About

Security leadership, from strategy to delivery

Aniruddha Khandwe

Principal Security Engineer & Security Practice Lead

I lead the cybersecurity practice at Aurionpro Solutions Limited — running VAPT, Red Team, SOC, GRC and Security Solutioning teams end-to-end, with ownership of delivery, presales, OEM partnerships and practice P&L.

  • Role: Principal Security Engineer, Aurionpro Solutions Ltd.
  • Experience: 6 years in cybersecurity
  • Location: Nagpur, Maharashtra, India
  • Phone: +91 95612 15406
  • Education: M.Tech (Executive), Cloud Computing — IIT Patna
    B.E. Electrical & Electronics — YCCE Nagpur
  • Certifications: CISA · CISM · CEH · ISO 27001 / 20000-1 / 22301 LA · ISO 31000 RM
  • Email: aniruddha1khandwe@gmail.com

I design and deliver enterprise security programmes for banks, insurers, market infrastructure institutions, power utilities, smart cities and government bodies — covering security architecture, offensive security, SOC build and operations, and regulatory compliance under RBI, SEBI CSCRF, IRDAI, PCI DSS, ISO 27001 and the DPDP Act. I also own the OEM partner ecosystem across 20+ security vendors, running evaluations, demonstrations and proofs of concept so that every solution is matched to the client's risk posture and regulatory mandate.

More recently I have built out an AI security service line — AI-augmented VAPT, LLM and GenAI application testing, and AI governance aligned to NIST AI RMF, ISO/IEC 42001, OWASP LLM Top 10 and MITRE ATLAS — and contribute as part of the team within the CERT-In AI Cyber War Room, working on AI Security Blueprint drafting and governance.

 Download CV    View Profile

Enterprise & Government Clients

Years in Cybersecurity

Practice Teams Led

Professional Certifications

Focus Depth

Security Architecture & Design 92%
Governance, Risk & Compliance 90%
VAPT & Red Teaming 88%
Presales & Tender Solutioning 88%
SOC Build & Operations 82%
Cloud Security (AWS · Azure · GCP) 80%

Frameworks & Domains

ISO 27001 / 22301 / 20000

PCI DSS

SEBI CSCRF

RBI & IRDAI Guidelines

CERT-In Directions

DPDP Act 2023

NIST CSF & SP 800-53

NIST AI RMF · ISO 42001

OWASP Top 10 · MASVS · LLM

MITRE ATT&CK · ATLAS

Zero Trust & ZTNA

Cloud Security & DevSecOps

Resume

Experience, education and credentials

Summary

Aniruddha Khandwe

Cybersecurity leader with 6 years of experience across security practice management, security architecture, governance and offensive security. Currently leading the cybersecurity practice at Aurionpro Solutions Limited, serving 20+ enterprise and government customers across BFSI, insurance, stock exchange, power utilities, smart city and public sector.

  • Nagpur, Maharashtra, India
  • +91 95612 15406
  • aniruddha1khandwe@gmail.com

Education

M.Tech (Executive), Cloud Computing

2024 - 2026

Indian Institute of Technology (IIT) Patna

Advanced study in cloud architecture, distributed systems and secure infrastructure design.

B.E., Electrical & Electronics Engineering

2021

Yashwantrao Chavan College of Engineering (YCCE), Nagpur

Final year project: YCCE Buddy, an autonomous hospitality assistant replacing a traditional reception desk.

Certifications

Governance & Audit

  • CISA — Certified Information Systems Auditor (ISACA)
  • CISM — Certified Information Security Manager (ISACA)
  • ISO/IEC 27001 Lead Auditor
  • ISO/IEC 20000-1 Lead Auditor
  • ISO 22301 Lead Auditor
  • ISO 31000 Risk Manager

Technical

  • CEH v11 — Certified Ethical Hacker (EC-Council)
  • Certified Penetration Tester — National Security Database
  • Google Cloud — Core Infrastructure & Security

Professional Experience

Principal Security Engineer — Security Practice Lead

2024 - Present

Aurionpro Solutions Limited, India

  • Lead the cybersecurity business end-to-end across five delivery functions — VAPT, Red Team, SOC, GRC and Security Solutioning — covering strategy, staffing, capability build-out and delivery quality.
  • Own practice delivery, budgeting and P&L: effort and cost modelling, resource planning, margin tracking and commercial governance.
  • Manage a portfolio of 20+ active customers across BFSI, insurance, stock exchange, power utilities, smart city and government, acting as escalation and assurance owner.
  • Design enterprise security architectures — SOC / SIEM / SOAR, IAM, Zero Trust and ZTNA, WAF, EDR / XDR, MDM, DLP and cloud security.
  • Own the OEM and partner ecosystem across 20+ security vendors, running product demonstrations and proofs of concept, assessing fitment against client risk posture and regulation, and maintaining commercial and technical relationships.
  • Drive presales and tender solutioning for large public-sector and BFSI RFPs, including presenting the solution to client evaluation committees.
  • Build the practice governance layer — policies, SOPs, audit working papers and control checklists mapped to ISO 27001, ISO 22301, PCI DSS, SOC 2, NIST CSF, RBI and CERT-In requirements.
  • Built the AI security service line and contribute to the CERT-In AI Cyber War Room on AI Security Blueprint drafting and governance.

Cloud & Cyber Security Expert

2021 - 2024

Aurionpro Solutions Limited, India

  • Delivered VAPT and security audits across web applications, APIs, cloud workloads and network infrastructure, including remediation guidance and closure verification.
  • Designed and secured cloud and DevSecOps environments (AWS, Azure, GCP, NIC Cloud) — architecture review, hardening, CI/CD pipeline security and container security.
  • Ran security architecture reviews and threat modelling, translating findings into implementable design changes.

Test Engineer (Cyber Security)

Aug 2021 - Sep 2022

Ministry of Social Justice & Empowerment, Government of India — deputed through Aurionpro

  • Single point of accountability for cybersecurity across national citizen-facing portals — SACRED, SAGE, AGRASR, NMBA and SEED.
  • Continuous VAPT and remediation tracking, load testing, server management and CI/CD across test, QA and production; managed the security posture of NIC-hosted infrastructure.

Cyber Security Intern → Project Lead Trainee

Jul 2020 - Sep 2022

All India Council for Technical Education (AICTE), Ministry of Education, GoI

  • Led the cyber team for the National Apprenticeship Training Scheme (NATS), the AICTE Internship Portal and AMRUTUM 2.0 — web and network auditing, API security, patching and load testing.
  • Completed VAPT of multiple government sites and servers; built Python-based automation for security data collection and reporting.

Services

Security capabilities I lead and deliver

Security Assurance — VAPT

Web, mobile, API, network, infrastructure and cloud VAPT; red and purple teaming; source code review (SAST) and DAST; OT / ICS / SCADA testing; breach and attack simulation; hardening review and Safe-to-Host certification.

AI Security & AI System Audit

GenAI and LLM application security testing; prompt injection, jailbreak and data-poisoning assessment; AI red teaming and model-evasion testing; model risk, bias and robustness review; AIBOM and AI supply-chain security aligned to NIST AI RMF, ISO/IEC 42001 and the EU AI Act.

Proactive Defence & Threat Hunting

Hypothesis-driven, ATT&CK-mapped threat hunting; cyber threat intelligence and attack-surface management; APT defence, deception and honeypots; incident response, digital forensics and malware analysis; compromise assessment and CERT-In reporting.

Governance, Risk & Compliance

ISO 27001 / 22301 / 20000-1 / 42001, NIST CSF, CIS Controls, PCI DSS and SOC 1/2 implementation; internal, external and third-party audit; gap and maturity assessment; risk assessment and treatment; policy development; vendor risk (TPRM) and GRC tooling.

Regulatory & Data Privacy

RBI, SEBI CSCRF, IRDAI and MAS alignment; system and cyber audit for regulated entities; SAR audit; DPDP Act 2023 readiness; AUA / KUA compliance; dark pattern audit; DPO-as-a-Service; CERT-In empanelled audit support.

Security Engineering & Architecture

Zero Trust and ZTNA; IAM, IGA, PAM, MFA and NAC; next-generation SIEM, SOAR, UEBA and XDR; DLP, DAM, encryption and PKI; email security, WAF, CASB, CSPM, CWPP and container / Kubernetes security.

Advisory & CISO-as-a-Service

Virtual CISO engagements: security strategy, roadmap and programme build; security architecture advisory; board and executive risk reporting; tool rationalisation and budget optimisation; M&A due diligence; awareness programmes and cyber-insurance readiness.

Managed Security Services

SOC-as-a-Service with 24×7 monitoring and response; MDR and co-managed or fully managed SIEM; threat hunting, log management and analytics; managed VAPT and vulnerability management; managed PAM / IAM; device and patch management; dark-web monitoring.

Solutioning, Presales & OEM

RFP and tender solutioning for government and BFSI procurement; technical solution documents, compliance matrices, bill of materials and costing; OEM evaluation, product demonstrations and proofs of concept; bid defence and evaluation-committee presentations.

Case Studies

Selected engagements — client names withheld under NDA

  • All
  • Audit & Compliance
  • Offensive Security
  • Cloud & Transformation
  • Defence & Response
  • AI Security
SEBI CSCRF system and cyber audit

SEBI CSCRF System & Cyber Audit

Market Infrastructure Institution

Digital banking security assessment and DPDP readiness

Digital Banking Assessment & DPDP Readiness

Cooperative Bank — 12+ applications, 25+ APIs, 80+ servers; 95% of critical and high findings closed on re-test

Secure cloud transformation on-premise to AWS

Secure Cloud Transformation — On-Prem to AWS

Transit NCMC programme — Zero Trust, 300+ controls validated, 92% reduction in critical exposures

Ransomware response and recovery

Ransomware Response & Recovery

State transport department — full recovery in 48 hours, 1-hour RTO, zero data loss, no ransom paid

Managed threat hunting for enterprise SOC

Managed Threat Hunting

Enterprise SOC — 10,000+ endpoints; detection 60% faster, dwell time down 70%

Embedded VAPT programme for a regulated broker

Embedded VAPT Programme

SEBI-regulated broker — scaled coverage from 40 to ~290 applications and 300 to 500 APIs

ATM and POS security assessment

ATM & POS Security Assessment

Leading bank, Oman — onsite VAPT aligned to PCI DSS, EMV and Central Bank of Oman requirements

PCI DSS implementation and certification

PCI DSS Implementation & Certification

AWS payment platform — Zero Trust build, certification sustained over 3+ years

VAPT for AI and machine learning systems

VAPT for AI Systems

LLM applications, models and MLOps pipelines — prompt injection, model evasion, data poisoning and guardrail review

Contact

Open to conversations on security leadership, architecture and advisory

Location

Nagpur, Maharashtra, India

Available for engagements across India and the GCC

Social Profiles

Phone

+91 95612 15406

Designed by Tapi Technoserves