YOGESH V. MALVANKAR

CEO

Mumbai, Maharashtra, India30 yrs 5 mos experience
Highly StableAI Enabled

Key Highlights

  • Led IT GRC division at YES BANK to enhance compliance.
  • Developed comprehensive cybersecurity strategies at Angel One.
  • Expert in managing regulatory compliance across financial sectors.
Stackforce AI infers this person is a Cybersecurity and Compliance Leader in the Fintech industry.

Contact

Skills

Core Skills

GovernanceRisk ManagementCybersecurityRegulatory ComplianceSecurity AssessmentSecurity Strategy Development

Other Skills

Compliance (GRC)IT Risk ManagementInformation SecurityRegularly ComplianceCloud ComputingSecurityLeadershipArtificial Intelligence (AI)Project ManagementDisaster RecoverySolution ArchitectureBusiness AnalysisRemote Infrastructure ManagementIT Asset ManagementService Management

About

At the helm of YES BANK's IT GRC division, my mission is to fortify our digital assets against evolving threats, consistently abiding by stringent regulatory standards. The core competencies developed during my leadership as Group CISO at Angel One, including strategic cybersecurity, risk management, and governance, have been instrumental in enhancing our IT resilience and compliance posture. My recent work involves steering our teams to meticulously manage IT risks, drive policy adherence, and cultivate a robust compliance culture. This dedication has enabled the organization to navigate the complexities of financial regulations and cybersecurity challenges effectively, reinforcing our commitment to operational excellence and stakeholder trust.

Experience

30 yrs 5 mos
Total Experience
2 yrs 7 mos
Average Tenure
1 yr 10 mos
Current Experience

Yes bank

President - Head - IT GRC & Digital Governance

Jul 2024Present · 1 yr 10 mos · Mumbai · On-site

  • Developed and enforced comprehensive IT Governance, Risk, and Compliance frameworks aligned with RBI, SEBI, NSE, BSE, and MEITY standards.
  • Led IT risk assessments to identify vulnerabilities and implemented effective mitigation strategies.
  • Oversaw regulatory audits, ensuring timely management of evidence and closure of observations.
  • Managed IT third-party/vendor governance and data protection initiatives to enhance organizational resilience.
GovernanceRisk ManagementCompliance (GRC)IT Risk ManagementInformation SecurityCybersecurity+1

Angel one

Group CISO

May 2021Jun 2024 · 3 yrs 1 mo · Mumbai, Maharashtra, India · Hybrid

  • Empowering Businesses to Stay One Step Ahead of Cyber Threats. #CyberSecurity #ProtectionMatters @datasecurity💻🔒
  • Managing Regulatory Compliance - SEBI, NSE, BSE, MCX, NCDEX, MSEI, CERT-IN
  • Strategic Leadership: Develop and implement a comprehensive information security strategy that aligns with the business objectives
  • Security Governance: Establish and maintain effective information security governance structures, policies, and procedures.
  • Risk Management: Identify and assess cybersecurity risks, and develop risk mitigation plans to protect the organization's assets and reputation.
  • Regulatory Compliance: Ensure compliance with relevant financial regulations (e.g., SEC, FINRA) and cybersecurity standards (e.g., ISO 27001, NIST Cybersecurity Framework).
  • Incident Response: Develop and lead an incident response plan, including coordinating efforts to detect, respond to, and recover from security incidents and breaches.
  • Security Awareness: Promote a culture of security awareness among employees, ensuring that they are well-informed about cybersecurity best practices and potential threats.
  • Vendor Security Management: Evaluate and manage third-party vendors and their security practices to protect against supply chain vulnerabilities.
  • Security Architecture: Oversee the design and implementation of security architecture, including network security, access controls, and data protection measures.
  • Security Technology Evaluation: Continuously assess and recommend security technologies, tools, and solutions to enhance the organization's security posture.
  • Budget Management: Manage the cybersecurity budget effectively, ensuring optimal resource allocation for security initiatives.
  • Reporting and Metrics: Provide regular reports and key performance indicators (KPIs) on the organization's cybersecurity status to senior management and the board of directors.
Cloud ComputingSecurityLeadershipArtificial Intelligence (AI)Information SecurityCybersecurity+1

Freelance

Information & Cyber Security Consultant

Nov 2019May 2021 · 1 yr 6 mos · Hybrid

  • Security Assessment: Conduct thorough security assessments and audits of clients' existing infrastructure, applications, and processes to identify vulnerabilities and weaknesses.
  • Security Strategy Development: Collaborate with clients to create tailored cybersecurity strategies and roadmaps that align with their business objectives and compliance requirements.
  • Security Implementation: Implement security measures such as firewalls, intrusion detection systems, encryption, and access control mechanisms to strengthen clients' cybersecurity posture.
  • Incident Response: Develop and maintain incident response plans, and assist clients in responding to and mitigating cybersecurity incidents and breaches.
  • Security Awareness Training: Deliver training and awareness programs to educate clients' employees about cybersecurity best practices.
  • Compliance and Regulatory Guidance: Ensure clients' compliance with relevant industry standards and regulations (e.g., GDPR, HIPAA, ISO 27001).
  • Threat Intelligence Analysis: Stay up-to-date with the latest cyber threats and trends, and provide clients with insights on emerging risks.
  • Client Communication: Regularly communicate with clients to provide updates on security initiatives, share insights on security performance, and offer recommendations for improvements.
  • Documentation: Maintain detailed documentation of security assessments, strategies, and implementations for clients and internal purposes.
Project ManagementCloud ComputingSecurityLeadershipSecurity AssessmentSecurity Strategy Development

Kalpataru group

Group Chief Technology Officer

Jun 2018Oct 2019 · 1 yr 4 mos · Mumbai Area, India

Sterling talent solutions

Vice President - IT & CISO

Jan 2016May 2018 · 2 yrs 4 mos · Mumbai Area, India

  • About the company - SterlingBackcheck delivers confident hiring for a safer, more productive world. An NABPS accredited, global background screening partner, we employ over 3,000 people in 5 countries and help over 20,000 organizations hire and retain the right people. SterlingBackcheck is trusted by more than 25% of the Fortune 100 and 20% of the FTSE 100 to deliver accurate, efficient and compliant background and drug screening services. Our teams deliver extensive expertise in screening best practices, compliance and the client and applicant experience. Connected by the world’s most robust background check technology platform, SterlingBackcheck continuously reinvests in its business, customers and communities to ensure we remain an indispensable, global leader.
  • Job Description -
  • IT Service Desk Management
  • Network Operations Centre (NOC) Management
  • Business Continuity Management (BCP) Management
  • CRISIS Management
  • Information Security and Compliance Management
  • IT Infrastructure Service Management
  • IT Compliance Management (ISO 9001, 20000, 25999, 27001)
  • Data Center Operations Management
  • Security Operations Center (SOC) Management
  • Asset Management & Software Compliance Management

Aegis global

Vice President - IT & Security

Jun 2012Jan 2016 · 3 yrs 7 mos · Mumbai Area, India

  • High level Deliverables
  • Data Center Operations
  • Information Security and Compliance Management
  • IT Infrastructure Service Management
  • P&L Responsibility
  • IT Compliance Management
  • Process Excellence
  • Pre-Sales Management
  • Network Operations Center
  • Asset Management

Cms info systems pvt. ltd.

Head - Network Operations Center & Chief Information Security Officer (CISO)

Dec 2009Jun 2012 · 2 yrs 6 mos · Mumbai Area, India

  • Highlevel Deliverables
  • P & L Responsibility of Network Operations Center business vertical
  • Design & Implementation of Data Center Services
  • Preparing NOC (Network Operations Center) Sales Offering
  • Technical Resourcing for Service Delivery Projects
  • Develop and implement ITIL based practices processes and procedures for all aspects of a 24/7/365 NOC forNetwork Infrastructure products
  • Setting of Center Of Excellence Team for Quality Technical Delivery Services
  • Leading the Operations & Maintenance team
  • Develop coverage plans to ensure staffing levels are adequate to support a 24/7/365 operation
  • Institute a center of technical expertise that provides quality support and resolution of customer reported events in a timely and effective manner
  • Adhere to all developed/contracted Service Level Agreements (SLA) in association with specific services/customers
  • Drive all necessary escalations, as required, through resolution
  • Prepare and deliver all reporting metrics in association with the 24/7/365 operations center
  • Incorporate all necessary product training and staff development to support changing and or new service offering
  • Ensure all operating policies and procedures are developed, maintained and adhered to by all operations staff, including customer sensitive data and security policies
  • Develop internal working SLAs to ensure Support Center Systems availability, to include redundant operations and disaster recovery procedures
  • Implement best-practice Policies and Procedures, Planning and Design techniques/tools in line with architectures and roadmaps
  • Identify and implement new methods of reducing CAPEX and OPEX costs (e.g. new technologies, network modifications etc) along with network engineering teams.
  • Build team by guiding and developing subordinates.

Atos

Head - Knowledge Management

Sep 2008Dec 2009 · 1 yr 3 mos · Mumbai Area, India

  • Center of Excellence (COE)
  • Competence Development
  • Identify Development & Training Needs along with SDM’s
  • Standard class room trainings
  • Industry Specific
  • Delta Trainings
  • Domain Trainings
  • Publish & Execute Training Plans
  • Plan Certifications
  • Knowledge Management
  • Setting up & implementing Knowledge Management (KM) Framework
  • Development & Implementation of KM Processes
  • Setup a Knowledge Management Repository (Web Portal) for Atos Origin India
  • Setting up web based Document Management portal for Atos Origin India
  • Defining RACI Matrix and defining the role of KM in Transition and Service Delivery
  • Technology Work Instruction Documentation from Knowledge Associates
  • Lean Management
  • Supporting LEAN Management implementation in AOI and reporting to top management in Paris
  • Strategic planning to align with Global objective of the company to ensure company growth and profitability
  • Process Operations
  • Implementation of CSDM Processes for all the projects NL & BE countries
  • Process Co-Ordination for all the projects NL & BE countries

Zapak digital entertainment limited

Head - IT Projects & Operations

Apr 2007Sep 2008 · 1 yr 5 mos · Mumbai Area, India

  • Managing complete NOC (24 x 7 x 365) & Server Infrastructure
  • Managing MPLS & ELL Network across country
  • Acting as L3/L4 level Technical Support for Infrastructure Management Team.
  • Designing & Implementing Security Policies for securing Network & Server environment
  • People Management
  • Implementation of Red Hat Enterprise Linux environment for implementing various server roles and applications
  • Migration of all the Applications from Windows 2000 to Windows 2003
  • Implementation of Windows 2003 Domain Infrastructure.
  • Implementation of Centralized Backup System using Veritas for backing up Oracle, MySQL & Systems Data
  • Vendor Management
  • Managing SLA and performing Service Quality Audits with all the vendors
  • IT Procurement of Hardware / Network components
  • Setting up NOC with ITIL Compliant processes
  • Handling Order Escalation.
  • Process Documentation, Implementation & Periodic review
  • Periodic visits and IT Service Review all the Gaming Centers for IT Audit

Wns global services

Manager – IT Infrastructure

Dec 2003Aug 2006 · 2 yrs 8 mos · Mumbai Area, India

  • Providing Severity level 1/2 level support to Windows 2000/2003/Enterprise Linux/Sun Solaris/ IBM AIX
  • Managing Servers in Clustered Environment
  • Setting up & Managing Servers in Following Roles
  • Implementation of Centralized Server Monitoring System
  • Team Management
  • Providing Support to Oracle Database / SQL Server / Network / Firewall
  • Providing Technical Training to Team
  • Managing Maximum Server Uptime
  • Vendor Co-Ordination
  • Patch Management
  • Preparing / Updating Server RACK Elevation Diagrams
  • Setting up Centralised Backup Network using Veritas NetBackup & LTO25
  • Implementation of NAS (SUN PowerStorage 5210)

Clover infotech

IT - Project Manager

Mar 2001Dec 2003 · 2 yrs 9 mos · Mumbai Area, India

  • Plan, Manage and implement projects
  • Server Sizing
  • Implementing IBM Web sphere and IBM MQSeries
  • Managing Projects based Red hat Linux, HP-Unix 11i,IBM AIX 5L
  • Supporting the onsite and offsite teams for administration of Redhat Enterprise Linux, HP-Unix 11i, IBM AIX 5L
  • Setting up High Availability Clusters in Linux and AIX.
  • Kernel tuning and Upgradation Redhat Linux Advance server 2.1 / 3.0
  • Implementing Products like Oracle 9i Database, Oracle 11i Apps, IBM Web sphere and MQSeries
  • Setting up server roles
  • Planning and implementing Backup strategies
  • Setting up host based security policies

Accel frontline ltd

Project Leader

Jan 1995Mar 2001 · 6 yrs 2 mos · Mumbai Area, India

  • Data Center Implementation
  • Vendor Co-Ordination
  • Implementing enterprise Mail Server, Qmail (linux/AIX)
  • Web Server - (Apache (Linux and AIX) / Oracle 9i AS
  • Firewall - (IPTables / CheckPoint)
  • IDS (Intruder Detection System), SNORT (Linux), eTrust (CA)
  • Providing Technical Training on various OS & Server technologies
  • Network Monitoring System, NAGIOS based on Linux/AIX
  • Planning and Implementing Backup Solutions using VERITAS
  • Planning and Implementing Disaster Recovery Solutions
  • Managing & configuring NetApps Filers for database storage
  • Imparting Technical Training to onsite engg.
  • Supporting Oracle 9i Database on Linux Advance Server and AIX
  • Supporting Oracle 9i AS on Linux Advance Server and IBM AIX
  • Performance monitoring and tuning of all Unix based servers
  • Find and fix the latest vulnerability issues on O/S level.
  • Implementing O/S level Security on Linux / AIX / Win 2000 Servers

Education

Yonsei University

Internet of Things & Augmented Reality Emerging Technologies — Business

Madurai Kamaraj University

Master of Business Administration (M.B.A.) — Information Technology

Madurai Kamaraj University

Post Graduate Diploma In Computer Applications (PGDCA)

Madurai Kamaraj University

Bachelor’s Degree — B.Sc. Mathematics

Gokhale High School

High School

PREPARIS, INC

Advanced Crisis Team Certification — Crisis/Emergency/Disaster Management

Jan 2017Present

PREPARIS, INC

Crisis Team Certification Program — Crisis/Emergency/Disaster Management

Jan 2017Present

Stackforce found 100+ more professionals with Governance & Risk Management

Explore similar profiles based on matching skills and experience