Senior Consultant, Cyber Strategy at Deloitte USI (2021-12 – Present)
- Led teams for tech risk engagements to help multiple FSI clients manage inherent and residual risk by developing risk scoring methodologies, baseline control framework across cyber risk domains (IAM, DLP, Network, Governance) and evaluating risk mitigation efforts through risk scorecards and KRI for enterprise clients.
- Spearheaded multiple Cyber GRC, regulatory compliance engagements for financial services clients, owning client workshops and communications while building a customized Integrated Requirements Library (IRL) based on industry best practices and driving gap remediation efforts through comprehensive policies and procedures; mentored team members to deliver prioritized recommendations that strengthened governance and compliance programs and significantly reduced non-compliances.
- Orchestrated pre and post-Day 1 cyber MnA integration for a large investment bank, partnering with the CISO and workstream leads to define Transition Services Agreement (TSA), stand up joint Incident Management, DLP, Cyber Defense/Threat Response workflows, assessed buyer/seller security posture against a Cyber Risk Institute (CRI) Profile Tier 4 baseline, and deliver a comprehensive post-Day 1 roadmap ahead of application migrations.
- Designed and delivered a cloud security Target Operating Model (TOM) for a large UK-based insurer, aligning capabilities and service catalogue to the Cloud Security Alliance (CSA) Cloud Security Maturity Model; established shared responsibility model, RACIs, governance forums, target org/FTE roadmap, and key cloud processes to embed accountable cloud security delivery.
- Key contributor in driving internal strategic initiatives including 1. Cyber OP innovation portfolio management - collaborating with asset leaders to accelerate product development, guiding teams through the funding process, performance evaluation and creation and packaging of cyber asset demos for client visits 2.
Market
Research on FSI Regulatory trends - Conducted comprehensive research for a thought leadership POV on cyber and data privacy trends across NAM, LATAM, EMEA, APAC regions with key themes and focus areas.
Senior Executive, Analyst Relations at HCL Technologies (2019-05 – 2021-10)
- Owned Analyst Relations (AR) for HCL Cyber Security, independently managing global engagements with Gartner, Forrester and Everest to position HCL cybersecurity as a leader in security space, shaping external market perception and influence deal outcomes.
- Drove security-services positioning through strategic AR plans for leadership, competitive assessments, and continuous market research, translating analyst insights into actionable recommendations.
- Partnered with customers on thought leadership (case studies, webinars) and built onboarding/induction programs to ramp new joiners effectively.
Senior Associate, ITIM at Quinnox Consultancy Services (2017-01 – 2018-04)
- Planned and executed end-to-end Information Security Management System (ISMS) internal audits and policy reviews aligned to ISO/IEC 27001:2013.
- Developed and periodically delivered enterprise-wide information security awareness training, including content creation and ongoing reinforcement.
- Identified risks in the Bluecoat web security solution and recommended Zscaler; Implementation of Zscaler improved web security by 24%, while monitoring the Managed Security Services (MSS) dashboard for violations and incident alerts.
Analyst, IT Risk Assurance at Ernst & Young LLP (2014-07 – 2016-07)
- Performed information security and compliance policy reviews for global banks and insurers, benchmarking controls against Reserve Bank of India (RBI) guidelines and ISO 27001:2013 standards.
- Played a key delivery role across Risk and Control Self-Assessments (RCSAs) and Business Continuity Planning/Disaster Recovery (BCP/DR) migration engagements, supporting risk identification and control effectiveness.
- Supported presales by developing and presenting technical/commercial proposals and request for proposal (RFP) responses tailored to client requirements.