Impact Industries Expertise Experience Why CISO Tech Stack Credentials Services Contact
Open to CISO & Advisory Roles

Security Executive · CISO · Advisor

Joshna
Yarlagadda

Head of Security, IT & DevOps

Enterprise Security & Technology Executive with 15+ years leading Information Security, IT, and DevOps across Finance, Payments, Healthcare, Retail, and Analytics. Zero major audit findings across SOC 2 and PCI. Trusted advisor to executive leadership and boards — translating cyber risk into business impact.

CCISO CISM CEH AWS Security ISO 27001
Joshna Yarlagadda
15+
Years in Security
50%+
Vuln Reduction
40%
MTTD/MTTR Gain
Zero
Major Audit Findings

Measurable Outcomes

50%+
Reduction in
Critical Vulnerabilities
40%
Improvement in
MTTD / MTTR
45%
Fewer Cloud
Misconfigurations
Zero
Major Findings Across
SOC 2 & PCI Audits

Sectors

Industries Served

Security leadership across regulated and high-growth environments — building programs that meet the specific risk profile of each sector.

💳
Payments & Fintech
PCI DSS, SOC 2 Type II, payment platform security, M&A due diligence
🏦
Financial Services
Enterprise fintech, regulatory compliance, FFIEC-aligned controls
🏥
Healthcare
HIPAA compliance, patient data protection, clinical system security
🛒
Retail
Consumer data privacy, POS security, CCPA/CPRA compliance
📊
Analytics & SaaS
Cloud-native security, multi-tenant architecture, SOC 2 readiness
🔬
Semiconductor & Manufacturing
OT/ICS security, IP protection, supply chain risk management
🌐
Technology & Platforms
DevSecOps, product security, SDLC integration, cloud security
⚖️
Regulated Environments
GDPR, EU–US Data Privacy Framework, NIST CSF, multi-framework compliance

Core Competencies

Security Leadership Across the Stack

From boardroom risk conversations to hands-on cloud controls — leading security, IT, and DevOps as a unified function that protects revenue and enables growth.

01
🛡️

Security Program Leadership

Building enterprise security programs aligned to NIST CSF, ISO 27001, and CIS Controls. Risk governance, GRC frameworks, board-level KPI reporting, and security roadmap ownership — delivered with measurable maturity gains.

NIST CSFGRCRisk ManagementBoard Reporting
02
📋

Compliance & Audit Leadership

Zero major findings across SOC 2 Type II and PCI DSS programs. Deep practitioner across ISO 27001, NIST CSF, CCPA/CPRA, GDPR, and HIPAA — owning the full lifecycle from control design through external auditor management.

SOC 2 Type IIPCI DSSISO 27001GDPR / HIPAA
03
⚙️

Cloud Security & DevSecOps

Securing AWS and Azure environments with Zero Trust architecture, CIS-hardened systems, and SAST/DAST/SCA embedded into CI/CD — a 45% reduction in cloud misconfigurations. IAM transformation via Okta and Azure AD.

AWS / AzureZero TrustSAST / DASTOkta / Azure AD

Career

Executive Track Record

15+ years of progressive security leadership across Finance, Payments, Healthcare, Retail, Semiconductor, Manufacturing, and Analytics — always owning more than just security.

2023 — Present
Chief Cybersecurity Architect / Head of IT, Security & DevOps
Optimized Payments

Full executive ownership of Security, IT Operations, and DevOps for a high-growth payment analytics platform.

  • Achieved SOC 2 Type II with zero major findings; improved security program maturity by 30% in 12 months.
  • Reduced critical vulnerabilities by 50%+, cloud misconfigurations by 45%, and MTTD/MTTR by 40% via SIEM/EDR deployment.
  • Led Zero Trust architecture using Zscaler and Okta/Azure AD, cutting orphaned accounts by 60%.
  • Integrated SAST/DAST/SCA into CI/CD, reducing pre-production vulnerabilities by 35%.
  • Architected Model Context Protocol (MCP) integrations connecting enterprise systems to AI agents, and established an AI authorization framework governing access, permissions, and data exposure across every AI-connected tool.
  • Key personnel driving enterprise-wide AI adoption — leading security evaluation, procurement, and governed rollout of OpenAI, Anthropic (Claude), Cursor, and Grok (xAI) across the organization.
  • Leading confidential M&A due diligence — security risk assessment, control evaluation, and integration planning.
2022 — 2023
Information Security Manager II
Fiserv

Led enterprise security strategy, roadmap, and compliance programs at one of the world's largest fintech firms.

  • Built and scaled security teams as principal security architect for enterprise initiatives.
  • Directed threat hunting and SIEM operations across the environment.
  • Supported PCI DSS, SOC 2, and maturity assessments at enterprise scale.
2021 — 2022
Manager – IT Security
Fiserv · Alpharetta, GA

Led security engineering and operations initiatives across enterprise systems, strengthening threat detection and response.

  • Supported enterprise compliance, risk management, and M&A integration.
  • Led post-merger security integration of Ondot Systems, aligning IAM and compliance controls.
  • Consolidated security tooling across merged environments.
2015 — 2021
Senior Manager – Information Security
Raise Networks / Ondot Systems · San Francisco Bay Area

Led enterprise security programs for fintech and payment platforms, designing security architecture and controls from the ground up.

  • Built SIEM and monitoring capabilities, improving detection coverage by 50%.
  • Implemented IAM, DLP, and endpoint security across the organization.
  • Led PCI DSS, SOC, and ISO compliance initiatives through multiple audit cycles.
2010 — 2014
Senior IT Security Specialist / Information Security Consultant
JenPro InfoTech · India

Implemented enterprise security controls, monitoring, and risk assessments — building the foundational practitioner depth that underpins all subsequent leadership.

  • Conducted security audits and compliance support across client environments.
  • Assisted in the implementation of enterprise security frameworks.

The CISO Case

Why I'm Ready for the Chair

Most security leaders own one dimension. I've been running three simultaneously — and delivering measurable outcomes in each.

Measurable Outcomes

Numbers That Matter to Boards

50%+ reduction in critical vulnerabilities. 40% improvement in MTTD/MTTR. 45% fewer cloud misconfigurations. Zero major audit findings across SOC 2 and PCI. These are the metrics boards care about — and I deliver them.

Breadth of Ownership

IT + Security + DevOps — Unified

Most CISO candidates own security in isolation. I own the full technology operating layer — infrastructure, pipelines, and security controls — which means I speak the language of every stakeholder and eliminate the silos that create risk.

Regulatory Depth

Built for Regulated Environments

Regulated industries demand more than checkboxes. With hands-on depth across SOC 2, PCI DSS, ISO 27001, NIST CSF, GDPR, CCPA, and HIPAA — and 8 active certifications — I bring the rigor complex environments require without slowing the business down.

M&A Experience

Security Through Transactions

M&A is where security programs get exposed. I've led security diligence, post-merger integration, and IAM consolidation at both Fiserv (Ondot acquisition) and in a current confidential transaction — providing boards with real risk visibility at the most critical moment.

Tools & Platforms

Tech Stack

Hands-on depth across the full security and infrastructure toolchain — from SIEM to DevSecOps pipelines.

Cloud & Infrastructure
AWSAzureAzure Key VaultTerraformAzure DevOpsZscaler
Identity & Access
OktaAzure ADAuth0Zero TrustMFA / SSOPAMIAM
Security Operations
ELK StackLogRhythmSIEMEDRThreat HuntingSOAR
DevSecOps
SASTDASTSCACI/CD SecuritySDLCContainer Security
Endpoint & IT
MDM / UEMITSMDLPEndpoint SecurityVulnerability Mgmt
GRC & Compliance
NIST CSFCIS ControlsSOC 2PCI DSSISO 27001GDPR / HIPAA
AI Projects
MCPAI Chatbot

Credentials

Certifications & Education

Eight active credentials spanning security leadership, audit, ethical hacking, cloud, and governance.

👑
CCISO
Certified Chief Information Security Officer · EC-Council
🛡️
CISM
Certified Information Security Manager · ISACA
🎯
CEH
Certified Ethical Hacker · EC-Council
☁️
AWS Security – Specialty
AWS Certified Security · Amazon Web Services
📜
ISO 27001 Lead Auditor
ISO/IEC 27001:2013 · Lead Auditor Certified
🔒
CompTIA Security+
Security+ · CompTIA
🌐
CCNA
Cisco Certified Network Associate · Cisco
📊
COBIT 5
COBIT 5 Foundation · ISACA

Education

Master of Science
Computer Science · San Francisco Bay University
Bachelor of Science
Computer Science · JNTUH

Continuing Education

Hacker Halted — C|RAGE Masterclass
EC-Council · Upcoming · Registered Attendee

Engagements

Consulting & Audit Services

Available for fractional advisory, audit readiness, and framework gap-assessment engagements alongside full-time opportunities — the same rigor that delivered zero major findings across SOC 2 and PCI DSS, brought to your program on a retainer or fixed-scope basis.

01
🎯

Fractional / vCISO Advisory

Ongoing part-time security leadership for organizations not yet ready for a full-time CISO — board and executive reporting, risk governance, security roadmap ownership, and vendor/tooling strategy.

vCISOBoard ReportingRisk Governance
02
📋

Compliance Readiness & Audit Preparation

End-to-end readiness for SOC 2 Type II, PCI DSS, ISO/IEC 27001, HIPAA, GDPR, and CCPA/CPRA — control design, evidence collection, gap remediation, and direct auditor liaison through to report issuance.

SOC 2 Type IIPCI DSSISO 27001
03
🧭

Multi-Framework Gap & Maturity Assessments

Structured gap assessments against NIST CSF, NIST SP 800-53, CIS Controls v8, and COBIT 2019 — cross-mapped so evidence gathered once satisfies multiple frameworks instead of separate, duplicative audits.

NIST CSFCIS Controls v8COBIT 2019
04
☁️

Cloud Security & Zero Trust Architecture Review

Architecture and configuration review of AWS/Azure environments — IAM and Zero Trust design, CIS-hardened baselines, and DevSecOps pipeline security (SAST/DAST/SCA), targeting measurable reductions in misconfiguration risk.

AWS / AzureZero TrustDevSecOps
05
🤝

M&A Security Due Diligence

Security risk assessment and control evaluation for buy-side or sell-side transactions, plus post-merger integration planning — IAM consolidation, tooling rationalization, and compliance alignment across merged environments.

Due DiligenceRisk AssessmentPost-Merger Integration
06
🚨

Incident Response & SecOps Build-out

Design or uplift of detection and response capability — SIEM/EDR deployment, incident response playbooks, tabletop exercises, and MTTD/MTTR improvement grounded in live production experience.

SIEM / EDRIR PlaybooksTabletop Exercises
07
🤖

MCP & AI Chatbot — End-to-End Lifecycle

Full lifecycle delivery for Model Context Protocol integrations and enterprise AI chatbots — architecture and tool/resource design, an access-authorization framework governing what each AI-connected system can see and do, secure production deployment, and long-term support: model/tool governance, permission audits, and ongoing maintenance as the AI ecosystem evolves.

MCPAI ChatbotAI Authorization & GovernanceLong-Term Support
Discuss an Engagement →

Engagements are scoped individually — retainer, fixed-fee, or project-based — depending on the framework(s) in scope and current program maturity.

What I'm Pursuing

Open to CISO & Advisory Roles

Actively exploring Chief Information Security Officer roles, fractional CISO engagements, board-level security advisory positions, and strategic consulting. Fintech, payments, SaaS, and high-growth companies are a natural fit. GitHub is the source of truth for the hands-on work — compliance frameworks, MCP integrations, and tooling — referenced throughout this site.

Send a Message

✓   Message sent — I'll be in touch shortly.