vCISO & Security Advisory

Helping leadership
understand & act on
security risk.

Most organisations don't lack security tools. They lack clarity on the risk — and what to do about it. I help leadership understand, prioritise, and act.

Role
Virtual CISO (vCISO)
Background
Network → Cloud → Security → GRC
Education
M.S. Cybersecurity, Australia
Certified
ISO 27001 Lead Auditor
ISO 27001 Lead Implementor
CEH v12
CompTIA Security+
AWS Cloud Practitioner
CCNA
Trained
CISA
Cyber Security Expert — Simplilearn
View full profile on LinkedIn
Amit · Ami IT InfoSec Solutions
0Years of experience
0Sectors served
0Frameworks delivered
0Countries active
The gap I fill

One lens is never enough. Organisations need both.

"Security decisions are strongest when governance, risk, compliance, and technical realities are viewed together."
Services
Where I can help

Advisory or hands-on — depending on what you need. The goal is always the same: reduce risk and help the business make informed decisions.

01 — vCISO

Virtual CISO

Senior security leadership without the full-time cost. Strategy, risk translation, and team guidance — on a fractional basis.

Board reportingSecurity strategyRisk quantificationTeam guidance
02 — GRC

Governance, Risk & Compliance

Policies, frameworks, risk registers, and compliance structures that hold up under audit — and actually reflect how your organisation operates.

ISO 27001SOC 2HIPAADPDPACERT-InITGCIT Act
03 — ISO 27001

ISO 27001 Implementation

Gap analysis to certification readiness — end-to-end, run as project lead with an auditor's eye on every deliverable.

Gap analysisISMS designAudit readinessPolicy framework
04 — Technical

Technical & Infrastructure Advisory

Assessments across infrastructure, networks, cloud, and applications — grounded in how systems actually work, translated into what leadership needs to hear.

Cloud securityNetworkInfrastructureApplication security
Sectors I work with

Wherever data flows, risk follows. If your organisation exchanges, stores, or acts on information — that's where I come in.

💻Technology & SaaS
🏥Healthcare
🏦BFSI
📡Telecom & Media
🏛️Government & Public Sector
🎓Education
🛒Retail & E-commerce
🏭Manufacturing & Industrial
⚖️Legal & Professional Services
About
A practitioner who speaks both languages.

I started as a network engineer — so I understand how systems are built, not just documented. After completing my Masters in Cybersecurity in Australia, I returned to India in 2021 and built a practice around a gap I kept seeing.

Most security professionals see through one lens — technical or compliance. Organisations need both. That became my focus.

I come in, understand the environment from both lenses, quantify risk in business terms, and help leadership decide what to prioritise. Boards care about numbers, not jargon.

Broad technical foundation
Hands-on experience across infrastructure, networks, cloud, application support, and cybersecurity — from network engineering to security leadership.
ISO 27001 Lead Auditor
Certified to plan and lead ISMS audits. Active in implementation engagements with audit experience built through supervised practice.
Regulatory depth
ISO 27001, SOC 2, HIPAA, DPDPA, CERT-In requirements, IT Act, and ITGC controls — across regulated industries.
M.S. Cybersecurity, Australia
Graduate-level education complementing practitioner experience across technical and governance disciplines.
Independent practice
You work directly with a senior practitioner — not a junior resource assigned after a sales pitch.
Why vCISO
Full-time CISO vs. Virtual CISO

Full-time CISO

₹40–80L+ per year — salary, benefits, overheads
3–6 months to hire and get up to speed
Single perspective — one industry at a time
Technical or compliance — rarely both

Virtual CISO — Ami IT InfoSec

Fraction of the cost — senior expertise, flexible retainer
Immediate start — no hiring cycle
12+ sectors — broader perspective by design
Governance and technical — always together
"[CLIENT TESTIMONIAL — Replace this with a real quote when you have one. One powerful sentence about what working with you delivered. Get permission from the client first.]"
[Client Name, Title] · [Company]
Global reach
A small, capable team —
distributed across time zones.
🇮🇳India
🇦🇺Australia
+ expanding →
How I work
How an engagement works.
01

Understand the environment

Governance and technical — what exists, what's documented vs. reality, where the gaps are.

02

Quantify risk in business terms

Technical findings translated into business impact. Numbers leadership can act on.

03

Advise on priorities

What to fix now, what to plan, what to accept — with clear rationale.

04

Execute or guide

Hands-on or advisory — whatever the engagement needs.

FAQ

Questions I get asked before every engagement.

Let's talk

A consultant typically comes in for a defined project — an audit, a pen test, a gap assessment — and leaves. A vCISO is ongoing security leadership: I sit in your corner, understand your business context, advise your leadership, and evolve the strategy as your organisation grows. Think of it as the difference between a project hire and a trusted advisor.

Primarily growth-stage startups and mid-sized organisations — typically 50 to 2,000 employees — who need senior security leadership but aren't ready to justify a full-time CISO headcount. I also work with larger organisations on specific programs like ISO 27001 implementation or GRC maturity.

Yes. My team spans India and Australia, and I work with organisations across both regions. Engagements are primarily remote with on-site presence when needed. I'm familiar with both Indian regulatory requirements (DPDPA, CERT-In, IT Act) and international frameworks (ISO 27001, SOC 2, HIPAA).

Articles & Posts
Thinking out loud.

Security leadership,
without the full-time hire.

Founder, CXO, or board member who needs security leadership without a full-time hire?

Technology · Healthcare · BFSI · Government · Manufacturing & more

info@amiit.in
Or connect via LinkedIn above