Summary
Overview
Work History
Education
Skills
Certification
Languages
Timeline
Generic

AVINASH KUMAR THAPA

Mississauga,Canada

Summary

Results-driven Technical Lead with over 11 years of expertise in cybersecurity and 3+ years in management. Adept at leading high-impact security teams and spearheading security transformation initiatives. Specializes in offensive security, cloud security (AWS, Azure, GCP), security architecture, and compliance (NIST, ISO27001, PCI-DSS, SOC2). Brings a wealth of knowledge to ensure robust protection. Proficient in Red Teaming, security testing, and DevSecOps. Deep understanding of Kubernetes, blockchain, and emerging attack vectors. Committed to bridging security gaps, automating security processes, and nurturing teams to cultivate resilient and threat-aware organizations.

Overview

11
11
years of professional experience
1
1
Certification

Work History

VP TECHNICAL LEAD

Chaleit
05.2022 - Current

Lead security architecture, cloud security, and offensive security strategies for global retail, financial, and tech enterprises. Specialize in Red Team operations, threat modeling, penetration testing, and cloud security (AWS, Azure, GCP).

  • Designed scalable security frameworks, IAM, zero-trust models, and cloud security posture management (CSPM) for AWS, Azure, and GCP
  • Strengthened container security (Kubernetes, Docker) and serverless security while ensuring compliance with NIST, PCI-DSS, ISO 27001, and SOC2
  • Conducted stealth Red Team operations, reverse-engineered encryption protocols, and exposed critical vulnerabilities in high-security environments
  • Led threat modeling exercises across cloud and on-prem infrastructure
  • Managed end-to-end security projects, team performance, and quarterly growth objectives
  • Conducted performance reviews and mentored security professionals
  • Built Infrastructure as Code (IaC) security solutions, reducing vulnerabilities by 30% across hybrid cloud environments
  • Integrated security into CI/CD pipelines using Terraform, Python, and automation tools
  • Developed cloud security hardening strategies, achieving a 15% reduction in risk exposure while maintaining compliance with regulatory standards
  • Advised CISOs, security architects, and DevOps teams, ensuring security strategy aligns with business objectives

SENIOR SECURITY CONSULTANT

Security Compass Technologies Ltd.
12.2019 - 05.2022

Reporting to the Director, responsible for scoping, leading and executing varieties of offensive security engagements for clients in financial, legal and telecommunication services

  • Led offensive security engagements across financial, legal, and telecom sectors, improving cybersecurity by 40%
  • Conducted web, mobile, API, and network security testing, uncovering critical vulnerabilities
  • Designed & executed Red Team & Purple Team strategies, strengthening client defenses
  • Managed end-to-end security projects, tailoring solutions to mitigate key risks
  • Provided expert security guidance & training, fostering team growth & a learning culture
  • Delivered executive-level security reports, translating findings into business-driven insights
  • Researched & integrated emerging cybersecurity trends, enhancing client security postures

SECURITY THREAT ASSESSMENT SPECIALIST

Emirates NBD
04.2018 - 11.2019

Under the guidance of the VP of Threat and Compliance Management, I spearheaded a team that enhanced bank security by 20% through comprehensive Red Teaming, and purple teaming activities

  • Led Red Teaming operations, uncovering 50+ critical vulnerabilities, boosting security resilience by 20%
  • Developed & refined threat models, security protocols, and risk assessments (NIST 800-30/53)
  • Conducted Purple Team exercises, testing detection capabilities against MITRE ATT&CK techniques
  • Automated security tasks using PowerShell scripts for OSINT & attack simulations
  • Provided QA oversight on security deliverables, ensuring technical accuracy
  • Assessed firewall & security configurations against CIS benchmarks for enterprise clients
  • Designed cybersecurity training programs, strengthening staff expertise in incident handling & security best practices

SENIOR INFOSEC SME

Emirates NBD
06.2017 - 04.2018

Under the guidance of the VP of Security Architecture, I directed the projects for threat modelling, Agile and DevSecOps. Major contributor in onboarding security tools such as Veracode, and cloud security solutions within the bank

  • Led threat modeling, Agile security, and DevSecOps initiatives, strengthening security frameworks
  • Spearheaded Veracode onboarding & cloud security solutions, enhancing application security
  • Integrated security protocols into Agile/DevSecOps, ensuring compliance & continuous evaluation
  • Established risk management strategies, significantly reducing operational security risks
  • Advised on vendor selection & security architecture, influencing key compliance decisions

SENIOR SECURITY CONSULTANT

NotSoSecure
01.2017 - 05.2017

Reporting to the Manager, responsible for conducting infrastructure and web applications vulnerability assessment and penetration testing activities

  • Conducted penetration tests on infrastructure & web applications, identifying critical vulnerabilities
  • Led Red Team operations, simulating adversarial attacks to enhance security defenses
  • Delivered security training to technical teams, improving awareness & best practices
  • Spearheaded R&D initiatives, identifying emerging threats & enhancing industry security knowledge
  • Managed end-to-end security projects, ensuring timely & high-quality delivery

SENIOR INFORMATION SECURITY ANALYST

Network Intelligence India
06.2014 - 01.2017

Reporting to the Manager, responsible for conducting infrastructure and web applications vulnerability assessment and penetration testing activities

  • Led a variety of security evaluations and penetration testing for government organizations identifying and fixing over 200 security concerns to strengthen overall security measures
  • Led penetration testing, wireless security checks, and automation of security testing procedures
  • Provided cybersecurity trainings and contributed to industry research

Education

Bachelor of Engineering - Electronics And Communication

Kurukshetra Univerysite
Haryana, India
04-2014

Skills

    Security Architecture & Offensive Security – Designed and implemented security frameworks, offensive security strategies, and secure digital transformations

    Cloud Security & DevSecOps – Expertise in cloud computing (AWS, Azure, GCP), Infrastructure as Code (Terraform), Kubernetes security, and integrating security into CI/CD pipelines

    Red Teaming & Penetration Testing – Led stealth Red Team operations, security assessments, and exploits development to uncover vulnerabilities

    Blockchain Security – Reviewed smart contracts for security vulnerabilities and assessed blockchain-based applications

    Risk & Compliance Management – Specialized in ISO 27001, SOC2, PCI-DSS, HIPAA, and cloud security hardening for enterprise compliance

    Automation & Programming – Automated security processes using Python & Shell scripting, reducing manual workload & enhancing efficiency

    Shared Responsibility Model – Expertise in evaluating security postures across SaaS, PaaS, IaaS environments

    Team Leadership & Mentorship – Led and mentored security teams, fostering a high-performance cybersecurity culture

    Strategic Communication & Stakeholder Engagement – Effectively communicated complex security concepts to executives, technical teams, and cross-functional stakeholders

    Vendor & Client Relations – Managed vendor partnerships and developed customer relationship strategies for cybersecurity solutions

    Problem-Solving & Decision-Making – Adept at identifying security gaps, mitigating risks, and aligning security efforts with business goals

    Performance & Project Management – Led security projects, conducted performance evaluations, and developed strategic growth plans

Certification

· Certified Information Systems Security Professional (CISSP) - (06/2023 - Present)

· Certified Cloud Security Professional (CCSP) - (07/2024 - Present)

· Offensive Security Certified Professional (OSCP) - (01/2016 - Present)

· Offensive Security Certified Expert (OSCE) - (09/2016 - Present)

· AWS Solution Architect Associate - (01/2020 - 01/2023)

· AWS Certified Security Specialty - (06/2020 - 06/2023)

Languages

English
Hindi

Timeline

VP TECHNICAL LEAD

Chaleit
05.2022 - Current

SENIOR SECURITY CONSULTANT

Security Compass Technologies Ltd.
12.2019 - 05.2022

SECURITY THREAT ASSESSMENT SPECIALIST

Emirates NBD
04.2018 - 11.2019

SENIOR INFOSEC SME

Emirates NBD
06.2017 - 04.2018

SENIOR SECURITY CONSULTANT

NotSoSecure
01.2017 - 05.2017

SENIOR INFORMATION SECURITY ANALYST

Network Intelligence India
06.2014 - 01.2017

Bachelor of Engineering - Electronics And Communication

Kurukshetra Univerysite
AVINASH KUMAR THAPA