Selected work
Professional & Academic projects
Selected work demonstrating measurable impact
01 — Professional
Full-Time
- CYBER GOVERNANCE
Policy Development
PWC
Developed 17 domain-specific system security policies balancing regulatory requirements, team's technical capabilities, and business needs
- Reduced risk exposure window by over 50%
- Eliminated recurring audit findings
- Supported successful acquisition of the payment aggregator license for business expansion
Access ManagementAnti-MalwareAsset ManagementEncryption ManagementData ClassificationCloud SecurityThird-Party Risk ManagementChange ManagementException ManagementVulnerability ManagementSecure CodingLog ManagementInformation and Media HandlingPassword & Account ManagementPatch ManagementSOC ManualDLP Incident ManagementNIST 800-53NIST 800-61 ISO 27001ISO 27002Confluence OWASP Top 10 - TPRM
Third Party Risk Management Program Optimization
PWC
Overhauled the TPRM function of a regulated financial services client with a vendor base of 600+ vendors
- Improved assessment quality and throughput by ~30% within two quarters
- Updated and re-structured the risk profile questionnaire for vendor profiling
- Standardized assessment scoping mechanism for repeatable and consistent use
- Trained the team on vendor assessment best practices
SIG LiteCIS AWS BenchmarksISO 27001ServiceNow - CLOUD SECURITY
Cloud Security Assessment
PWC
Conducted cloud security assessment covering 12 AWS services across 8 domains
- Identified 87% medium-to-high risk issues
- Delivered a risk-prioritized remediation roadmap
- Prevented ~$12M in losses by improving the cloud security posture
IAMCompute Services - EC2, LambdaVPCLogging & Monitoring - AWS CloudTrail, AWS ConfigStorage Services - S3, EBSSecurity & Compliance Services - AWS Certificate Manager, KMSApplication Integration Service - SNSNetwork & Content Delivery Service - Amazon CloudFrontAWSAWS Service Security Best PracticesCIS AWS Benchmarks - DATA PRIVACY
Privacy Operations
CAPGEMINI
Developed GDPR compliant records of processing activities (RoPA) and conducted privacy impact assessments (PIA) for 16 regional and 6 global engagements spanning Europe, India, China, and the US
- Identified, assessed, communicated, treated, and monitored critical data processing risks
- Established end-to-end data mapping
- Established audit-ready compliance with stringent regulatory and client contractual requirements
GDPRHIPAACCPA - INFORMATION SECURITY
Information Security Risk Management
CAPGEMINI
Conducted end-to-end asset-based risk assessments for 22 engagements
- Identified, assessed, communicated, treated, and monitored critical information security risks
- Established audit-ready compliance with stringent regulatory and client contractual requirements
ISO 27001ISO 27005 - BUSINESS CONTINUITY
Business Continuity Management
CAPGEMINI
Developed end-to-end tailored business continuity plans for 22 engagements
- Enhanced operational resilience
- Established financial, legal, operational, and reputational impact at minutes, hourly, daily, weekly, and monthly service disruption levels
- Established operational criticality at service/product, process, and activity level
- Mapped asset-to-service dependencies to ensure continuity of operations as per the committed RTO, MAO, and RPO
- Conducted threat assessment and identified plausible continuity strategies to ensure continuity of operations as per the committed RTO, MAO, and RPO
ISO 22301Tabletop Exercise
02 — Academic
Part-Time Experiential Projects
- CYBER RISK MANAGEMENT CAPSTONE
Cybersecurity in the Post-Quantum World
MCKINSEY & COMPANY AND INDIANA UNIVERSITY
Developed a risk-based PQC transition strategy, clarifying near-term leadership investment priorities and system design imperatives to enable seamless cryptographic transitions for achieving digital resilience in the post-quantum world
- Threat outlook
- Key systems and data at risk
- Top 5 PQC transition challenges
- PQC transition scoping strategy
- Crypto agility maturity measurement
Cryptographic Agility Maturity Model (CAMM)FIPS 203 (ML-KEM)FIPS 204 (ML-DSA)FIPS 205 (SLH-DSA) - CYBER CLINIC
Cyber Risk Assessment
TANDEM AND INDIANA UNIVERSITY
Strengthened HIPAA compliance for a non-profit healthcare organization
- Identified 20+ gaps by conducting a cyber risk assessment
- Delivered a cost-effective and risk-prioritized remediation roadmap
- Delivered a NIST 800-61 aligned incident response plan
HIPAAHIPAA Security RuleHIPAA Privacy RuleNIST 800-61ISO 27001 - RESEARCH ASSISTANT
Smart, but Safe? Assessing the Health of Medical Device Cybersecurity
INDIANA UNIVERSITY
Co-authored a law review article examining medical device cybersecurity governance gaps in the U.S., with a particular emphasis on the evolving role of AI
- Approved for publication and forthcoming in the Minnesota Journal of Law, Science, and Technology
FDAAI Governance - RESEARCH ASSISTANT
Agentic AI : The Layered Security Approach
INDIANA UNIVERSITY
Defined security control requirements and guardrails for AI Agents, LLMs, and Autonomous Agentic Systems
- Case study on a hypothetical FinTech Enterprise
- Applied CSA's MAESTRO framework to identify threats, vulnerabilities, risks, and mitigations across the seven-layer reference architecture for agentic AI
MAESTROOWASP LLM Top 10OWASP Top 10 for Agentic ApplicationsAI Risk Management - RESEARCH ASSISTANT
AI Adoption Framework
INDIANA UNIVERSITY
Developed an AI adoption framework synthesizing AI regulations of 12 countries
- Enabled risk-informed decision making for under-resourced local communities and organizations on AI adoption
ISO 42001NIST AI RMFEU AI ActColorado AI Act - EXPLOITING & PROTECTING WEB APPLICATIONS
Web Application Security
STANFORD UNIVERSITY
Exploited OWASP Top 10 web application vulnerabilities in a simulated environment
- Articulated the vulnerability POC, risk, ease of exploitation, business impact, and appropriate mitigations
OWASP Top 10Burp Suite - NETWORK SECURITY
Network Security Project
STANFORD UNIVERSITY
Exploited network vulnerabilities in a simulated environment
- Articulated the exploitation procedure step-by-step and mitigations to be put in place
NmapMetasploitHydraWireshark