Akshay Suryawanshi

Lead Information Security Engineer & Acting Team Lead

Owning the complete security program for a global enterprise.

3,000+ Employees secured
22 Countries US · EU · AU · NZ
3 Person team

I secure what I've built and operated. Eight years of building infrastructure — on-premises servers, Active Directory, virtualization, cloud environments, large-scale AWS migrations — before moving into security. That operational depth means my architecture reviews catch what framework-only security professionals miss, my threat models reflect how systems actually break, and my incident response starts with knowing exactly where to look.

Cloud Security Security Architecture Incident Response Threat Modeling AppSec Zero Trust Vulnerability Management AI Security GRC
Akshay Suryawanshi - Lead Information Security Engineer

Impact

Outcome-focused initiatives across security operations, governance, and program leadership

  • Led 6 P1 security incidents end-to-end in FY26 — including a third-party supply-chain compromise and an enterprise cloud environment breach — coordinating response across the business unit and Cimpress Group Security

  • Reduced phishing click-through rates by 65% through a simulation and awareness program covering 3,000+ employees across the US, Europe, Australia, and New Zealand

  • Authored the enterprise AI Usage & Governance Policy — aligning with NIST AI RMF and EU AI Act requirements — governing ChatGPT, Copilot, Gemini, and Claude usage across the organization

  • Designed and implemented cloud security architecture assessments and threat modeling across AWS, Azure, and OCI — evaluating, approving, or rejecting new solutions from a security perspective

  • Own the GRC program for the business unit — aligning controls with ISO 27001, SOC 2, NIST CSF, GDPR, CCPA, and managing quarterly SOX User Access Reviews

  • Run the AppSec / SSDLC program end-to-end — personally triaging SCA and SAST findings from Snyk with development teams, assessing contextual severity, and driving remediation. Hands-on engineering work, not just tool ownership

  • Authored the Security Architecture Best Practices document — serving as the security baseline for all new solution designs and architecture reviews across the business unit

  • Built and now lead the business unit InfoSec team — hiring, mentoring PR1–PR3 engineers, running daily operations, and presenting security roadmaps to the Extended Leadership Team

Case Studies

Selected initiatives shown as Problem → Approach → Outcome

Incident Response DFIR SOC

Incident Response — Enterprise Supply-Chain Attack

Led end-to-end response to a third-party supply-chain compromise affecting enterprise infrastructure.

AI Security GRC Policy

AI Governance — Enterprise AI Usage & Governance Policy

Authored the organization's first AI governance policy — aligning with NIST AI RMF and EU AI Act.

Cloud Security AWS Architecture

Cloud Security — AWS Network Security Hardening

Led AWS network security hardening — designing phased NACL controls and tightening Security Group port restrictions across the cloud environment.

Security Awareness Human Risk Metrics

Human Risk — Phishing Simulation Program

Designed and executed a phishing program that reduced click-through rates by 65%.

Threat Modeling Security Architecture STRIDE

Threat Modeling — STRIDE Implementation for Cloud Applications

Built the threat modeling program from scratch using STRIDE methodology.

Core Domains

Specialized expertise across seven key security domains

Cloud Security

Independent cloud security assessments across AWS, Azure, and OCI — covering IAM, network segmentation, compute hardening, container security (EKS/ECS), IaC reviews (Terraform, CloudFormation), logging, and monitoring.

Security Architecture & Threat Modeling

Independently evaluate, approve, and reject new solutions and architectures from a security perspective — including API architectures, authentication flows (OAuth/OIDC), and API gateway configurations. Perform STRIDE-based threat modeling as part of architecture reviews. Apply Zero Trust principles — Conditional Access, identity-based access controls, and micro-segmentation.

Vulnerability Management

End-to-end vulnerability management program — scanning, risk-based prioritization using CVSS and asset criticality, SLA-driven remediation, and executive reporting.

Incident Coordination

Coordinate incident response across the business unit — 3,000+ employees across the US, Europe, Australia, and New Zealand — liaising with Cimpress SOC for investigation and driving remediation.

Governance, Policy & Vendor Security

Policy authoring, SOPs, and security framework ownership for the business unit. Risk Register management and Risk Acceptance workflows. Vendor security assessments with formal approval/rejection authority. SOX User Access Reviews (quarterly). Compliance alignment with ISO 27001, NIST CSF, GDPR, CCPA, and SOC 2.

AI Security & Governance

Authored the enterprise AI Usage & Governance Policy aligned with NIST AI RMF and EU AI Act. Govern adoption of ChatGPT, Copilot, Gemini, and Claude across the organization. Define data-handling rules, prohibited use cases, and approval workflows for new AI tools.

AppSec, SSDLC & Supply Chain

Hands-on triage of SCA and SAST findings from Snyk with development teams — reviewing each finding, assessing contextual severity, and driving remediation. Validate pentest findings via retesting (BurpSuite). Coordinate the SSDLC program and secure the software supply chain.

Projects & Key Initiatives

Delivering Measurable Outcomes Across Security & Infrastructure

Information Security

SOC Automation

AI-Driven SOC Triage & Automation

~50% faster triage 200+ daily alerts processed Lower false positive rate

Built intelligent L1 alert triage workflow — iteratively improved through enrichment, correlation, and false-positive tuning.

GRC

AI Usage & Governance Policy

Org-wide policy Responsible AI adoption

Authored the organization's AI Usage and Governance Policy, establishing guardrails for responsible and secure AI adoption across the business unit.

GRC SOC

NIST-Aligned Incident Response Program

NIST aligned P1-P4 workflows

Developed comprehensive IR framework with defined RACI, escalation workflows, playbooks, and metrics.

Cloud Security

Multi-Cloud Security Architecture Reviews

40% reduced attack surface 3 Clouds AWS/Azure/OCI

Conducted comprehensive security assessments across AWS, OCI, and Azure — including container, IaC, and API architecture reviews.

VM

Vulnerability Management Program

60% backlog reduction 7-day critical SLA

Established the business unit vulnerability management program with risk-based prioritization and SLA-driven remediation.

GRC

Security Awareness & Phishing Simulation Program

65% click rate reduction 95%+ training completion

Implemented comprehensive security awareness training with monthly phishing simulations reducing click rates by 65%.

VM GRC

Pentest Coordination & Hands-On Retesting

100% critical SLA met BurpSuite retesting

Coordinate annual penetration testing engagements and personally retest every finding using BurpSuite and other tools — validating that remediation is actually effective before sign-off.

Security Ops

Threat Intelligence Operationalization

40% faster detection 3+ TI platforms

Operationalized enterprise threat intelligence platforms for the business unit, enabling proactive threat detection and dark web monitoring.

Network

Firewall Security Review & Rule Optimization

35% rules reduced 1000+ rules reviewed

Conducted comprehensive firewall security reviews to identify misconfigurations, optimize rulesets, and reduce attack surface.

Identity Zero Trust

SSO Hardening — Microsoft Entra ID

Enterprise-wide SSO rollout Reduced credential attack surface

Led the security workstream for SSO integration via Microsoft Entra ID — hardening authentication flows, reducing password-based attack surface, and enforcing Conditional Access policies across the organization.

GRC

GRC

Global Retention Policy & Data Governance

30% storage savings GDPR/CCPA compliant

Led organization-wide data retention policy project ensuring compliance with GDPR, CCPA, and industry regulations.

GRC

ISO 27001 & Compliance Framework

Zero critical findings 60% faster audit prep

Aligned security program with ISO 27001, NIST CSF, and CIS Controls for audit readiness and continuous compliance.

Leadership GRC

Executive Security Metrics & Dashboards

C-level reporting Data-driven decisions

Built comprehensive security KPI dashboards for C-level executives and board reporting.

Security Architecture GRC

Architecture Best Security Practices

Org-wide baseline Security-by-Design

Authored the Architecture Best Security Practices document, serving as the security baseline for all new solution designs across the business unit.

Infrastructure: Windows Server (2000-2022), On-Premise, Virtual & Cloud Engineering

Cloud AWS

AWS Large-Scale Migration (Hundreds of Servers)

500+ servers migrated Zero downtime

Led end-to-end migration of 500+ on-premises servers to AWS using Application Migration Service.

Cloud FinOps

Cloud Cost Optimization Initiative

33% cost reduction $240K annual savings

Achieved 33% reduction in AWS infrastructure costs through rightsizing, reserved instances, and resource optimization.

Windows Identity

Windows Server Administration & Management (2000-2022)

10,000+ users 8+ years experience

Comprehensive Windows Server administration across multiple versions (2000-2022) with enterprise-scale deployment and management.

Virtualization Data Center

Virtualization & Data Center Management

200+ VMs managed 99.9% uptime

Managed enterprise virtualization platforms (VMware ESXi/vSphere, Nutanix) supporting 200+ VMs with high availability.

Identity Azure AD

Active Directory & Identity Management

3,000+ users Hybrid identity

Managed enterprise Active Directory infrastructure for 3,000+ users with Azure AD hybrid integration.

M365 Collaboration

Microsoft 365 & Exchange Administration

Enterprise scale DLP enabled

Managed enterprise M365 environment including Exchange Online, SharePoint, and Teams for organization-wide collaboration.

Leadership

Building teams. Owning programs. Translating security risk into business decisions.

Team Building

Rebuilt the business unit InfoSec team after multiple departures — creating job descriptions, leading the hiring process for Senior InfoSec Engineers, and mentoring team members from PR1 to PR3 level. Currently leading a team across L1, L2, and L3 security functions.

Stakeholder Management

Present security roadmaps, metrics, and initiative progress to the Extended Leadership Team (ELT). Manage upward through the CTO chain — reporting to the Senior Manager of InfoSec, who reports to the Sr. Director of Technical Services, who reports to the CTO.

Program Ownership

Own the complete information security program for a business unit with 3,000+ employees operating across the US, Europe, Australia, and New Zealand. The business unit security team operates largely independently — handling SOC, DFIR, threat intelligence, GRC, and cloud security — with Cimpress Group Security engaged for P1/P2 escalations.

Risk-to-Business Translation

Translate technical security risks into business language for leadership. Own formal risk acceptance workflows where business justification overrides security recommendations — ensuring risks are documented, tracked annually, and reviewed with stakeholders.

Professional Experience

8+ YearsFrom Infrastructure to Security

Eight years of building and operating infrastructure — on-premises servers, Active Directory, virtualization, cloud environments, large-scale AWS migrations — before moving into security. Every prior layer of the stack is now first-hand context that makes architecture reviews sharper, threat models more realistic, and incident response faster.

Mar 2024 – Present Cimpress India Private Limited Remote

Lead Information Security Engineer

(Acting Team Lead)

Team Leadership Program Owner Global Scope

Key Impact

  • Coordinate Incident Response and security operations across a 3,000+ employee organization spanning the US, Europe, Australia, and New Zealand — liaising with Cimpress SOC for investigation and driving remediation with business unit stakeholders
  • Reduced phishing click rates by 65% through security awareness program
  • Cut critical vulnerability backlog by 60% via risk-based prioritization
  • Built executive security dashboards enabling data-driven investment decisions
  • Achieved zero critical audit findings through alignment with global security frameworks and regulatory acts
Apr 2023 – Feb 2024 Cimpress India Private Limited

Lead Cloud Engineer

Migration Lead Cost Owner

Key Impact

  • Migrated hundreds of servers to AWS with zero downtime
  • Saved $240K/year through cloud cost optimization ($60K → $40K/month)
  • Enabled remote workforce with AWS Workspaces for 500+ users
Jul 2021 – Mar 2023 Cimpress India Private Limited

Senior Systems Engineer

Infrastructure Owner

Key Impact

  • Owned VM infrastructure supporting 200+ systems across VMware ESXi/vSphere and Nutanix
  • Led complex migrations: P2P, P2V, V2V, V2C with minimal downtime
  • Accountable for 99.9% uptime across critical infrastructure
Sep 2020 – Jun 2021 Cimpress India Private Limited

Systems Engineer

Key Impact

  • Owned Windows Server ecosystem spanning versions 2003-2022
  • Implemented hybrid identity with Azure AD Connect and Intune
  • Deployed enterprise monitoring using SolarWinds for proactive alerting
Oct 2019 – Aug 2020 ThinkApps Solutions Pvt. Ltd Onsite

Server Engineer

(Client: Leading Media Company)

Key Impact

  • Administered Windows Server for enterprise media infrastructure
  • Managed Microsoft 365 and Group Policy for 500+ users
  • Maintained VMware infrastructure ensuring availability and performance
Nov 2018 – Sep 2019 Microland Limited Onsite

Senior Engineer (Server Management)

(Client: Leading Insurance Company)

Key Impact

  • Managed Active Directory and DC replication for enterprise environment
  • Drove SCCM patching operations ensuring compliance posture
  • Owned O365 and infrastructure monitoring for proactive incident management
May 2017 – Apr 2018 Nityo Infotech Pvt. Ltd Onsite

Desktop Support Engineer

(Client: Leading Banking & Investment Management Company)

Key Impact

  • Led EOSL migration for 2,000+ systems ensuring business continuity
  • Delivered end-user technical support for banking operations
  • Managed IT assets and vendor relationships for hardware lifecycle

Certifications

Industry-Recognized Credentials & Qualifications

NEW
CISM Certification Badge

CISM

ISACA

Certified Information Security Manager

Issued Sep 2025 · Expires Jan 2029

Verify
AWS AI Practitioner Foundational Certification Badge

AWS AI Practitioner

Amazon Web Services

Certified AI Practitioner

Issued Dec 2024 · Expires Dec 2027

Verify
AWS Solutions Architect Associate Certification Badge

AWS Solutions Architect

Amazon Web Services

Solutions Architect – Associate

Issued Jul 2024 · Expires Jul 2027

Verify
CompTIA Security+ Certification Badge

CompTIA Security+

CompTIA

Security Fundamentals Certification

Issued May 2024 · Expires May 2027

Verify
Microsoft Azure Security Engineer Associate Certification Badge

Azure Security Engineer

Microsoft

Azure Security Engineer Associate

Issued May 2024 · Expires May 2027

Verify

Get In Touch

Reach out for collaboration, conversation, or opportunities

Email

Phone

Location

Mumbai, India

Availability

Open to opportunities — India & Global · Remote · Hybrid