DIRECTOR · SECURITY ARCHITECTURE & OPERATIONS

I secure clouds.
I summon AI.
Some call it sorcery.

11+ years protecting platforms that hundreds of millions rely on — currently leading security at Careem (an Uber company) after 3 years as a Senior Security Engineer (L5) at AWS. I don't just advise on AI security — I build AI agents that do security ops.

Guilds served: CAREEMAMAZON AWSPwCMcKINSEYHCL
Dubai, UAE Open to Director / VP / Head of Security roles CISM · CEH · AZ-500 · ISO 27001
LEVEL11+
GUILD: CAREEM ex-AWS · L5
region: Dubai
Bharat Gandhi
CLASS: AI CYBER SORCERER
Cloud Warding
96
Threat Divination
94
Agent Summoning
93
Incident Banishing
92
Team Enchantment
91
Compliance Sigils
90
XP: 11+ YRS GUILDS: 5 MANA: ∞ COFFEE
11+
years in security
176
territories secured at PwC
L5 DIR
AWS engineer to Careem director
10+
certifications incl. CISM
☁️

Cloud Security at AWS Scale

3 years as an AWS L5 Security Engineer — threat modeling, DevSecOps, cryptographic architecture, and hardening production systems across ECS, Lambda, KMS, RDS. I know what "secure by design" means at the world's largest cloud.

🤖

AI-Powered Security Ops

I don't just talk about AI in security — I ship it. Autonomous agents for threat detection, LLM-driven triage, automated response playbooks. My GitHub is the proof. This is the future of SecOps and I'm already building it.

🏰

Director-Level Leadership

Currently owning security architecture and operations at Careem (Uber venture) across 10+ countries. Previously built security programs at PwC across 176 territories and ran global SecOps at McKinsey. I build teams, not just tooling.

QUEST LOG

Track record

// every quest completed, difficulty rising
Nov 2024 — Present
Dubai, UAE
~1 yr

Director, Security Architecture & Operations @ Careem (an Uber company)

Leading security for a super-app operating across 10+ countries in the Middle East

▲ First security director hire — building the function end-to-end
  • Own security architecture and operations end-to-end for Careem's distributed microservices platform
  • Driving AI-assisted detection and response — autonomous agents embedded into alert triage and incident workflows, reducing MTTR
  • Lead AWS cloud security strategy: GuardDuty, Security Hub, CloudTrail, KMS, IAM governance at scale
  • Embed security into SDLC through threat modeling standards, secure-by-design reviews, and developer enablement
  • Align InfoSec, engineering, product, and C-suite on risk posture and security investment priorities
Dec 2021 — Nov 2024
Canada
3 yrs

Senior Security Engineer, L5 @ Amazon Web Services

Security engineering at the scale of the world's largest cloud provider

▲ L5 — top 15% individual contributor band at Amazon
  • Led threat modeling and security design reviews across multiple AWS product lines — from design to launch
  • Drove DevSecOps adoption for two-pizza teams: security gates in CI/CD, automated SAST/DAST, dependency scanning
  • Ran security campaigns and gamedays to stress-test production defenses and build team muscle memory
  • Architected secure multi-account AWS environments: ECS, S3, ALB, RDS, KMS encryption, Lambda least-privilege
  • Contributed to cryptographic solutions and hardened system architectures across distributed services
  • Mentored engineers on secure coding practices; drove security culture beyond a gatekeeper model
Aug 2018 — Dec 2021
Gurgaon, India
3 yrs 4 mos

Cyber Security Manager @ PwC

Global cybersecurity practice serving enterprise clients across five continents

▲ Delivered security visibility across 176 PwC territories
  • Built Splunk and Ohana dashboards giving leadership real-time security metrics visibility across all 176 territories
  • Automated SOC operations with Python and PowerShell — reduced manual alert triage, freed analysts for high-value work
  • Implemented ISO 27001:2013 control frameworks and led internal audit cycles for enterprise clients
  • Managed endpoint security stack (Symantec, McAfee) and oversaw cloud security posture for client environments
  • Developed and presented security metrics for IT Risk programs to C-suite and board-level stakeholders
Jan 2017 — Oct 2018
Global
1 yr 9 mos

Senior IT Security Operations Specialist @ McKinsey & Company

Global security operations for one of the world's most targeted consulting firms

  • Managed enterprise SIEM environment and built advanced Splunk correlation searches for threat detection
  • Implemented SOAR automation — orchestrated playbooks cutting manual response time across common attack patterns
  • Led vulnerability assessments and penetration testing engagements across McKinsey's global infrastructure
  • Managed network security infrastructure, access controls, and firewall policy governance
Nov 2013 — Jan 2017
India
3 yrs 2 mos

Security Specialist @ HCL Technologies

Foundation years — learning enterprise security from the ground up

  • SOC operations, 24/7 security monitoring, and alert triage for enterprise client environments
  • ISO 27001:2013 risk identification, assessment, and remediation tracking
  • Conducted vulnerability assessments and security audits; delivered findings to client leadership
  • Built security governance frameworks and ran org-wide security awareness training programs
THE OFFER

What you actually get

// the checklist your CISO is looking for

Technical depth, not just governance

I write code. I build agents. I've shipped production security tooling at AWS and I can review a threat model, a CloudFormation template, or a Python exploit PoC — and have an intelligent conversation about all three.

Proven at scale — Tier 1 companies

AWS (3 yrs, L5), PwC (3 yrs, global), McKinsey (global). These aren't logos — they're proof of operating in high-stakes, highly scrutinized environments where security mistakes cost reputations and billions.

AI-native security thinking

Most security leaders are still figuring out how to write a ChatGPT prompt. I'm building autonomous agents for threat detection, automated triage, and AI-powered interview coaching. I bring the future into the present.

Business-aligned communication

I've presented security metrics to boards and built dashboards for 176-territory global programs. I can translate technical risk into business language — and make executives care about security without fear tactics.

Cloud-first, multi-cloud fluent

AWS-certified (Security Hub, GuardDuty, KMS, IAM, ECS, Lambda), Azure-certified (AZ-500, AZ-900), Google Cloud experience. Not cloud-agnostic by default — cloud-native by choice, with real production scars to show for it.

Builder who scales teams

At Careem I'm building the security function from the ground up. At PwC I scaled SOC operations across continents. I know the difference between a hero-mode security team and a self-sustaining security program.

SUMMONS

AI builds & projects

// I don't just talk AI security — I conjure it
SPELLBOOK

Skills & tools

Cloud Security

  • AWS GuardDuty
  • AWS Security Hub
  • CloudTrail · KMS · IAM
  • ECS · Lambda · S3 · ALB
  • Azure MDATP · AZ-500
  • O365 Security
  • Google Cloud Security
  • Serverless & container sec

AI & Automation

  • AI agents & tool use
  • LLM-powered SecOps
  • SOAR / playbook automation
  • Python · PowerShell
  • TypeScript · JavaScript
  • CI/CD security gates
  • DevSecOps pipelines
  • GitLab · GitHub Actions

Security Operations

  • Threat modeling
  • Incident response
  • Threat hunting
  • Splunk · QRadar · ArcSight
  • Qualys · Nessus · Burp Suite
  • Palo Alto · Fortinet · Cisco
  • Vulnerability management
  • Penetration testing

Leadership & GRC

  • Security architecture strategy
  • ISO 27001 — implement & audit
  • Board-level risk reporting
  • Cross-functional leadership
  • Exec security metrics
  • Compliance management
  • Secure SDLC enablement
  • Security program building
RUNES & SIGILS

Certifications

CISMISACA — Certified Information Security Manager
AZ-500 · AZ-900Microsoft Azure Security & Fundamentals
CEHEC-Council — Certified Ethical Hacker
ISO 27001:2013 Lead AuditorISO Certification
CompTIA Security+CompTIA
Splunk ×4Architecture · Admin · Knowledge Objects · Search & Reporting
CISSPIn progress — final rune being inscribed
THE SUMMONING CIRCLE

Summon me

Need a security leader who can architect for cloud scale, run operations under pressure, and bring real AI into the security program — not just a slide deck about it? No incantation required. Just email. I read every message.