Neeraj Kumar
Sr.Vice President - Security Strategy & Engineering @ SBI Card
About
With over 20 years of experience in IT, Information Security, and Cybersecurity, I have built and led enterprise security programs that mitigate complex risks, strengthen governance frameworks, and ensure regulatory compliance across highly regulated environments. My experience spans BFSI/NBFC, IT/ITES, aviation, and telecom sectors, where I have driven large-scale cybersecurity initiatives and enhanced organizational resilience. I possess strong expertise in globally recognized frameworks such as ISO/IEC 27001, NIST CSF, and PCI-DSS, along with Indian regulatory requirements including RBI and IRDAI guidelines. My core strengths include enterprise risk assessments, Third-Party Risk Management, Vulnerability and Application Security, control assurance, and IT risk governance—ensuring alignment with business risk appetite and compliance mandates. Currently, I lead Information Security Operations, Strategy, and Engineering at SBI Cards & Payment Services Ltd, one of India’s leading credit card issuers. I oversee an enterprise-wide cybersecurity program covering Security Operations (SOC), cyber defense, threat intelligence, incident response, security architecture, identity and access management, data protection, and regulatory governance. I have transformed traditional SOC environments into intelligence-driven cyber defense platforms by integrating SIEM, EDR/XDR, MDR, UEBA, and advanced detection engineering capabilities, strengthening 24x7 monitoring and response effectiveness. My experience includes leading high-impact incident response and cyber crisis management in regulated financial ecosystems, maturing SOC processes from reactive to optimized states, and institutionalizing automation-driven detection and response playbooks. I have also implemented secure architectures across networks, endpoints, applications, and cloud environments, embedding security into enterprise technology and digital initiatives. Beyond technology, I have built and mentored high-performing cybersecurity teams, fostering accountability, collaboration, and continuous improvement. I regularly engage with executive leadership, risk committees, auditors, and partners to align cybersecurity strategy with business priorities and deliver measurable risk reduction. I am committed to protecting critical systems and assets while enabling secure, sustainable business growth through strategic and collaborative leadership.
India
Gurugram
Banking
Security Incident Management, IT Service Delivery, Technical Service Delivery, Data Leakage, Application Packaging, Windows Deployment Services (WDS), Microsoft Deployment Toolkit (MDT), Operating Systems, System Deployment, Desktop Application Support, Desktop Administration, Technical Support, Help Desk Support, Service Desk, Desktop Computers, Cybersecurity Incident Management, Data Security, Information Security Management, IT Security Operations, Security Operation Center (SOC)
Experience

Vice President - Security Strategy & Engineering
Gurugram, Haryana, India
- Accountable for monitoring the development and maintenance of the information security program & controls across enterprise (Technology areas) - Accountable for developing Information Security solutions, Security Roadmap, Security architecture assessment, and infra/application change to the existing environment inline to regulatory requirement. - Managing Information security programs including Cyber Threat Detection, Security Operation Center, Incident Response, Cyber Brand Monitoring & Threat Intelligence, Threat & Vulnerability Management, Application Security, Penetration Testing exercise, Identity & Access Management, Privileged Access Management, Security Assessment including strategy for continual improvement & governance - Accountable for implementation and assurance of RBI, Cert-In, NCIIPC regulatory driven Information Security Control and Compliance requirements - Leading the design of security controls and architecture principles, balancing industry standard methodologies with the risk appetite of the business including Change Management Review for IT and Business driven change into enterprise systems - Present Information Security program status, KPI & KRI to Risk Management & Governance Committee - Conducting Risk Based Assessments for Security Technology for effectiveness of controls and supporting Security Audits - Support Governance Risk and Compliance (GRC) and Vendor Risk Management areas with technical assistance - Manage and Mentor a large high-performance team of Information & Cyber Security experts including hiring, performance review, appraisal, and succession planning. - Manage Financial forecasting and budget for Information Security expenditure. - Manage relationships with security service providers & vendors to ensure the quality and effectiveness of outsourced services. - Support awareness programs to promote a culture of security awareness, especially for Phishing Simulation & communications

Assistant Vice President- Information & Cyber Security, Data Privacy
Noida, Uttar Pradesh, India
- Evaluate, Plan, Implement solutions and manage Information Security Operation for Cyber Defense, Data Security & Incident Response capabilities for global footprints including India, Philippines, Europe and USA - Lead a hybrid team of in-house & partner resource for service assurance on Threat Detection & Response (SOC: Security Operations Center / Cyber Defense Center), Threat Intelligence & Hunting and Insider Threat Detection areas in alignment to Cyber Kill Chain and MITRE ATT&CK framework. - Manage and mature Technology landscape of SIEM, Data Loss Prevention (DLP), End-Point Detection & response (EDR), Anti-APT (Advance Persistent Threat), eMail Seucrity & Cloud Security Solutions, covering all global footprints - Managing Information Security Incidents including assessment, quantification, investigation and mitigation - Stakeholder, Supplier (Vendor) & Financial Management for Information Security Operations - Technical Risk Identification, releasing Critical Threat Advisory and driving mitigation for detection & prevention - Support Cyber Resilience through alignment with NIST Cyber Security Framework - Support in business development activities by responding technical RFI/RFP, supporting audits and demonstration of developed capabilities

Project Manager- Security Management
Pune, Maharashtra, India
- Accountable for service delivery of Cyber Security Services for clients including Infrastructure Security, Security Monitoring, Vulnerability Management, Risk & Compliance, End-Point Security, Application Security and BCP/DR per SoW and SLAs. - Direct responsible for C-SAT and Revenue generation from clients - Technology deliverables includes IDAM, Vulnerability & Threat Management, SIEM, Virus Protection, Encryption, Patch Management, Perimeter Security, and System Security components

Project Manager- Security Management
Gurgaon, Haryana, India
- In a Techno manager role, responsible for managing Information Security operations, SoW and SLA delivery for Security Operation Center, Incident Response and Data Security programs. Direct responsible for C-SAT scores - Technology operations for SIEM, IDS/IPS/WIPS, Anti-Virus, Data Loss Prevention & Vulnerability Assessment solutions for global footprints - Assuring process compliance & producing Security Scorecard / Security Metric & Dashboard to Customer - Assuring external audit requirements for IT controls and related evidences by IT Operation Teams - Security awareness ( Limited to IT Support staff) and Incident Management

Manager - Security Risk Management
Gurgaon, Haryana, India
- Managing Information Security programs, especially Data Loss Prevention (DLP) Program and Vulnerability Management for global footprints - Infrastructure Security Risk assessment, both at infrastructure design (Architecture) & implementation level projects for India region - Security Incidents Response & Investigation for India region

Technical Specialist - Security Management
Hyderabad, Telangana, India
- Technology Management for Vulnerability Assessment, Anti-Virus management, System Security, SIEM, IDS/IPS/WIPS, Network Access Control and DLP management as per SLA & SoW - Technical solution implementation for System Security/End Point Security services - IT Security Audits support and delivery of Unified Compliance Framework (UCF) for supporting ISO: 27001, PCI-DSS , ISAE & SOX lifecycle with internal & external auditors - Security Incident (Technical) Investigation &root cause analysis, reporting and implementation of corrective actions; as directed by clients - In additional role of EUC & SCCM technical lead –delivered services from Yr-2008 to Yr-2011 by Leading SCCM/Patch Management Team and End-User Computing-L3 (10 colleagues). Worked on Imaging, Packaging, Deployment, and Technical Incident Management (IT)

Engineer - Helpdesk Management
Gurugram, Haryana, India
- Started as helpdesk engineer for end-user computing for troubleshooting application/hardware issues & service request management. - Team Lead for a site of 3000+ users for End-User Computing/ Desktop Support (< 6 months) - Started my Information Security journey with Device Encryption (Safeboot) and Patch Management as part of End-User Information Security Services.
Neeraj Kumar's Contact Information
Phone
Find the Right Leads
Find Verified Contact Data
What LeadContact does well
Find verified emails, phone numbers, and decision-makers with 98% accuracy.
Find Leads
Find the right people by company, role, industry, location, and more.
925M+ professional profiles

Find Emails
Access verified email addresses for your target contacts.
657M+ emails

Find Phone Numbers
Get cross-validated phone data from multiple top sources.
239M+ phone numbers

More Accurate. Lower Cost.
Find contact data in 1 tool with 98% accuracy
LeadContact integrates leading enrichment tools to deliver more accurate contact data—without paying for each one.
Great conversations start with the right contact.
It’s time to find yours.




