Cybersecurity LeaderCyber Risk Assessments & AssuranceDesign, Build, Activate & Operate Cyber ProgramsCyber Go-To-MarketOrigination & SalesPeople Development & Mentorship
Fourteen years in cybersecurity consulting at EY and PwC. I build and run the security programs CISOs depend on, turn what works into offerings, and sell the work — mostly in regulated industries: healthcare, pharma, automotive, consumer products, and energy.
- Exceeded $10M in closed cybersecurity engagements every fiscal year as an EY pursuit leader.
- Directed a $10M+, 10-workstream transformation securing a connected-product portfolio worth $24B+ in services revenue.
- Closed a material NERC CIP finding carrying $1M+ per-violation, per-day exposure.
- Ran a NIST CSF assessment across 34 countries and turned it into a board-approved roadmap.
- Recently led an AI governance readiness assessment against the NIST AI RMF.
I build and run the functions a CISO operates — GRC, product security governance, third-party risk, compliance — and take them from control design through build, activation, and day-to-day operation.
- $10M+ multi-year transformation: 10 workstreams, 20+ professionals, cybersecurity embedded into connected-product design, development, and operations.
- Product security governance for 1M+ connected assets — ISO 21434 / SAE J3061 controls, ServiceNow cataloging and GRC, testing, executive reporting.
- Healthcare cyber transformation: 10 in-flight initiatives across GRC, data protection, cloud, medical OT, TPRM, IAM, and PMO.
- NIST RMF risk program ($2M+) that remediated a material NERC CIP finding and returned the client to compliance.
- Took an enterprise security program from 0 to 3+ CMMI maturity; set up the operating cadence of an Office of the CISO.
- SEC cyber disclosure readiness across a holding company and seven portfolio companies; NIST AI RMF readiness assessment.
I turn client work into repeatable offerings and own the pursuit from qualification to signed deal — solution, proposal, pricing, staffing, and deal governance.
- Co-developed a connected-product security offering with one client, then packaged and positioned it for others in the sector.
- Own pursuits end to end and presented each deal to EY Americas Deal Governance for approval before closing.
- Shaped and priced solutions with CISOs and their teams across multiple sectors.
- Led CISO / CIO / CFO / strategy workshops at a $6.2B CPG company to turn business drivers into a funded 3-year cyber strategy.
- Built business cases that unlocked funding for next-generation connected-vehicle security across 34 countries.
Carried a $5M–$10M annual sales goal at EY and closed more than $10M every year. Opened a new healthcare logo at $250K and grew it to a $10M account in two years.
- $5M–$10M annual goal as pursuit leader; $10M+ closed every fiscal year.
- New healthcare logo: $250K assessment → $10M account in year two, by converting findings into a funded multi-workstream program.
- Full cycle with CISOs and their leadership — identify, qualify, shape, price, close — consistently across sectors.
- Expanded accounts by translating assessment findings into follow-on programs and multi-year roadmaps.
EY (Ernst & Young LLP)
Denver, CO · Chicago, IL · Cybersecurity Strategy, Risk & Program TransformationSenior Manager — Cybersecurity Risk & Program Management
Business development & origination
- Carried a $5M–$10M annual sales goal as pursuit leader and exceeded $10M in closed cybersecurity engagements every fiscal year.
- Owned pursuits end to end — opportunity identification, qualification, proposal development, pricing, and staffing models — presenting each deal to EY Americas Deal Governance leadership for approval prior to closing.
- Originated a new healthcare brand for the practice: entered on a $250K security assessment and converted it into a $10M account in year two by translating findings into a funded multi-workstream cybersecurity transformation.
- Ran the full cycle with CISOs and their leadership teams — identifying and qualifying opportunities, shaping and pricing solutions, and closing consistently across multiple industry sectors.
Solutions & offerings
- Co-developed a new connected product security program offering alongside a client, then packaged and positioned it for other clients in the same sector — turning a single engagement into a repeatable go-to-market play.
- Embedded within a newly formed CISO organization at a $6.2B publicly traded CPG leader; led executive workshops with the CISO, CIO, CFO, and corporate strategy to align business drivers and constraints into a 3-year cybersecurity strategy and roadmap.
- Planned and executed an AI governance readiness assessment aligned to the NIST AI Risk Management Framework — AI use-case inventory, model risk, third-party AI exposure, and governance structures — and delivered the prioritized roadmap to close gaps.
Delivery in regulated markets
- Directed a $10M+ multi-year transformation across 10 workstreams and 20+ professionals, embedding cybersecurity into connected product design, development, and operations — enabling the secure rollout of a portfolio generating $24B+ in services revenue.
- Developed a product security governance program for 1M+ connected assets globally — ISO 21434 and SAE J3061-aligned control frameworks, ServiceNow-based product cataloging and GRC, product security testing, and executive reporting.
- Delivered a board-ready multi-year cybersecurity roadmap for automotive operations by managing a NIST CSF assessment across thirty-four countries in Europe, Asia, the Middle East, and the Americas, with business cases supporting next-generation connected vehicles.
- Directed a 6-member global team with 10+ SMEs on a cybersecurity maturity assessment for a leading healthcare organization across IT, medical OT, and supply chain, presenting to the C-suite to secure funding; then ran the transformation — 10 in-flight initiatives, 20+ professionals across GRC, data protection, cloud security, medical OT, third-party risk, IAM, and cyber PMO.
- Led an SEC cybersecurity disclosure readiness assessment across a publicly traded media and entertainment holding company and seven portfolio companies — materiality determination, escalation, and disclosure processes — and designed the approach standardizing 10-K and 8-K disclosures.
- Guided an enterprise security program from 0 to a 3+ CMMI maturity rating over multiple years, protecting a global portfolio of consumer brands; recognized by the CISO in a LinkedIn recommendation for sustained program leadership.
Executive & team leadership
- Established the operating cadence for a client Office of the CISO — operating models, steering committee structure, governance workshops, and reporting touchpoints.
- Drove board, audit committee, and executive steering committee reporting for CISOs across multiple sectors, translating technical risk into funding and prioritization decisions; managed OPEX/CAPEX forecasting, resource planning, and sourcing models for $5M+ program budgets.
- Held performance oversight for 10+ direct reports globally; advanced 5+ through promotions by tracking KPI progress and presenting their cases to leadership.
Manager — Cybersecurity Risk, Controls & Compliance
- Led a $2M+ program to remediate a material NERC CIP audit finding carrying regulatory exposure of $1M+ per violation, per day; operationalized a NIST RMF-based cyber risk program and stood up enterprise risk oversight that closed the finding and eliminated ongoing penalty risk.
- Partnered with Archer GRC developers to design, pilot, and deploy cyber risk management capability enabling enterprise-wide risk tracking, measurement, and remediation.
- Designed and activated third-party risk management programs, cyber risk operating models, cybersecurity policies, and metrics/reporting frameworks.
- Built executive dashboards and persona-based reporting that converted cyber risk metrics into leadership decision inputs rather than compliance status.
- Advanced client cyber programs from initial to defined maturity over 2–3 years through risk-prioritized roadmaps tailored to sector, threat profile, and business context.
Senior Consultant — Cybersecurity Risk & Audit
- Executed cybersecurity program and controls assessments against NIST CSF, NIST RMF, and ISO standards, producing risk-prioritized findings and remediation roadmaps.
- Facilitated workshops with cyber leadership, internal audit, engineering, and business stakeholders to evaluate program maturity and define target-state capability.
- Authored cybersecurity policies, standards, and control documentation, and drove activation across client operating models.
- Built cyber metrics and reporting dashboards to track program maturity against target state and developed business cases supporting multi-year investment decisions.
PwC (PricewaterhouseCoopers LLP)
Indianapolis, IN · IT Risk AssuranceExperienced Associate — IT Risk Assurance
- Led IT general controls (ITGC) and process control assessments delivering SOX and SSAE 16 compliance outcomes for Fortune 500 clients, owning audit readiness and control remediation.
- Led SAP security audits identifying excessive access, redundant permissions, and segregation-of-duties conflicts across employees and contractors, and implemented remediation to strengthen access governance.
- Established governance and IT risk frameworks for a Fortune 500 pharmaceutical client — threat and vulnerability assessments, threat management policy, asset risk oversight, and exception tracking.
Accenture
Mumbai, IndiaAssociate Software Engineer — SAP Basis Security Administration
- SAP BASIS security administrator for a global mining and resources company — user provisioning, role and authorization design, and security administration across production SAP environments.
- Administered access controls and segregation-of-duties enforcement in live, audited enterprise systems.
Core competencies
Business development & go-to-market
Signings & revenue attainment · Pipeline origination · Opportunity identification & qualification · Pursuit & proposal leadership · Pricing, deal structuring & deal governance · Solution & offering development · Account planning & expansion · CISO and C-suite relationship management · SOW & scope definition
Security strategy & risk
Cyber risk management · Risk assessment · Controls design & testing · Risk register & issue management · Control libraries · Audit readiness & finding remediation · Regulatory compliance · Risk quantification
Frameworks
NIST CSF 2.0 · NIST RMF · NIST AI RMF · ISO 27001 · ISO 21434 / SAE J3061 · SOX · SSAE 16 / SOC 2 · SEC cyber disclosure readiness · HIPAA · NERC CIP · Policy & standards development
Third-party risk
TPRM program design · Vendor tiering · Due diligence · Contractual security requirements · Continuous monitoring
Program & executive
Cybersecurity PMO · Board & audit committee reporting · Executive dashboards & metrics · Roadmaps and business case development · OPEX/CAPEX planning · Resource and staffing models · Team leadership
Platforms
RSA Archer · ServiceNow GRC · AuditBoard · SAP Security
Education & certifications
Master of Science, Information Systems
Kelley School of Business, Indiana University Bloomington
Bachelor of Engineering, Information Technology
University of Mumbai