Krishnendu De

CEO

India25 yrs 8 mos experience
Highly StableAI Enabled

Key Highlights

  • Over 24 years of cybersecurity engineering experience
  • Led global cybersecurity transformation initiatives
  • Developed comprehensive cybersecurity solutions for critical infrastructure
Stackforce AI infers this person is a cybersecurity expert specializing in critical infrastructure protection and risk management.

Contact

Skills

Core Skills

Operational Technology Cyber SecuritySecurity Architecture And EngineeringCybersecurity StrategyManagement ConsultingIdentity & Access Management (iam)Application Security Architecture

Other Skills

OT Cyber SecuritySecurity EngineeringOT Cyber Security in DCS, PLC and SCADA SystemBudget OversightApplication SecurityZero Trust Security ArchitectureDetection engineeringResponsible AI FrameworkEndpoint Detection and ResponseDevSecOpsIAM platform modernizationPAMCSPMDFIRDSPM

About

With over 24 years of experience, I specialize in cybersecurity engineering, operations and defense, focusing on safeguarding mission-critical infrastructure in power generation and distribution, banking, stock exchanges and manufacturing. As Head of InfoSec and CISO at RPSG Power Business, I oversee IT and OT cybersecurity for systems like DCS, SCADA, and PLC, ensuring the resilience of electrical utilities. I have led many comprehensive cybersecurity transformation initiative worldwide and conduct red team simulations to address vulnerabilities across critical infrastructure. I continuously evolve my expertise and focus on newer developments like cyber security product development, Responsible AI Framework and advanced offensive security tactics. I aim to create robust, production-grade cybersecurity solutions that enhance resilience and risk management. I'm committed to empowering teams, driving innovation, and aligning security strategies with organizational objectives. Speraheading a self driven cyber security product development initiative. I am building a solution that will have the combined features of Vulnerability Management, Attack Surface Management, Firewall Security Assessment, Network Security Assessment, Security Configuration Assessment, Detection Engineering, OS security hardening, OT Vulnerability Assessment, CNAPP for Azure GCP and AWS, AI-SPM, SAP and Oracle Security Posture Assessment, SaaS Security Posture Management, Assessment of IAM and PAM solution and finally an Enterprise Cyber Risk Quantification and Management dashboard which will be able to quantify all risks in cash flow losses and EBITA terms within an organization. We will also be able to plan Atomic Red Teaming based on the findings and bring adequate cyber risk context into board room discussions to prioritise risk mitigation. Hence this will be a complete CXO dashboard for any organization. This will be kind of an Enterprise Security Planning (ESP) tool which will reduce you cyber investment by at least 90% yet give you sky high breach protection. https://github.com/Krishcalin

Experience

25 yrs 8 mos
Total Experience
2 yrs 11 mos
Average Tenure
2 yrs 4 mos
Current Experience

Rpsg power business

Head InfoSec & CISO (CESC Limited)

Dec 2023Present · 2 yrs 4 mos · India · On-site

  • Ownership of end-to-end IT and OT cyber security of electrical power generation and distribution. This includes safeguarding real-time systems such as Distributed Control System (DCS), SCADA, standalone PLC plants, Monitoring systems like GE Vernova OPC UA DA, AVEVA PI and critical infrastructure.
  • Conducting red team simulations to fortify defenses across DCS, Switchyard Automation, SCADA, and Distribution Automation, covering various attack scenarios within Sub-Stations, Distribution-Stations, FRTU, Metering headend systems, Load Dispatcher Center Interfaces, Disturbance recorder spanning HT, LT, and Smart metering.
  • Leading a comprehensive IT and OT cyber security transformation initiative encompassing Endpoint Detection and Response (EDR), DevSecOps, SASE implementation, IAM platform modernization, PAM, CSPM, DFIR, DSPM, and Core OT security solutions to enhance protection of OT communication protocols.
  • Building a responsible AI framework for agentic AI security, interaction with LLMs and managing data privacy and ethical response.
  • Navigating a heavily regulated landscape under the purview of Ministry of Power (MoP), Central Electricity Authority (CEA), NCIIPC, and CERT-In, adhering to rigorous cyber security standards and guidelines.
Operational Technology Cyber SecurityOT Cyber SecuritySecurity EngineeringOT Cyber Security in DCS, PLC and SCADA SystemBudget OversightApplication Security+5

Boston consulting group (bcg)

2 roles

Global Senior Director - Enterprise Security Services

Jul 2022Dec 2023 · 1 yr 5 mos

  • Consulting, Engineering, and Operations of Cloud Native Application Protection Platform (CNAPP), Digital Forensics and Incident Response (DFIR) Platform, Threat Intelligence, Data Security Posture Management (DSPM), Insider Threat Management and DevSecOps Tools that enhance security posture and lead to improved business and cyber risk management outcome for clients and stakeholders.
  • Assisting BCG in developing an exceptional Security Incident Management Program and DFIR Strategy.
  • Realized a 90% decrease in the cloud and digital attack surface through innovative remediation strategies.
  • In partnership with BCG AI specialists and clients, I have created a framework aimed at enhancing the management of risks linked to the application of artificial intelligence (AI) in business, government, and society. This framework seeks to improve the integration of trustworthiness factors into the design, development, utilization, and assessment of AI products, services, and systems.
  • Functioning within a framework that requires stringent adherence to data privacy, fiduciary responsibilities, and financial sector regulations.
Digital ForensicsRed TeamingIncident ResponseSecurity EngineeringBudget OversightManagement Consulting+9

Global Director - Enterprise Security Services

Jan 2020Jul 2022 · 2 yrs 6 mos

  • 1) Cloud security engineering in an agile drive product development landscape
  • 2) Embedding cyber security into business applications to significantly reduce the attack surface sometimes by 95%.
  • 3) Full Stack Software Vulnerability Management
  • 4) Implementation of full-scale Identity intelligence including IAM, PAM, Secrets Management and Cloud access tokens.
  • 5) Penetration Testing of digital products and Red Team Exercise of mission critical business application hosting platform
  • 6) Digital Forensics and Incident Response (DFIR)
  • 7) State of cyber security reporting to the leadership & board
Identity & Access Management (IAM)Red TeamingSecurity EngineeringBudget OversightApplication SecurityManagement Consulting+6

Kpmg

2 roles

Associate Director

Jan 2018Dec 2019 · 1 yr 11 mos

  • Secondment to International HQ. Working for Information Protection Group (IPG) within the Global CISO and DPO organization shaping the cloud security architecture for KPMG worldwide.
  • Developed the Global Security Operation Center (GSOC) for 150+ members firms across APAC, EMA and Americas region using RSA security analytics SIEM, triaging hundreds of incidents every day.
  • Established the Solutions Review Services (SRS) team primarily responsible for application security and penetration testing of global banking and financial services clients.
  • Leading application security architecture and SDLC process governance for a very large cloud transformation program involving Microsoft Azure.
Budget OversightApplication SecurityManagement ConsultingZero Trust Security ArchitectureSecurity Architecture and EngineeringOffensive Security Testing (Red and Blue Teaming)+5

Associate Director

Jun 2014Jan 2018 · 3 yrs 7 mos

  • I was the KPMG India National IT Security Officer (NITSO) building the internal cyber security program and working closely with the India Leadership Team (ILT) and Global CISO.
  • Worked on multiple assignments with many public sector banks relating to RBI regulations on cyber security. These engagements where from various domains like;
  • 1) Governance, Risk and Compliance
  • 2) Data Security and Privacy
  • 3) Data Leakage Prevention
  • 4) ISO27001 Certification
  • 5) Penetration Testing
  • 6) Network and System Security
  • 7) Security in Software Development
  • 8) Cyber Security Strategy Development
Identity & Access Management (IAM)Budget OversightManagement ConsultingSecurity Architecture and EngineeringDetection engineeringApplication Security Architecture+1

Pwc

Principal Consultant

Aug 2009Jun 2014 · 4 yrs 10 mos · New Delhi, Delhi, India · On-site

  • Cyber security consulting for clients in the Banking, Financial Services and Insurance sector on a variety of subject matter topics. I was part of the inception team at UIDAI Adhaar project in India.
  • Served a number of clients in assignments related to;
  • 1) Development of Security Operations Center (SOC)
  • 2) Development of Application Security Policies, Technology Framework, Architecture, Coding standards and Operating Procedures
  • 3) Penetration Testing of Custom Developed Applications
  • 4) Embedding cyber security controls in the Software Development Lifecycle (SDLC)
  • 5) Transformation of the Identity and Access Management (IAM) landscape.
  • 6) Securing the Data Center and branch office network using superior NGFW, WAF and Load Balancers.
Budget OversightManagement ConsultingSecurity Architecture and EngineeringOffensive Security Testing (Red and Blue Teaming)Enterprise Risk ManagementDetection engineering+2

Ibm

Senior Consultant

Aug 2008Aug 2009 · 1 yr · Kolkata, West Bengal, India · On-site

  • Identity and Access Management (IAM) modernization for the largest container logistics company A.P.Moller Maersk for its custom developed applications.
Identity & Access Management (IAM)Security Architecture and EngineeringApplication Security Architecture

Cognizant

Senior Engineer

Jul 2006Aug 2008 · 2 yrs 1 mo · Kolkata, West Bengal, India

  • Application security testing and validation for software product and services developed for JP Morgan Chase Private Banking, International Private Banking, Investment Management and Treasury Services.
Security Architecture and EngineeringApplication Security Architecture

Itc limited

Senior Engineer

Nov 2004Jul 2006 · 1 yr 8 mos · Kolkata, West Bengal, India · On-site

  • I was part of the ITC Infotech IT Shared Services (ITSS) team running the endpoint security services which include antivirus management and patch management for all desktops, laptops and servers across ITC Limited business units.

Tata consultancy services

Assistant Engineer

Jul 2003Nov 2004 · 1 yr 4 mos · Kolkata, West Bengal, India · On-site

  • Network and systems security engineering for client Offshore Development Center (ODC)

The calcutta stock exchange limited

Junior Executive IT

Jul 2000Jul 2003 · 3 yrs · Kolkata, West Bengal, India

  • Development, Operation and Maintenance of the Calcutta Stock Exchange Online Trading and reporting Platform CSTAR, market surveillance, settlement system and its integration with clearing house and banks that was generating a daily turnover of Rs 4000 crore during early 2001.
  • Key technology used were Tandem Himalaya S-Series system running programs in Tandem C, Nonstop SQL and TAL environment. Also used Java, PL/SQL and HP-UX systems.
  • I was part of the transformation team which migrated the manual trading mode of CSE to the online trading platform. Experienced the beginning of the financial market transformation journey of India from a T+15 settlement system to a T+5 system.

Education

Indian Institute of Technology, Kharagpur

PGDIT — Information Technology

Jan 1999Jan 2000

Calcutta University, Kolkata

Bachelor of Technology - BTech — Engineering

Jan 1995Jan 1999

University of Kalyani

BSc — Physics

Jan 1993Jan 1995

Kendriya Vidyalaya

High School — Science and Mathematics

May 1983Jun 1993

Stackforce found 28 more professionals with Operational Technology Cyber Security & Security Architecture And Engineering

Explore similar profiles based on matching skills and experience