Turn Compliance Into Operating Discipline
Translate FedRAMP, NIST, ISO, PCI, and customer trust requirements into controls, owners, evidence, and recurring security rhythms.
Personal portfolio / cybersecurity leadership
Information Security Director at Ontic
AppSec operator turned security program leader.
I help SaaS teams earn trust through FedRAMP, product security, cloud controls, audit readiness, vulnerability management, and practical risk reduction.
About
Translate FedRAMP, NIST, ISO, PCI, and customer trust requirements into controls, owners, evidence, and recurring security rhythms.
Embed AppSec, threat modeling, vulnerability management, SDLC guardrails, and cloud review directly into product delivery.
Reduce ambiguity for leadership through risk registers, measurable KPIs, audit posture, customer assurance, and board-ready reporting.
Current Chapter
Ontic provides AI-powered Connected Intelligence software for corporate and government security teams, unifying security operations, threat intelligence, investigations, case management, and response into a trusted system of record. My role is to help ensure that kind of platform can meet enterprise, public sector, and customer trust expectations without slowing the business down.
Supported the security program maturity, control evidence, remediation discipline, and cross-functional alignment needed for Ontic's FedRAMP Moderate authorization milestone.
Focused on security governance, cloud posture, audit readiness, policy maturity, access control, vendor risk, incident readiness, and customer-facing assurance.
Brought an AppSec operator's mindset to a modern SaaS platform: threat modeling, secure design, vulnerability intake, prioritization, remediation validation, and engineering partnership.
Govern RBAC, auditability, secure data flows, tenant trust, logging, and policy alignment for a centralized security system of record.
Protect ingestion pipelines, sensitive investigations, identity context, source handling, analyst workflows, and customer-specific risk data.
Drive evidence integrity, retention thinking, secure workflows, access governance, incident readiness, and operational resilience.
Own API security, third-party risk, secrets hygiene, cloud configuration, monitoring, vulnerability response, and remediation accountability.
Career Signal
Regulated SaaS · Connected Intelligence · Public sector readiness
Gurgaon · Major Australian banking client
Gurgaon · Banking security programs
Gurgaon · BFSI and SaaS clients
Gurgaon · Product and client security
Pune · Infrastructure and application security
Noida · Fraud operations
Capability Matrix
Proof Points
Education
Secure Channel
Based in Noida, India. Open to relocation and ready to discuss SaaS security leadership, FedRAMP, AppSec, cloud security, trust programs, GRC, and enterprise risk.