Dharmesh Mehta

CEO

Hyderabad, Telangana, India21 yrs 2 mos experience
Highly Stable

Key Highlights

  • 21+ years in Information Security leadership.
  • Expert in building high-performing security teams.
  • Proven track record in security compliance and risk management.
Stackforce AI infers this person is a seasoned leader in cybersecurity and information security across SaaS and healthcare sectors.

Contact

Skills

Core Skills

Information SecuritySecurity EngineeringGovernanceComplianceDevsecopsRisk ManagementSecurity Architecture

Other Skills

Agile MethodologiesApplication SecurityCISSPCloud SecurityCommunicationCompliance (GRC)Computer SecurityCross-functional Team LeadershipCybersecurityEnterprise ArchitectureGlobal Regulatory ComplianceGoal SeekISO 27001IT StrategyInformation Security Engineering

About

21+ years of diverse and progressive experience in the field of Information Security. Passionate about solving security problems at scale. My core competencies include building & leading high performing Security Teams/functions in areas of Security Engineering, DevSecOps, Vulnerability Management, Cyber Defense Operations, Cloud Security, Offensive Security, Security Operations, and governance risk and compliance. I have successfully built and operated scalable and robust security solutions for engineering and application platforms, products, and services, reducing risk for the organization and customers, and influencing peers, cross-functional partners, and IT/engineering leadership. I am also a passionate, collaborative, and results-oriented leader who enjoys working with geographically distributed and culturally diverse teams.

Experience

Google

Security Engineering Leader

Aug 2024Present · 1 yr 7 mos · Hyderabad, Telangana, India · On-site

Goto group

Head of Information Security

Oct 2021Aug 2024 · 2 yrs 10 mos

  • In my current role as Head of Information Security, I lead a global team of information security managers and senior security engineers.
  • Report to the Group CISO and lead and grow a team and continuously evolve the information security function to align and scale with the business.
  • Lead security engineering direction as well as Influence peers, cross-functional partners, and IT/engineering leadership. Serve as a trusted leader, advisor and lead a team to ensure that security requirements are met and aligned with business strategy.
  • Conduct regular Management reviews and update the management on information security aspects.
  • Accountable for Security of Gojek's engineering and application platforms, products and services.
  • Own & manage SDL, App & Infra Security, Security Engineering, Governance Risk & Compliance & Data Security & Privacy, DevSecOps, Cloud Security, Vulnerability Management, Patch Management, Bug Bounty program amongst the top portfolios end to end.
  • Responsible for security assurance & assessments of the products releases.
  • Lead and support cyber security capabilities including product security, security architecture, incident response, vulnerability management, technical and non-technical risk assessments, policy, procedures and compliance lifecycle.
  • Responsible to ensure successful compliance of regulatory audits as well as re-certification and surveillance audits including ISO 27001 & PCI.
  • Managing security in Gojek's engineering development environments, cloud infrastructure, source code repositories, and ensuring security is optimized in the SDLC and CI/CD arenas.
  • Own, develop and implement strategies to continuously shift left to ensure a security-at-birth model.
  • Partner with Engineering, Product, Core Fraud, and Risk, Privacy, and Compliance teams to ensure that security is effectively interlocked and aligned with key business stakeholders.
CybersecurityInformation SecurityISO 27001SecuritySecurity EngineeringDevSecOps+8

Microsoft

4 roles

Sr. Security Engineering Manager

Promoted

May 2016Oct 2021 · 5 yrs 5 mos · Hyderabad, Telangana

  • I am a security assurance and engineering leader with expertise in security engineering of products and services with focus on DevSecOps, Secure Code Analysis, Dynamic Analysis and Infrastructure Security. I have also led large and complex security initiatives like supplier/vendor security assurance and remediating critical security vulnerabilities in applications and infrastructure. In my current role,
  • I lead and manage a team of security program managers and software engineers to run and deliver security at scale at Microsoft.
  • Establish vision, strategy and roadmap for security assurance & engineering team.
  • Deliver key performance indicator reports on engineering and security metrics.
  • I am a passionate, collaborative, results-oriented leader with a proven track record of developing and operating effective and appropriate engineering solutions to deliver scale security solutions in DevOps, embed security in engineering lifecycle and reducing risk for Microsoft - while embracing automation and self-service. I love and enjoy the current experience in teaming with geographically distributed and culturally diverse work groups.
SecurityDevSecOpsLeadershipSecurity RiskCommunicationSecurity Testing+2

Sr Program Manager

Sep 2015Apr 2016 · 7 mos · Hyderabad, Telangana

  • Risk Management Lead for CSEO (formerly Microsoft IT) Hyderabad engineering groups.
SecurityCommunicationSecurity TestingRisk Management

Program Manager II

Promoted

Sep 2013Aug 2015 · 1 yr 11 mos · Hyderabad, Telangana

SecurityCommunicationSecurity Testing

Security Engineer

Feb 2012Aug 2013 · 1 yr 6 mos · Hyderabad, Telangana

SecurityCommunicationSecurity Testing

Mastek

4 roles

Technical Specialist - Application Security

Promoted

Aug 2009Feb 2012 · 2 yrs 6 mos · Mumbai, Maharashtra

  • Security Architect & Risk Management Specialist. Led team of software engineers to develop a patented security product in the space of Electronic Health Records (EHR) and pseudonymization.
SecurityCommunicationSecurity Testing

Technical Analyst - Security

Aug 2007Jul 2009 · 1 yr 11 mos · Mumbai, Maharashtra

  • Security Analyst with diverse experience assessing applications for multiple customers in US, UK, Europe and Asia.
RCACommunicationSecurity Testing

Sr Security Engineer

Aug 2005Jul 2007 · 1 yr 11 mos · Mumbai, Maharashtra

RCASecurity Testing

Programmer Trainee - Security Software Engineer

Aug 2004Jul 2005 · 11 mos · Mumbai, Maharashtra

  • Security engineer with a focus on learning J2EE and finding security vulnerabilities and remediation for projects at Mastek. Threat Modeling SME. Part of Technology Cell reporting to the CTO.
Security Testing

Owasp foundation

OWASP Mumbai Chapter Lead

Feb 2005Feb 2012 · 7 yrs · Mumbai, Maharashtra

  • OWASP Mumbai Chapter Leader and organizer. Led and presented on multiple security topics and built a great security community/network.
SecurityCommunicationSecurity Testing

Reliance industries limited

Software Intern

Jan 2003Jan 2004 · 1 yr · Jamnagar, Gujarat

  • Software Intern at Reliance Industries Limited. Worked as a .NET Developer developing Reliance's Learning Center Portal.
SecurityCommunicationSecurity Testing

Education

IIT Bombay - Shailesh J. Mehta School of Management

Executive General Business Management for Technical Professionals

Jan 2010Jan 2010

Gujarat University

B.E — Computer Science

Jan 2000Jan 2004

Stackforce found 100+ more professionals with Information Security & Security Engineering

Explore similar profiles based on matching skills and experience