Akshay Suryawanshi

Lead Information Security Engineer & Acting Team Lead

Cloud Security · Security Architecture · AI Security · GRC

I build and lead end-to-end security programs for enterprise platforms operating across the US, Europe, Australia, and New Zealand — across multi-cloud environments.

Currently securing National Pen (a Cimpress company) — 3,000+ employees across 22 countries. Exploring new opportunities — India & Global | Remote · Hybrid.

Akshay Suryawanshi - Lead Information Security Engineer

Impact

Outcome-focused initiatives across security operations, governance, and program leadership

  • Led 6 P1 security incidents end-to-end in FY26 — including a third-party supply-chain compromise and an enterprise cloud environment breach — coordinating response across the BU and Cimpress Group Security

  • Reduced phishing click-through rates by 65% through a simulation and awareness program covering 3,000+ employees across the US, Europe, Australia, and New Zealand

  • Authored the enterprise AI Usage & Governance Policy — aligning with NIST AI RMF and EU AI Act requirements — governing ChatGPT, Copilot, and Gemini usage across the organization

  • Designed and implemented cloud security architecture assessments and threat modeling across AWS, Azure, and OCI — evaluating, approving, or rejecting new solutions from a security perspective

  • Own the GRC program for the business unit — aligning controls with ISO 27001, SOC 2, NIST CSF, GDPR, CCPA, and managing quarterly SOX User Access Reviews

  • Initiated the developer security training program via Snyk — driving SSDLC adoption and coordinating code vulnerability remediation across all development teams

  • Authored the Security Architecture Best Practices document — serving as the security baseline for all new solution designs and architecture reviews across the business unit

  • Built and lead the BU InfoSec team — hiring, mentoring PR1–PR3 engineers, running daily operations, and presenting security roadmaps to the Extended Leadership Team

Infrastructure & Cloud Impact

Security-first cloud architecture, governance, and large-scale migrations

Cloud Cost Optimization

$240K+ Annual Cost Savings
33% Infrastructure Cost Reduction

Migration & Scale

500+ Servers Migrated to AWS

Security-first cloud migration approach

Case Studies

Selected initiatives shown as Problem → Approach → Outcome

Incident Response DFIR SOC

Incident Response — Enterprise Supply-Chain Attack

Led end-to-end response to a third-party supply-chain compromise affecting enterprise infrastructure.

AI Security GRC Policy

AI Governance — Enterprise AI Usage & Governance Policy

Authored the organization's first AI governance policy — aligning with NIST AI RMF and EU AI Act.

Cloud Security AWS Architecture

Cloud Security — AWS Network Security Hardening

Led AWS network security hardening — designing phased NACL controls and tightening Security Group port restrictions across the cloud environment.

Security Awareness Human Risk Metrics

Human Risk — Phishing Simulation Program

Designed and executed a phishing program that reduced click-through rates by 65%.

Threat Modeling Security Architecture STRIDE

Threat Modeling — STRIDE Implementation for Cloud Applications

Built the threat modeling program from scratch using STRIDE methodology.

More case studies coming soon →

Core Domains

Specialized expertise across seven key security domains

Cloud Security

Independent cloud security assessments across AWS, Azure, and OCI — covering IAM, network segmentation, compute hardening, logging, and monitoring.

Security Architecture & Threat Modeling

Independently evaluate, approve, and reject new solutions and architectures from a security perspective. Perform threat modeling as part of security architecture reviews.

Vulnerability Management

End-to-end vulnerability management program — scanning, risk-based prioritization using CVSS and asset criticality, SLA-driven remediation, and executive reporting.

Incident Coordination

Coordinate incident response across the business unit (3,000+ employees, multiple countries (US, EU, Australia etc.), liaising with Cimpress SOC for investigation and driving remediation.

Governance, Policy & Vendor Security

Policy authoring, SOPs, and security framework ownership for the BU. Risk Register management and Risk Acceptance workflows. Vendor security assessments with formal approval/rejection authority. SOX User Access Reviews (quarterly). Compliance alignment with ISO 27001, NIST CSF, GDPR, CCPA, and SOC 2.

AI Security & Governance

Authored the enterprise AI Usage & Governance Policy aligned with NIST AI RMF and EU AI Act. Govern adoption of ChatGPT, Copilot, and Gemini across the organization. Define data-handling rules, prohibited use cases, and approval workflows for new AI tools.

SSDLC, Code Security & Supply Chain Security

Driving secure development lifecycle adoption via Snyk, managing dependency vulnerability remediation with dev teams, and securing the software supply chain.

Projects & Key Initiatives

Delivering Measurable Outcomes Across Security & Infrastructure

Information Security

SOC Automation

AI-Driven SOC Triage Automation

~50% faster triage 200+ daily alerts processed

Built intelligent L1 alert triage workflow reducing manual investigation by ~50% through AI and automation.

GRC

AI Usage & Governance Policy

Org-wide policy Responsible AI adoption

Authored the organization's AI Usage and Governance Policy, establishing guardrails for responsible and secure AI adoption across the business unit.

GRC SOC

NIST-Aligned Incident Response Program

NIST aligned P1-P4 workflows

Developed comprehensive IR framework with defined RACI, escalation workflows, playbooks, and metrics.

Cloud Security

Multi-Cloud Security Architecture Reviews

40% reduced attack surface 3 Clouds AWS/Azure/OCI

Conducted comprehensive security assessments across AWS, OCI, and Azure reducing attack surface significantly.

VM

Vulnerability Management Program

60% backlog reduction 7-day critical SLA

Established the business unit vulnerability management program with risk-based prioritization and SLA-driven remediation.

GRC

Security Awareness & Phishing Simulation Program

65% click rate reduction 95%+ training completion

Implemented comprehensive security awareness training with monthly phishing simulations reducing click rates by 65%.

VM GRC

Penetration Testing Remediation Coordination

100% critical SLA met

Coordinated annual penetration testing remediation efforts with enterprise pentest team, driving cross-functional fixes for critical vulnerabilities.

Security Ops

Threat Intelligence Operationalization

40% faster detection 3+ TI platforms

Operationalized enterprise threat intelligence platforms for the business unit, enabling proactive threat detection and dark web monitoring.

Network

Firewall Security Review & Rule Optimization

35% rules reduced 1000+ rules reviewed

Conducted comprehensive firewall security reviews to identify misconfigurations, optimize rulesets, and reduce attack surface.

GRC

GRC

Global Retention Policy & Data Governance

30% storage savings GDPR/CCPA compliant

Led organization-wide data retention policy project ensuring compliance with GDPR, CCPA, and industry regulations.

GRC

ISO 27001 & Compliance Framework

Zero critical findings 60% faster audit prep

Aligned security program with ISO 27001, NIST CSF, and CIS Controls for audit readiness and continuous compliance.

Leadership GRC

Executive Security Metrics & Dashboards

C-level reporting Data-driven decisions

Built comprehensive security KPI dashboards for C-level executives and board reporting.

Security Architecture GRC

Architecture Best Security Practices

Org-wide baseline Security-by-Design

Authored the Architecture Best Security Practices document, serving as the security baseline for all new solution designs across the business unit.

Infrastructure: Windows Server (2000-2022), On-Premise, Virtual & Cloud Engineering

Cloud AWS

AWS Large-Scale Migration (Hundreds of Servers)

500+ servers migrated Zero downtime

Led end-to-end migration of 500+ on-premises servers to AWS using Application Migration Service.

Cloud FinOps

Cloud Cost Optimization Initiative

33% cost reduction $240K annual savings

Achieved 33% reduction in AWS infrastructure costs through rightsizing, reserved instances, and resource optimization.

Windows Identity

Windows Server Administration & Management (2000-2022)

10,000+ users 8+ years experience

Comprehensive Windows Server administration across multiple versions (2000-2022) with enterprise-scale deployment and management.

Virtualization Data Center

Virtualization & Data Center Management

200+ VMs managed 99.9% uptime

Managed enterprise virtualization platforms (VMware ESXi/vSphere, Nutanix) supporting 200+ VMs with high availability.

Identity Azure AD

Active Directory & Identity Management

3,000+ users Hybrid identity

Managed enterprise Active Directory infrastructure for 3,000+ users with Azure AD hybrid integration.

M365 Collaboration

Microsoft 365 & Exchange Administration

Enterprise scale DLP enabled

Managed enterprise M365 environment including Exchange Online, SharePoint, and Teams for organization-wide collaboration.

Leadership

Building teams. Owning programs. Translating security risk into business decisions.

Team Building

Rebuilt the BU InfoSec team after multiple departures — creating job descriptions, leading the hiring process for Senior InfoSec Engineers, and mentoring team members from PR1 to PR3 level. Currently leading a team across L1, L2, and L3 security functions.

Stakeholder Management

Present security roadmaps, metrics, and initiative progress to the Extended Leadership Team (ELT). Manage upward through the CTO chain — reporting to the Senior Manager of InfoSec, who reports to the Sr. Director of Technical Services, who reports to the CTO.

Program Ownership

Own the complete information security program for a business unit with 3,000+ employees operating across the US, Europe, Australia, and New Zealand. The BU security team operates largely independently — handling SOC, DFIR, threat intelligence, GRC, and cloud security — with Cimpress Group Security engaged for P1/P2 escalations.

Risk-to-Business Translation

Translate technical security risks into business language for leadership. Own formal risk acceptance workflows where business justification overrides security recommendations — ensuring risks are documented, tracked annually, and reviewed with stakeholders.

Professional Experience

8+ Years of Progressive Growth from Infrastructure to Security

A deliberate career pivot — from desktop support and Windows Server administration into virtualization, then cloud engineering, then security. Each prior layer of the stack is now first-hand context for security architecture decisions, threat modeling, and incident response.

Mar 2024 – Present Cimpress India Private Limited Remote

Lead Information Security Engineer

(Acting Team Lead)

Team Leadership Program Owner Global Scope

Key Impact

  • Coordinate Incident Response and security operations across a 3,000+ employee organization spanning multiple countries (US, EU, Australia etc.), liaising with Cimpress SOC for investigation and driving remediation with business unit stakeholders
  • Reduced phishing click rates by 65% through security awareness program
  • Cut critical vulnerability backlog by 60% via risk-based prioritization
  • Built executive security dashboards enabling data-driven investment decisions
  • Achieved zero critical audit findings through alignment with global security frameworks and regulatory acts
Apr 2023 – Feb 2024 Cimpress India Private Limited

Lead Cloud Engineer

Migration Lead Cost Owner

Key Impact

  • Migrated hundreds of servers to AWS with zero downtime
  • Saved $240K/year through cloud cost optimization ($60K → $40K/month)
  • Enabled remote workforce with AWS Workspaces for 500+ users
Jul 2021 – Mar 2023 Cimpress India Private Limited

Senior Systems Engineer

Infrastructure Owner

Key Impact

  • Owned VM infrastructure supporting 200+ systems across VMware ESXi/vSphere and Nutanix
  • Led complex migrations: P2P, P2V, V2V, V2C with minimal downtime
  • Accountable for 99.9% uptime across critical infrastructure
Sep 2020 – Jun 2021 Cimpress India Private Limited

Systems Engineer

Key Impact

  • Owned Windows Server ecosystem spanning versions 2003-2022
  • Implemented hybrid identity with Azure AD Connect and Intune
  • Deployed enterprise monitoring using SolarWinds for proactive alerting
Oct 2019 – Aug 2020 ThinkApps Solutions Pvt. Ltd Onsite

Server Engineer

(Client: Leading Media Company)

Key Impact

  • Administered Windows Server for enterprise media infrastructure
  • Managed Microsoft 365 and Group Policy for 500+ users
  • Maintained VMware infrastructure ensuring availability and performance
Nov 2018 – Sep 2019 Microland Limited Onsite

Senior Engineer (Server Management)

(Client: Leading Insurance Company)

Key Impact

  • Managed Active Directory and DC replication for enterprise environment
  • Drove SCCM patching operations ensuring compliance posture
  • Owned O365 and infrastructure monitoring for proactive incident management
May 2017 – Apr 2018 Nityo Infotech Pvt. Ltd Onsite

Desktop Support Engineer

(Client: Leading Banking & Investment Management Company)

Key Impact

  • Led EOSL migration for 2,000+ systems ensuring business continuity
  • Delivered end-user technical support for banking operations
  • Managed IT assets and vendor relationships for hardware lifecycle

Certifications

Industry-Recognized Credentials & Qualifications

NEW
CISM Certification Badge

CISM

ISACA

Certified Information Security Manager

Issued Sep 2025 · Expires Jan 2029

Verify
AWS AI Practitioner Foundational Certification Badge

AWS AI Practitioner

Amazon Web Services

Certified AI Practitioner

Issued Dec 2024 · Expires Dec 2027

Verify
AWS Solutions Architect Associate Certification Badge

AWS Solutions Architect

Amazon Web Services

Solutions Architect – Associate

Issued Jul 2024 · Expires Jul 2027

Verify
CompTIA Security+ Certification Badge

CompTIA Security+

CompTIA

Security Fundamentals Certification

Issued May 2024 · Expires May 2027

Verify
Microsoft Azure Security Engineer Associate Certification Badge

Azure Security Engineer

Microsoft

Azure Security Engineer Associate

Issued May 2024 · Expires May 2027

Verify

Get In Touch

Open to Information Security Roles & Collaboration

Email

Phone

Location

Mumbai, India

Availability

Open to India & Global · Remote · Hybrid roles

Open to Opportunities

Open to roles in Cloud Security, Security Architecture, AppSec & SSDLC, GRC, and Security Program Management at Lead, Manager, or Senior Engineer level — in India and Global — Hybrid · Remote