Santhosh Kumar M

Santhosh Kumar M

Director, Information Security - EMEA (Europe, Middle-East & Africa) Region @ MetLife

About

An information systems and security professional with a unique blend of experience as both a management consultant advising global organizations, and as a practitioner in industry. I have experience assisting global companies in managing risks to their information and technology assets and partnering with both IT and business personnel across Europe, Turkey, Levant (Egypt, Lebanon & Jordan) and Middle East (GCC), US, and India. Specialties: • Large scale regional Security Transformation programs • IT Risk Management • Non-Financial Risk Assessment (NFRA) / Risk & Control Self-Assessment (RCSA) • Regulatory Compliance • Security Strategy & Operating Model • PCI DSS Version 4 Compliance • Identity & Access Security • Security Consulting on New Business Initiatives / Divestitures (M&A) • Security Awareness & Training • IT Third Party Risk Management Qualifications: • MBA (Information Systems & Security) • The Leadership Sessions: Setting the Tone (Harvard Business Publishing Corporate Learning) • ISO/IEC 42001:2013 Lead Auditor (LA) Artificial Intelligence Management System • Certified Information Systems Security Professional (CISSP) • PCI Professional (PCIP) • Payment Card Industry - Internal Security Assessor (PCI ISA) • Certified Information Security Manager (CISM) • Certified Information Systems Auditor (CISA) • ISO/IEC 27001:2013 Lead Auditor (LA) Frameworks & Standards: NIST, NESA / UAE Information Assurance, ADHICS (UAE) & Qatar Cyber Security regulation

Country

United Arab Emirates

City

Dubai

Industry

Insurance

Skill

Credit Card Fraud Prevention, Artificial Intelligence (AI), AI Risk, AI Governance, Continuous Integration and Continuous Delivery (CI/CD), Symantec SiteMinder, Guardium, Data Masking, Multi-factor Authentication, Single Sign-On (SSO), Database Monitoring, DLP, Cyberark, Identity and Access Management (IAM), ISO 27001, IT Audit, Information Security, Risk Management, IS Strategy, CISA

Experience

MetLife

Director, Information Security - EMEA (Europe, Middle-East & Africa) Region

MetLife

LinkedIn
2019-11 - Present · 6 yrs 11 mos

United Arab Emirates

Strategize and manage regional Information Security programs across EMEA (20+ countries) with a team of Information Security SMEs. - Oversee IT Risk Management, Non-Financial Risk Assessment (NFRA) / and Risk & Control Self-Assessment (RCSA) - Ensure compliance with PCI DSS Version 4 and manage IT Third Party Risk Management - Drive Information Security Awareness initiatives and lead Customer Audits & Contract Reviews. - Provide Regulatory Assurance for DORA, UAE ADHICS, UAE Information Assurance, Jordan Central Bank Regulation and Qatar Cyber Security Regulation and - Report Information Security compliance to the Audit/Risk Committee and Executive Leadership - Contributed to technology and security assessments for major infrastructure changes, Mergers / Acquisitions and Divestitures (M&A). - Supervise Identity & Access Management programs Spearheaded multi-million dollar strategic regional security transformation programs, including: - Implementation of Privileged Access Management across 1,000+ servers - Deployment of Automated Access Recertification for 175+ applications - Rollout of Data Loss Prevention for 5,000+ endpoints - Establishment of Database Logging & Monitoring for 150+ database servers - Integration of Multi-Factor Authentication and Single Sign-On for 20 applications; and - Governance of Lower (non-PROD) Environment and Data Masking for 250+ applications Report Information Security compliance to Audit / Risk Committee & Executive Leadership. Assisted on technology and security consideration for country divestitures (M&A).

MetLife

Manager - IT Risk & Security EMEA region

MetLife

LinkedIn
2018-1 - 2019-10 · 1 yr 10 mos

Dubai, United Arab Emirates

MetLife

IT Risk & Security Lead - Middle East & Africa (MEA)

MetLife

LinkedIn
2016-6 - 2017-12 · 1 yr 7 mos

Dubai, United Arab Emirates

Deloitte

Assistant Manager

Deloitte

LinkedIn
2015-2 - 2016-5 · 1 yr 4 mos

United Arab Emirates

Part of the Security & Management Transformation (SMT) team. Area of Expertise : - Led the development of InfoSec Strategy, Roadmap, and Governance Model that significantly elevated the security maturity of the UAE health sector, achieving stronger regulatory alignment and risk management. - Skilled in developing business proposals and responding to Requests for Proposals (RFPs), contributing to new business opportunities and strategic partnerships. - Extensive experience in conducting IT & Information Security Audits, including the creation and management of comprehensive IT Audit Plans. - Advisory and audit experience in the implementation of Information Security Standards & Best Practices, including ISO 27001/27002:2013, ISO 27005:2011, NESA (UAE), and ADSIC (UAE) frameworks. - Proven track record in People Development, including mentoring, coaching, and managing talent to cultivate high-performing teams and future leaders.

EY

Assistant Manager - Information Security

EY

LinkedIn
2009-11 - 2014-12 · 5 yrs 2 mos

Qatar / Oman / India

Specialization in Information Security and Risk Management, Governance, and Compliance: - Led the development of Qatar’s national Information Security Risk Management Framework for the Ministry of ICT, managing risk assessments for government and financial entities. - Supervised a multi-disciplinary team of consultants to deliver a comprehensive Cybersecurity and GRC advisory portfolio, including IT Risk Assessment, Information Security Management Systems (ISMS), IT General Controls Audits, and SOC 2 reporting. - Developed and implemented IT and Information Security Policies, Procedures, and Process Maps, ensuring alignment with industry standards and organizational objectives. - Led COSO IT Control Transformation initiatives, enhancing internal control frameworks and IT governance models. - Extensive experience conducting SAS 70 (SOC) Audits, ensuring regulatory compliance and operational efficiency. - Skilled in performing IT & Information Security Audits, identifying and mitigating risks to strengthen overall security posture. - Specialized in Supply Chain Security Management, safeguarding data integrity and compliance across third-party relationships.

Axis Bank

IT Executive

Axis Bank

LinkedIn
2009-6 - 2009-11 · 6 mos

Executive-IT at Axis Bank, Mumbai

Allied Digital

Managed Security Services Consultant (Internship)

Allied Digital

LinkedIn
2008-4 - 2008-7 · 4 mos

Consultant - Managed Security Services

Education

SCIT - Symbiosis Centre For Information Technology

SCIT - Symbiosis Centre For Information Technology

LinkedIn

Information Systems & Security

2007 - 2009 · 2 yrs
Loyola College

Loyola College

LinkedIn

Computer Science

2004 - 2007 · 3 yrs

Santhosh Kumar M's Contact Information

Email

******@***.com

Phone

(**) *** ****

Find the Right Leads
Find Verified Contact Data

Try with: Jensen Huang @ nvidia.com Click to autofill
LeadContact awards, five-star ratings, and GDPR compliance badges

What LeadContact does well

Find verified emails, phone numbers, and decision-makers with 98% accuracy.

Find Leads

Find Leads

Find the right people by company, role, industry, location, and more.

925M+ professional profiles

Find Leads
Find Emails

Find Emails

Access verified email addresses for your target contacts.

657M+ emails

Find Emails
Find Phone Numbers

Find Phone Numbers

Get cross-validated phone data from multiple top sources.

239M+ phone numbers

Find Phone Numbers

More Accurate. Lower Cost.

Find contact data in 1 tool with 98% accuracy

LeadContact integrates leading enrichment tools to deliver more accurate contact data—without paying for each one.

LeadContact Logo
Competitor Tools

All these = $289 per month

Great conversations start with the right contact.

It’s time to find yours.