Summary
Overview
Work History
Education
Skills
Websites
Certification
Awards
Leadership And Community
Timeline
Generic

VIMALAASREE ANANDHAN

Head of Cybersecurity - AI & Application Security
Chennai

Summary

Cybersecurity leader with ~20 years of experience building and scaling security functions across e-commerce, financial services, and telecom. Currently heading AI & Product Security at Poshmark India - driving AI security governance, product security frameworks, application security posture, and enterprise IT security across a global platform. Deep expertise across the full security stack: LLM/GenAI security, threat modeling, ASPM, API & mobile security, DevSecOps, cloud security, and vendor risk management. Known for embedding security into product development lifecycles, leading high-performing global teams, and translating technical risk into business outcomes. Two-time Best Cybersecurity Leader Award winner (AVAR 2024, BSides 2025) | Nominated - Cybersecurity Woman of the World Edition 2026 | CISM Rank 1 | CSSLP | AWS Security Specialty.

Overview

19
19
years of professional experience
1
1
Certification

Work History

Head of Cybersecurity - AI & Application Security

Poshmark India
Chennai
09.2023 - Current
  • Leading enterprise-wide security strategy, product security, and AI security governance for a global social commerce platform.
  • Established an AI security governance framework encompassing policy definition, AI gateway for observability and access control, and secure integration patterns for MCP-based and LLM-powered systems.
  • Led threat modeling for 15+ AI-driven product initiatives - identifying attack vectors, trust boundaries, and control gaps across LLM and GenAI features; improved threat detection effectiveness by 40%.
  • Defined reusable security architecture patterns and reference designs for AI systems, creating secure-by-design guardrails adopted across engineering teams.
  • Developed enterprise guardrails for GenAI tool usage, defining acceptable use policies, data classification boundaries, and control frameworks governing how employees interact with AI-powered tools.
  • Established a review and approval process for MCP connectors and AI integrations embedded in existing enterprise tools, assessing security posture, data flow risks, and third-party trust boundaries before deployment.
  • Driving evaluation and adoption of AI-powered capabilities within the cybersecurity function - identifying use cases across threat detection, vulnerability triage, and security operations where AI can augment team effectiveness.
  • Embedded a product security framework into the product development lifecycle, ensuring security requirements, threat models, and architecture reviews are built into every stage from ideation to release - reducing vulnerabilities reaching production and accelerating secure delivery.
  • Led onboarding of Application Security Posture Management (ASPM) platform across all Poshmark repositories, consolidating security findings across SAST, DAST, SCA, and cloud into a unified risk view for engineering and leadership.
  • Designed and enforced API security standards across internal microservices and third-party integrations, applying OWASP API Top 10 controls and OAuth/JWT hardening across the product ecosystem.
  • Established mobile security program for Poshmark's iOS and Android apps, conducting OWASP MASVS-aligned assessments and embedding mobile SAST into the release pipeline to secure the platform's primary consumer touchpoints.
  • Managed end-to-end external penetration testing program - scoping engagements, coordinating third-party vendors, triaging findings, and driving remediation governance across product and infrastructure teams.
  • Integrated SAST, DAST, and SCA security controls into CI/CD pipelines, enabling automated policy enforcement at scale.
  • Implemented CSPM solutions to identify and remediate cloud misconfigurations across multi-environment AWS deployments.
  • Established a third-party security review program for enterprise financial applications, conducting vendor risk assessments, security questionnaires, and architecture reviews to identify and remediate supply chain risks.
  • Improved EDR detection capabilities across 900+ endpoints by fine-tuning detection rules, expanding coverage, and reducing alert fatigue through systematic noise reduction and threat-aligned rule engineering.
  • Integrated 8 endpoint, application, and cloud log sources into the enterprise SIEM, significantly enhancing visibility across the attack surface and enabling faster threat detection and incident correlation.
  • Strengthened enterprise email security posture by enforcing DMARC, DKIM, and SPF policies across all organizational domains, ensuring full email authentication compliance and eliminating spoofing risks.
  • Implemented anti-phishing and Business Email Compromise (BEC) controls, including phishing simulation campaigns, user awareness training, and technical countermeasures to detect and block targeted email-based attacks.
  • Developed and executed enterprise-wide security strategy, achieving 100% PCI DSS compliance and reducing security incidents by 30%.
  • Led a global security organization of 13 professionals across GRC, Product Security, Infrastructure Security, and Security Operations; improved team performance by 25%.
  • Scaled the security function by 30% through strategic hiring; drove security awareness programs educating 1,000+ employees with 40% improvement in security culture metrics.
  • Oversaw incident response for 100+ incidents annually; established metrics and performance frameworks improving operational efficiency by 35%.

Senior Manager - DevSecOps & Cloud Security

Ernst & Young (EY)
Chennai
03.2022 - 09.2023
  • Led global DevSecOps and software security practice, including go-to-market strategy, client solutioning, and delivery management.
  • Led global DevSecOps pipeline security initiatives - building CI/CD security templates using Jenkins, AWS CodeStar, and GitLab - for enterprise clients across banking and financial services.
  • Served as cloud security ambassador, delivering architectural guidance and security roadmaps to client leadership.
  • Managed penetration testing programs for a major banking client, overseeing a team of 25 testers and delivering on-time, within-budget outcomes.
  • Built and scaled a 20-member DevSecOps and cloud security practice, driving hiring, capability development, and delivery excellence across client engagements.

Deputy General Manager - Security Projects Engineering

Tata Communications Limited
Chennai
04.2020 - 03.2022
  • Reported directly to the Global CISO; responsible for security architecture, DevSecOps, and governance across critical infrastructure products.
  • Implemented DevSecOps for critical products - integrating SAST/DAST/SCA tools and automating security testing across CI/CD pipelines.
  • Established governance framework for open-source usage - covering API security, public code repositories, and developer contributions - reducing third-party software risk across product teams.
  • Established cloud infrastructure governance framework including cloud posture assessment, workload protection, and security policy/standards.
  • Revamped the Information Security Assurance process to embed architecture review, static/dynamic analysis, and remediation governance throughout SDLC.
  • Launched a Software Security training program for 350+ developers with platform-specific foundational and advanced courses.

Senior Security Architect

Cognizant Technology Solutions
Jersey City
12.2007 - 03.2020
  • 12-year progression from security engineer to senior architect; led delivery of large-scale application and cloud security programs across global clients.
  • Conducted Cloud Security Assessments for 150+ applications; presented findings and remediation roadmaps to CTO/CISO-level client stakeholders.
  • Managed delivery as lead for 15 Shared Services security projects, overseeing a team of 40+ across design reviews, risk assessments, static/dynamic analysis, and vulnerability management.
  • Co-authored white paper: 'Application Vulnerability: Trend Analysis and Correlation of Coding Patterns Across Industries' (published via Cognizant/SlideShare).

Education

M.Sc. - Software Engineering

BITS Pilani
01.2014

PGDBA - undefined

Symbiosis Centre of Distance Learning
01.2009

B.E. - Computer Science

M.N.M Jain Engineering College
01.2004

Skills

  • AI Security & Governance
  • LLM / GenAI Risk Management
  • Application Security Architecture
  • Threat Modeling (STRIDE/PASTA)
  • Product Security & Secure SDLC
  • ASPM & Security Posture Management
  • DevSecOps & CI/CD Security
  • API & Mobile Security
  • Cloud Security (AWS/CSPM)
  • EDR / SIEM & Security Operations
  • Third-Party & Vendor Risk Management
  • Security Organization Building & Leadership

Certification

  • Certified Information Security Manager (CISM), ISACA, 1st Rank Holder
  • Certified Software Security Lifecycle Professional (CSSLP), ISC2
  • AWS Certified Security - Specialty
  • ISO 27001 Lead Implementer
  • Certified Information Systems Auditor (CISA), ISACA
  • Certified Ethical Hacker (CEH), EC-Council
  • CompTIA Security+
  • AWS Certified Cloud Practitioner
  • Board Member Program & Leadership Essentials, IronLady

Awards

  • Nominated - Cybersecurity Woman of the World Edition, 2026
  • Best Cybersecurity Leader Award, AVAR, 2024
  • Best Cybersecurity Leader Award, BSides Bangalore, 2025
  • Certificate of Excellence in Vendor Security, Tata Communications, 2021
  • Cognizant's Prestigious Challenge Coin Award, 2019
  • Golden Mentor of the Year Award, 2013
  • Multiple team and delivery excellence awards at Cognizant, 2010-2013

Leadership And Community

  • Chennai Chapter President, IronLady, Leading a Pan-India women's leadership community; spearheaded Walk to Board 2026 across 7 cities, mobilising 800+ women leaders.
  • Founder, NexGenCyberWomen, Built and runs a cybersecurity community dedicated to mentoring and advancing women in the field.
  • Speaker & Guest Lecturer, Keynote speaker and panelist at industry conferences (BSides, AVAR) and engineering colleges on cybersecurity leadership and AI security.
  • Professional Memberships, ISACA, ISC2, Women in CyberSecurity (WiCyS), Bsides

Timeline

Head of Cybersecurity - AI & Application Security

Poshmark India
09.2023 - Current

Senior Manager - DevSecOps & Cloud Security

Ernst & Young (EY)
03.2022 - 09.2023

Deputy General Manager - Security Projects Engineering

Tata Communications Limited
04.2020 - 03.2022

Senior Security Architect

Cognizant Technology Solutions
12.2007 - 03.2020

M.Sc. - Software Engineering

BITS Pilani

PGDBA - undefined

Symbiosis Centre of Distance Learning

B.E. - Computer Science

M.N.M Jain Engineering College
VIMALAASREE ANANDHANHead of Cybersecurity - AI & Application Security