S

Surya Prakash Pullabhotla

Director of Engineering

Dubai, United Arab Emirates15 yrs 1 mo experience
Highly Stable

Key Highlights

  • Led enterprise-wide cybersecurity strategy and governance.
  • Achieved PCI-DSS certification and Saudi PDPL compliance.
  • Built large-scale vulnerability management programs for 10K+ assets.
Stackforce AI infers this person is a Cybersecurity expert specializing in governance, risk management, and cloud security.

Contact

Skills

Core Skills

Governance, Risk Management, And Compliance (grc)Cloud SecurityThird Party Risk Management (tprm)LeadershipSecurity Operations CenterSecurity Incident ResponseSecurity MonitoringVulnerability AssessmentPenetration TestingVulnerability Management

Other Skills

DevSecOpsSecurity OperationsCross-functional Team LeadershipThreat & Vulnerability ManagementCompliance SupportMobile SecurityWeb Application Security AssessmentRisk ManagementSecurity Information and Event Management (SIEM)Cybersecurity Incident ManagementManaged Security ServicesApplication Security ArchitectureData GovernancePayment Card Industry Data Security Standard (PCI DSS)Vulnerability Assessment and Penetration Testing (VAPT)

About

Information Security Leader with a proven track record of driving enterprise-wide cybersecurity strategy, governance, and risk management across complex global environments. My experience spans the full security lifecycle—covering GRC, DevSecOps, cloud security, application security, SOC operations, incident response, and third-party risk management. I specialize in designing, implementing, and optimizing enterprise security frameworks that align with business objectives while meeting stringent regulatory requirements. I bring the ability to simplify complex risks for executives, embed security into technology and business processes, and lead organizations toward a mature, scalable security posture. Throughout my career, I have: Led ISO 27001 programs, delivered PCI-DSS certifications, and driven Saudi PDPL compliance. Built and operationalized large-scale vulnerability management programs (10K+ assets). Integrated security into CI/CD pipelines and strengthened SOC detection, monitoring, and response capabilities. Architected and secured cloud workloads across AWS and Azure, implementing CSPM, IAM governance, and workload protections. Deployed enterprise data protection and DLP strategies aligned with legal, regulatory, and business needs. Contributed to AI security governance, cyber insurance readiness, secure SDLC implementation, and advanced threat monitoring initiatives. I am passionate about building a strong security culture—leading awareness programs, running phishing simulations, mentoring teams, and promoting security-by-design across the organization. My collaborative leadership style enables me to work effectively with engineering, product, and executive stakeholders to create a shared cybersecurity vision. Core Strengths • Security Governance & Compliance (ISO 27001, PCI-DSS, PDPL) • DevSecOps, SSDLC & Application Security • Vulnerability Management & Penetration Testing • Cloud Security (Azure, AWS, IAM, CSPM) • SOC Leadership, Incident Response & Threat Hunting • Data Protection, DLP & Identity Security • Third-Party Risk Management (TPRM) • Security Architecture & Risk Advisory • AI Security, Policy Governance & Cyber Insurance Readiness

Experience

15 yrs 1 mo
Total Experience
2 yrs 6 mos
Average Tenure
1 mo
Current Experience

Zysec ai

Director of Cyber Security Operations

Apr 2026Present · 1 mo · Abu Dhabi Emirate, United Arab Emirates · On-site

Osn

Information Security & Compliance Manager

Sep 2022Apr 2026 · 3 yrs 7 mos · Dubai, United Arab Emirates · On-site

  • Driving enterprise-wide cybersecurity strategy covering governance, compliance, cloud security, DevSecOps, and risk management.
  • Key Achievements & Responsibilities
  • Revamped cybersecurity governance frameworks aligned to ISO 27001, ensuring compliance with regulatory, legal, and organizational requirements.
  • Spearheaded Saudi PDPL compliance program—led data mapping, privacy audits, and deployment of privacy-enhancing technologies.
  • Designed and implemented a full Third-Party Risk Management (TPRM) lifecycle, including vendor risk classification, onboarding controls, and automated due-diligence workflows.
  • Successfully achieved and maintained PCI-DSS certification through gap remediation, readiness assessments, and QSA coordination.
  • Advised executive leadership with security dashboards, risk briefings, audit results, and strategic cybersecurity recommendations.
  • Led enterprise Cyber Insurance program, ensuring control adherence and compliance with insurer security requirements.
  • Built and managed organization-wide Security Awareness Programs, including phishing simulations and targeted training campaigns.
  • Oversaw MSSP operations—improving incident response, SOC performance, alert triage, and threat hunting workflows.
  • Implemented enterprise DLP controls aligned with legal and business requirements to mitigate insider and data leakage risks.
  • Integrated SSDLC and DevSecOps practices into CI/CD (SAST, DAST, VAPT), improving application security posture.
  • Tuned and optimized WAF policies to mitigate OWASP Top 10 and zero-day threats.
  • Deployed CSPM tools to secure AWS and Azure environments by remediating misconfigurations.
  • Implemented Microsoft 365 E5 Defender security stack (EDR, email protection, identity security, DLP).
  • Led dark web monitoring and breach-response readiness to reduce external exposure risks.
Governance, Risk Management, and Compliance (GRC)Cloud SecurityDevSecOpsVulnerability ManagementThird Party Risk Management (TPRM)Security Operations+2

G42

Senior Security Engineer (Lead) – SOC, SOAR, Incident Response

Jun 2020Sep 2022 · 2 yrs 3 mos · Abu Dhabi Emirate, United Arab Emirates · On-site

  • SOC Leadership & Mentorship: Directed L1/L2 SOC operations, fostering professional growth through mentorship while architecting Standard Operating Procedures (SOPs) and automated incident response playbooks.
  • Tier-3 Escalation SME: Served as the senior Subject Matter Expert for complex threat hunting and advanced investigations, performing deep-dive Root Cause Analysis (RCA) for high-priority incidents.
  • Security Architecture & Visibility: Led the end-to-end onboarding and integration of SIEM platforms, vulnerability management tools, and centralized logging to eliminate visibility gaps.
  • Detection Engineering: Optimized SIEM detection logic and data pipelines, significantly improving alert high-fidelity and reducing false-positive fatigue for the SOC team.
  • Incident Lifecycle & Reporting: Managed the full incident lifecycle—from detection to remediation—and delivered executive-level security posture reports to stakeholders.
  • Audit & Compliance: Ensured 100% audit readiness and strengthened technical controls for PCI-DSS and ISO 27001 frameworks.
Security Operations CenterSecurity MonitoringSecurity Incident ResponseThreat & Vulnerability ManagementCompliance Support

Deloitte

Assistant Manager (VAPT)

Jul 2018Feb 2020 · 1 yr 7 mos · Hyderabad Area, India · On-site

  • Comprehensive VAPT: Led end-to-end Vulnerability Assessment and Penetration Testing (VAPT) across diverse ecosystems, including Web, Mobile, API, and Network infrastructures.
  • Application Security (AppSec): Spearheaded SAST/DAST initiatives and secure code reviews using industry-standard tools to identify and mitigate vulnerabilities early in the development lifecycle.
  • API Security & Testing: Performed deep-dive API security testing utilizing advanced toolsets to ensure robust endpoint protection and data integrity.
  • Threat Modeling & Governance: Developed detailed threat models and designed security controls to ensure technical architectures remained aligned with global compliance standards.
  • Security Awareness: Engineered targeted phishing simulation campaigns to strengthen organizational resilience against social engineering attacks.
  • Third-Party Risk Management (TPRM): Conducted technical risk assessments for third-party onboarding to ensure vendor integrations met internal security benchmarks.
Vulnerability AssessmentPenetration TestingMobile SecurityWeb Application Security AssessmentRisk Management

Ibm india private limited

Information Security Advisor (VA/PT,ISIM)

Oct 2016Jun 2018 · 1 yr 8 mos · Hyderabad Area, India · On-site

  • Vulnerability Lifecycle Management: Managed the end-to-end vulnerability lifecycle for 10,000+ assets, overseeing discovery, prioritization, stakeholder coordination, and final remediation verification using enterprise-grade tools.
  • Detection Engineering & SIEM: Strengthened security posture by conducting deep-dive Root Cause Analysis (RCA) and developing custom SIEM detection rules to identify complex threat patterns.
  • VAPT & Cross-Functional Leadership: Executed comprehensive VAPT engagements, acting as a technical lead to guide infrastructure and application teams through successful remediation cycles.
  • Strategic Client Advisory: Served as a subject matter expert for clients, providing actionable insights on emerging threats and long-term mitigation strategies.
Vulnerability ManagementPenetration TestingSecurity Information and Event Management (SIEM)Cybersecurity Incident ManagementRisk ManagementManaged Security Services

Bestflux technologies pvt ltd

Senior Security Consultant

Dec 2014Oct 2016 · 1 yr 10 mos · Hyderabad, Telangana, India · On-site

Penetration TestingVulnerability AssessmentApplication Security ArchitectureVulnerability Management

Innefu labs pvt. ltd.

Security Analyst

Sep 2008Oct 2012 · 4 yrs 1 mo · Delhi, India · On-site

Education

JNTUH College of Engineering Hyderabad

Bachelor of Technology - BTech — Computer Science

Stackforce found 100+ more professionals with Governance, Risk Management, And Compliance (grc) & Cloud Security

Explore similar profiles based on matching skills and experience