Ketan Karnick

CTO

Singapore, Singapore22 yrs 5 mos experience
Highly Stable

Key Highlights

  • Led multi-million dollar security programs.
  • Achieved 100% application integration in IAM.
  • Drove cybersecurity maturity improvements across multiple markets.
Stackforce AI infers this person is a seasoned leader in enterprise security and IAM within the telecom industry.

Contact

Skills

Core Skills

Enterprise SecurityIdentity And Access Management (iam)IamApplication SecuritySecurity ManagementPenetration TestingSoftware DevelopmentEndpoint Security

Other Skills

Endpoint secuirtyDLPPrivacy by DesignAdvanced data governancePrivileged Access ManagementSecurity StrategySecurity Program ManagementMobile SecurityC/C++.NetProduct DevelopmentLinux Systems ProgrammingSecurity Tools DevelopmentC++ Secure CodingBudget Management

About

I lead enterprise security and identity programs for Circles, owning security maturity, IAM transformation, and customer-facing security delivery for partnerships. My career spans 22 years across security leadership and software development — from building endpoint protection products at Symantec for 15 years, to scaling application security teams at Grab, to now driving end-to-end security enablement for enterprise telecom launches at Circles. What I bring to the table: the ability to operate at both the architectural and executive level. I've led teams of 15 security engineers, owned multi-million dollar budgets, delivered security clearance for the latest south east asian partnership on schedule, unblocking revenue for the Indonesia market, and built IAM programs from scratch achieving 100% application integration. I'm equally comfortable in a security architecture review and a customer-facing discussion driving security culture and thought leadership. Domains: Enterprise Security, IAM & PAM, Application Security, Secure-SDLC, Zero-Trust Architecture, Data Security & DLP, SIEM/SOC, Cloud Security, GRC & Compliance

Experience

22 yrs 5 mos
Total Experience
9 yrs 9 mos
Average Tenure
2 yrs 11 mos
Current Experience

Circles

Head of Enterprise Security | Identity & Access Management

Jun 2023Present · 2 yrs 11 mos · Singapore · On-site

  • Leading enterprise security and identity programs across a multi-market MVNO platform, owning security maturity, IAM transformation, and customer-facing security delivery for telecom partnerships including Telkomsel (Indonesia).
  • Led end-to-end security enablement for the Telkomsel Indonesia market launch as the primary customer-facing security leader, delivering all workstreams — Privacy by Design, Advanced data governance, Privileged Access Management, and delivered security clearance for the Telkomsel partnership on schedule, unblocking revenue for the Indonesia market — at 100% quality and improved cybersecurity maturity compared to previous launches.
  • Drove the organization to Managed IAM maturity: 100% JumpCloud integration across all engineering applications, 90% access standardization, introduced identity broker for enabling multi-IDP support for native business critical applications.
  • Drove product discussion with the Identity vendor to define and derive the accurate requirements that are critical for enablement at Circles.
  • Elevated Enterprise Security maturity to 3.5/5 through VPN consolidation, regional hardening across Singapore, India, and Sri Lanka, BigID DLP rollout across three markets, and 90%+ SIEM/SOC log ingestion with critical business logs forwarded to the customer's Splunk instance.
  • Led comprehensive security architecture and migration reviews across data security, infrastructure, and access management. Drove Cloudflare deployment and customer-facing attestation discussions for code and infrastructure security.
Endpoint secuirtyDLPEnterprise SecurityIdentity and Access Management (IAM)

Grab

2 roles

Senior Security Engineering Manager, Application Security

Promoted

Apr 2022Jun 2023 · 1 yr 2 mos

  • Led a team of 9 security engineers executing application security across Grab's engineering organization — technical design reviews, static analysis, penetration testing, and full remediation support across all product teams.
  • Drove the cybersecurity roadmap with direct contribution to annual budgeting and resource allocation. Established and presented security metrics to senior leadership, quantifying application security debt reduction and demonstrating measurable ROI of the security program.
  • Mentored security engineers on technically sound decision-making, helping product teams reduce their application security debt systematically.
Application SecuritySecurity StrategySecurity Management

Security Engineering Manager II

Oct 2018Apr 2022 · 3 yrs 6 mos

  • Progressed from Senior Security Program Manager to Security Engineering Manager, building and scaling a team of 10–15 penetration testing engineers using agile practices to maximize security review throughput across product teams.
  • Owned the InfoSec organization budget and managed vendor procurement, interfacing with legal, finance, and procurement teams. Negotiated multi-year contracts delivering significant cost savings.
  • Stepped up to lead the team through an engineering manager departure, maintaining continuity and improving the execution model for individual contributors. Led organization-wide incident response campaigns, keeping stakeholders including the senior stakeholders informed on progress.
  • Evangelized security initiatives with leadership, securing buy-in for tooling investments. Initiated and delivered organization-wide technical talks presenting deep-dives on security issues discovered by the team.
Penetration TestingSecurity Program ManagementSecurity Management

Symantec

2 roles

Principal Software Engineer

Promoted

Jun 2012Sep 2018 · 6 yrs 3 mos · On-site

  • Transitioned from product development to becoming Symantec's internal security assessment lead, working across the Software Security Group (2012–2017) and Data Center Security (2017–2018).
  • Conducted penetration testing across Web, Mobile, and Cloud domains with deep specialization in Android and iOS application security, assessing Symantec's own products for vulnerabilities.
  • Built internal security assessment tools using Python, Perl, .NET/MVC, AngularJS, and Java — including a JavaFX-based tool that translated XML configurations into Selenium test cases, significantly reducing manual test development effort.
  • Developed and delivered security training on C/C++ secure coding, mobile security, and secure design patterns across Symantec development centers in Pune, Chennai, Bangalore, and Culver City (US).
  • Led research and evaluation of emerging mobile security tools and techniques. Drove penetration test coordination with external vendors, owning technical coverage specifications and achieving maximum coverage at optimum cost.
  • Filed 4 invention disclosures on Android security. Attended BlackHat Asia 2015 and RSA Conference 2016/2017. Mentored junior engineers and served as project guide for university students on security research.
Penetration TestingMobile SecurityApplication SecuritySecurity Management

Senior Software Engineer → Associate Software Engineer — Endpoint Protection

Nov 2003Jun 2012 · 8 yrs 7 mos · On-site

  • 9-year progression across three product teams: Configuration Management (2003–2007), Enterprise Security Manager (2007–2009), and Endpoint Protection (2009–2012). Grew from Associate Software Engineer to Senior Software Engineer and team lead.
  • Designed and developed the Remote Management and Monitoring (RMM) feature for Symantec Endpoint Protection's small business edition.
  • Built a timeout-driven security technology re-enablement mechanism preventing endpoints from remaining vulnerable after administrator-initiated disabling.
  • Designed agent-based automation architecture enabling QA to automate large-scale test case execution, including Linux agent development.
  • Served on the customer response team analyzing and resolving complex escalations. Full lifecycle experience from requirements analysis through cross-location team collaboration.
  • Filed 2 invention disclosures. Received multiple Symantec Applause Awards (Level 2 and Level 4) for contributions to Endpoint Protection releases.
Endpoint SecurityC/C++Software Development

Education

Savitribai Phule Pune University

B.E — Information Technology

Jan 1999Jan 2003

Stackforce found 100+ more professionals with Enterprise Security & Identity And Access Management (iam)

Explore similar profiles based on matching skills and experience