Pankaj Moolrajani

CTO

San Francisco, California, United States14 yrs 2 mos experience
Most Likely To SwitchHighly Stable

Key Highlights

  • Expert in application and cloud security.
  • Led enterprise-scale security transformations.
  • Strong background in vulnerability management and incident response.
Stackforce AI infers this person is a Cybersecurity expert with extensive experience in application and cloud security.

Contact

Skills

Core Skills

Information SecurityCloud Security

Other Skills

Identity & Access Management (IAM)Amazon Web Services (AWS)Software DevelopmentKubernetesVulnerability ManagementMachine LearningIncident ResponseProduct SecurityThreat ModelingThreat & Vulnerability ManagementCyber Threat Intelligence (CTI)Threat DetectionTerraformPython (Programming Language)Node.js

About

I am deeply invested and passionate about application security, infrastructure security and cloud security with extensive hands on experience. My colleagues acknowledge me for successfully leading transformational initiatives at enterprise scale.

Experience

Motive

Head of Security and Compliance

Apr 2021Present · 5 yrs · San Francisco Bay Area

  • Established the KT Cyber Security Strategy
  • Building the Security Org from ground up
  • Building foundation Security Platforms to empower developers to reduce the overall Cyber Security Risk of our products
  • Scaling Security Operations by designing lean and efficient Security Services such as Vulnerability Management, Identity and Access Management, Cloud Security Posture Management
  • Established Security Assurance function by introducing services such as TPRE, TPRM, Audit Support, Sales Support, M&A, Pentesting, Risk Controls Monitoring and Validation etc.
Information SecurityIdentity & Access Management (IAM)Amazon Web Services (AWS)Software DevelopmentCloud Security

Delta dental ins.

Principal Security Architect

Jul 2018Apr 2021 · 2 yrs 9 mos · San Francisco Bay Area

  • Built the security engineering team from ground up which is responsible for designing, building, implementing and operationalizing security platforms for the enterprise
  • Led the vision and development of enterprise wide security platforms such as Services Security Platform, WebApp Security Platform, Authentication & Authorization Platform, Kubernetes and Container Security Platform, Secrets Management Platform, Vulnerability Management Platform, Security Event Management Platform.
  • Envisioned and developed cloud security strategy, migration plans and enabled the modernization of the enterprise applications in Azure. Led the spotlight team to evaluate and implement security tooling on cloud in short span of time. Developed architectural blueprints for azure native services, custom developed apps/services deployed in cloud and third party apps.
  • Led the adoption of DevSecOps practices and implementation of related tooling in CI/CD pipeline such as SAST, DAST, IAST, CIS benchmark, IaC verification etc
  • Engage with internal teams for architecture reviews, threat modeling, providing security requirements, development of security standards etc
Information Security

Facebook

Security Engineer

Apr 2017Jul 2018 · 1 yr 3 mos · San Francisco Bay Area

  • Developed next-gen security platform to keep track of employee security posture. This platform calculated security score for each employee based on their behavior. The score was ultimately used to provision access automatically and to suggest what employees need to do to improve their respective score.
  • Developed a platform to manage all 2fac authentication operations for over 30k+ employees
  • Designed & Developed tooling for Vulnerability Management which could work at Scale. This included identifying assets in the network, identifying vulnerabilities and automating the remediation process.
  • Secured Docker environment by developing services, by establishing content trust in internal
  • registries, by setting up security scanners, and by defining & implementing detection rules.
  • Actively working as Security Partner with different teams such as WhatsApp, Oculus, Facebook AI - doing code reviews, threat modeling and security design for their infrastructure security.
Information Security

Salesforce

Security Engineer

Mar 2016Apr 2017 · 1 yr 1 mo · San Francisco Bay Area

  • Designed and developed of security framework to improve security posture of the company using machine learning which could detect malicious employee behavior and can block certain access.
  • Developed security guidelines to onboard container technologies like docker, heroku with existing legacy systems. Founding member of the team responsible for adoption of docker and heroku in IT.
  • Application Security in IT - Code Reviews, Configuring Scans, Trainings
  • Work as security consultant within organization, working with other dept/teams providing security view of the application architecture, providing security requirements, and validating implementation of security controls.
Information Security

Ondeck

Application Security Engineer

Sep 2015Dec 2015 · 3 mos · Greater New York City Area

  • Application Security - Threat Modeling, Vulnerability Management, AppSec Scanning (HP Web Inspect, Checkmarx). Closely working with developers to remediate vulnerabilities within SLA.
  • Developed security libraries to implement Authentication & Authorization for internal apps and users
Information Security

Urban ft

Junior System Engineer

May 2015Aug 2015 · 3 mos · New York, New York

  • Design & Implementation of security policies according to PCI compliance standards
  • Working with partner banks & card management companies to understand their system architecture and then integrating Urban FT's product securely with their infrastructure
  • Developed automated security testing and log monitoring to look for attack patterns
  • Implemented SIEM, Secure SDLC and Network Security Practices.
  • Offensive Security - Finding ways to compromise the infrastructure and application developed by the enterprise

New york university

2 roles

Research Assistant

Jan 2015Jun 2015 · 5 mos

  • A Framework for Securing Software Update Systems
  • The Update Framework (TUF) helps developers secure their new or existing software update systems. Software update systems are vulnerable to many known attacks, including those that can result in clients being compromised or crashed. TUF helps solve this problem by providing a flexible security framework that can be added to software updaters.
  • My Role: Discovery & then escape from inconsistencies in package managers like pypi, debain, ruby gems, rpm

SPIKE Intern for StyleSage (Backend & Security)

Sep 2014May 2015 · 8 mos

  • Implementing security policies and protocols to ensure infrastructure and application security
  • Developed crawling framework and scraping scripts to fetch data for big data analytics
  • Created incident response plans, responding to attacks & mitigating security risks accordingly
  • Developed security awareness & training program

Ab newswire

Development Engineer

Jan 2014May 2014 · 4 mos · Noida Area, India

  • Developed scripts to scrape industry data for sales team to reach new clients, resulted in increase of 34% in sales
  • Developed ERP to manage sales, customer relationships, accounting and generate reports which helped managers in decision making and strategy development

Techno softwares

Linux System Administrator

Aug 2012Jan 2014 · 1 yr 5 mos · Jaipur Area, India

  • Configuring and managing cluster of web services and application servers
  • Building robust network infrastructure to ensure scalability and security of applications
  • Client interaction & understanding requirements to provide overall security solutions

Linux world, jaipur

Research Intern

Jan 2012Aug 2012 · 7 mos · Jaipur Area, India

  • Discovery and analysis of authentication and authorisation flaws in large scale production environment using kerberos and ldap

Ducat india

Software Developer Intern

Oct 2011Jan 2012 · 3 mos · Jaipur Area, India

  • Requirement analysis, design & development of finance management software using Java, Swing & Oracle DB. It records student's financial activities to generates reports and alerts for administration department of the organisation.

Grras

Research Intern

Dec 2010Sep 2011 · 9 mos · Jaipur Area, India

  • Analysis of network traffic and application behaviour to help IT managers making security policies Design and implementation of infrastructure for the services offered by the company

Education

New York University

Master's degree — Cyber Security & Computer Science

Jan 2014Jan 2016

Suresh Gyan Vihar University

Bachelor of Technology (BS) — Information Technology

Jan 2009Jan 2013

Stackforce found 100+ more professionals with Information Security & Cloud Security

Explore similar profiles based on matching skills and experience