Krishna Pandey

CEO

Bengaluru, Karnataka, India18 yrs 9 mos experience
AI EnabledAI ML Practitioner

Key Highlights

  • Nearly 20 years of global cybersecurity leadership experience.
  • Pioneered AI Security frameworks for major organizations.
  • Served as President of (ISC)2 Bangalore Chapter.
Stackforce AI infers this person is a Cybersecurity Executive with extensive experience in AI Security and Cloud Security.

Contact

Skills

Core Skills

Cyber Security Strategy & GovernanceCloud SecurityAi Security & GovernanceSecurity EngineeringApplication SecurityThreat DetectionLeadershipCommunity EngagementProduct SecurityRisk ManagementDevsecopsPlatform SecurityVulnerability ManagementSecurity OperationsEngineeringCyber Threat Intelligence

Other Skills

AI SecurityApache HadoopBusiness ContinuityCloud ApplicationsCoaching & MentoringCritical Infrastructure ProtectionCyber Threat Intelligence (CTI)CybersecurityDesign ReviewDisaster RecoveryExecutive VisibilityGeneral Data Protection Regulation (GDPR)Hadoop SecurityISO 27001IT Infrastructure Management

About

Visionary Cyber Executive with nearly 20 years of global leadership experience defining enterprise security strategy and governance for major organizations - Scaling the Trust. Direct experience managing multi-million dollar budgets, scaling India GCC operations, and securing multi-cloud ecosystems. Successfully pioneering AI Security frameworks and driving quantifiable risk reduction across the C-suite. With nearly two decades of experience at Xerox, Salesforce, Citrix, Cloudera (Hortonworks) and C-DAC R&D, I have a diverse background in scaling India-based GCC security operations, executing critical risk reduction measures at scale for Fortune 100 enterprises, securing government agencies, and building security programs from the ground up at startups. I believe in giving back to the community and served as President of the (ISC)2 Bangalore Chapter. I am also a frequent speaker and panelist at cyber security conferences across India, Europe, and the USA. Core Competencies: • Cyber Security Strategy & Governance • Cloud Security (Multi-Cloud) • Security Architecture • AI Security & Governance • Product Security & Secure SDLC • DevSecOps • Vulnerability Management & Offensive Security • Threat Detection & Incident Response • Identity & Access Management (IAM) • GRC (ISO 27001, SOC2, GDPR, FedRAMP) Certifications: CISSP, CCSP, CEH, CHFI, ISO 27001:2013 Lead Implementer, ITIL Service Operations

Experience

Xerox

Senior Director, Xerox Cybersecurity

May 2024Present · 1 yr 10 mos · Bengaluru, Karnataka, India · Remote

  • I lead the global strategy and operations for multiple security divisions, including Cloud Security & Vulnerability Management, Security Architecture, AI Security, Product Security, Offensive Security, Security Engineering and PSIRT/XSRC, overseeing the enterprise-wide risk posture reporting to the Global CISO.
  • My Team ensures the secure rollout of strategic AI security framework, leading AI architecture reviews for SaaS and proprietary apps, and overseeing AI-specific red-teaming. I direct four cross-functional security teams, and collaborate with IT, Network, and R&D to translate complex technical risks into actionable business decisions for executive leadership. My leadership has translated strategic roadmap objectives into tangible security enhancements, driving a significant uplift in our multi-cloud security posture and a marked increase in our incident readiness. By methodically rolling out preventive controls, we have systematically strengthened our defenses, achieving near-immediate remediation SLAs for critical cloud vulnerabilities, improving Mean Time to Resolution (MTTR), and other compliance scores.
Security EngineeringAI SecurityCloud SecurityThreat & Vulnerability ManagementBusiness ContinuityCyber Threat Intelligence (CTI)+7

Salesforce

Director - Security Engineering

Apr 2022May 2024 · 2 yrs 1 mo · Bangalore Urban, Karnataka, India

  • Leading and mentoring a high performance, agile, cross-functional and geographically distributed team [India & US] of Security Architects, Developers and Engineers in the domain of Application Security, Malware, Threat & Vulnerability Management.
  • Responsible for continued operational and engineering excellence of security services & infrastructure including robust on-call process, business and operational KPIs.
  • Lead a team for development, scaling and maintaining security products - home grown and commercial to suit large scale deployment for the entire Salesforce ecosystem.
  • Work with peers from CSIRT, Threat Detection & Response, Cloud Security and other stakeholders (Product, Program, CXOs, Customers, etc.) for critical risk reduction programs.
  • Collaborate in creating long-term roadmaps and annual execution plan for owned products/services. Quarterly release planning with stakeholders and ensure deliverables as per schedule.
  • Responsible for continuous uplift of Application Security and Malware detection enterprise program by improving signal-to-noise ratio, developer experience, addition of detection for new attack vectors and ongoing tech debt remediation.
  • Representing Salesforce at various C-level/Executive security conferences/events. Got featured in Salesforce Blog and Engineering Blog.
  • As part of Salesforce India security leadership, responsible for overseeing and execution of several initiatives for entire India Security Org - Scaling Security, Easy Collaboration, Growth, Equality & Diversity
CybersecuritySecurity EngineeringLeadershipThreat & Vulnerability ManagementResearch and Development (R&D)Application Security

Citrix

Senior Manager - Security Engineering

Oct 2020Apr 2022 · 1 yr 6 mos · Bengaluru, Karnataka, India

  • Heads the Security Engineering and Product Security Teams for Citrix Endpoint Management, Citrix Workspace App on Android, iOS, MacOS, Linux, Windows, Chrome platforms, Linux VDA, Wrike and Security tools automation teams working closely with peers and teams located primarily in India, China, UK and US - East and West coasts.
  • Part of the leadership team in Global Security Org headed by the CISO responsible for execution of key product security initiatives related to cloud, automation, privacy, identity, attack surface management, logging, left-shift initiatives combined with Developer training, etc.
Coaching & MentoringExecutive VisibilityResearch and Development (R&D)Security EngineeringProduct Security

(isc)² bangalore chapter

President & Chair

Apr 2019Aug 2022 · 3 yrs 4 mos · Bangalore

  • Taking key decisions and chair the Chapter [7 Board Members, 200+ Chapter Members] proceedings.
  • Successfully spearheaded and organized several meetups with help from other Board Members.
  • Collaboration with other national and international Chapters/Conferences/Groups/Companies
  • Attended (ISC)² Regional Chapter Leadership Meeting 2019, APAC and put across my views, suggestion, concerns in front of delegation of all APAC countries.
Coaching & MentoringNon-profit VolunteeringLeadershipCommunity Engagement

Cloudera

3 roles

Global Head - Product Security & Security Engineering

Promoted

Jan 2019Oct 2020 · 1 yr 9 mos

  • Spearheaded the Engineering Platform (Infra and Product) Security team at Cloudera - "The Enterprise Data Cloud Company". He was responsible for company-wide SDL and even actively engaged with Customer CISOs to resolve their concerns regarding Cloudera's product and SaaS platform. Platform security team helped our Sales org win many multi-million dollar deals by providing timely support with Customer concerns. He led many DevSecOps project to reduct TAT for Customer queries which resulted in less Engineering escalations and more developer productivity.
  • Speaker at Data Works Summit, Barcelona 2019 presenting Apache Knox - Hadoop Security Swiss Knife.
Coaching & MentoringExecutive VisibilityRisk AssessmentCyber Threat Intelligence (CTI)Security EngineeringProduct Security+1

Engineering Manager - Platform Security

Jan 2018Jan 2019 · 1 yr

  • Founding member of Platform Security team in Hortonworks India Development center and grew the function from scratch.
  • Speaker at Data Works Summit, 2018, San Jose [talk about "Securing your Hadoop Ecosystem and challenges"]
  • Contributor to Apache Knox, Apache Zeppelin and Apache Spark.
  • Driving static code analysis, penetration testing, architecture review, software composition analysis and change management activities.
  • Help in identifying and fixing security issues during product development via effective collaboration with multiple teams spread across Globe.
  • Analysing Design Documents for Security issues, Threat modeling and Attack Surface Reduction.
  • Delivering internal trainings on Secure SDLC, Secure Coding, OWASP Top 10 PoC and remedies.
  • Collaborating and working with Customers, Contractors, Consultants, 3rd Party Auditors and Vendors.
  • Nominated Horton Heroes for Hortonworks, Q2, 2017
  • Writing and executing system, security and high availability tests in Java/Python/Shell.
Coaching & MentoringEngineeringResearch and Development (R&D)Threat & Vulnerability ManagementCyber Threat Intelligence (CTI)Platform Security+1

Staff Software Engineer

Sep 2015Jan 2018 · 2 yrs 4 mos

Center for development of advanced computing (c-dac)

2 roles

Technical Officer

Oct 2011Sep 2015 · 3 yrs 11 mos · Mumbai Metropolitan Region

  • Managed Platform Security (System, Applications, Database, Infra & Network), Security Operations, Threat Intelligence and GRC for national and state e-governance projects on behalf of Ministry of Electronics & Information Technology (MeitY), Govt. of India with a team of 10+ Engineers, PgMs & Consultants. Team activities included Secure Design and Architecture review, Vulnerability & Patch Management, SAST, DAST and Penetration Testing, External Audit (ISO 27001).
  • Also managed a team for DevOps and SecOps. Change and Configuration Management. Planning BCP and Disaster Recovery drills. Managing nation-wide Solution/Service Deployment and System Integration. Providing L2 Linux Administration Support, Performing Hardening and Performance tuning of O/S, Web Applications. Cluster Configuration and Troubleshooting. Managing SAN, Tape Library, Load-balancers, Switches, Deployment of Services on Cloud. Evaluating Security Products.
  • Managing Vendors - Hardware, Software, Security Solutions, RFPs, Price Negotiation.
  • Providing Internal Training. Keeping an eye on relevant Security domains and new attack vectors.
Coaching & MentoringRisk AssessmentResearch and Development (R&D)Cyber Threat Intelligence (CTI)Business ContinuityRisk Management+1

Staff Scientist

Mar 2008Sep 2011 · 3 yrs 6 mos · Mumbai Metropolitan Region

  • Job responsibilities included Programming, Research, OSINT, continuous monitoring and detection, vulnerability management and incident response for 3 Datacenters hosting services like Web, App, Database, DNS, DHCP, Mail Server, LDAP, Firewalls, proxy server, firewall, Windows Active Directory, etc. Also implemented defense-in-depth by hardening Operating System, Application, Network and Database as per NSA recommendations and CIS Benchmarks.
Coaching & MentoringEngineeringResearch and Development (R&D)Cyber Threat Intelligence (CTI)Cyber Threat Intelligence

Ohm securities

System Engineer

Jul 2006Apr 2007 · 9 mos · On-site

  • Website development, System and Network administration. Hardening and patching Windows Infrastructure.

Education

SVKM's Narsee Monjee Institute of Management Studies (NMIMS)

Master's Degree — Information Technology

Centre for Development of Advanced Computing (C-DAC)

Post Graduate Diploma in Advanced Computing (ACTS

North Maharashtra University

Bachelor of Engineering — Information Technology

Stackforce found 100+ more professionals with Cyber Security Strategy & Governance & Cloud Security

Explore similar profiles based on matching skills and experience