I've delivered risk assessments, pentest assurance, and audit-ready security documentation at AXA, helping align global applications with regulatory risk appetites and AXA's Pentest Framework.
Previously, I built HIPAA- and ISO27001-compliant security frameworks for US healthcare and IT startups, led penetration testing for Fortune 500 clients at EY, and performed application and network vulnerability validation at Indusface. My work spans GRC, SOC2, HIPAA, ISO27001, web/API/network VAPT, threat modeling, cloud security, policy development, and incident-response planning.
