- Own enterprise cloud & AI security strategy across hybrid multi-cloud — setting the operating model and governance direction (Zero Trust, CNAPP, AI security) and reporting risk posture at board level.
- SPOC for the cybersecurity partner ecosystem — executive relationships, term negotiation, roadmap alignment, and joint GTM motions that expanded service revenue.
- Evaluated and integrated AI security posture, hybrid identity, and XDR platforms — reducing MTTD and strengthening board-level risk posture.
- Building reusable AWS Security Accelerators with multi-agent AI — automated assessment engines, Landing Zone hardening blueprints, and LLM security reference architectures.
Himanshu Jain
Security posture, proven — not just documented.
15+ years turning threat landscapes into board-level risk narratives and investment-prioritised roadmaps — pairing governance rigour with modern, automation-led delivery across cloud, Zero Trust, identity, and detection & response.
Profile
Cybersecurity leader with 15+ years across enterprise and highly regulated environments — combining executive security strategy with hands-on architecture.
Experienced in standing up and running security programmes — owning enterprise risk, ISO 27001 / NIST CSF-aligned governance, regulatory compliance, and multi-vendor / MSSP oversight. Proven delivery across cloud (AWS, Azure, hybrid), Zero Trust, identity, and detection & response for government, healthcare, financial-services, and critical-infrastructure-adjacent clients across Asia-Pacific and India.
Security operating models and governance frameworks — policy, risk registers, control baselines and audit readiness — for organisations that need CISO-level leadership.
AI-powered security accelerators and multi-agent workflows that compress cloud assessments and posture hardening from months to days — enterprise assurance at lower cost.
Core competencies
Security Strategy & vCISO Leadership
Operating model, roadmap and budget — CISO-level direction that maps security investment to enterprise risk.
Governance, Risk & Compliance
ISO 27001 · NIST CSF · King IV · POPIA — control baselines, risk registers and audit readiness.
Enterprise & Cloud Security Architecture
AWS · Azure · hybrid · multi-cloud — secure-by-design landing zones, segmentation and encryption.
Identity & Access Management
IAM · PAM · PIM · hybrid identity — federation, least privilege and privileged-access governance.
Threat Detection & Response
SIEM · SOAR · XDR/EDR · IR playbooks — telemetry, automation and measurable MTTD reduction.
Zero Trust & Network Security
Micro-segmentation · ZTNA · segmentation — cutting lateral movement across the estate.
OT / ICS & Critical Infrastructure
IT/OT convergence and risk governance for critical-infrastructure-adjacent environments.
Vendor, MSSP & Programme Governance
Multi-vendor operations, audits and SLAs — holding an ecosystem to a single standard.
AI Security & Automation
LLM security · Bedrock · reusable security accelerators — assurance built with multi-agent AI.
Certifications
AWS Amazon Web Services
AZ Microsoft Azure
+ Specialist & Vendor
Professional experience
- Designed and optimised security architectures for large-scale cloud transformation — authoritative SME for cloud-native security, identity, and threat management.
- Directed Threat & Risk Assessments (TRA), translating findings into C-suite risk narratives and investment-prioritised remediation roadmaps.
- Led EDR/XDR deployment across 10,000+ endpoints (CrowdStrike / SentinelOne) — policy, automation, threat-intel integration, and IR playbooks.
- Architected cloud-native CSPM for hybrid AWS — reduced misconfigurations by 70% in 90 days; micro-segmentation cut lateral-movement risk by 60%.
- Delivered multi-cloud frameworks (AWS + Azure) and drove pre-sales that converted into multi-crore mandates.
- Designed cloud-native posture management for a hybrid Azure AD + on-prem environment, reducing misconfigurations by 70%.
- Deployed an EDR strategy across 10,000+ endpoints using CrowdStrike, with policy automation and threat-intel integration.
- Guided Zscaler ZTNA deployment for 5,000+ users.
- Led security programme delivery and multi-vendor governance in a highly regulated, zero-tolerance environment under Singapore's Ministry of Health.
- Owned policy, risk and compliance oversight across the estate.
- Led AWS cloud transition — secure multi-account environments (IAM, VPC, Organizations, CloudFront); ISMS audits, vendor governance, and vulnerability management.
- Directed IT security operations for Singapore's financial and government programmes — zero major findings across PwC and EY audits; PCI DSS and AGO compliance.
- Managed Tripwire, RSA MFA, McAfee DLP, Imperva WAF, and CyberArk PAM.
- Led a 7-member network security team; multi-site IDS/IPS and firewall deployments.
- F5 LTM, Cisco / Palo Alto rule optimisation, VPN, and SSL lifecycle management.
- End-to-end network security for a US-based global hospitality chain — firewalls (Checkpoint, Cisco, Palo Alto), VPNs, PCI compliance, and incident / change management.
Education
Make your security posture a board-level asset.
Fractional CISO leadership, cloud & AI security architecture, and audit readiness for regulated organisations.