VAPT • SWIFT CSCF • Hardening • Secure Release • Remediation
Security work that goes beyond finding issues and into validation, hardening, and delivery.
I approach security as an engineering and delivery problem, not just a testing exercise. That means validating fixes, improving release readiness, hardening environments, and building systems that make those workflows repeatable.
Customer VAPT & CSP Assessments
Handling customer-facing security engagements across BFSI environments—from initiation and execution to remediation walkthroughs and project closure.
20+
Banking Engagements
200+
Cases Managed
5 ★
Bhutan RMA Satisfaction
SWIFT CSP & CSCF Assessments
The SWIFT Customer Security Programme (CSP) was established to drive cybersecurity alignment and fraud prevention across the global SWIFT financial network. At the core of this initiative is the Customer Security Controls Framework (CSCF), which demands that participating organizations perform an annual independent assessment of their security controls.
A CSCF assessment evaluates both mandatory and advisory controls across key objectives: securing the local infrastructure, preventing and detecting fraud, and responding to incidents. This involves reviewing logical and physical access control boundaries, validating segregation, hardening critical databases and operating systems, and ensuring endpoint monitoring integrity.
Key Assessment Domains Addressed:
- Secure Zone Segmentation
- HSM & Payment Servers
- Multi-Factor Authentication
- Log Auditing & Wazuh SIEM
Securing Major Banking Systems
I have guided over 20+ financial institutions through complex SWIFT audits and secure zone setups. This includes isolating message-handling systems (e.g., SWIFT Alliance Access, Alliance Gateway, SWIFT Web Platform) from general corporate networks to prevent threat propagation.
My engagements have spanned leading banks across India and Bhutan, including:
- Indian Financial Institutions: Successfully managed control implementation and verification for marquee banks including Indian Bank, Indian Overseas Bank, Tamilnad Mercantile Bank, and City Union Bank.
- Bhutan Banking Infrastructure: Led security assessments and secure zone design for major Bhutanese commercial banks and the Royal Monetary Authority of Bhutan (RMA), the central bank of Bhutan, securing a 5-star client satisfaction rating.
* Collaborated closely with internal stakeholders and external assessment groups (KPMG, Deloitte, McKinsey) to achieve 100% compliance attestations with zero critical findings.
SWIFT CSCF Implementation
Supported BFSI customer environments driving implementation readiness, control validation, and evidence collection.
SWIFT CSCF Assessments
End-to-end assessment engagements covering architecture reviews, control validation, gap identification, and remediation walkthroughs.
Customer VAPT Engagements
Enterprise banking VAPT covering vulnerability assessment, remediation validation, rescans, and technical explanation of findings.
Windows & RHEL Hardening
Validating infrastructure security posture at the operating-system level across banking and SWIFT-aligned contexts. This is where security becomes operationally real.
- CIS benchmark-aligned baseline validation
- Windows & RHEL security assessment
- Secure configuration posture review
- Remediation verification
"It is one thing to say a system should be secure. It is another to review the actual configuration, validate what has been implemented, and support teams until the environment is in a defensible state."
NSmart Secure Release & Development
Release Validation
Owned security validation across multiple NSmart releases (v3.20.12.0 - v3.20.18.10), covering vulnerability assessment, regression testing, remediation verification, and release-readiness validation.
Outcome:
Subsequent third-party security assessments returned zero Critical, High, or Major findings.
Secure Development Supported
ECDH-based Session Exchange
Secure frontend-to-backend key exchange.
Meta CSP Implementation
Frontend security hardening.
JavaScript Obfuscation
Reducing exposure of sensitive client-side logic.
Snyk SBOM Scanning
Visibility into library-level risk.
Apache Tomcat Hardening
Improving deployment security posture.
Process Improvement & Internal SOPs
If the same mistakes keep recurring because the process is weak, the technical work is only doing half the job.
Safe VAPT SOP
Authored a structured Web Application Penetration Testing SOP for sensitive banking environments, covering safe execution sequencing, vulnerability validation, and controlled testing methodologies ensuring technical accuracy without disrupting production.
DevSecOps & AI-Assisted Workflows
Introduced process improvements including structured remediation tracking, dependency scanning, AI-assisted validation workflows, and the Remediation Validation Platform to reduce manual release security effort.
Knowledge Transfer & Capability Building
A useful security team needs shared capability. I conducted internal KT sessions for new members and peers on Windows/Linux Security, Web App VAPT, Active Directory, Cyber Kill Chain, and Practical Lab Simulations.
How security connects to the broader picture
My security work overlaps heavily with telemetry platforms, remediation systems, hardening workflows, and customer delivery.