Gaurav Verma

CTO

Melbourne, Victoria, Australia16 yrs 2 mos experience
Most Likely To SwitchHighly Stable

Key Highlights

  • Over 16 years of experience in IT and Cyber Security.
  • Expert in aligning IT strategy with business goals.
  • Proven track record in managing global cybersecurity operations.
Stackforce AI infers this person is a Cybersecurity leader with extensive experience in IT operations across Fintech and Logistics sectors.

Contact

Skills

Core Skills

CybersecurityRisk ManagementIt Operations

Other Skills

Artificial Intelligence (AI)Business ResilienceChange ManagementCloud ComputingCloud SecurityCommunicationCompliance frameworksCross-functional Team LeadershipCyber Risk ManagementCyber Threat Hunting (CTH)Cybersecurity risk assessmentsCybersecurity roadmapData PrivacyData backupDatabase architecture

About

Currently rocking the cyber scene from Down Under, Australia! Indian at heart, currently blending strategy, security, and just the right amount of sarcasm 😏 to keep both hackers πŸ§‘β€πŸ’» and auditors πŸ“‹ guessing. With over 16 years in IT & Cyber Security πŸ”, I’ve worn plenty of hats 🎩 β€” from hands-on techie to strategic advisor to senior leader. Currently steering the ship 🚒 as Head of IT Risk at Monvia (previously known as Axe Group), navigating choppy cyber waters 🌊 while aligning business goals, governance, and gigabytes (okay, petabytes) πŸ’Ύ. Whether it’s securing global cloud infrastructures ☁️, advising execs πŸ‘” on cyber resilience, or building security cultures that last β€” I bring the fire πŸ”₯ (and, of course, the firewall 🧱). 🧠 What I Bring to the Table: 🧭 CIO/CISO Lens: I don’t just secure systems β€” I align IT and cyber strategy with business goals, enable secure digital transformation 🌐, manage vendor risk 🀝, and report directly to the board πŸ§‘β€βš–οΈ and regulators. πŸ“œ Regulatory Compliance & Certifications: βœ… Certified CISSP, ISO 27001 Lead Auditor, and ISO 27001 Implementer. πŸ“˜ Deep working knowledge of ISO 27001, APRA CPS 234, CPS 230, HIPAA, PCI-DSS, CIS, NIST CSF, SOC 2, Essential Eight, GDPR, and local privacy laws πŸ›οΈ. πŸ› οΈ Designed and implemented end-to-end Information Security Management Systems (ISMS) across multiple industries. πŸ›‘οΈ Leadership in Cyber Operations: βš”οΈ Led global SoC operations, incident response, and risk governance programs. πŸ—οΈ Defined enterprise-wide security architecture, BCP/DR, vulnerability management, and third-party risk frameworks. πŸ’» Hands-on Tech Mastery (I still roll up my sleeves!): πŸ” SIEM, WAF, NGFW, Advanced Email Security (G Suite, M365), XDR, CSPM, CNAPP, SOAR, DLP, MDM, Encryption, Web Proxy, EDR, AV, RF/IoT hacking πŸ“‘, and threat emulation tools. πŸ” Strong foundations in cryptography, bug bounty, and secure cloud architecture across AWS, Azure, and GCP ☁️. 🧱 Infrastructure Expertise: 🌐 Entire DC/Cloud stack, including next-gen firewalls, DMZs, IDS/IPS, VPN/IPSec, DNS, SMTP, HTTP proxies, and Active Directory πŸ–₯️. Let’s hack-proof the world together 🌍, one laugh at a time!

Experience

Monvia

Head of IT Risk and Security

May 2021 – Present Β· 4 yrs 10 mos Β· Sydney, New South Wales, Australia

  • Create and execute the Cybersecurity roadmap along with reviewing security policies, change
  • Controls and incident response plans, DR/BCP plans and ensuring that they are regularly tested.
  • Managing SIEM, XDR, email security, VA, Pentest, Bug Bounty, DC/Cloud security incidents including reviewing investigations after breaches or incidents, including digital forensics.
  • Performing simulated phishing campaigns and security awareness training as well as ongoing
  • Communication to staff of cyber security policies and procedures.
  • Maintaining regulatory compliance to all relevant and applied standards (e.g. SOC2, APRA
  • CPS234, ISO 27001 & PCIDSS).
  • Constantly update the cyber security strategy to reflect changing laws and applicable regulations, and to leverage new technology and threat information.
  • Communicate best practices and risks to all parts of the business along with managing third party risks.
  • Ensure that our vendors and IT contractors are compliant with their risk and security responsibilities.
  • Running monthly risk forums & ensuring that systems are regularly patched and hardened.
  • Implemented Digital Forensics and Incident Response service.
  • Ensure that any security vulnerabilities that have been raised are mitigated, coordinating between stakeholders and technical resources where needed.
Cybersecurity roadmapSecurity policiesIncident response plansRegulatory complianceDigital forensicsCybersecurity+1

Paytm

DGM - IT

Aug 2019 – May 2021 Β· 1 yr 9 mos Β· Noida, Uttar Pradesh, India

  • Oversee entire IT Infrastructure & Security at Paytm/One97 group of companies for ~10k employees across multiple entities.
  • Lead IT Support, Asset management, Server/Network Security teams in resolving the issues with minimal escalations along with implementing best industry practices to secure IT infrastructure.
  • Led operations & hands-on experience of the following platforms: NGFW, Advanced Email Security and administration (G Suite), AWS, AV, EDR, DLP, ATP, MDM, Encryption, Web Proxy, Anti-Phishing, end-point protection & training along with next-generation firewall products, IDS, DMZ, IAM, IPsec, DNS, SMTP, SSL, Active Directory, etc.
  • Reviewed detailed risk assessments on new technologies and maintenance of IT security measurement and reporting systems to aid in monitoring effectiveness of IT Infrastructure.
  • Maintained quality service by establishing and enforcing organization standards. Implementing Best Practices and compliance as per ITIL, PCI_DSS, and ISO_27001.
  • Experience and thought leadership with infrastructure designs for highly secure / trusted computation environments
  • Driven compliance frameworks like ISO_27001 & PCI-DSS w.r.t IT
  • Ensuring successful service delivery SLA achievement & high level of customer satisfaction along with healthy collaboration when one team collaborates with the other one.
  • Worked with project teams to define and provide guidance on strategic IT security controls, directions and set guidelines to counter any incident.
IT InfrastructureSecurity teamsRisk assessmentsCompliance frameworksIT OperationsCybersecurity

Rivigo

Senior Manager - Information Technology

Jul 2018 – Aug 2019 Β· 1 yr 1 mo Β· Gurugram, Haryana, India

  • Partnered with CTO to lead the IT Security strategy and execution for the enterprise for ~5k employees and ~400 offices.
  • Formulate and establish IT Security policies and procedures to support the implementation of strategies set by the executives on a leadership level.
  • Establish a 3-year rolling security roadmap strategy to address trends, threats and opportunities along with providing guidance and set direction in regard to Security policy and processes
  • Review and sign off IT infrastructure and system design architecture with documentation of identified cyber security weaknesses and required mitigations
  • Design monitoring systems to ensure confidentiality and integrity of data and availability of all network services
  • Overseeing and determining timeframes for major IT/Security projects including system updates, backups/recovery, firewall and server upgrades, migrations, and outages with enforced security controls and implementation of vulnerability management processes and tools
  • Worked on network and security architectures covering Software Defined Networking (SDN), Network Access Control (NAC), Bring-your-own-Device (BYOD), and Cloud/Virtualization
  • Hands-on technical depth enables direct oversight, problem-solving leadership, and participation for complex infrastructure implementation, system upgrades, and troubleshooting.
  • Liaise between all parties including IT/Security partners/suppliers to procure all assets/services
  • Design and conduct cyber security risk assessments or tests to identify security exceptions and design practical compensating controls
IT Security strategySecurity policiesCybersecurity risk assessmentsCybersecurityRisk Management

Payu

Senior Manager - Information Technology

Apr 2012 – Jul 2018 Β· 6 yrs 3 mos Β· Gurugram, Haryana, India

  • Built & managed the entire IT Infrastructure/Security team of 22+ persons for Data Centre across PAN India from scratch.
  • Created IT security policies, procedures, Standard operating procedures and documentation.
  • Seamless implementation and maintenance of security applications like Anti-Virus Servers, Multi-Factor Authentication, Drive Encryption, Firewalls, Trend AV/APT, Naming conventions, Data Classification, backups, DLP & Phishing training campaigns for end users enforcing security controls along with guidelines and procedures.
  • Troubleshooting of hardware/software failures along with Windows Server backups, File Server Resource Manager, Disk Quota, Active Directory, GPO, FSMO Roles, DHCP, DNS, WDS, WSUS, IIS, vulnerability scanning via Nessus along with other end point security products incorporating workstations and communication infrastructure.
  • Architecture designing, testing, debugging & maintenance, future server/network upgrades, Active Directory, databases, Sites & Services, security log monitoring, disaster recovery planning, system logging, WSUS, WDS with centralized Management.
  • Observing, surveying network and provide early warning of abnormalities or issues along with recommendations to adjust performance of network to enhance security.
  • Coordination with IT Security vendors, Implementing Best security Practices and compliance as per ITIL, PCI_DSS, and ISO_27001.
IT InfrastructureSecurity applicationsCompliance frameworksIT OperationsCybersecurity

Raheja developers ltd.

Assistant IT Systems

Dec 2011 – Apr 2012 Β· 4 mos Β· Delhi, India

  • Assisted senior management team in providing day-to-day operational IT Security support for AD, VPN, server, storage, Anti-Virus Servers, network infrastructures & server architecture.
  • Assisted with storage and server data backup, data migration and disaster recovery planning operations.
  • Created IT Security policies and analyzed log monitoring for in house data center.
  • Assisted with software and operating system security upgrades and track systems licensing.
  • Assisted with configuring advanced security settings, access permissions for groups and individuals including firewalls, IDS/IPS and other IT security products.
  • Provided technical support to users by troubleshooting, analyzing & fixing problems related to hardware/software, network security or platform related issues.
  • Preparing documents, procedures and troubleshooting procedures related to systems/network security and hardware along with policies, procedures as per standard operating procedures.
  • Responsible for writing security reports, RCAs, tracking inventory, evaluating new technologies, negotiating contracts with vendors, and developing contingency plans in case of network failure including upgrades and enhancements in IT infrastructure.
Operational IT SecurityData backupNetwork securityIT OperationsCybersecurity

Master computers

System Engineer

Jan 2010 – Nov 2011 Β· 1 yr 10 mos Β· Gurugram, Haryana, India

  • Designed, managed and responsible for databases architecture & IT security service requests.
  • Handled daily IT support activities on desktop support, IT Security, data network, and server management.
  • Responsible for maintaining policies, processes for Information Security.
  • Developed and managed effective professional working relationships with partners, co-workers, clients after logging IT Security tickets and resolving all issues.
  • Responsible for creation of disaster recovery & security risk plan for data centers.
  • Configure computers and install security software for various applications and programs.
  • Networked with staff on desktop security problems and their resolution with no escalations.
  • Network devices monitoring & troubleshooting within the organization during issues.
  • Procurement of computer systems, IT accessories & security products in coordination with purchase and supplies department.
Database architectureIT security service requestsTechnical supportIT OperationsCybersecurity

Education

Maharshi Dayanand University

Master of Computer Applications (M.C.A.)

Jan 2011 – Jan 2013

SYMBIOSIS INTERNATIONAL UNIVERSITY

Cyber Law β€” Cybersecurity

Jan 2017 – Jan 2018

Maharshi Dayanand University

Bachelor of Computer Applications (B.C.A.)

Jan 2008 – Jan 2011

Stackforce found 100+ more professionals with Cybersecurity & Risk Management

Explore similar profiles based on matching skills and experience