Sushil S. profile photo

Sushil S.

Certified Cyber Lawyer & Digital Forensics Professional | TOGAF®9,PMP, CISSP, CISA, CISM | CISO | Application & IT Security | Data Protection & DPDPA Expert | GRC | Digital Transformation | Speaker | CSO/CIO 100 Awardee

1,797 connections
LinkedIn

About

Lawyer and Certified Cyber Law & Forensic Practitioner with 22 + years of experience in the banking industry across NBFC/BFSI & Insurance Public Sector, Private Sector, and MNC banks. Skilled in IT strategy, digital transformation, and managing complex infrastructure, including hosted Data Centers and MPLS-connected networks across 450+ urban and rural branches. Experienced in cyber investigations, digital forensics, and legal compliance, bridging law, technology, and cybersecurity to strengthen organizational resilience and risk management. Experience working in a risk based environment and completely aware of regulatory environment. Managing delivery of Programs/Projects pertaining to Retail Banking, International Banking, Private Banking and Group functions. TECHNICAL EXPERTISE: • Manage operation and design of enterprise class IT infrastructure including high end Routers, Switches, Servers, telecommunications facilities and network security devices like Firewall, Proxy’s, IPS, SIEM etc. • Strong Network LAN/WAN/WLAN knowledge and troubleshooting skills • Understands the lifecycle of the network threats, attack vectors and methods of exploitation. • Exposure in wan optimizers, load balancers, bandwidth shapers • Security Frameworks - ISO 27001, COBIT, ITIL. • Compliance Experience - PCI-DSS, HIPAA, 21 CFR • Assessment and Risk Management - Penetration Testing, Vulnerability Assessment, Risk / Compliance Assessment CERTIFICATIONS: • ITIL v3 – Information Technology Infrastructure Library • CISSP – Certified Information System Security Professional • Completed PMI Project Management Professional Training • CCNA - Cisco Certified Network Administrator • CCNP - Cisco Certified Network Professional • CCIE Routing and Switching Qual written 350-001 • Cisco Data Center Unified Computing Design Specialist • ISO 27001 LA – Information Security Management System lead Auditor

Experience

S

Head of Technology & Security

Star Union Dai-ichi Life Insurance Company Limited · Full-time

Sep 2025 - Present · 8 mos·Mumbai, Maharashtra, India

Responsible for shaping and executing the organization’s technology and information security strategy, with a strong focus on enabling secure, scalable, and resilient business growth. Include driving digital transformation, strengthening cyber security and risk management, ensuring regulatory compliance with IRDAI and the DPDP Act, and building a robust framework around data governance, privacy, and business continuity. I will also focus on enhancing IT service excellence, managing third-party and cloud risks, and embedding a security-first culture across the organization. Equally important is building high-performing technology and security teams, fostering collaboration across business, risk, legal, and compliance functions, and leveraging innovation to support faster product launches, better customer experience, and operational efficiency.

G

CISO-Head of Information Security & Governance

GHFL · Full-time

Jan 2025 - Sep 2025 · 9 mos·Mumbai, Maharashtra, India

CISO is not limited to ensuring security compliance; it is about enabling the business to operate securely, efficiently, and with strong data protection. Our mission is to embed security into the very fabric of the organization so that innovation, growth, and business agility are not hindered by threats, but instead are empowered by a resilient and adaptive security posture.

N

Information Technology Security Specialist

Nuvama Wealth · Full-time

Nov 2021 - Feb 2025 · 3 yrs 4 mos·Mumbai, Maharashtra, India
N

Consultant-Cyber Security Advisory

NSE ,Singapore Exchange (SGX) & Amazon Web Services (AWS) · Self-employed

Feb 2021 - Nov 2021 · 10 mos·Mumbai, Maharashtra, India

• Developed Information Security strategy and security architecture (ZACHMAN and SABSA models) • Collaborated with top executive management to establish what levels of risk are considered acceptable for the organisation; • Established a corporate-wide information risk management programme to ensure that i. • First in the Indian banking industry to achieve certification in ISO 27001, Business Continuity, and PCI-DSS for the Bank. • Completely implemented an IT GRC solution across the Bank, including access control, data leakage prevention, identity and access management, Two Factor Authentication, and encryption. • Developed, disseminated, and put into action a risk-based procedure for the management of vendor risk, which included the evaluation and mitigation of potential dangers posed by partners, consultants, and other service providers • Developed a framework for the protection of sensitive information that is integrated with the broader information security management system • Offering strategic risk advise for information technology initiatives, including the assessment and recommendation of technological controls • Ensure that security programmed are in conformity with applicable laws, rules, and policies in order to reduce or get rid of audit findings and risks.

H

VP-Information Security Compliance

HDFC Bank · Full-time

Aug 2019 - Feb 2021 · 1 yr 7 mos·Mumbai

• Work closely with related functions or programs like Privacy, Audit, Risk, BCM and coordinate the development of implementation plans and procedures to ensure that business-critical services are recovered in the event of a security event. • Roll out of information security risk assessment program which includes Vulnerability Assessment, Penetration testing, Network & Security Architecture, Application Security reviews, Endpoint security. Skills and experience: • Data protection/GDPR and Information security standards specified by the various regulators policies and procedures • Framework and boundaries as defined by Group. Responsibilities • Manage compliance of Information Security and Information Technology of the organization, consisting of direct reports and indirect reports • Work directly with business units to facilitate IS and IT risk assessment processes • Provide strategic risk guidance for IT projects, including the evaluation and recommendation of technical controls • Provide direction, support and in-house consulting in these areas • Coordinating the information security compliance efforts of all internal and outsourced functions that have one or more information security-related responsibilities, to ensure that organization-wide information security compliance efforts are consistent

Education

S

Symbiosis Law School, Pune

Postgraduate certification in cyber law, Cyber/Computer Forensics and Counterterrorism, Cyber/Computer Forensics and Counterterrorism

Apr 2025

P

Punjab Technical University

MBA, IT, IT

2009 - 2010