Ajay Soni, CISSP, CISM, CISA, CRISC

Operations Associate

Hyderabad, Telangana, India8 yrs 6 mos experience
Highly Stable

Key Highlights

  • 6+ years in Cybersecurity with strong compliance expertise.
  • Proven track record in mentoring and building high-performing teams.
  • Certified in multiple key security frameworks and tools.
Stackforce AI infers this person is a Cybersecurity expert with a focus on compliance and risk management in regulated industries.

Contact

Skills

Core Skills

GrcCompliance ManagementSecurity EngineeringCloud SecurityEndpoint SecurityLeadership

Other Skills

IT Risk ManagementSecurity AuditsCISAGeneral Data Protection Regulation (GDPR)Security OperationsQualysCrowdstrikeDuoNetskopeOktaStrategic PlanningAir ForceSOC2Security ControlsAWS Identity and Access Management (AWS IAM)

About

I am a Cybersecurity professional with 6+ years of experience reducing enterprise risk and enhancing infrastructure resilience across regulated industries. Certified in CISSP, CISM, CISA, CRISC, Security+, Okta, and Qualys VM, with expertise in IAM, SIEM, and vulnerability management. Skilled in aligning security strategy with compliance frameworks including HITRUST, SOC 2, and HIPAA, and in leading audit readiness, automation, and Cloud posture optimization. Over the past 3 years, I’ve mentored junior analysts and built agile, high-performing security teams. My foundation at the National Defence Academy instilled a mission-first mindset, strategic focus, and leadership under pressure—qualities I carry into every engagement. Outside the cyber realm, I recharge through photography, travel, football, and gardening.

Experience

Backbase

IT GRC Compliance Manager

Oct 2025Present · 5 mos · Hyderabad, Telangana, India

IT Risk ManagementSecurity AuditsGRCCompliance Management

Health catalyst

2 roles

Associate Security Engineering Manager

Oct 2024Oct 2025 · 1 yr

  • Led cross-functional collaborations to achieve and maintain critical compliance certifications (HITRUST, SOC2 etc.), ensuring adherence to regulatory standards.
  • Developed and documented comprehensive security compliance policies and procedures, streamlining audit processes.
  • Managed penetration testing initiatives, identifying and remediating vulnerabilities to strengthen application and infrastructure security.
  • Mentored and upskilled junior analysts, fostering a high-performing and efficient security team.
IT Risk ManagementCISACompliance ManagementSecurity Engineering

Sr. Information Security Analyst

Jul 2022Oct 2024 · 2 yrs 3 mos

  • Orchestrated the migration and consolidation of security solutions (Qualys, Taegis, Crowdstrike), optimizing security operations and reducing redundancies.
  • Implemented and managed Cloud Security Posture Management (CSPM) to fortify AWS infrastructure security while optimizing costs.
  • Integrated diverse data sources into Sumologic for comprehensive log aggregation, analytics, and proactive threat detection.
  • Evaluated and procured new security tools, demonstrating strong decision-making and strategic technology adoption.
  • Provided coaching and mentorship to team members, enhancing their technical skills and fostering professional growth.
General Data Protection Regulation (GDPR)Security OperationsCloud SecuritySecurity Engineering

Stratogent

3 roles

System Analyst

Promoted

Dec 2021Jun 2022 · 6 mos

  • Successfully conducted Proof of Concepts (POCs) for Qualys and Netskope Secure Web Gateway, demonstrating technical proficiency and problem-solving skills.
  • Implemented Qualys, Netskope, and Okta solutions within client environments, significantly enhancing their security infrastructure.
  • Strategized and executed vulnerability assessments, diligently tracking remediation efforts to mitigate security risks.
  • Gained valuable experience in implementing IAM solutions
DuoGeneral Data Protection Regulation (GDPR)Security Engineering

System Engineer

Aug 2020Dec 2021 · 1 yr 4 mos

  • Part of SecOps Team responsible for protecting the client's network through endpoint security management, monitoring intrusions and anomalies detected by various security tools using Splunk SIEM solution.
  • Involved in the vulnerability management, analyzing malware incidents, handling phishing attacks and threat analysis.
  • Experienced in ServiceNow ticketing tool.
DuoSecurity OperationsEndpoint Security

System Trainee

Aug 2019Aug 2020 · 1 yr

DuoSecurity Operations

Jazz pharmaceuticals

Information Security Engineer (Contract position through Stratogent Technology Services)

Aug 2019Jun 2022 · 2 yrs 10 mos

DuoSecurity Operations

National defence academy(nda)

Officer Cadet

Jan 2013Jan 2015 · 2 yrs · Pune Area, India

  • Served as an Under Training officer at Indian Air Force and gained various leadership, time management and team oriented skills followed by a medical withdrawal due to injury.
  • During this tenure, I was trained on various military administration traits like planning & organizing, leadership, resource management, group planning and mental stamina .
Strategic PlanningAir ForceLeadership

Education

Sir M Visvesvaraya Institute of Technology, BANGALORE

Bachelor of Engineering - BE — Mechanical Engineering

Jan 2015Jan 2015

National Defence Academy

Military and Strategic Leadership

Jan 2013Jan 2015

St. Paul's Senior Secondary School

Junior High/Intermediate/Middle School Education and Teaching

Jan 2000Jan 2013

Stackforce found 100+ more professionals with Grc & Compliance Management

Explore similar profiles based on matching skills and experience