Results-driven Technical Lead with over 11 years of expertise in cybersecurity and 3+ years in management. Adept at leading high-impact security teams and spearheading security transformation initiatives. Specializes in offensive security, cloud security (AWS, Azure, GCP), security architecture, and compliance (NIST, ISO27001, PCI-DSS, SOC2). Brings a wealth of knowledge to ensure robust protection. Proficient in Red Teaming, security testing, and DevSecOps. Deep understanding of Kubernetes, blockchain, and emerging attack vectors. Committed to bridging security gaps, automating security processes, and nurturing teams to cultivate resilient and threat-aware organizations.
Lead security architecture, cloud security, and offensive security strategies for global retail, financial, and tech enterprises. Specialize in Red Team operations, threat modeling, penetration testing, and cloud security (AWS, Azure, GCP).
Reporting to the Director, responsible for scoping, leading and executing varieties of offensive security engagements for clients in financial, legal and telecommunication services
Under the guidance of the VP of Threat and Compliance Management, I spearheaded a team that enhanced bank security by 20% through comprehensive Red Teaming, and purple teaming activities
Under the guidance of the VP of Security Architecture, I directed the projects for threat modelling, Agile and DevSecOps. Major contributor in onboarding security tools such as Veracode, and cloud security solutions within the bank
Reporting to the Manager, responsible for conducting infrastructure and web applications vulnerability assessment and penetration testing activities
Reporting to the Manager, responsible for conducting infrastructure and web applications vulnerability assessment and penetration testing activities
Security Architecture & Offensive Security – Designed and implemented security frameworks, offensive security strategies, and secure digital transformations
Cloud Security & DevSecOps – Expertise in cloud computing (AWS, Azure, GCP), Infrastructure as Code (Terraform), Kubernetes security, and integrating security into CI/CD pipelines
Red Teaming & Penetration Testing – Led stealth Red Team operations, security assessments, and exploits development to uncover vulnerabilities
Blockchain Security – Reviewed smart contracts for security vulnerabilities and assessed blockchain-based applications
Risk & Compliance Management – Specialized in ISO 27001, SOC2, PCI-DSS, HIPAA, and cloud security hardening for enterprise compliance
Automation & Programming – Automated security processes using Python & Shell scripting, reducing manual workload & enhancing efficiency
Shared Responsibility Model – Expertise in evaluating security postures across SaaS, PaaS, IaaS environments
Team Leadership & Mentorship – Led and mentored security teams, fostering a high-performance cybersecurity culture
Strategic Communication & Stakeholder Engagement – Effectively communicated complex security concepts to executives, technical teams, and cross-functional stakeholders
Vendor & Client Relations – Managed vendor partnerships and developed customer relationship strategies for cybersecurity solutions
Problem-Solving & Decision-Making – Adept at identifying security gaps, mitigating risks, and aligning security efforts with business goals
Performance & Project Management – Led security projects, conducted performance evaluations, and developed strategic growth plans
· Certified Information Systems Security Professional (CISSP) - (06/2023 - Present)
· Certified Cloud Security Professional (CCSP) - (07/2024 - Present)
· Offensive Security Certified Professional (OSCP) - (01/2016 - Present)
· Offensive Security Certified Expert (OSCE) - (09/2016 - Present)
· AWS Solution Architect Associate - (01/2020 - 01/2023)
· AWS Certified Security Specialty - (06/2020 - 06/2023)