Akshay Suryawanshi
Lead Information Security Engineer
Cloud Security | Security Architecture | AppSec & SSDLC | GRC | Security Program Management | Acting Team Lead
Lead Information Security Engineer and Acting Team Lead with 8+ years of experience across Infrastructure and Information Security. I lead the end-to-end Information Security program for National Pen, a Cimpress business unit, focusing on cloud security assessments, security architecture reviews, threat modeling, vulnerability management, and hands-on security control guidance across AWS, Azure, and OCI environments — advising and guiding teams on implementing cloud security controls, evaluating and approving new solutions end-to-end, and owning the GRC program including risk management, compliance, and vendor security — while coordinating with Cimpress central security teams on incident response and broader security operations.
Currently at National Pen, a Cimpress Company
Currently based in Mumbai, India
Open to opportunities in India and Global
Open to Hybrid · Remote roles
CISM
CompTIA Security+
AWS Solutions Architect Associate
AWS AI Practitioner
AZ-500
Key Security Initiatives Led
- Independently conduct cloud security architecture assessments and threat modeling across AWS, Azure, and OCI environments, evaluating new solutions and recommending security posture improvements
- Independently evaluate, approve, and reject new solutions and architectures from a security perspective for the business unit
- Authored the organization's AI Usage and Governance Policy, establishing guardrails for responsible AI adoption
- Authored the Architecture Best Security Practices document, serving as the security baseline for all new solution designs
- Manage the Vulnerability Management program for the business unit — leading weekly review cadences, scanning, prioritizing remediation using CVSS and asset criticality, and driving security posture improvements
- Coordinate Incident Response across the business unit (3,000+ employees, multiple countries (US, EU, Australia etc.), liaising with Cimpress SOC for investigation and driving remediation with stakeholders
- Designed and executed phishing awareness and simulation programs, reducing click-through rates by 65%
- Initiated the developer security awareness program via Snyk, driving SSDLC adoption and coordinating vulnerability remediation with development teams
- Operationalized enterprise threat intelligence tooling for the business unit, onboarding feeds and integrating with local security operations
- Independently conduct vendor and third-party security assessments — providing formal approval or rejection based on the security baseline; where business justification overrides rejection, risks are documented in the Risk Register for annual follow-up and review
- Own and maintain the Risk Register for the business unit — managing risk identification, assessment, treatment plans, and formal Risk Acceptance workflows with stakeholders and leadership, with annual review cycles for all accepted risks
- Own the GRC program for the business unit — authoring and maintaining security policies, SOPs, and security frameworks; aligning controls with ISO 27001, SOC 2, NIST CSF, GDPR, and CCPA; and driving governance across all security domains
- Manage SOX User Access Reviews (UAR) on a quarterly basis as part of the GRC program — coordinating access certifications across systems and ensuring compliance with SOX control requirements
- Lead an InfoSec team — running daily standups, 1:1s, mentoring junior team members, and driving complete security operations