Mumbai, India · 8+ cybersecurity

Hi, I'm Amit. Here's what eight years of security work have taught me

I make security
work at scale.

I build security programs that help organizations move with confidence: clearer decisions, stronger systems, and less friction between security and the business. After 8 years in cybersecurity, I have learned that the best security work is rarely the loudest. It is the work that makes good engineering easier to trust.

I bring technical, regulatory, and business perspectives together to make risk understandable, decisions defensible, and the safer path practical enough to ship.

01

8+

years in cybersecurity

02

Global

security perspective

03

16+

security credentials

04

6

core security domains

01 / About me

The person behind the security work.

Security leadership · security architecture · high-leverage security problems

What does good security look like when the real problem is not just technical?

I've spent the last eight years across consulting and in-house security, helping teams make difficult calls where technology, risk, customers, regulation, and business priorities meet. I enjoy the moments where the answer is not obvious and good judgment matters as much as technical depth.

My work spans cloud and application security, privacy, third-party risk, customer assurance, AI governance, and security programs. The thread through it all is simple: understand the system, understand the people around it, and make the safer path practical enough to move.

I'm based in Mumbai, work comfortably across functions and cultures, and prefer letting the work show you how I think.

Outside security, I like keeping things moving in a more hands-on way: badminton when I can get a game in, building furniture and tinkering with woodwork, running on weekends, and trekking whenever I get the chance. There's something satisfying about making a physical thing with your hands, getting out on a trail, or simply being active after spending the week solving problems that mostly live on screens.

Where I'm based

Mumbai, India

Working across security, technology, and business teams.

What shaped me

Cybersecurity · Entrepreneurship · Technology Consulting · Privacy · Leadership

Education

Bachelor of Technology — Computer Science and Engineering

Amity University Mumbai · Mumbai, India

Languages

Bengali · Hindi · English · Marathi · French

02 / Experience

Career, with evidence.

May 2025 — Present

Current
01

NielsenIQ

Security Leader - Regional Information Security Office (RISO)

Mumbai, India

What changed

Making security, trust, and AI governance repeatable across an enterprise environment.

Cloud SecurityGRCRisk ManagementEnterprise TrustTPRMAI SecurityPrivacy
  • Lead security and compliance initiatives across business units, improving security maturity and audit readiness.
  • Drive vendor risk management and third-party security assessments, strengthening assurance and secure onboarding.
  • Lead MSA, DPA, RFP, and contractual security reviews, translating security requirements into clear positions for Legal, Procurement, Sales, and business stakeholders.
  • Support customer security assessments, due diligence, and assurance requests by translating technical controls into defensible evidence.
  • Partner with engineering, product, procurement, legal, sales, data, and business teams to turn security requirements into workable decisions.
  • Develop and operationalize enterprise AI security and governance practices, including GenAI risk assessment, data handling controls, secure prompt/output governance, and AI risk checkpoints.
  • Secure AI workloads involving LLM integrations and vector database services through RBAC, audit monitoring, prompt sanitization, and output validation mechanisms.
  • Maintain NIQ's Internal Trust Portal to centralize customer security documentation and reduce manual due diligence effort.
  • Collaborated with OpenAI and internal executive stakeholders to structure and close NIQ's enterprise AI engagement while aligning privacy, security, contractual safeguards, and responsible AI controls.
CIS v8.1NISTISO 27001ISO 27018EU AI ActGDPRCybersecurity EssentialsLegalSOC 2

Mar 2022 — May 2025

02

Jio Haptik Technologies Limited

Assistant Manager - Senior Security Consultant

Mumbai, India

What changed

Built security and compliance practices that supported product delivery, customer trust, and regulatory readiness.

Cyber SecurityCloud SecurityRisk ManagementGRCDevSecOpsPrivacy
  • Led day-to-day Cyber/Information and Cloud Security activities across the organization.
  • Performed application and API security testing for Haptik platforms and third-party integrations.
  • Led ISO 27701:2019 (PIMS) and HIPAA compliance projects.
  • Conducted recurring audits of platform and cloud infrastructure to identify and resolve security risks.
  • Maintained GDPR, CCPA, and PDPA compliance through privacy audits and regional regulatory reviews.
  • Handled RFP, DPA, and MSA reviews for Legal-InfoSec and customer security audits, including security and privacy requirements in commercial engagements.
  • Worked directly with customers on RBI, SEBI, IRDAI, and other compliance requirements, supporting security questionnaires and assurance discussions.
  • Managed deployment of WAF, DAST, and SAST capabilities; the resume reports a 90% reduction in security vulnerabilities.
  • Led negotiations with Microsoft Azure and enabled Azure Marketplace listings for Haptik's Contakt and Interakt platforms.
  • Supported secure product delivery by coordinating security findings, remediation, customer requirements, and compliance evidence across engineering and business teams.
ISO 27701ISO 27018HIPAAGDPRCCPAPDPARBISEBIIRDAI

Jan 2021 — Mar 2022

03

BDO India LLP

Security Consultant — Business Advisory Services

Mumbai, India

What changed

Helped clients turn security and privacy requirements into operating programs, assessments, and measurable risk reduction.

GRCRiskPrivacySecurity TestingCloud Security
  • Led ISO 27001 (ISMS) implementation for clients across pharmaceutical, AI, and startup sectors.
  • Implemented EU-GDPR and CCPA compliance for consumer data.
  • Ran targeted phishing exercises for more than 1 million employees across India's BFSI and NBFC sectors; the resume reports a reduction from 10% to 3%.
  • Performed risk, mitigation, and data privacy assessments for BFSI clients and emerging AI startups.
  • Developed custom risk assessment methodologies and governance policies.
  • Supported red teaming, penetration testing, and vulnerability analysis.
  • Reviewed configurations for security controls including antivirus, firewalls, IDS/IPS, and DLP while supporting cloud security infrastructure projects.
ISO 27001EU-GDPRCCPA

Early career

04

Early Career Internships

Cybersecurity, Technology & Cloud

Mumbai, India

What changed

Built early exposure across legal incident response, consulting, cloud, reliability, product, and software engineering environments.

Incident ResponseCloudTechnology ConsultingAzure
  • Clifford Chance — worked through practical cybersecurity incident-response scenarios involving an ICO Dawn Raid, data leaks, legal assessment, and data-related damage claims.
  • Deloitte — worked through client discovery, business-case design, project approach, mobilisation considerations, market scans, analysis, solution presentation, cloud feasibility, and cloud readiness assessment.
  • Microsoft — covered Azure, cloud network engineering, data and applied sciences, product and program management, service engineering, site reliability engineering, software development, and software engineering.
Microsoft AzureSite Reliability EngineeringIncident Response

03 / Leadership

How I lead security work.

Leadership, to me, is less about being the loudest person in the room and more about making the room better at making decisions.

01

Start with the decision

Understand what the business is trying to achieve before prescribing a control. Good security makes the important trade-offs visible.

02

Design for real engineering

Controls have to survive production systems, delivery pressure, changing technology, vendors, and the people expected to operate them.

03

Make trust scalable

The goal is not another approval queue. It is a repeatable way for teams, customers, and leadership to make confident decisions.

04

Enterprise scope

Lead security and compliance work across business units, coordinating decisions across technology, product, legal, procurement, sales, data, and business stakeholders.

05

Translation across functions

Move comfortably between technical risk, regulatory requirements, customer assurance, contracts, engineering realities, and executive priorities.

06

Leadership through influence

Create alignment across technical and non-technical stakeholders, helping teams make defensible security decisions without relying solely on formal authority.

07

Executive communication

Turn complex security positions into concise decisions, options, and trade-offs for leadership and business stakeholders.

08

Security program design

Build repeatable practices across AI governance, TPRM, customer assurance, privacy, testing, and compliance rather than isolated controls.

09

Outcome-oriented execution

Carry security work from assessment and recommendation through remediation, evidence, stakeholder alignment, and measurable results.

04 / Case studies

What the work looks like when you go one level deeper.

A portfolio should not ask you to take claims on faith. These are synthesized from real work and show the problem, the decision, the execution, and the outcome without exposing confidential material.

NielsenIQ · AI Security

Enterprise AI Security & Governance

01

The problem

AI adoption was moving faster than the controls needed to make sensitive data, access, prompts, outputs, and accountability trustworthy.

The decision

Treat AI security as an operating model rather than a single review: risk assessment, data handling, access control, prompt/output governance, and checkpoints embedded into adoption.

What I did

  • GenAI risk assessment and governance checkpoints
  • RBAC and audit monitoring for AI workloads
  • Prompt sanitization and output validation
  • Executive, privacy, security, and business alignment

Outcome

A practical governance layer for enterprise AI adoption, designed to reduce uncertainty without blocking useful technology.

What I learned

The best AI security control is one that teams can understand before they need it and operate after they adopt the technology.

NielsenIQ · Trust · TPRM

Enterprise Trust & Customer Assurance

02

The problem

Customer and third-party security reviews can become repetitive evidence hunts that slow deals and consume security teams.

The decision

Create a reusable trust layer that centralizes evidence and connects vendor risk, contractual reviews, customer assessments, and security documentation.

What I did

  • Internal Trust Portal ownership
  • Vendor risk and contractual security reviews
  • Customer security assessments and assurance evidence
  • Cross-functional coordination with sales, legal, procurement, and security

Outcome

A more repeatable path for answering security questions and making assurance evidence useful to the business.

What I learned

Trust scales when evidence is treated as a product, not a document collection.

Haptik · AppSec · Cloud · DevSecOps

Security Engineering That Ships

03

The problem

Security controls only create value when they survive delivery pressure and become part of how engineering teams actually work.

The decision

Combine testing, cloud reviews, vulnerability management, and security tooling into repeatable engineering practices instead of isolated assessments.

What I did

  • Application and API security testing
  • WAF, DAST, and SAST deployment
  • Cloud and platform security reviews
  • Recurring vulnerability identification and remediation

Outcome

A more operational security program supporting product delivery, with the resume reporting a 90% reduction in security vulnerabilities.

What I learned

Security maturity is less about adding controls and more about making the right controls easy to use repeatedly.

05 / Selected work

The problems I choose to solve.

01

Making AI adoption safe enough to scale

AI Security · Governance · Product

Built practical controls around AI risk, data handling, access, prompts, outputs, and review checkpoints so teams can adopt AI without treating security as a brake.

02

Turning trust into a business capability

Third-Party Risk · Customer Assurance · Trust

Connected vendor assurance, contractual security reviews, customer assessments, and internal security evidence into a workflow designed to help the business move with confidence.

03

Reducing security friction in engineering

Cloud · AppSec · DevSecOps

Combined cloud assessment, application and API testing, vulnerability management, and security tooling to make secure engineering more repeatable.

04

Building security programs people can operate

GRC · Privacy · Regulatory

Turned standards and regulations into working practices across ISO 27001, ISO 27701, HIPAA, GDPR, CCPA, PDPA, and sector-specific requirements.

06 / How I think

The principles behind the decisions.

These are not generic security slogans. They are the patterns I keep coming back to when the technical answer alone is not enough.

01

Security is a decision system

Controls matter, but the real product of security is better decisions: what to protect, what to accept, what to fix now, and what can safely wait.

02

Trust is an engineering problem too

Customer assurance, privacy, contracts, and security evidence become scalable when they are designed as repeatable systems rather than manual queues.

03

Good security removes friction

The strongest security programs make the safer path easier to understand and easier to execute, especially when engineering and business priorities are moving quickly.

07 / Capabilities

Protect the enterprise

Enterprise SecuritySecurity ArchitectureThird-Party Risk ManagementRisk ManagementSecurity Risk AssessmentIncident ResponseVulnerability ManagementCyber Threat IntelligenceSecurity Awareness and TrainingPhishing Simulation

Secure the product

Application & API SecurityCloud SecurityCloud Infrastructure SecurityIdentity & Access ManagementWAFDAST / SASTOffensive Penetration TestingCI/CD SecuritySecurity Testing

Make AI trustworthy

AI GovernanceAI ComplianceGenAI RiskLLM SecurityPrompt SanitizationOutput ValidationAI Workload SecurityResponsible AI

Turn trust into evidence

Customer AssuranceCustomer Security AssessmentsInternal Trust PortalSecurity ReviewsRFP / DPA / MSA ReviewsVendor Contract ReviewsSOC 2Security Documentation

Build practical programs

ISO 27001 / ISMSISO 27701 / PIMSPrivacy ProgramsData PrivacySecurity Testing ProgramsSecurity Configuration ReviewSIEM / Log ManagementSecurity Program Management

Regulatory Compliance

RBISEBIIRDAIGDPRCCPAPDPAHIPAAEU AI ActISO 27001ISO 27018Cybersecurity EssentialsRegulatory & Compliance Advisory

08 / Evidence Library

Selected proof, without the badge wall.

01

AI SECURITY

AI workload security controls

RBAC, audit monitoring, prompt sanitization, output validation, GenAI risk assessment, data handling, and governance checkpoints.

02

CUSTOMER TRUST

Internal Trust Portal

Ownership of a centralized security evidence capability supporting customer assurance, due diligence, and recurring security documentation.

03

APPLICATION SECURITY

WAF, DAST & SAST program

Security tooling deployment and remediation program; the resume reports a 90% reduction in security vulnerabilities.

04

PRIVACY

Privacy & compliance programs

ISO 27701 PIMS, HIPAA, GDPR, CCPA and PDPA work translated into practical assessments, controls, and evidence.

05

CLOUD & PRODUCT

Azure product enablement

Worked with Microsoft Azure and enabled Marketplace listings for Haptik platforms while coordinating security and product requirements.

06

THIRD-PARTY RISK

Vendor risk & security reviews

Third-party assessments, secure onboarding, contractual security reviews, and assurance workflows connecting vendor risk decisions with business requirements.

09 / Credentials

Proof of range, not a badge wall.

Selected credentials are here for signal. The full list remains available below without taking over the page.

CISSPCCSKOneTrust Fellow of Privacy TechnologyIBM Cybersecurity ProfessionalIncident Response ExpertAdvanced Cyber Threat IntelligenceOffensive Penetration Testing
View all credentials
OneTrust Fellow of Privacy TechnologyCertified Information Systems Security Professional (CISSP)Certificate of Cloud Security Knowledge (CCSK)IBM Cybersecurity ProfessionalIncident Response ExpertOffensive Penetration TestingCompTIA Network+Network Security Expert | NSE 2 Network Security AssociateAdvanced Cyber Threat IntelligenceCybersecurity EssentialsMitigating Security Vulnerabilities on Google Cloud PlatformIBM Cybersecurity Analyst ProfessionalApply end-to-end Security to a Cloud ApplicationEnterprise Security Leadership: Negotiation Skills for Cyber LeadersSix Sigma White Belt CertificationICSI | CNSS Certified Network Security Specialist

10 / Contact

Let's talk about the hard problems.

I bring my best work to the intersection of security, technology, risk, and business judgment, turning complex challenges into practical decisions and meaningful outcomes.

scows-row-07@icloud.com

11 / People I've worked with

Amit has been my go-to expert for compliance programs, regional privacy laws, and customer-initiated audits and assessments (TPRM). He brings deep expertise in GRC, Privacy, DevSecOps, and Third-Party Risk Management.
Kishore Mavuri · Associate Director - InfoSec & Compliance | DPO at Haptik
I had the pleasure of working with Amit for a year at BDO India LLP. I was always in awe of Amit's ability to grasp concepts quickly, his sincerity and his hard work.
Theron Menezes · Former colleague at BDO India LLP