Ashish Shrivastava
Director of Cyber Security @ Honeywell
About
I help organizations scale secure innovation in an era of AI-enabled products, connected industrial systems, and increasingly stringent global regulations. With 20 years of progressive leadership experience, I specialize in Product Security, AI Security, OT/Industrial Cybersecurity, and Enterprise Cyber Risk Management, enabling organizations to deliver trusted, resilient, and compliant products at scale. As Director – Cyber Security at Honeywell, I lead global security strategy, architecture, and engineering initiatives across industrial products, digital platforms, and cloud-connected services. I partner closely with engineering, product management, legal, and executive leadership to embed security and privacy by design across the full product lifecycle—from concept and architecture to deployment and operations. I am a trusted advisor to the CTO and senior leadership, guiding strategic decisions related to AI risk, secure product architecture, software supply chain security, and regulatory readiness. My work increasingly focuses on AI and ML system security, including threat modeling for AI-enabled features, secure data pipelines, model risk considerations, and governance alignment to ensure responsible and secure AI adoption. I have built and scaled global programs covering Secure SDLC, threat modeling, PSIRT, vulnerability management, DevSecOps, data protection, and supplier risk management, driving efficiency through automation, analytics, and measurable security outcomes, ensuring security acts as a business enabler. With deep experience in OT and critical infrastructure environments, I have led initiatives aligned to ISA/IEC 62443, strengthening product and system resilience across industrial control systems. I also drive compliance and readiness for EU Cyber Resilience Act (CRA), EU Radio Equipment Directive (RED), NIST frameworks, GDPR, and secure open-source governance through Open Source Program Office (OSPO) leadership. I am passionate about building a security-first engineering culture, mentoring future security leaders, and actively engaging with industry and standards communities to advance modern product, AI, and industrial cybersecurity practices. Core Expertise & Keywords: AI Security | Product Security Leadership | OT & Industrial Cybersecurity | Secure Software Development (Secure SDLC, SSDF) | Threat Modeling | DevSecOps | Software Supply Chain Security | Cyber & Privacy Risk Management | PSIRT | Security Governance | Regulatory Compliance (ISA/IEC 62443, EU-CRA, EU-RED, NIST, GDPR) | OSPO & Open-Source Security
India
Bengaluru
Computer & Network Security
Certified Chief Information Security Officer (CCISO) Online Training & Certification Course, Thought Leader Platform, Community and Influencer Marketplace, AI sec, Cybersecurity, Security Testing Orchestration, Information Security Management, Cloud Security, C, Linux, C++, Security, Embedded Systems, Algorithms, Agile Methodologies, RTOS, Multithreading, Linux Kernel, Embedded Software, TCP/IP, Data Security
Experience

Director of Cyber Security
Bengaluru, Karnataka, India
As a Product Cybersecurity Leader and trusted advisor to executive leadership, I provide strategic direction and hands-on leadership for the design, execution, and continuous evolution of Honeywell’s global product cybersecurity program. I drive security outcomes across industrial products, OT environments, and digital services, ensuring security enables innovation, customer trust, and regulatory readiness. I lead the end-to-end implementation of Product Security and Secure SDLC, embedding security and privacy by design across the product lifecycle—from architecture and development through deployment and operations. My role bridges engineering, product, legal, and executive stakeholders, enabling informed, risk-based business decisions aligned with corporate strategy. I have successfully driven adoption and certification against critical industrial and regulatory frameworks, including ISA/IEC 62443 for IACS, Secure Software Development Framework (SSDF), and EU Radio Equipment Directive (RED) 2014/53/EU. I currently spearhead enterprise initiatives to align products with the EU Cyber Resilience Act (CRA) and lead the establishment of an Open Source Program Office (OSPO) to strengthen software supply chain security and open-source governance. Key responsibilities and impact include: - Provide strategic leadership for Honeywell’s global product cybersecurity strategy, balancing security, compliance, and business objectives. - Act as a trusted advisor to the CTO and senior leadership, translating cyber risk into executive-level decision support. - Govern and enforce product security practices across architecture, engineering, and operations. - Lead OT and industrial cybersecurity initiatives, strengthening resilience of IACS-aligned products. - Define and track security metrics and KPIs to measure program effectiveness and drive continuous improvement. - Influence and mentor senior leaders and engineering teams, fostering a security-first culture.

Product Security Leader | Senior Cyber Security Manager
Bengaluru, Karnataka, India
Working as a Product security leader cyber security, here Leading the global Product Security team, responsible for secure development. I am responsible for performing Security and Privacy Assessments for Healthcare & Hospital products. Below are the responsibilities handled during the assessments, • Responsible for designing, building, testing and implementing security systems to ensure security/ safety of Baxter medical devices and the ecosystem they operate in. As a Security Architect also responsible to respond promptly and effectively to possible breaches of security. It also Include a strategic understanding of the business, customer/ patient needs. • Proactively drive the security requirements phase along with the product owner(s). Implement Proof of Concept projects to define innovative security solutions. Proactively derive the implementation of medical device cybersecurity functionalities that are part of the overall security architecture. Support medical device cybersecurity certification programs. • Assess security findings from various system validation activities. This includes Static code analysis and penetration test. Identify known/unknown vulnerabilities associated with Baxter’s medical devices, and provide inputs/technical expertise to multiple devices, and provide inputs/technical expertise to multiple teams to eliminate/mitigate identified cybersecurity risks. • Perform impact assessment, threat modeling, technical and operational feasibility on the appropriate technology, detect critical cyber security deficiencies, and recommend solutions for improvement. • Assist with the research, evaluation and design of new technologies, architectures, and security products that will support business security requirements for the enterprise and its third-party service providers.

Product Cyber Security Leader | Security Architect | Product Security & Privacy Officer
Bengaluru Area, India
As Product Cyber Security Leader, I provide strategic leadership in the design and execution of the company product cybersecurity program. Responsible for performing Security and Privacy Assessments for the Strategic Innovation Group projects in Philips, which is responsible for providing the healthcare solutions for the Emerging Markets. My responsibilities include, • Provide strategic leadership in the design and execution of the company product cybersecurity program. • Review of health suite platform, which includes all the platform micro services from security and privacy perspective, identify the risks, and suggest mitigations to the team. • Hands on experience in performing information security reviews of application designs architecture & application development. Experience working on secure development practices. • Responsible for planning, design, implementation, attack mitigation and ongoing support of security systems of high complexity to fulfill the business needs. • Collaborate with CTO, Engineering leader, Architects, and developers to understand Organization external and internal security and privacy compliance requirements. • Balance cybersecurity requirements with business needs while providing technical expertise to the CTO enabling informed business risk decisions. • Knowledge of industry security frameworks and regulatory standards such as FIPS140-2, ISO-27001, NIST Framework for Improving Critical Infrastructure Cybersecurity HIPAA, data protection and Cloud Security best practices and guidelines. • Ensure effective DevSecOps integration into Agile CD/CD release trains. • Govern and enforce effective implementation of product security practice throughout the entire lifecycle. • Train and mentor product design and development teams on cybersecurity awareness, secure by design, privacy by design, Threat modeling and secure coding practices. • Ensure that product portfolio meets current and emerging cyber regulatory and privacy requirements

Cyber Security Specialist, Architect, Consultant
Bangalore
My responsibilities included as Security leader ● Own and drive the development of secure coding program including standards and best practices. ● Promote best practice throughout engineering team at all stages of SDLC by performing code reviews, giving training and mentoring. Secure coding guideline and Developer Education & Security Evangelist ● Requirements Gathering, Resource Planning, Scheduling, Process Improvement, Collaborative Leader, Knowledge of Design and Development various activity of Mobile Security Platform. ● Act as Security Applications Architect, providing consulting solutions and support to application development teams. ● Actively manage the security activities associated with Secure Software Development to address existing and evolving risks and threats appropriately. ● Application privilege design and implementation review ● Smack based Access control and sand-boxing for native and web apps ● Secure application life cycle (Permissions, Signing, SDK, and so on) ● Responsible for Security Modules Development it includes (PKI, PKCS, X.509, Crypto, OCSP, Signing Tool, Access Control, SSL, OpenSSL), Platform Security Vulnerability Analysis. ● Creating project plans and schedules, managing resource allocation, people management. Resource allocation management.

Security Development Lead
Bangalore
I have worked on Samsung Mobile Development. My area of work includes Mobile Security. I have been working on different Security areas in mobile, it includes PKI, PKCS, Cryptography, SSL etc. I have been involved in implementation of different Security algorithms and standards. Projects worked Involved : PKI, PKCS, Authentication Module, Crypto Algorithm, Access Control, C,C++, IPC. ● Responsibilities include design and development of security module like Security Reports, SPD, certificate Management for mobile. ● Leading a team which caters requirements for mobile security issue. ● Ownership of security module commercialization. ● Non-technical responsibility includes customer interaction, Requirement analysis, release plan, team management, schedule plan. ● Technical responsibility includes design and development of key features.

Lead Cyber Security Engineer
Bangalore
* security research in detecting and mitigating security vulnerabilities, customer communications on product security-related issues. * Knowledge of secure protocols/standards (such as SSL/TLS, PKI, PKCS) * Knowledge of the internals of mobile or embedded operating systems * Experience of applying software static or dynamic analysis tools (such as Klocwork, Coverity, LLVM sanitizers and popular fuzzing tools) * Mobile platform security such as Android * Secure code review, analysis and vulnerability assessment * Product security incident response in mobile, embedded device or automotive industry

Senior Software Security Engineer
Bangaon Area, India
Promote best practice throughout engineering team at all stages of Secure SDLC by performing secure code reviews, giving training and mentoring on Cyber security, Security best practices & guideline creator, Developer Education & Security Evangelist. • Worked as a security module developer and is responsible for Development of security related feature. Developed and deliver Information Security Awareness training program for senior management and other employees. • Responsible for the open source contribution in Evolution mail client for GNOME. As a co-maintainer of Contact Management (Address Book), I was responsible for design and development of feature.

Security Software Engineer
Bangalore
I have worked as a security module developer i.e. Certificate management feature, PKI etc. Actively manage the security activities associated with Secure Software Development to address existing and evolving risks and threats appropriately. As a module lead I was responsible for the design and development of interface for Screen and web access, software upgrade, video enhancement over call control/Call processing. Played important role in system design. Involved in Requirement analysis, Preparing requirement and functional specification document, time estimation, Contributed in Unit, Integration and System testing and various types of stress and acceptance testing. Languages Used: C programming, SIP-VoIP protocol, Linux Internals, Multithreading, Socket Programming, IPC Mechanism. Platform Used: Embedded Linux
Ashish Shrivastava 's Contact Information
Phone
Find the Right Leads
Find Verified Contact Data
What LeadContact does well
Find verified emails, phone numbers, and decision-makers with 98% accuracy.
Find Leads
Find the right people by company, role, industry, location, and more.
925M+ professional profiles

Find Emails
Access verified email addresses for your target contacts.
657M+ emails

Find Phone Numbers
Get cross-validated phone data from multiple top sources.
239M+ phone numbers

More Accurate. Lower Cost.
Find contact data in 1 tool with 98% accuracy
LeadContact integrates leading enrichment tools to deliver more accurate contact data—without paying for each one.
Great conversations start with the right contact.
It’s time to find yours.



