Surya Prakash Pullabhotla — Director of Engineering
Information Security Leader with a proven track record of driving enterprise-wide cybersecurity strategy, governance, and risk management across complex global environments. My experience spans the full security lifecycle—covering GRC, DevSecOps, cloud security, application security, SOC operations, incident response, and third-party risk management. I specialize in designing, implementing, and optimizing enterprise security frameworks that align with business objectives while meeting stringent regulatory requirements. I bring the ability to simplify complex risks for executives, embed security into technology and business processes, and lead organizations toward a mature, scalable security posture. Throughout my career, I have: Led ISO 27001 programs, delivered PCI-DSS certifications, and driven Saudi PDPL compliance. Built and operationalized large-scale vulnerability management programs (10K+ assets). Integrated security into CI/CD pipelines and strengthened SOC detection, monitoring, and response capabilities. Architected and secured cloud workloads across AWS and Azure, implementing CSPM, IAM governance, and workload protections. Deployed enterprise data protection and DLP strategies aligned with legal, regulatory, and business needs. Contributed to AI security governance, cyber insurance readiness, secure SDLC implementation, and advanced threat monitoring initiatives. I am passionate about building a strong security culture—leading awareness programs, running phishing simulations, mentoring teams, and promoting security-by-design across the organization. My collaborative leadership style enables me to work effectively with engineering, product, and executive stakeholders to create a shared cybersecurity vision. Core Strengths • Security Governance & Compliance (ISO 27001, PCI-DSS, PDPL) • DevSecOps, SSDLC & Application Security • Vulnerability Management & Penetration Testing • Cloud Security (Azure, AWS, IAM, CSPM) • SOC Leadership, Incident Response & Threat Hunting • Data Protection, DLP & Identity Security • Third-Party Risk Management (TPRM) • Security Architecture & Risk Advisory • AI Security, Policy Governance & Cyber Insurance Readiness
Stackforce AI infers this person is a Cybersecurity expert specializing in governance, risk management, and cloud security.
Location: Dubai, United Arab Emirates
Experience: 15 yrs 1 mo
Skills
- Governance, Risk Management, And Compliance (grc)
- Cloud Security
- Third Party Risk Management (tprm)
- Leadership
- Security Operations Center
- Security Incident Response
- Security Monitoring
- Vulnerability Assessment
- Penetration Testing
- Vulnerability Management
Career Highlights
- Led enterprise-wide cybersecurity strategy and governance.
- Achieved PCI-DSS certification and Saudi PDPL compliance.
- Built large-scale vulnerability management programs for 10K+ assets.
Work Experience
ZySec AI
Director of Cyber Security Operations (1 mo)
OSN
Information Security & Compliance Manager (3 yrs 7 mos)
G42
Senior Security Engineer (Lead) – SOC, SOAR, Incident Response (2 yrs 3 mos)
Deloitte
Assistant Manager (VAPT) (1 yr 7 mos)
IBM India Private Limited
Information Security Advisor (VA/PT,ISIM) (1 yr 8 mos)
Bestflux Technologies Pvt Ltd
Senior Security Consultant (1 yr 10 mos)
Innefu Labs Pvt. Ltd.
Security Analyst (4 yrs 1 mo)
Education
Bachelor of Technology - BTech at JNTUH College of Engineering Hyderabad