
Leadership Partner, Gartner Best Practices Council for Information Security Executives
Greater New York City Area

Leadership Partner, Gartner Best Practices Council for Information Security Executives
Greater New York City Area
Ashwini Ahuja (Ash) is the Senior Council Director of the Gartner Best Practices Council for Information Security Executives. He works with a community of clients and Gartner analysts to discover and share expertise, insights and experiences through council forums and ongoing community collaboration.
Ash has over 19 years of experience in architecting and building enterprise systems in the areas of Identity and access management, security, web applications, workflow automation, process control systems, and aviation software. He started his career as a developer, and moved up the chain to an Enterprise Architect, building one to n-tier applications on both the client-server and the web platform. He has also managed IT Consulting practices deploying technology solutions for Fortune 100 clients. With this experience, he understands what it takes to build solutions from the ground up, or to integrate different components of an enterprise technology stack. He has been focused on Information Security for the past 7-8 years and has led multiple strategic initiatives for Fortune 50 clients like BP, Coca-Cola, Tyco/ADT, United Technologies, and American Standard. The focus of these initiatives has been to define their information security governance strategy, business alignment, architecture, road-map, product selection, implementation and operations planning.
Security
- Featured speaker presenting “Unified Identity, Access & Entitlements Management” at the ISSA CT event.
- Featured speaker on Information Security Governance at the ISACA annual event
- Featured speaker panel hosted by the Burton Group on entitlement management
- Services Oriented Architecture evangelist, Steering Committee member for the SOA Consortium, featured panelist on SOA/BPM adoption and best practices
CISM, Certified Information Security Manager, Information Security, Risk Management, Application Security, SOA, Strategy, Architecture, Road map, Security, Identity Management, Access Management, Federation, Provisioning Solutions, Single-Sign-On Frameworks, Application Integration, SOX Compliance, HIPPA Compliance, Strategy, Architecture, Road map, Deployment, and Support, SOA Consortium, SOA Security.
(Public Company; IT; Information Technology and Services industry)
May 2009 — Present (3 months)
As Senior Council Director of the Gartner Best Practices Council for Information Security Executives I works with a community of clients and Gartner analysts to discover and share expertise, insights and experiences through council forums and ongoing community collaboration.
Gartner Best Practices Councils - is an exclusive program for CSO's to meet other senior executives with similar interests, compatible philosophies and/or comparable IT environments in a sharing environment. As a member you will have a dedicated relationship manager, access to interactive forums, and actionable solutions based on the experience of members - guided by Gartner Best Practices research.
Members are senior executives in companies that are over $1 billion in revenue in North America and $750 million in Europe. Council members are responsible for the budget, organization and strategy for their functional areas.
CSO's/Information Security Executives get to learn more about the best practices covering information security management issues. Members interact and exchange on critical issues such as designing an effective information security organization; ensuring proper governance, compliance practices and enforcement policies are in place; and guaranteeing that security plans keep the enterprise agile, flexible and secure.
(Information Technology and Services industry)
October 2007 — Present (1 year 10 months)
Help foster communication and collaboration between members of the chapter in order to leverage the extended knowledge that we maintain as a collective unit. Sharing of knowledge on technology concepts and practices.
(Information Technology and Services industry)
October 2007 — Present (1 year 10 months)
http://www.soa-consortium.org/steering-committee.htm
(Privately Held; Information Technology and Services industry)
March 2008 — May 2009 (1 year 3 months)
External and Internal Leader for the Governance, Risk & Compliance Business Unit that provides solutions across the entire GRC landscape. Responsible for growing this service offering across all horizontal technology areas and vertical industry offerings. Have an extensive focus on areas that are typically not very mature in most large enterprises like a unified Security Strategy, Application Security, SOA Security & Architecture, Data Leakage Protection, Endpoint Security, Identity & Access Management, Entitlement Management, Program Development, Training, etc.
These span across securing the entire gamut of enterprise, ERP, Web 2.0, social networking, infrastructure, and legacy systems.
(Privately Held; 51-200 employees; Management Consulting industry)
February 2007 — March 2008 (1 year 2 months)
- Information Security & Risk Management Assessments, Recommendations, Road maps.
- Application Security Assessments, Security integration into the SDLC
- Services Oriented Architecture SOA Security Architecture
- Unique, holistic approach to unify traditional silos of Security for Network & Infrastructure, Application, SOA and Enterprise Identity & Access Management
(Privately Held; 201-500 employees; Information Technology and Services industry)
December 2005 — January 2007 (1 year 2 months)
IT strategy, architecture, process and roadmap consulting to our key clients like General Electric, British Petroleum, Coca-Cola, Tyco/ADT etc. Building new practices within SDG.
(Privately Held; 201-500 employees; Information Technology and Services industry)
June 2003 — December 2005 (2 years 7 months)
Primary responsibilities included the development and growth of the Security, Identity & Access Management practice, and providing strategy, architecture, process and roadmap consulting to our key clients like General Electric, British Petroleum, Coca-Cola, etc.
Created Virtual Engineering teams distributed between our multiple locations to offer services in the practice. These teams provided maximum flexibility to SDG’s growth strategy while increasing employee skills and satisfaction.
Created alliances with select primary vendors like OctetString, Trusted Network Technologies, Ping Identity, and Sun.
(Privately Held; 201-500 employees; Information Technology and Services industry)
April 2000 — June 2003 (3 years 3 months)
Single technical point of contact for all client projects in the US Midwest. Managed over 35 local and remote consultants structured in teams of solution architects, project managers, leads and developers.
• Worked closely with distributed teams in the offshore development center in India.
• Developed and presented solutions, proposals, and pitches for new projects working along-with the corporate business development resources to grow the business locally.
• Closely monitored projects on client expectations, project schedules, deliverables, resources and budgets.
• Coached and mentored project teams on methodology, process and effective ways to keep the project on track and budget.
• Reviewed solution architecture and design of all projects to ensure delivery for best of breed solutions to clients.
(Privately Held; 51-200 employees; Information Technology and Services industry)
January 1999 — March 2001 (2 years 3 months)
Lead and managed a team of over 65 resources consisting of Technical Leads, Software Engineers, and Infrastructure Support Engineers. Formulated processes to be able to better manage the development center, with improved project tracking, communication and quality measures. Managed Alliance/Business Partnerships in India and enabling the development facility to be in compliance with strict international guidelines to become an Technical Center of Excellence for our key clients.
(Information Technology and Services industry)
1998 — 1999 (1 year)
(Information Technology and Services industry)
1997 — 1998 (1 year)
(Privately Held; 11-50 employees; Information Technology and Services industry)
July 1988 — May 1997 (8 years 11 months)
new technology, security, ethical hacking, federation, extreme programming, gadgets and gizmos, location (gps) based solutions, web based collaboration spaces, social networking, writing, photography, flying, RC flying, cars, cars, cars..
Information Systems Audit and Control Association (ISACA)
The Information Systems Security Association (ISSA)®
SOA Consortium, Infoworld SOA Executive Summit, Airforce friends