Background

Experience & Education 

Roles, research, and rigor - the path so far... 

Timeline

Key Achievements

  1. AUG 2024 — MAY 2026

    Lead Researcher

    Indiana University Bloomington

    • Co-authored a law review article examining the medical device cybersecurity governance gaps in the U.S., with a particular emphasis on the evolving role of AI; the piece has been approved for publication and is forthcoming in the Minnesota Journal of Law, Science, and Technology
    • Developed an AI adoption framework synthesizing AI regulations of 12 countries and frameworks including OECD, ISO 42001, NIST AI RMF, EU AI Act, and the Colorado AI Act to help the under-resourced local clients make risk informed decisions and improve AI onboarding outcomes.
    • Applied MAESTRO framework to identify threats, vulnerabilities, risks, and defined controls & guardrails for AI agents, LLMs, and Autonomous Agentic Systems  
  2. JUNE — JULY 2025

    SOC Intern

    OmniSOC, Indiana University Bloomington

    • Established visibility and detection capability for IU's AWS environment by analyzing the TTPs of the five most prevalent adversaries and delivering optimized logging recommendations with a detection rulebook mapped to the MITRE ATT&CK and DeTT&CT frameworks
  3. MAY 2025 — DEC 2025

    Research Intern

    Advanced Cyber Law 

    • Enabled meaningful podcast discussions by developing structured podcast scripts that framed questions targeting core challenges in emerging cybersecurity issues like agentic AI identity risks, hacking back the hackers, and incident response under cybersecurity decentralization in the U.S. 
  4. JAN 2023 — AUG 2024

    Associate

    PwC, Advisory - Risk Consulting Practice - Strategy & Governance Capability

    • Mitigated systemic risks and enabled successful acquisition of the payment aggregator license by addressing compliance gaps and developing 15 domain-specific system security policies for a regulated Fintech client operating in a cloud-native environment          
    • Reduced third-party assessment time by ~40% by leading an organization-wide ISO 27001:2022 implementation for a regulated FinTech startup covering 8 functions across governance, technology, HR, legal, compliance, and administration
    • Developed a unified compliance management dashboard enabling single-pane tracking and visibility across 300+ control requirements spanning multiple compliance and control frameworks for a regulated FinTech startup
    • Reduced enterprise risk exposure window by over 50% by designing and operationalizing an end-to-end vulnerability management and change management framework for a regulated FinTech client    
    • Improved the cloud security posture of an M&E client by identifying 87% medium-to-high risk findings across networking, storage, compute, logging & monitoring, application integration, and security & compliance AWS services, during a cloud security assessment leveraging CIS benchmarks and delivering risk-based recommendations   
    • Strengthened the cybersecurity posture of a regulated Financial Services client by identifying 65% medium-to-high risk findings across 12 domains during the cybersecurity maturity assessment using NIST 800-53 and delivering risk-based recommendations
    • Overhauled a financial services client's information security component of the TPRM function end-to-end, improving assessment quality and  throughput by ~30% within two quarters   
  5. NOV 2021 - JAN 2023

    Compliance Associate

    Capgemini, Global Risk & Compliance Function

    • Owned and managed end-to-end compliance program across 22 engagements, covering ISO 27001, ISO 27701, ISO 22301, SOC 2, and customer contractual information security requirements
    • Improved the information security posture across 22 engagements by conducting asset-based information security risk assessment and managing risks end-to-end from identification to mitigation, documentation, and reporting 
    • Established audit-ready compliance with stringent regulatory frameworks, including GDPR, HIPAA, and CCPA by developing records of processing activities (ROPAs) and conducting privacy impact assessments (PIAs) across 16 regional and 6 global engagements spanning India, China, Europe, and the US  
    • Identified significant compliance gaps by independently conducting cross-site internal audits of Business Continuity Management System (BCMS), Privacy Information Management System (PIMS), and Information Security Management System (ISMS), evaluating technological, organizational, and physical security controls
    • Enhanced operational resilience by developing end-to-end business continuity plans for 22 engagements

Education

Where curiosity met credentials

  1. AUG 2024 — MAY 2026

    M.S., Cybersecurity Risk Management

    Indiana University Bloomington

    Interdisciplinary graduate coursework across three schools of Indiana University: Maurer School of Law, Kelley School of Business, and Luddy School of Informatics.

    Coursework

    • Cybersecurity Law and Policy
    • Information Privacy Law 
    • AI: Law and Technology
    • Technical Foundations of Cybersecurity
    • Security for Networked Systems
    • Cloud Computing
    • Cyber Risk Management Capstone
    • Cyber Clinic
    • Information Technology Principles
  2. AUG 2020 — APRIL 2021

    Advanced Certificate, Computer Security

    Stanford University

    Online Certificate Program by Stanford Centre for Professional Development designed for industry professionals to hone their skills in Computer Security.

    Coursework

    • Foundations of Information Security
    • Exploiting and Protecting Web Applications
    • Using Cryptography Correctly
    • Network Security
    • Emerging Threats and Defences
    • Software Security
  3. AUG 2015 — MAY 2019

    B.Tech, Mechanical and Automation Engineering

    GGSIP University

    Foundation in engineering mechanics.