Vice President and Chief Information Security Officer at QualityKiosk Technologies (2025-05 – Present)
GRC | TPRM | RBI Compliance | DPDP | Cloud Security
- Develop and maintain security and privacy policies, standards, and governance frameworks
- Drive implementation and governance of Digital Personal Data Protection (DPDP) compliance
- Lead enterprise-wide cybersecurity, privacy, and IT risk management strategy
- Lead SOC Operations, incident response, including data breach management
- Implement vendor risk management and third-party security frameworks
- Oversee threat intelligence, vulnerability management, and security testing programs
- Maintain ISO 27001, ISO 27701 and SOC 2 Type II certifications
- Drive enterprise-wide privacy and security awareness programs
Assistant Vice President – Information Security at Star Union Dai-ichi Life Insurance (2016-11 – 2025-05)
GRC | IRDAI Compliance | BCM | Awareness | Cloud Security | Internal and External Audit
- Defined and executed enterprise cybersecurity and privacy strategy aligned with IRDAI, ISO 27001, NIST, UIDAI, DPDPA and JV partner's frameworks
- Established and managed Governance, Risk and Compliance (GRC), Third Party Risk Management (TPRM), and Business Continuity Management (BCM) frameworks
- Defined and enforced security standards across core technology platforms, lead security control implementations across IT and Cloud infrastructure and assisted selection of security technologies to strengthen organizational resilience
- Managed Security Operations Center (SOC) operations
- Led cyber incident response and crisis management
- Oversee Vulnerability Assessment and Penetration Testing (VAPT) program, Red Team & BAS exercises
- Implemented and managed Privilege Access Management (PAM), Data Leak Prevention (DLP), Mobile Data Management (MDM) solutions
- Promoted security and privacy culture through awareness programs and simulations
- Managed regulatory audits, partner inspections and certifications
- CERT-IN Incident reporting and Implementing CERT-IN threat advisories
- Managed cyber insurance and claims
- Presented cyber security compliance and risk posture to senior leadership, board, and Information Security Risk Management Committee (ISRMC) periodically
- Define Business Continuity Framework
- Conduct Business Impact Analysis (BIA) and prioritize critical processes for Business Continuity and Disaster Recovery (DR) systems
- Define Business Continuity Strategy, Prepare Business Continuity Policy and Plans
- Conduct table top exercise
- Invoke BCM Steering Committee, provide regular updates during crisis and assist in recovery
Senior Manager – Head IT & Information Security at Cheers Interactive India Pvt. Ltd. (2012-02 – 2016-11)
GRC | AD | Firewall | DLP | IRM | VMWare | ITIL
- Developed information security and privacy policies and processes
- Implemented Information Risk Management (IRM) solution
- Ensured data protection compliance and client-specific security requirements
- Conducted periodic reviews of security controls (AD, firewall, DLP, endpoint security)
- Managed enterprise IT infrastructure, virtualization (VMware), and networks
- Led ITIL processes: incident, problem, and change management
- Implemented DLP, patching, antivirus, and capacity management
- Managed vendors, budgets, and service delivery operations
- Oversee threat intelligence, vulnerability management, and security testing programs
- Maintain ISO 27001, ISO 27701 and SOC 2 Type II certifications
- Drive enterprise-wide privacy and security awareness programs
Manager — PMO and Business Continuity at Bharti AXA Life Insurance (2008-05 – 2012-02)
IRDAI Compliance | BCM | Project Management
- Execute strategic programs from concept, analysis to design and implementation followed by benefit monitoring
- Create project plans engaging team members and vendors, address risks, and develop work breakdown structures
- Project status monitoring, reporting and participation in project portfolio reviews
- Assist Program Portfolio Management Committee (PPMC) on decisions on future projects by analyzing bid-papers basis cost, benefits and alignment with strategic objectives
- Organize and execute Project Management trainings, workshops and PM mentoring programs
- Implement and Manage Business Continuity processes across all functions and offices
- Document BIA, BCRA and Business Continuity Plans for all the departments
- Design and Document Branch BCP's for all branches pan India
- Periodic testing of BCP's for all the departments and branches
- Assist in developing DR plans and its periodic testing
- Organize trainings for Business Continuity
Assistant Manager — Information Security and BCM at ABN AMRO Bank (2006-07 – 2008-05)
RBI Circulars, Guidelines, Advisories and SEBI Compliance | BCM
- Conduct Technology Risk assessment and Security Testing of RTGS, NEFT and ATM systems
- Monitor Audit issues and assist in its closures
- Review and update Business Continuity and Disaster Recovery plans
- Assist in Testing Business Continuity and Disaster Recovery Plans for the Bank
Deputy Manager - Information Security at Bombay Stock Exchange (2004-02 – 2006-06)
SEBI Compliance | Information Security
- Assist in implementation of Information Security policy
- Risk Analysis and Risk Treatment for Online Trading System
- Implementing and Updating Information Systems and Security Policies
- User Acceptance Testing for major releases. Liaison with other systems personnel for interface and reporting needs
- Assist in testing IT DR plans periodically
- Upgrading BS7799 certification to ISO27001 for BSE Online Trading System