Background
Experience & Education
Roles, research, and rigor - the path so far...
Timeline
Key Achievements
AUG 2024 — MAY 2026
Lead Researcher
Indiana University Bloomington
- Co-authored a law review article examining the medical device cybersecurity governance gaps in the U.S., with a particular emphasis on the evolving role of AI; the piece has been approved for publication and is forthcoming in the Minnesota Journal of Law, Science, and Technology
- Developed an AI adoption framework synthesizing AI regulations of 12 countries and frameworks including OECD, ISO 42001, NIST AI RMF, EU AI Act, and the Colorado AI Act to help the under-resourced local clients make risk informed decisions and improve AI onboarding outcomes.
- Applied MAESTRO framework to identify threats, vulnerabilities, risks, and defined controls & guardrails for AI agents, LLMs, and Autonomous Agentic Systems
JUNE — JULY 2025
SOC Intern
OmniSOC, Indiana University Bloomington
- Established visibility and detection capability for IU's AWS environment by analyzing the TTPs of the five most prevalent adversaries and delivering optimized logging recommendations with a detection rulebook mapped to the MITRE ATT&CK and DeTT&CT frameworks
MAY 2025 — DEC 2025
Research Intern
Advanced Cyber Law
- Enabled meaningful podcast discussions by developing structured podcast scripts that framed questions targeting core challenges in emerging cybersecurity issues like agentic AI identity risks, hacking back the hackers, and incident response under cybersecurity decentralization in the U.S.
JAN 2023 — AUG 2024
Associate
PwC, Advisory - Risk Consulting Practice - Strategy & Governance Capability
- Mitigated systemic risks and enabled successful acquisition of the payment aggregator license by addressing compliance gaps and developing 15 domain-specific system security policies for a regulated Fintech client operating in a cloud-native environment
- Reduced third-party assessment time by ~40% by leading an organization-wide ISO 27001:2022 implementation for a regulated FinTech startup covering 8 functions across governance, technology, HR, legal, compliance, and administration
- Developed a unified compliance management dashboard enabling single-pane tracking and visibility across 300+ control requirements spanning multiple compliance and control frameworks for a regulated FinTech startup
- Reduced enterprise risk exposure window by over 50% by designing and operationalizing an end-to-end vulnerability management and change management framework for a regulated FinTech client
- Improved the cloud security posture of an M&E client by identifying 87% medium-to-high risk findings across networking, storage, compute, logging & monitoring, application integration, and security & compliance AWS services, during a cloud security assessment leveraging CIS benchmarks and delivering risk-based recommendations
- Strengthened the cybersecurity posture of a regulated Financial Services client by identifying 65% medium-to-high risk findings across 12 domains during the cybersecurity maturity assessment using NIST 800-53 and delivering risk-based recommendations
- Overhauled a financial services client's information security component of the TPRM function end-to-end, improving assessment quality and throughput by ~30% within two quarters
NOV 2021 - JAN 2023
Compliance Associate
Capgemini, Global Risk & Compliance Function
- Owned and managed end-to-end compliance program across 22 engagements, covering ISO 27001, ISO 27701, ISO 22301, SOC 2, and customer contractual information security requirements
- Improved the information security posture across 22 engagements by conducting asset-based information security risk assessment and managing risks end-to-end from identification to mitigation, documentation, and reporting
- Established audit-ready compliance with stringent regulatory frameworks, including GDPR, HIPAA, and CCPA by developing records of processing activities (ROPAs) and conducting privacy impact assessments (PIAs) across 16 regional and 6 global engagements spanning India, China, Europe, and the US
- Identified significant compliance gaps by independently conducting cross-site internal audits of Business Continuity Management System (BCMS), Privacy Information Management System (PIMS), and Information Security Management System (ISMS), evaluating technological, organizational, and physical security controls
- Enhanced operational resilience by developing end-to-end business continuity plans for 22 engagements
Education
Where curiosity met credentials
AUG 2024 — MAY 2026
M.S., Cybersecurity Risk Management
Indiana University Bloomington
Interdisciplinary graduate coursework across three schools of Indiana University: Maurer School of Law, Kelley School of Business, and Luddy School of Informatics.
Coursework
- Cybersecurity Law and Policy
- Information Privacy Law
- AI: Law and Technology
- Technical Foundations of Cybersecurity
- Security for Networked Systems
- Cloud Computing
- Cyber Risk Management Capstone
- Cyber Clinic
- Information Technology Principles
AUG 2020 — APRIL 2021
Advanced Certificate, Computer Security
Stanford University
Online Certificate Program by Stanford Centre for Professional Development designed for industry professionals to hone their skills in Computer Security.
Coursework
- Foundations of Information Security
- Exploiting and Protecting Web Applications
- Using Cryptography Correctly
- Network Security
- Emerging Threats and Defences
- Software Security
AUG 2015 — MAY 2019
B.Tech, Mechanical and Automation Engineering
GGSIP University
Foundation in engineering mechanics.