technical risk into business outcomes. Two-time Best Cybersecurity Leader Award winner (AVAR 2024, BSides 2025) | Nominated - Cybersecurity Woman of the World Edition 2026 | CISM Rank 1 | CSSLP | AWS Security Specialty.
Overview
19
19
years of professional experience
1
1
Certification
Work History
Head of Cybersecurity - AI & Application Security
Poshmark India
Chennai
09.2023 - Current
Leading enterprise-wide security strategy, product security, and AI security governance for a global social commerce platform.
Established an AI security governance framework encompassing policy definition, AI gateway for observability and access control, and secure integration patterns for MCP-based and LLM-powered systems.
Led threat modeling for 15+ AI-driven product initiatives - identifying attack vectors, trust boundaries, and control gaps across LLM and GenAI features; improved threat detection effectiveness by 40%.
Defined reusable security architecture patterns and reference designs for AI systems, creating secure-by-design guardrails adopted across engineering teams.
Developed enterprise guardrails for GenAI tool usage, defining acceptable use policies, data classification boundaries, and control frameworks governing how employees interact with AI-powered tools.
Established a review and approval process for MCP connectors and AI integrations embedded in existing enterprise tools, assessing security posture, data flow risks, and third-party trust boundaries before deployment.
Driving evaluation and adoption of AI-powered capabilities within the cybersecurity function - identifying use cases across threat detection, vulnerability triage, and security operations where AI can augment team effectiveness.
Embedded a product security framework into the product development lifecycle, ensuring security requirements, threat models, and architecture reviews are built into every stage from ideation to release - reducing vulnerabilities reaching production and accelerating secure delivery.
Led onboarding of Application Security Posture Management (ASPM) platform across all Poshmark repositories, consolidating security findings across SAST, DAST, SCA, and cloud into a unified risk view for engineering and leadership.
Designed and enforced API security standards across internal microservices and third-party integrations, applying OWASP API Top 10 controls and OAuth/JWT hardening across the product ecosystem.
Established mobile security program for Poshmark's iOS and Android apps, conducting OWASP MASVS-aligned assessments and embedding mobile SAST into the release pipeline to secure the platform's primary consumer touchpoints.
Managed end-to-end external penetration testing program - scoping engagements, coordinating third-party vendors, triaging findings, and driving remediation governance across product and infrastructure teams.
Integrated SAST, DAST, and SCA security controls into CI/CD pipelines, enabling automated policy enforcement at scale.
Implemented CSPM solutions to identify and remediate cloud misconfigurations across multi-environment AWS deployments.
Established a third-party security review program for enterprise financial applications, conducting vendor risk assessments, security questionnaires, and architecture reviews to identify and remediate supply chain risks.
Improved EDR detection capabilities across 900+ endpoints by fine-tuning detection rules, expanding coverage, and reducing alert fatigue through systematic noise reduction and threat-aligned rule engineering.
Integrated 8 endpoint, application, and cloud log sources into the enterprise SIEM, significantly enhancing visibility across the attack surface and enabling faster threat detection and incident correlation.
Strengthened enterprise email security posture by enforcing DMARC, DKIM, and SPF policies across all organizational domains, ensuring full email authentication compliance and eliminating spoofing risks.
Implemented anti-phishing and Business Email Compromise (BEC) controls, including phishing simulation campaigns, user awareness training, and technical countermeasures to detect and block targeted email-based attacks.
Developed and executed enterprise-wide security strategy, achieving 100% PCI DSS compliance and reducing security incidents by 30%.
Led a global security organization of 13 professionals across GRC, Product Security, Infrastructure Security, and Security Operations; improved team performance by 25%.
Scaled the security function by 30% through strategic hiring; drove security awareness programs educating 1,000+ employees with 40% improvement in security culture metrics.
Oversaw incident response for 100+ incidents annually; established metrics and performance frameworks improving operational efficiency by 35%.
Senior Manager - DevSecOps & Cloud Security
Ernst & Young (EY)
Chennai
03.2022 - 09.2023
Led global DevSecOps and software security practice, including go-to-market strategy, client solutioning, and delivery management.
Led global DevSecOps pipeline security initiatives - building CI/CD security templates using Jenkins, AWS CodeStar, and GitLab - for enterprise clients across banking and financial services.
Served as cloud security ambassador, delivering architectural guidance and security roadmaps to client leadership.
Managed penetration testing programs for a major banking client, overseeing a team of 25 testers and delivering on-time, within-budget outcomes.
Built and scaled a 20-member DevSecOps and cloud security practice, driving hiring, capability development, and delivery excellence across client engagements.
Deputy General Manager - Security Projects Engineering
Tata Communications Limited
Chennai
04.2020 - 03.2022
Reported directly to the Global CISO; responsible for security architecture, DevSecOps, and governance across critical infrastructure products.
Implemented DevSecOps for critical products - integrating SAST/DAST/SCA tools and automating security testing across CI/CD pipelines.
Established governance framework for open-source usage - covering API security, public code repositories, and developer contributions - reducing third-party software risk across product teams.
Established cloud infrastructure governance framework including cloud posture assessment, workload protection, and security policy/standards.
Revamped the Information Security Assurance process to embed architecture review, static/dynamic analysis, and remediation governance throughout SDLC.
Launched a Software Security training program for 350+ developers with platform-specific foundational and advanced courses.
Senior Security Architect
Cognizant Technology Solutions
Jersey City
12.2007 - 03.2020
12-year progression from security engineer to senior architect; led delivery of large-scale application and cloud security programs across global clients.
Conducted Cloud Security Assessments for 150+ applications; presented findings and remediation roadmaps to CTO/CISO-level client stakeholders.
Managed delivery as lead for 15 Shared Services security projects, overseeing a team of 40+ across design reviews, risk assessments, static/dynamic analysis, and vulnerability management.
Co-authored white paper: 'Application Vulnerability: Trend Analysis and Correlation of Coding Patterns Across Industries' (published via Cognizant/SlideShare).
Multiple team and delivery excellence awards at Cognizant, 2010-2013
Leadership And Community
Chennai Chapter President, IronLady, Leading a Pan-India women's leadership community; spearheaded Walk to Board 2026 across 7 cities, mobilising 800+ women leaders.
Founder, NexGenCyberWomen, Built and runs a cybersecurity community dedicated to mentoring and advancing women in the field.
Speaker & Guest Lecturer, Keynote speaker and panelist at industry conferences (BSides, AVAR) and engineering colleges on cybersecurity leadership and AI security.
Professional Memberships, ISACA, ISC2, Women in CyberSecurity (WiCyS), Bsides
Timeline
Head of Cybersecurity - AI & Application Security
Poshmark India
09.2023 - Current
Senior Manager - DevSecOps & Cloud Security
Ernst & Young (EY)
03.2022 - 09.2023
Deputy General Manager - Security Projects Engineering