Akshay Suryawanshi

Lead Information Security Engineer

Cloud Security | Security Architecture | AppSec & SSDLC | GRC | Security Program Management | Acting Team Lead

Lead Information Security Engineer and Acting Team Lead with 8+ years of experience across Infrastructure and Information Security. I lead the end-to-end Information Security program for National Pen, a Cimpress business unit, focusing on cloud security assessments, security architecture reviews, threat modeling, vulnerability management, and hands-on security control guidance across AWS, Azure, and OCI environments — advising and guiding teams on implementing cloud security controls, evaluating and approving new solutions end-to-end, and owning the GRC program including risk management, compliance, and vendor security — while coordinating with Cimpress central security teams on incident response and broader security operations.

Currently at National Pen, a Cimpress Company

Currently based in Mumbai, India

Open to opportunities in India and Global

Open to Hybrid · Remote roles

CISM CompTIA Security+ AWS Solutions Architect Associate AWS AI Practitioner AZ-500

Key Security Initiatives Led

  • Independently conduct cloud security architecture assessments and threat modeling across AWS, Azure, and OCI environments, evaluating new solutions and recommending security posture improvements
  • Independently evaluate, approve, and reject new solutions and architectures from a security perspective for the business unit
  • Authored the organization's AI Usage and Governance Policy, establishing guardrails for responsible AI adoption
  • Authored the Architecture Best Security Practices document, serving as the security baseline for all new solution designs
  • Manage the Vulnerability Management program for the business unit — leading weekly review cadences, scanning, prioritizing remediation using CVSS and asset criticality, and driving security posture improvements
  • Coordinate Incident Response across the business unit (3,000+ employees, multiple countries (US, EU, Australia etc.), liaising with Cimpress SOC for investigation and driving remediation with stakeholders
  • Designed and executed phishing awareness and simulation programs, reducing click-through rates by 65%
  • Initiated the developer security awareness program via Snyk, driving SSDLC adoption and coordinating vulnerability remediation with development teams
  • Operationalized enterprise threat intelligence tooling for the business unit, onboarding feeds and integrating with local security operations
  • Independently conduct vendor and third-party security assessments — providing formal approval or rejection based on the security baseline; where business justification overrides rejection, risks are documented in the Risk Register for annual follow-up and review
  • Own and maintain the Risk Register for the business unit — managing risk identification, assessment, treatment plans, and formal Risk Acceptance workflows with stakeholders and leadership, with annual review cycles for all accepted risks
  • Own the GRC program for the business unit — authoring and maintaining security policies, SOPs, and security frameworks; aligning controls with ISO 27001, SOC 2, NIST CSF, GDPR, and CCPA; and driving governance across all security domains
  • Manage SOX User Access Reviews (UAR) on a quarterly basis as part of the GRC program — coordinating access certifications across systems and ensuring compliance with SOX control requirements
  • Lead an InfoSec team — running daily standups, 1:1s, mentoring junior team members, and driving complete security operations
Get In Touch
Akshay Suryawanshi - Lead Information Security Engineer

Security Impact

Measurable outcomes across security operations, risk reduction, and compliance

Security Operations & Incident Response

3,000+ Employees Protected
22 Countries Supported
200+ Daily Alerts Processed

Risk Reduction

65% Phishing Click-Rate Reduction
60% Critical Vuln Backlog Reduction
~50% Improved MTTD/MTTR

Compliance & GRC

Zero Critical Audit Findings
~60% Faster Audit Preparation

Alignment with global security frameworks and regulatory acts

Cloud Security & Architecture

AWS Security Architecture
Azure Security Architecture
OCI Security Architecture

IAM, network security, threat modeling, logging & monitoring reviews. Preventive and detective guardrails.

Infrastructure & Cloud Impact

Security-first cloud architecture, governance, and large-scale migrations

Cloud Cost Optimization

$240K+ Annual Cost Savings
33% Infrastructure Cost Reduction

Migration & Scale

500+ Servers Migrated to AWS

Security-first cloud migration approach

Core Domains

Specialized expertise across six key security domains

Cloud Security

Independent cloud security assessments across AWS, Azure, and OCI — covering IAM, network segmentation, compute hardening, logging, and monitoring.

Security Architecture & Threat Modeling

Independently evaluate, approve, and reject new solutions and architectures from a security perspective. Perform threat modeling as part of security architecture reviews.

Vulnerability Management

End-to-end vulnerability management program — scanning, risk-based prioritization using CVSS and asset criticality, SLA-driven remediation, and executive reporting.

Incident Coordination

Coordinate incident response across the business unit (3,000+ employees, multiple countries (US, EU, Australia etc.), liaising with Cimpress SOC for investigation and driving remediation.

Governance, Policy & Vendor Security

Policy authoring, SOPs, and security framework ownership for the BU. Risk Register management and Risk Acceptance workflows. Vendor security assessments with formal approval/rejection authority. SOX User Access Reviews (quarterly). Compliance alignment with ISO 27001, NIST CSF, GDPR, CCPA, and SOC 2.

Security Leadership & Enablement

Acting Team Lead — mentoring engineers, running standups and 1:1s, and driving security awareness programs.

SSDLC, Code Security & Supply Chain Security

Driving secure development lifecycle adoption via Snyk, managing dependency vulnerability remediation with dev teams, and securing the software supply chain.

Projects & Key Initiatives

Delivering Measurable Outcomes Across Security & Infrastructure

Information Security

SOC Automation

AI-Driven SOC Triage Automation

~50% faster triage 200+ daily alerts processed

Built intelligent L1 alert triage workflow reducing manual investigation by ~50% through AI and automation.

GRC

AI Usage & Governance Policy

Org-wide policy Responsible AI adoption

Authored the organization's AI Usage and Governance Policy, establishing guardrails for responsible and secure AI adoption across the business unit.

GRC SOC

NIST-Aligned Incident Response Program

NIST aligned P1-P4 workflows

Developed comprehensive IR framework with defined RACI, escalation workflows, playbooks, and metrics.

Cloud Security

Multi-Cloud Security Architecture Reviews

40% reduced attack surface 3 Clouds AWS/Azure/OCI

Conducted comprehensive security assessments across AWS, OCI, and Azure reducing attack surface significantly.

VM

Vulnerability Management Program

60% backlog reduction 7-day critical SLA

Established the business unit vulnerability management program with risk-based prioritization and SLA-driven remediation.

GRC

Security Awareness & Phishing Simulation Program

65% click rate reduction 95%+ training completion

Implemented comprehensive security awareness training with monthly phishing simulations reducing click rates by 65%.

VM GRC

Penetration Testing Remediation Coordination

100% critical SLA met

Coordinated annual penetration testing remediation efforts with enterprise pentest team, driving cross-functional fixes for critical vulnerabilities.

Security Ops

Threat Intelligence Operationalization

40% faster detection 3+ TI platforms

Operationalized enterprise threat intelligence platforms for the business unit, enabling proactive threat detection and dark web monitoring.

Network

Firewall Security Review & Rule Optimization

35% rules reduced 1000+ rules reviewed

Conducted comprehensive firewall security reviews to identify misconfigurations, optimize rulesets, and reduce attack surface.

Leadership, Governance & Risk Management (GRC)

Leadership

Acting Team Lead - Business Unit Security

3,000+ employees Global scope

Leading the business unit security program — cloud security, vulnerability management, incident coordination, and governance as Acting Team Lead.

GRC

Global Retention Policy & Data Governance

30% storage savings GDPR/CCPA compliant

Led organization-wide data retention policy project ensuring compliance with GDPR, CCPA, and industry regulations.

GRC

ISO 27001 & Compliance Framework

Zero critical findings 60% faster audit prep

Aligned security program with ISO 27001, NIST CSF, and CIS Controls for audit readiness and continuous compliance.

Leadership GRC

Executive Security Metrics & Dashboards

C-level reporting Data-driven decisions

Built comprehensive security KPI dashboards for C-level executives and board reporting.

Security Architecture GRC

Architecture Best Security Practices

Org-wide baseline Security-by-Design

Authored the Architecture Best Security Practices document, serving as the security baseline for all new solution designs across the business unit.

Infrastructure: Windows Server (2000-2022), On-Premise, Virtual & Cloud Engineering

Cloud AWS

AWS Large-Scale Migration (Hundreds of Servers)

500+ servers migrated Zero downtime

Led end-to-end migration of 500+ on-premises servers to AWS using Application Migration Service.

Cloud FinOps

Cloud Cost Optimization Initiative

33% cost reduction $240K annual savings

Achieved 33% reduction in AWS infrastructure costs through rightsizing, reserved instances, and resource optimization.

Windows Identity

Windows Server Administration & Management (2000-2022)

10,000+ users 8+ years experience

Comprehensive Windows Server administration across multiple versions (2000-2022) with enterprise-scale deployment and management.

Virtualization Data Center

Virtualization & Data Center Management

200+ VMs managed 99.9% uptime

Managed enterprise virtualization platforms (VMware ESXi/vSphere, Nutanix) supporting 200+ VMs with high availability.

Identity Azure AD

Active Directory & Identity Management

3,000+ users Hybrid identity

Managed enterprise Active Directory infrastructure for 3,000+ users with Azure AD hybrid integration.

M365 Collaboration

Microsoft 365 & Exchange Administration

Enterprise scale DLP enabled

Managed enterprise M365 environment including Exchange Online, SharePoint, and Teams for organization-wide collaboration.

Professional Experience

8+ Years of Progressive Growth from Infrastructure to Security

Mar 2024 – Present Cimpress India Private Limited Remote

Lead Information Security Engineer

(Acting Team Lead)

Team Leadership Program Owner Global Scope

Key Impact

  • Coordinate Incident Response and security operations across a 3,000+ employee organization spanning multiple countries (US, EU, Australia etc.), liaising with Cimpress SOC for investigation and driving remediation with business unit stakeholders
  • Reduced phishing click rates by 65% through security awareness program
  • Cut critical vulnerability backlog by 60% via risk-based prioritization
  • Built executive security dashboards enabling data-driven investment decisions
  • Achieved zero critical audit findings through alignment with global security frameworks and regulatory acts
Apr 2023 – Feb 2024 Cimpress India Private Limited

Lead Cloud Engineer

Migration Lead Cost Owner

Key Impact

  • Migrated hundreds of servers to AWS with zero downtime
  • Saved $240K/year through cloud cost optimization ($60K → $40K/month)
  • Enabled remote workforce with AWS Workspaces for 500+ users
Jul 2021 – Mar 2023 Cimpress India Private Limited

Senior Systems Engineer

Infrastructure Owner

Key Impact

  • Owned VM infrastructure supporting 200+ systems across VMware ESXi/vSphere and Nutanix
  • Led complex migrations: P2P, P2V, V2V, V2C with minimal downtime
  • Accountable for 99.9% uptime across critical infrastructure
Sep 2020 – Jun 2021 Cimpress India Private Limited

Systems Engineer

Key Impact

  • Owned Windows Server ecosystem spanning versions 2003-2022
  • Implemented hybrid identity with Azure AD Connect and Intune
  • Deployed enterprise monitoring using SolarWinds for proactive alerting
Oct 2019 – Aug 2020 ThinkApps Solutions Pvt. Ltd Onsite

Server Engineer

(Client: Leading Media Company)

Key Impact

  • Administered Windows Server for enterprise media infrastructure
  • Managed Microsoft 365 and Group Policy for 500+ users
  • Maintained VMware infrastructure ensuring availability and performance
Nov 2018 – Sep 2019 Microland Limited Onsite

Senior Engineer (Server Management)

(Client: Leading Insurance Company)

Key Impact

  • Managed Active Directory and DC replication for enterprise environment
  • Drove SCCM patching operations ensuring compliance posture
  • Owned O365 and infrastructure monitoring for proactive incident management
May 2017 – Apr 2018 Nityo Infotech Pvt. Ltd Onsite

Desktop Support Engineer

(Client: Leading Banking & Investment Management Company)

Key Impact

  • Led EOSL migration for 2,000+ systems ensuring business continuity
  • Delivered end-user technical support for banking operations
  • Managed IT assets and vendor relationships for hardware lifecycle

Core Skills

Domain expertise across security operations, cloud, and governance

Cloud Security (AWS, Azure, OCI)

AWS Security Architecture Azure Security OCI Security IAM Network Security Logging & Monitoring Secure Cloud Migrations Cloud Architecture Reviews

Security Architecture, Threat Modeling & Design Reviews

Architecture Reviews Threat Modeling Security Design Principles Solution Evaluation Security Sign-off

Security Governance, Risk & Compliance

Risk Register Management Risk Acceptance Workflows SOX User Access Reviews Vendor Security Approvals Security Policy & Framework Authoring Audit Readiness & Evidence ISO 27001 NIST CSF SOC 2 Regulatory Compliance

Security Policy Development (AI Governance, SOPs)

Policy Authoring AI Governance SOPs & Procedures Security Standards Acceptable Use Policies

Vulnerability Management

CVSS-Based Prioritization Asset Criticality Exploitability Analysis Full Lifecycle Management Remediation Tracking (Jira) Weekly Review Cadence

Incident Coordination & Management

P1/P2 Incident Coordination IR Lifecycle Stakeholder Communication Enterprise SOC Liaison Business Unit Remediation

Vendor & Third-Party Security Assessments

Vendor Risk Assessments Third-Party Reviews Security Questionnaires Due Diligence

Security Team Leadership & Mentoring

Team Leadership Daily Standups & 1:1s Junior Mentoring Security Operations Management Performance Management

AppSec, SSDLC & Code Security

Snyk SSDLC Secure Code Awareness Dependency Vulnerability Management Developer Security Training

Security Program Management

Program Strategy Executive Reporting Security Roadmap KPIs & Metrics Stakeholder Management

Certifications

Industry-Recognized Credentials & Qualifications

NEW
CISM Certification Badge

CISM

ISACA

Certified Information Security Manager

Issued Sep 2025 · Expires Jan 2029

Verify
AWS AI Practitioner Foundational Certification Badge

AWS AI Practitioner

Amazon Web Services

Certified AI Practitioner

Issued Dec 2024 · Expires Dec 2027

Verify
AWS Solutions Architect Associate Certification Badge

AWS Solutions Architect

Amazon Web Services

Solutions Architect – Associate

Issued Jul 2024 · Expires Jul 2027

Verify
CompTIA Security+ Certification Badge

CompTIA Security+

CompTIA

Security Fundamentals Certification

Issued May 2024 · Expires May 2027

Verify
Microsoft Azure Security Engineer Associate Certification Badge

Azure Security Engineer

Microsoft

Azure Security Engineer Associate

Issued May 2024 · Expires May 2027

Verify

Get In Touch

Open to Information Security Roles & Collaboration

Email

Phone

Location

Mumbai, India

Open to Opportunities

Open to roles in Cloud Security, Security Architecture, AppSec & SSDLC, GRC, and Security Program Management at Lead, Manager, or Senior Engineer level — in India and Global — Hybrid · Remote