Senior Vice-President, Cyber Security Centre at BNY Mellon (2023-10 – Present)
With a strong concentration on the security, I am leading Cyber operations for multiple business units. As my primary responsibilities are to oversee the complete Technology, Operations, Execution, Program management, and growth of team and business. Functions like SecOps, Incident Response, Digital Forensics, Threat & Vulnerability Management, as well as looking after the Risk Management are under the purview of my responsibilities.
I work as an enabler and empower team to provide right resource on time, vendor management and handling internal client's communication are also under our team charter.
- Partner with internal and external stakeholders to define, plan, execute and refine strategy, definitions, and roadmaps to execute the Information Security strategy and planning to maintain the planning and raise the security bar.
- Collaborate with leadership to mitigate risks and recommend cost effective solutions.
- Managing a high-performing team, fostering growth, training, and professional advancement to increase productivity and team morale by almost 60%
- Implement and optimize security tools and technologies to enhance operations and strengthen defenses.
- Project management to track and on time deliveries for business-critical programs.
- Establish and maintain compliance with industry regulations and standards.
- Reduced false positive rates of security alerts by 40%, by regular review, risk-based alerting, and UBA implementation.
- Achieved an 40% transition of security operations to automation, enhancing responsiveness and reducing human error.
- Slashed external dependency costs by 35%, maintaining robust security bar.
- Drive a culture of innovation, continuous improvement, and operational excellence.
Vice-President, Threat Detection & Management at Credit Suisse (2022-08 – 2023-10)
During my tenure in the Bank, I led Global Security Operations and Threat Management, Threat Intelligence, and Hunting teams of over 30 members. Played a key role in scaling and enhancing the bank's cyber security capabilities while driving strategic decisions. Notable achievements during this small period include the successful transition of Security operations from manual to automation processes through the deployment of SOAR, RPA, scaling existing capabilities through innovative approaches.
Participated in regulators' audits and owned the closure of all finding.
- Leading a multi-disciplinary global team, (35+ people), responsible for Secops, Forensics, and Cloud Incident Response, Threat Hunting, Systems Security and Detection Infrastructure.
- Responsible for handling critical/escalated incidents especially those which require MIM (Major Incident Management) call to proceed with investigation.
- Provide support to RBI Cyber Security Drill, regulatory activities, internal audits, external audits. oversight, coordination, and delivering the activities that support successful regulatory activities, internal audits, external audits and Manage complex cross team programs from ideation to delivery.
- Build and operate Secops, Threat Hunting, and Threat Modeling programs including providing expert analysis and expert opinion on these functions.
- Planned procurement for the Lab Setup for enhancing & strengthening the Malware & Forensics related investigations by mapping the respective use cases corresponding to the abilities & capabilities.
- Leadership reporting for identified risk, impact, and remediation strategies.
- Continued innovation, development, and implementation of cyber security services.
Senior Manager, Global Cyber Defence Centre at GAP.Inc (2020-09 – 2022-08)
As Senior Manager in the firm, I led global operations and was focused on delivering exceptional cyber security services. Engaging with global operations across various industries, I was mainly responsible for driving deliveries and fostering growth in the cyber security practice. Key responsibilities include strategic growth planning, client interactions, Hiring, Growth, and ensuring the delivery of high-quality cyber security services
- Develop and manage a best-in-class defensive cyber capability centered on incident response, threat intelligence, forensics, and Cloud Incident Response.
- Building productive partnerships with various technology, legal, security, and analytics teams across GAP.
- Manage team building, hiring, and professional/career growth of team members by implementing training programs and training opportunities.
- Developing in-house capability of threat intelligence platform and Threat Hunting.
- Managed 24*7 Global Cyber Defense, Log source integration, use case development and Threat rules.
- Transitioning of Manual operations to Automated by Deploying SOAR.
- Participated in the evaluation and recommendations for selection of Security Solution, hardware system components.
Lead, Security Ops Engineering at Bharti Airtel (2018-08 – 2020-08)
During my tenure, I made significant contributions to enhance cybersecurity operations. Highlights include executing cybersecurity by maintaining a strong hold in Cyber Defense and Threat Management capabilities. As the leader of the Security Operations team, I focused on bringing maturity to people, processes, and capabilities in the realm of Cyber Defense, conducting security operations leading operational tasks for improved incident response and threat hunting efficiency.
- Managed Security Requirements for IT infrastructures, banking systems and telecommunication network.
- Identification and assessment of risk associated with projects, process and technologies, communication to key stakeholder and drive risk remediation.
- Led decision-making processes for Cyber Defense infrastructure, incident response, threat hunting, and threat intelligence.
- Perform vulnerability assessment and drive the critical finding to closure and apprise leadership in context with Risk and Impact to organization.
- Guiding Senior Management in formulations/ Revision of information security policy and designing new Security Program. Designed, implemented, and managed Security Operations Center.
- Ensure information security compliance with business objective and as per known frameworks.
- Managed 24*7 SOC Operations.
- Ensured that the right level of processes and procedures are followed in line with the overall enterprise security strategy.
Information Security Specialist at Indian Navy (2003-07 – 2018-07)
I embarked on my cyber security journey within the Navy, where I primarily served in the Cyber Wing of the Navy and worked for an extended period, during this period I played a key role while learning security to setup the cyber policies for the Navy, prepare the operational road map of cyber, conduct various audit and assessment, engaged with government agencies and worked with native forces cyber wings to address critical cyber incidents.
- Spearheaded the establishment of indigenous Security Operations for the Navy, ensuring robust cyber-Defense capabilities.
- Implemented comprehensive threat intelligence and incident response operations, enabling proactive identification and mitigation of cyber threats.
- Collaborated with various government agencies to conduct effective cyber operations, fostering strong partnerships for collective Defense.
- Ensure compliance on Vulnerability Assessment, Antivirus, Hardening, Basic Hygiene, Patch Management, and User ID validation.
- Developed SLA and Catalogues for achieving the goals of the organization.
- Developed and implemented cyber policies for the Navy, ensuring compliance with PAN Navy standards and regulations.
- Played a pivotal role in training and upskilling naval personnel, empowering them with essential cyber security knowledge and skills.
- Managed vendor relationships, ensuring smooth coordination and effective vendor management practices.