Professional profile
I am a technology and security leader working in a regulated financial-market environment, currently serving as Chief Information Security Officer at J V Equities Pvt. Ltd.
My work spans governance and strategy as well as hands-on delivery — writing and maintaining policy, working through audit and regulatory requirements, and staying close to the operational routines that keep systems dependable day to day.
Three principles I work to
Controls must work in operation, not only on paper
- Security controls designed around how work is actually done, so they hold up under operational pressure rather than only in review.
Regulatory requirements become practical, measurable controls
- Expectations mapped to concrete controls, owners and evidence — so compliance is a by-product of how work is done, not a separate effort.
Operations, resilience and security are connected disciplines
- Posture, continuity and daily operations designed together, because a control an operational process cannot sustain is not a control.
One system, several vantage points
Security, governance, regulation and operations are frequently treated as separate disciplines. In practice they describe the same system viewed from different angles: a control that cannot be operated is not a control, and a regulatory requirement that never reaches an operational process is not compliance.
My professional work sits at that intersection — translating security and regulatory expectations into controls, policies and operating practices that hold up in day-to-day use, and keeping technology decisions aligned with the risk and regulatory context they exist in.
What the role covers
Related areas of practice, applied across a regulated technology estate.
Cybersecurity
- Security posture, controls design and the operational practices that sustain them.
Information Security
- Protection of information assets through policy, process and technical controls.
Governance, Risk & Compliance
- Governance structures, risk oversight and compliance alignment across technology.
IT Risk
- Identification, assessment and treatment of technology risk in an operating context.
Regulatory Compliance
- Interpreting technology-related regulatory requirements and operationalising them.
IT Audit & Assurance
- Audit readiness, evidence discipline, findings response and remediation tracking.
Technology Operations
- Infrastructure, change discipline, monitoring and daily operational routines.
Business Continuity
- Continuity planning, backup and recovery operations, and recovery verification.
Operational Resilience
- The ability to keep critical operations dependable through disruption.
How the work gets done
Risk-based security
Effort placed where exposure and business impact are highest, rather than spread evenly for its own sake.
Regulatory alignment
Requirements mapped to concrete controls and owners so compliance is a by-product of how work is done.
Operational effectiveness
Controls designed to be run by the people who own the process, within the time they actually have.
Measurable controls
Controls defined so their operation can be evidenced and reviewed, not assumed.
Resilience
Continuity and recovery treated as tested capabilities rather than documents.
Continuous improvement
Findings, incidents and reviews fed back into policy and practice instead of closed and forgotten.