Security Architect - SSE at IKEA (2021-11 – 2026-05)
- Transformed Product Security Strategy by defining roadmap and embedding Security-by-Design, Secure SDLC, Threat Modeling, and Security Architecture for 100+ products, reducing critical gaps by 65% and achieving 5/5 ratings.
- Transformed enterprise Secure SDLC by integrating Security-by-Design and Threat Modeling, reducing production vulnerabilities by 70% and accelerating delivery.
- Enhanced Application Security through Application Security Testing, OWASP Top 10 remediation, Vulnerability Assessments, and Secure Code Validation, strengthening protection for 2,000+ user stories across enterprise applications.
- Established Vulnerability Management processes by implementing IBM/HCL AppScan, leading to a 60% improvement in SLA compliance across engineering teams.
- Established scalable Security Architecture standards through design reviews and governance for cloud-native platforms, ensuring consistent security controls across global solutions.
- Led Secure SDLC adoption by driving SAST, SCA, DAST, secrets scanning, and vulnerability remediation across engineering teams, collaborating with DevOps to integrate security into CI/CD and increasing automated security coverage from 30% to 65%.
- Enhanced privileged access governance by 50% across business-critical platforms by implementing Zero Trust Security, Least-Privilege Compliance, and IAM Control Optimization.
- Automated compliance with NIST SP 800-53, ISO 27001, PCI DSS, and GDPR, enhancing Security Governance and boosting audit readiness from 35% to over 75%.
- Strengthened Third-Party Risk Management (TPRM) by performing Vendor Risk Assessments, security due diligence, and supplier security assessments, reducing third-party security exposure by 55% across strategic technology partners.
- Facilitated security strategy alignment for 25+ stakeholders by partnering with cross-functional teams to deliver key risk reporting initiatives, supporting business growth.
- Established enterprise AI Security Governance by performing AI Threat Modeling, AI Risk Assessments, and implementing LLM Security & AI Controls aligned with OWASP LLM and NIST AI RMF, enabling secure enterprise GenAI adoption.
- Led Incident Response & RCA to enhance enterprise resilience, investigating emerging attack vectors and reducing recurring security incidents by 40%.
- Directed a 13-member global cybersecurity team, achieving large-scale security transformation across retail operations through strategic planning and capability development.
Tech Lead at Capgemini Engineering (2020-07 – 2021-11)
- Spearheaded an enterprise Application Security (AppSec) transformation by establishing a unified Secure SDLC, security testing strategy, Secure by Design practices, and product security controls, increasing security assessment coverage by 90% while reducing OWASP Top 10 remediation time by 75%.
- Developed a mandatory Security Design Review framework aligned with NIST CSF, ISO 27001, and PCI DSS, reducing defects by 70% and achieving 100% adoption.
- Standardized secure engineering practices across teams by embedding security throughout the SDLC, improving testing effectiveness by 40%.
- Delivered executive security reporting that improved remediation timelines by 50%, earning Star Employee, WOW, Client First Team Excellence, and Kudos awards.
Senior Security Engineer at Capgemini Engineering (2017-09 – 2020-07)
- Validated critical security findings via PoC exploitation and risk analysis, increasing executive vulnerability acceptance by 60% and enhancing cyber risk governance.
- Addressed live banking penetration testing operations findings by remediating critical DoS and application security vulnerabilities, preventing customer-facing exploitation and reducing exposure.
- Integrated security analysis and remediation into Agile SDLC, eliminating 70% of recurring application vulnerabilities pre-deployment.
- Drove enterprise-wide Application Security, Product Security, Security Architecture, Secure Development, DevSecOps collaboration, developer enablement, and vulnerability governance initiatives across Banking, Healthcare, Government, and Engineering domains, consistently delivering award-winning security outcomes while improving organizational cyber resilience.
Application Security Consultant at Optum Global Solutions (2015-08 – 2017-08)
- Performed 55+ Vulnerability Assessments and Penetration Tests (VAPT) across web applications, APIs, cloud-hosted platforms, thick clients, and application architectures, identifying 100+ security vulnerabilities and enabling 95% remediation before production, reducing security defects by 40%.
Information Security Consultant at AKS IT Services (2014-09 – 2015-07)
Information Security Analyst at Codec Network (2012-12 – 2014-09)