← Back to list
Senior
Registration: 19.05.2025

Shaju Bhaskaran

Specialization: Cyber Security / Information Risk Management
— 23 years of contribution in the entire gamut of Cyber Security Operations, Network Security, OT Cyber Security, Risk Management, InfoSec Strategy & Governance, Project/Program Management, Service Delivery, Implementation and Support in various global companies. — Extensive experience in Cyber Security Operations and IT Risk Management Practice with Banks in India, Southeast Asia, Middle East and Europe. Worked with Central Banks like RBI, IRDA, MAS, QCB etc. to ensure compliance with Technology Risk. — Managed overly complex network security projects for Banks, Telco's and other industries. — Spearheaded InfoSec Architecture, Cloud Risk assessment, Security controls for migrating to MS Office 365/Azure cloud. — Security controls for MS 365, Azure DevOps and Implementation/Operations of Azure Sentinel. — Technology risk identification, risk assessment, risk mitigation, response and risk reporting. Creating & managing the IT Risk framework for the company, Key Risk Indicators for all the areas of IT risk and Regulatory compliance. — Possess broad competence in strategic management of technical/business matters (especially in the banking and financial sector) with the distinction of launching and driving new Information security initiatives and managing multiple concurrent complex projects, achieving organisational objectives within specified timelines. — Comprehensive expertise in developing and implementing an Enterprise Information Security Program with deftness in Security Strategy, Security Architecture, Technology Risk assessment & mitigation, Data Privacy, Technology Audits, Security Reviews, Incident management, Security Governance and IT Compliance management. — Adept at leading and managing a team for running successful process operations & experience of implementing a robust information security architecture, GRC framework, technology risks, business continuity plans, information security policies and procedures, also worked on GRC tools like Archer & SAS, also did consulting for GRC tools, SOC and other Information Security services. — Spearheaded the implementation, maintenance and renewal of ISO27001:2013 and PCI-DSS projects at major Banks in INDIA, Southeast Asia and Middle East. — Compliance to COBIT, ITIL & NIST frameworks across all the regions of global banks. — Developed Information Security & Business Continuity strategy for large companies including banks. — Designed and implemented Data security program for the bank including data discovery, classification, policy development and applying the policies in the Data Loss Prevention (DLP) solution. — Successful design and implementation of security controls for Online Banking, Mobile Banking apps and 3D secure system. — Designed security architecture and implemented security controls for SWIFT system, ATM & POS environments etc. — Vulnerability management & Security Testing of IT infrastructure and Banking applications like E Wallet. — Managing Penetration testing and Red & Blue team exercises. — Implementation & Day-to-Day operations of Identity & Privilege Access Management.
— 23 years of contribution in the entire gamut of Cyber Security Operations, Network Security, OT Cyber Security, Risk Management, InfoSec Strategy & Governance, Project/Program Management, Service Delivery, Implementation and Support in various global companies. — Extensive experience in Cyber Security Operations and IT Risk Management Practice with Banks in India, Southeast Asia, Middle East and Europe. Worked with Central Banks like RBI, IRDA, MAS, QCB etc. to ensure compliance with Technology Risk. — Managed overly complex network security projects for Banks, Telco's and other industries. — Spearheaded InfoSec Architecture, Cloud Risk assessment, Security controls for migrating to MS Office 365/Azure cloud. — Security controls for MS 365, Azure DevOps and Implementation/Operations of Azure Sentinel. — Technology risk identification, risk assessment, risk mitigation, response and risk reporting. Creating & managing the IT Risk framework for the company, Key Risk Indicators for all the areas of IT risk and Regulatory compliance. — Possess broad competence in strategic management of technical/business matters (especially in the banking and financial sector) with the distinction of launching and driving new Information security initiatives and managing multiple concurrent complex projects, achieving organisational objectives within specified timelines. — Comprehensive expertise in developing and implementing an Enterprise Information Security Program with deftness in Security Strategy, Security Architecture, Technology Risk assessment & mitigation, Data Privacy, Technology Audits, Security Reviews, Incident management, Security Governance and IT Compliance management. — Adept at leading and managing a team for running successful process operations & experience of implementing a robust information security architecture, GRC framework, technology risks, business continuity plans, information security policies and procedures, also worked on GRC tools like Archer & SAS, also did consulting for GRC tools, SOC and other Information Security services. — Spearheaded the implementation, maintenance and renewal of ISO27001:2013 and PCI-DSS projects at major Banks in INDIA, Southeast Asia and Middle East. — Compliance to COBIT, ITIL & NIST frameworks across all the regions of global banks. — Developed Information Security & Business Continuity strategy for large companies including banks. — Designed and implemented Data security program for the bank including data discovery, classification, policy development and applying the policies in the Data Loss Prevention (DLP) solution. — Successful design and implementation of security controls for Online Banking, Mobile Banking apps and 3D secure system. — Designed security architecture and implemented security controls for SWIFT system, ATM & POS environments etc. — Vulnerability management & Security Testing of IT infrastructure and Banking applications like E Wallet. — Managing Penetration testing and Red & Blue team exercises. — Implementation & Day-to-Day operations of Identity & Privilege Access Management.

Skills

Enterprise Information
Cyber Security strategy
Cyber Security Operations / SOC
Network & Application Security
Identity & Access Management
Information Risk Management & GRC
Data Security
OT Cyber Security
Cyber Security Architecture
ISO 27001
PCI-DSS
Regulatory Compliance
GDPR
Project Management
Azure Sentinel

Work experience

Head - Cyber Security & IT Risk
since 01.2023 |Equinor
Enterprise Information & Cyber Security strategy, Cyber Security Operations / SOC, Network & Application Security, Identity & Access Management. Information Risk Management & GRC, Information Security Policy Documentation and Implementation, Data Security, OT Cyber Security, Cyber Security Architecture, ISO 27001:2013, PCI-DSS, Regulatory Compliance, GDPR, Cloud Security & DevSecOps, Securing MS 365 & Azure DevOps, Email, Web & Mobile Security, Azure Sentinel
● Managing customer expectaions with regards to Cyber Security. ● Ensure compliance with regulatory and legal requirements related to cybersecurity. ● Complying to ISO 27001 framework & GDPR. ● Ensuring compliance to Cyber Security policies & procedures. ● Conducting risk assessments to identify vulnerabilities and threats to the organization. ● Implement and oversee a risk management program to mitigate cyber risks. ● Assessing OT Cyber Security and providing recommendations. ● Assess and manage security risks associated with vendors and partners. ● Working with customer on GRC Framework & tool implementation. ● Managing a team of Cyber Security engineers. ● Day to day operations of network security devices. ● Managing PKI for internal & external certificate management. ● Managing End point, Identity Access, Cloud security. ● Overseeing efficiency of SOC activities & continuous improvement. ● Managing VA scanning & closure of vulnerabilities. ● Managing external PT exercise conducted by our teams & third party. ● Assisst customer with Red & Blue team exercise. ● Work with customer to build IR process & capabilities. ● Consistently working on improvements & automation of existing operational tasks. ● Automation of Cert Management, FW rule optimisation, auto-ticket remediation etc. ● Corodinating with OEMs to ensure smooth operations. ● Following Incident, Change, Problem management as per ITIL process.
Chief Information Security Officer
05.2021 - 01.2023 |Ooredoo
Enterprise Information & Cyber Security strategy, Cyber Security Operations / SOC, Network & Application Security, Identity & Access Management. Information Risk Management & GRC, Information Security Policy Documentation and Implementation, Data Security, OT Cyber Security, Cyber Security Architecture, ISO 27001:2013, PCI-DSS, Regulatory Compliance, GDPR, Cloud Security & DevSecOps, Securing MS 365 & Azure DevOps, Email, Web & Mobile Security, Azure Sentinel
● Ensuring cyber security compliance for the Qatar SMART Nation program and all its Use Cases. ● Entire Cyber Security for FIFA World cup 2022 Real Time Crowd Management Use Case. ● Cyber security for other Smart City Use Cases like Smart Parking, Digital Twin. ● Cloud & IOT security for the one of the biggest MS Azure implementations in GCC region. ● Ensuring compliance for International and Regional IS & Privacy standards for Cloud & IOT. ● Managing Information Security Operations, Risk Management, people & vendor management for Qatar Smart Program (known as TASMU), an initiative to make the country smart in multiple areas by 2030 by using MS Azure Cloud Platform, one of the biggest and ambitious program by the QATAR Government till date in the Digital space. ● Ensuring security for IOT end-points for various Use cases like SMART City, Digital Twin etc. ● Building and managing the SOC Operations for Qatar Smart Program, one of the biggest and advanced SOC in the country with complete automation using Azure Sentinel, Cloud AI features, threat hunting platform, IR and MDR capabilities. ● Ensuring data governance for Azure data lake integrations by data classification & applying principles of data security & privacy. ● Managing all aspects of MS Azure Cloud Security, MS 365, D365 and Azure DevOps Security. ● Working on new Security projects like PKI, VA/PT, Security Architecture reviews. ● Security testing for the mobile apps, cloud platform and the entire ecosystem. ● Ensuing Security & Compliance for new Smart Use Cases for various ministries in Qatar. ● Managing Qatar Airways (biggest Airline of the world) SOC (Biggest in Qatar) running on LogRhythm as an additional responsibility. ● Managing two biggest SOC in QATAR for Ooredoo (Azure Sentinel) and Qatar Airways (LogRythm).
Chief Information Security Officer
08.2014 - 02.2021 |Ahlibank
Enterprise Information & Cyber Security strategy, Cyber Security Operations / SOC, Network & Application Security, Identity & Access Management. Information Risk Management & GRC, Information Security Policy Documentation and Implementation, Data Security, OT Cyber Security, Cyber Security Architecture, ISO 27001:2013, PCI-DSS, Regulatory Compliance, GDPR, Cloud Security & DevSecOps, Securing MS 365 & Azure DevOps, Email, Web & Mobile Security, Azure Sentinel
● Meeting the expectations of the Board & Senior Management by developing Information Security Strategy and managing Cyber Security Operations for the bank. ● Detecting & responding to new threats, IT Risk Management, Project Management, People/Vendor management, annual IS budget planning & spend, ensuring regulatory requirements are met, managing Internal, External & Regulatory Audits. My team’s day-to-day activities: ● Developed enterprise IT Risk strategy that consists of strategically integrated elements of NIST risk management and Cybersecurity frameworks, SANS Critical Controls, ISO 27001/27002, PCI DSS, GDPR & other Regional standards like NIA, FIFA World Cup Cyber Security Framework 2022. ● Design and manage the entire Lifecycle IT Risk management by continuous Risk Assessments, Risk Mitigation, Reporting & managing the residual risk. ● Revamping the traditional SOC to Managed Detection & Response Center. ● Managing day to day Cyber Security Operations. ● Continuous Risk Assessments of all the critical IT Applications and Infrastructure. ● Ensuring data integrity, confidentiality and availability of information as well as creating controls on how data is processed by the organization. ● IT Security Governance structure to reduce risks in business processes, enhance information security, and comply with regulatory requirements. ● Ensuring Data Privacy by implementation of National Data Privacy laws, GDPR. ● Managing the Information Security Budgeting every year in alignment with the IS Strategy & Bank’s Vision. ● Ensuring Bank’s Information Security Compliance across different regions/countries. ● Working closely with Regulatory audit bodies like Central Banks & CERT teams. ● Collaborate with Regional CISO’s to keep abreast of any changing trends. ● Participating in Cyber Drills every year conducted by Country’s CERT team across all industries. ● Information Security metrics to depict the IS posture of the bank to Management and the Board. ● Ensuring Security compliance in the Change Lifecycle Management. ● Incident Response procedures and metrics. ● Creation and deployment of Security Awareness Program. ● Working on the Blue team & Red team model for continuous enhancement of the Information Security Gap Assessment which covers the entire IT landscape. ● Third part RA’s, Vendor & People Management. Projects successfully implemented in my tenure: ● Migrating applications & IT Infra components to cloud ● PCI DSS Certification, first bank in Qatar ● ISO 27001 ● Security Compliance on Cloud Projects like Microsoft Azure, Oracle. ● Completed end-to-end security assessments for projects like Core Banking upgrade, Internet Banking migration, payment applications, Card & Pin printing Solution, Trading apps & E-Wallet ● Identity Access & Privilege Access Management ● Governance, Risk & Compliance solution ● Anti-Malware/APT prevention at Web, Email & EDR ● Volumetric & Application DDOS protection ● Implementation of Anti Phishing solution for email & Web ● GDPR & National Privacy law Compliance ● Qatar National Information Assurance Policy & Cyber Security Framework 2022 Compliance ● Data Classification and DLP for Email, Web & Endpoints ● Privilege ID management – Covered all critical applications, Databases and Network Devices. Password Management, Session recording, approval workflows, Integration of UNIX Environments with Active Directory. ● Identity & Access Management – User Access Governance & Provisioning for critical applications ● Revamping the traditional MSSP in to Managed Detection Response Center ● Designing Cryptographic controls policy for the bank ● App Security testing & Compromise Assessments on the IT infrastructure
Head - Information Risk Management
08.2011 - 07.2014 |ING Group
Enterprise Information & Cyber Security strategy, Cyber Security Operations / SOC, Network & Application Security, Identity & Access Management. Information Risk Management & GRC, Information Security Policy Documentation and Implementation, Data Security, OT Cyber Security, Cyber Security Architecture, ISO 27001:2013, PCI-DSS, Regulatory Compliance, GDPR, Cloud Security & DevSecOps, Securing MS 365 & Azure DevOps, Email, Web & Mobile Security, Azure Sentinel
Managing a team of Information Security professionals and solely responsible for the Information Security posture of the company by constantly sensitizing the top management on the critical issues. Some achievements in my tenure: ● Implemented Data Loss Prevention project for network and endpoints. ● Ethical Hacking assessment to test the robustness of the network & systems. ● Implementing end point security solution to manage end points centrally. ● Security Architecture review. ● Designing the preparedness of IT systems for cloud computing. ● Security baseline for BYOD & Mobile applications. ● ISO 27001 Gap Analysis. ● PCI DSS assessment. ● SOX Compliance review. ● Creating the Application Security Assessment guidelines. ● Implementing IT GRC Solution using IBM OpenPages. ● Implemented RSA Envision for security incident & event monitoring.
Cyber Security Architect
12.2009 - 07.2011 |Dimension Data
Cyber Security Operations / SOC, Network & Application Security, Identity & Access Management. Information Risk Management & GRC, Information Security Policy Documentation and Implementation, Data Security, OT Cyber Security, Cyber Security Architecture, Regulatory Compliance, GDPR, Securing MS 365 & Azure DevOps, Email, Web & Mobile Security, Azure Sentinel
● Responsible for delivering high end IT security and compliance solutions to clients across all verticals like BFSI, Telco’s, IT companies, Public Sector companies. ● Mostly we focused on the BFSI segment. ● We did evaluation of different solutions for the clients, audits & assessments, fixing of the gaps found, detailed documentations for compliance, pre-RFP preparation. Some Achievements in my tenure: ● Did complete ISMS readiness for a financial services company & others across Asia. ● Designed security architecture for one of the biggest oil companies in India. ● Did complete Security Architecture review for a multinational BPO. ● Did multiple assessments for VA/PT, ISO 27001 across domains like BFSI, Telecom, Manufacturing, BPO. ● Worked on Arbor DDOS solution, which was a hosted solution from Telco’s for corporates. ● Consulting on DR for datacenter for a large BPO company in India ● Did BCP for a BFSI from a risk-based approach. ● Did the review of the risk management framework for one of the biggest automobile company of the world for its India division. ● Managed projects for one of India’s largest Telecom company involving very high-end customized security solutions.
Manager - Information Security
07.2008 - 10.2009 |Standard Chartered
Vulnerability Management & Security
● Managed a team of security analysts and project leads working in designing, implementing and operating Vulnerability Management & Security log monitoring for the bank worldwide.
Assistant Manager, Information Security
12.2006 - 07.2008 |Aricent Technologies
Information Security
● Responsible for managing a team handling the Information Security Management System (ISMS) for Aricent worldwide.
Information Security Specialist
10.2004 - 12.2006 |GE Money
Information Security
● Responsible for all the Information Security operations and projects across GE Money India.
Senior Network Security Engineer
05.2002 - 10.2004 |R Systems
Network Security, Technical Support
● Providing support for implementing, troubleshooting and supporting high-end Enterprise/Mid-Range/SOHO level Firewall VPN Security Solutions for WATCHGUARD®, USA.

Educational background

Computer Science (Masters Degree)
Maharshi Dayanand University
Commerce (Bachelor’s Degree)
Pandit Ravi Shankar Shukla University

Languages

EnglishUpper Intermediate