Ashish  Shrivastava

Ashish Shrivastava

Director of Cyber Security @ Honeywell

About

I help organizations scale secure innovation in an era of AI-enabled products, connected industrial systems, and increasingly stringent global regulations. With 20 years of progressive leadership experience, I specialize in Product Security, AI Security, OT/Industrial Cybersecurity, and Enterprise Cyber Risk Management, enabling organizations to deliver trusted, resilient, and compliant products at scale. As Director – Cyber Security at Honeywell, I lead global security strategy, architecture, and engineering initiatives across industrial products, digital platforms, and cloud-connected services. I partner closely with engineering, product management, legal, and executive leadership to embed security and privacy by design across the full product lifecycle—from concept and architecture to deployment and operations. I am a trusted advisor to the CTO and senior leadership, guiding strategic decisions related to AI risk, secure product architecture, software supply chain security, and regulatory readiness. My work increasingly focuses on AI and ML system security, including threat modeling for AI-enabled features, secure data pipelines, model risk considerations, and governance alignment to ensure responsible and secure AI adoption. I have built and scaled global programs covering Secure SDLC, threat modeling, PSIRT, vulnerability management, DevSecOps, data protection, and supplier risk management, driving efficiency through automation, analytics, and measurable security outcomes, ensuring security acts as a business enabler. With deep experience in OT and critical infrastructure environments, I have led initiatives aligned to ISA/IEC 62443, strengthening product and system resilience across industrial control systems. I also drive compliance and readiness for EU Cyber Resilience Act (CRA), EU Radio Equipment Directive (RED), NIST frameworks, GDPR, and secure open-source governance through Open Source Program Office (OSPO) leadership. I am passionate about building a security-first engineering culture, mentoring future security leaders, and actively engaging with industry and standards communities to advance modern product, AI, and industrial cybersecurity practices. Core Expertise & Keywords: AI Security | Product Security Leadership | OT & Industrial Cybersecurity | Secure Software Development (Secure SDLC, SSDF) | Threat Modeling | DevSecOps | Software Supply Chain Security | Cyber & Privacy Risk Management | PSIRT | Security Governance | Regulatory Compliance (ISA/IEC 62443, EU-CRA, EU-RED, NIST, GDPR) | OSPO & Open-Source Security

Country

India

City

Bengaluru

Industry

Computer & Network Security

Skill

Certified Chief Information Security Officer (CCISO) Online Training & Certification Course, Thought Leader Platform, Community and Influencer Marketplace, AI sec, Cybersecurity, Security Testing Orchestration, Information Security Management, Cloud Security, C, Linux, C++, Security, Embedded Systems, Algorithms, Agile Methodologies, RTOS, Multithreading, Linux Kernel, Embedded Software, TCP/IP, Data Security

Experience

Honeywell

Director of Cyber Security

Honeywell

LinkedIn
2022-5 - Present · 4 yrs 5 mos

Bengaluru, Karnataka, India

As a Product Cybersecurity Leader and trusted advisor to executive leadership, I provide strategic direction and hands-on leadership for the design, execution, and continuous evolution of Honeywell’s global product cybersecurity program. I drive security outcomes across industrial products, OT environments, and digital services, ensuring security enables innovation, customer trust, and regulatory readiness. I lead the end-to-end implementation of Product Security and Secure SDLC, embedding security and privacy by design across the product lifecycle—from architecture and development through deployment and operations. My role bridges engineering, product, legal, and executive stakeholders, enabling informed, risk-based business decisions aligned with corporate strategy. I have successfully driven adoption and certification against critical industrial and regulatory frameworks, including ISA/IEC 62443 for IACS, Secure Software Development Framework (SSDF), and EU Radio Equipment Directive (RED) 2014/53/EU. I currently spearhead enterprise initiatives to align products with the EU Cyber Resilience Act (CRA) and lead the establishment of an Open Source Program Office (OSPO) to strengthen software supply chain security and open-source governance. Key responsibilities and impact include: - Provide strategic leadership for Honeywell’s global product cybersecurity strategy, balancing security, compliance, and business objectives. - Act as a trusted advisor to the CTO and senior leadership, translating cyber risk into executive-level decision support. - Govern and enforce product security practices across architecture, engineering, and operations. - Lead OT and industrial cybersecurity initiatives, strengthening resilience of IACS-aligned products. - Define and track security metrics and KPIs to measure program effectiveness and drive continuous improvement. - Influence and mentor senior leaders and engineering teams, fostering a security-first culture.

Baxter International Inc.

Product Security Leader | Senior Cyber Security Manager

Baxter International Inc.

LinkedIn
2021-12 - 2022-5 · 6 mos

Bengaluru, Karnataka, India

Working as a Product security leader cyber security, here Leading the global Product Security team, responsible for secure development. I am responsible for performing Security and Privacy Assessments for Healthcare & Hospital products. Below are the responsibilities handled during the assessments, • Responsible for designing, building, testing and implementing security systems to ensure security/ safety of Baxter medical devices and the ecosystem they operate in. As a Security Architect also responsible to respond promptly and effectively to possible breaches of security. It also Include a strategic understanding of the business, customer/ patient needs. • Proactively drive the security requirements phase along with the product owner(s). Implement Proof of Concept projects to define innovative security solutions. Proactively derive the implementation of medical device cybersecurity functionalities that are part of the overall security architecture. Support medical device cybersecurity certification programs. • Assess security findings from various system validation activities. This includes Static code analysis and penetration test. Identify known/unknown vulnerabilities associated with Baxter’s medical devices, and provide inputs/technical expertise to multiple devices, and provide inputs/technical expertise to multiple teams to eliminate/mitigate identified cybersecurity risks. • Perform impact assessment, threat modeling, technical and operational feasibility on the appropriate technology, detect critical cyber security deficiencies, and recommend solutions for improvement. • Assist with the research, evaluation and design of new technologies, architectures, and security products that will support business security requirements for the enterprise and its third-party service providers.

Philips

Product Cyber Security Leader | Security Architect | Product Security & Privacy Officer

Philips

LinkedIn
2016-9 - 2021-12 · 5 yrs 4 mos

Bengaluru Area, India

As Product Cyber Security Leader, I provide strategic leadership in the design and execution of the company product cybersecurity program. Responsible for performing Security and Privacy Assessments for the Strategic Innovation Group projects in Philips, which is responsible for providing the healthcare solutions for the Emerging Markets. My responsibilities include, • Provide strategic leadership in the design and execution of the company product cybersecurity program. • Review of health suite platform, which includes all the platform micro services from security and privacy perspective, identify the risks, and suggest mitigations to the team. • Hands on experience in performing information security reviews of application designs architecture & application development. Experience working on secure development practices. • Responsible for planning, design, implementation, attack mitigation and ongoing support of security systems of high complexity to fulfill the business needs. • Collaborate with CTO, Engineering leader, Architects, and developers to understand Organization external and internal security and privacy compliance requirements. • Balance cybersecurity requirements with business needs while providing technical expertise to the CTO enabling informed business risk decisions. • Knowledge of industry security frameworks and regulatory standards such as FIPS140-2, ISO-27001, NIST Framework for Improving Critical Infrastructure Cybersecurity HIPAA, data protection and Cloud Security best practices and guidelines. • Ensure effective DevSecOps integration into Agile CD/CD release trains. • Govern and enforce effective implementation of product security practice throughout the entire lifecycle. • Train and mentor product design and development teams on cybersecurity awareness, secure by design, privacy by design, Threat modeling and secure coding practices. • Ensure that product portfolio meets current and emerging cyber regulatory and privacy requirements

Samsung Electronics

Cyber Security Specialist, Architect, Consultant

Samsung Electronics

LinkedIn
2013-4 - 2016-9 · 3 yrs 6 mos

Bangalore

My responsibilities included as Security leader ● Own and drive the development of secure coding program including standards and best practices. ● Promote best practice throughout engineering team at all stages of SDLC by performing code reviews, giving training and mentoring. Secure coding guideline and Developer Education & Security Evangelist ● Requirements Gathering, Resource Planning, Scheduling, Process Improvement, Collaborative Leader, Knowledge of Design and Development various activity of Mobile Security Platform. ● Act as Security Applications Architect, providing consulting solutions and support to application development teams. ● Actively manage the security activities associated with Secure Software Development to address existing and evolving risks and threats appropriately. ● Application privilege design and implementation review ● Smack based Access control and sand-boxing for native and web apps ● Secure application life cycle (Permissions, Signing, SDK, and so on) ● Responsible for Security Modules Development it includes (PKI, PKCS, X.509, Crypto, OCSP, Signing Tool, Access Control, SSL, OpenSSL), Platform Security Vulnerability Analysis. ● Creating project plans and schedules, managing resource allocation, people management. Resource allocation management.

Samsung Electronics

Security Development Lead

Samsung Electronics

LinkedIn
2011-4 - 2013-3 · 2 yrs

Bangalore

I have worked on Samsung Mobile Development. My area of work includes Mobile Security. I have been working on different Security areas in mobile, it includes PKI, PKCS, Cryptography, SSL etc. I have been involved in implementation of different Security algorithms and standards. Projects worked Involved : PKI, PKCS, Authentication Module, Crypto Algorithm, Access Control, C,C++, IPC. ● Responsibilities include design and development of security module like Security Reports, SPD, certificate Management for mobile. ● Leading a team which caters requirements for mobile security issue. ● Ownership of security module commercialization. ● Non-technical responsibility includes customer interaction, Requirement analysis, release plan, team management, schedule plan. ● Technical responsibility includes design and development of key features.

Samsung Electronics

Lead Cyber Security Engineer

Samsung Electronics

LinkedIn
2009-5 - 2011-3 · 1 yr 11 mos

Bangalore

* security research in detecting and mitigating security vulnerabilities, customer communications on product security-related issues. * Knowledge of secure protocols/standards (such as SSL/TLS, PKI, PKCS) * Knowledge of the internals of mobile or embedded operating systems * Experience of applying software static or dynamic analysis tools (such as Klocwork, Coverity, LLVM sanitizers and popular fuzzing tools) * Mobile platform security such as Android * Secure code review, analysis and vulnerability assessment * Product security incident response in mobile, embedded device or automotive industry

Novell

Senior Software Security Engineer

Novell

LinkedIn
2007-5 - 2009-3 · 1 yr 11 mos

Bangaon Area, India

Promote best practice throughout engineering team at all stages of Secure SDLC by performing secure code reviews, giving training and mentoring on Cyber security, Security best practices & guideline creator, Developer Education & Security Evangelist. • Worked as a security module developer and is responsible for Development of security related feature. Developed and deliver Information Security Awareness training program for senior management and other employees. • Responsible for the open source contribution in Evolution mail client for GNOME. As a co-maintainer of Contact Management (Address Book), I was responsible for design and development of feature.

Dlink Link India Limited

Security Software Engineer

Dlink Link India Limited

LinkedIn
2004-8 - 2007-4 · 2 yrs 9 mos

Bangalore

I have worked as a security module developer i.e. Certificate management feature, PKI etc. Actively manage the security activities associated with Secure Software Development to address existing and evolving risks and threats appropriately. As a module lead I was responsible for the design and development of interface for Screen and web access, software upgrade, video enhancement over call control/Call processing. Played important role in system design. Involved in Requirement analysis, Preparing requirement and functional specification document, time estimation, Contributed in Unit, Integration and System testing and various types of stress and acceptance testing. Languages Used: C programming, SIP-VoIP protocol, Linux Internals, Multithreading, Socket Programming, IPC Mechanism. Platform Used: Embedded Linux

Education

Birla Institute of Technology and Science, Pilani

Birla Institute of Technology and Science, Pilani

LinkedIn

Software System

2012 - 2014 · 2 yrs
Rajiv Gandhi Prodyogiki Vishwavidyalaya

Rajiv Gandhi Prodyogiki Vishwavidyalaya

LinkedIn

Computer Science

1999 - 2003 · 4 yrs

BE

Ashish Shrivastava 's Contact Information

Email

******@***.com

Phone

(**) *** ****

Find the Right Leads
Find Verified Contact Data

Try with: Jensen Huang @ nvidia.com Click to autofill
LeadContact awards, five-star ratings, and GDPR compliance badges

What LeadContact does well

Find verified emails, phone numbers, and decision-makers with 98% accuracy.

Find Leads

Find Leads

Find the right people by company, role, industry, location, and more.

925M+ professional profiles

Find Leads
Find Emails

Find Emails

Access verified email addresses for your target contacts.

657M+ emails

Find Emails
Find Phone Numbers

Find Phone Numbers

Get cross-validated phone data from multiple top sources.

239M+ phone numbers

Find Phone Numbers

More Accurate. Lower Cost.

Find contact data in 1 tool with 98% accuracy

LeadContact integrates leading enrichment tools to deliver more accurate contact data—without paying for each one.

LeadContact Logo
Competitor Tools

All these = $289 per month

Great conversations start with the right contact.

It’s time to find yours.