Krishnaveni Palanivelu

Hello

I'm Krishnaveni Palanivelu !

A SVP @ Citi
Cyber Security Architect

Forward-thinking cybersecurity leader with deep expertise in Information Security Strategy, Cloud Security, Regulatory Compliance, Risk Management, and Enterprise Security Architecture.
Committed to building resilient, secure, scalable, and future-ready cyber systems.

Hello

I'm Krishnaveni Palanivelu !

A SVP @ Citi
Cyber Security Architect

Forward-thinking cybersecurity leader with deep expertise in Information Security Strategy, Cloud Security, Regulatory Compliance, Risk Management, and Enterprise Security Architecture.
Committed to building resilient, secure, scalable, and future-ready cyber systems.

My Certifications

Certified Expertise in Cloud, Security & Technology

CISM

Certified Information Security Manager

01

ITIL Foundation

ITIL Foundation.

02

Solutions Architect – Professional

AWS Certified Solutions Architect – Professional

03

Solutions Architect – Associate

AWS Certified Solutions Architect – Associate

04

SysOps Administrator – Associate

AWS Certified SysOps Administrator – Associate

05

Foundations Associate

Oracle Cloud Infrastructure 2019 Foundations Associate

06

Architect Associate

Oracle Cloud Infrastructure 2019 Architect Associate

07

Database Specialist

Oracle Autonomous Database Specialist

08

About Me

Krishnaveni Palanivelu

SVP @ Citi | 20+ Years in IT & Cyber Security
Cyber Security Architect | Financial Domain Expert

I am a forward-thinking technology leader and Information Security Professional with 20+ years of experience in the IT industry, primarily within the financial services domain. Throughout my career, I have successfully directed strategic cybersecurity planning, shaped long-term technology visions, and strengthened enterprise-wide security frameworks.

As a goal-oriented team leader, I excel at selecting, mentoring, and empowering top-performing cross-functional teams. I consistently drive organizations to meet ambitious expectations, maintain the highest quality standards, and stay ahead in a rapidly evolving digital landscape.

With deep technical expertise across security architecture, governance, cloud, compliance, and risk, I regularly advise senior leadership on positioning the organization for future success, resilience, and growth.

I am known for exceptional analytical thinking, the ability to design innovative solutions for complex issues, and a strong commitment to building secure environments at scale.

My Specializations Include

01

Information Security Strategy

02

Information Security Governance

03

IT Compliance & Data Privacy

04

Intrusion Detection & Prevention

05

Network & System Security

06

Vulnerability Assessment

I have a passion for continuous learning and adapting to emerging technologies. I firmly believe learning is the key to success, and with the right team, strategy, and tools, anything is possible.

Work Experience

SVP, Cyber Security Architect - Citi

SVP, Cyber Security Architect

Citi – United States

Aug 2022 – Present · 3 yrs 3 mos

Responsibilities:

  1. As a senior application security architect support Global Functions Technology, conducting architectural risk assessments, Cloud/High Risk Exception reviews for SaaS vendor applications and coordination of firm-wide projects with SASA architects in the other sectors. Evaluate and recommend new and emerging external products and technologies to
    implement.
  2. Support 42 BISO’s, 14 TISO’s, 8 GISO’s, 12 businesses, ~1000 GFT applications, and 11 GFT Senior Leaders. The overall objective of this role is to ensure the execution of Information Security directives and activities in alignment with Citi’s data security policy.
  3. Work with GFT Applications Development function to drive the development of strategies and plans for improving both architecture and application security.
  4. Conduct and facilitate security reviews for SaaS vendor application architectures and tabletop/red-team/scenario analysis exercises in conjunction with other Subject Matter Experts by monitoring changes in the risk profile and exposure for the application.
  5. Identify new requirements / enhancements to standards, tools, and processes
  6. Define secure configurations leveraging technical knowledge and problem-solving skills in the network, database, server, and desktop technology areas in accordance with the secure process and develop functional specifications and documentation.
  7. Assist with responsibilities over the technical strategy for an area, technical integrity of process, operations, and associated results.
  8. Participate in the evaluation and selection of applications and systems with specific focus on IS implications.
  9. Appropriately assess risk when business decisions are made, demonstrating consideration for the firm’s reputation and safeguarding Citigroup, its clients, and assets, by driving compliance with applicable laws, rules, and regulations, adhering to Policy, applying sound ethical judgment regarding personal behavior, conduct and business practices, and
    escalating, managing, and reporting control issues with transparency.
  10. Experience leading/performing Threat Modeling using industry standard methodologies (e.g. STRIDE) and evaluation IriusRisk tool.
  11. Familiarity with the latest security technologies and trends, such as Zero Trust architecture, AI/ML in cybersecurity.

VP, Cloud security Architect

JPMorgan Chase – United States

 Nov 2017 – Aug 2022 · 3 yrs 3 mos

Responsibilities:

  1. Proactively and strategically partners with all lines of business and functions to enable them to design, adopt and integrate appropriate controls, deliver processes and secure solutions efficiently and consistently.
  2. Design, Implement, Document and maintain complex cloud security infrastructure to support Application development.
  3. Help teams maintain and follow Security Architecture Best Practices, established standards and provide solutions / proof of concepts.
  4. Collaborate with lead cloud architects and peer Compliance, Privacy, Risk Assessment teams.
  5. Analyze vulnerabilities, threats, designs, procedures, and architectural design, producing reports and sharing intelligence.
  6. Assess security threats and risks in order to define and implement appropriate architectural security models.
  7. Design and Support highly efficient, secure, optimized, and reliable environment on AWS and PCF Cloud environments.
  8. Creating or securing cloud solutions for cloud security technologies including but not limited to identity and access management (IAM), two-factor authentication (2FA), SIEM, public key infrastructure (PKI), network security, firewalls, IDS/IPS, anti-malware, email security, web content filtering, DDoS mitigation, endpoint detection & response, patch management, configuration management, data loss protection (DLP), application security.
  9. Exposure to orchestration and configuration management tools like GIT, Jenkins, Terraform, Kubernetes.
  10. Perform Risk and control assessment on applications to be deployed on GKP Production environments.
  11. Accessing Aqua’s Container Security Platform to provide an end-to-end security solution for containerized environments. Image Assurance, Container Firewall, Access Management, Reports and Audit trial categories are under evaluation.
  12. Responsible for audit compliance, ensure appropriate security best practices are developed and implemented across the DevOps space.
  13. Implement continuous process improvement, including but not limited to, policy, procedures, and production monitoring.
  14. Negotiate, plan, and manage release activities with environment owners and stakeholders as needed for scheduled releases, work with the change management process to represent release quality and make sure production deployments are well orchestrated and have the proper visibility.
  15. Identify and escalate risks and issues around releases and their coordination to the program team, working towards solutions for issues within the release cycle, and working with teams for root cause analysis where applicable.
  16. Run Governance meetings with C level executives to share the status of application delivery.
  17. Based on business requirements, designs and implements cloud-native architectures and designs that will allow those requirements to be met with a minimal degree of risk and with appropriate security controls present.
  18. Represents Security Platform in development and implementation of the overall global enterprise cloud architecture.
  19. Acts as Security Architecture representative while engaging with other senior technical leaders throughout organization in design and implementation of cloud and cloud/hybrid based implementations and solutions.
  20. Drive automation of controls and Implemented monitoring on all enterprise applications and Infrastructure systems (Dynatrace, AppDynamics) which reduced overall critical incidents and provided self-healing features to be architected and implemented.
  21. Serving as a point of contact and liaison between business, application users and tech teams to identify the technical/product/governance requirements.
  22. Manage all incidents, enhancement requests and business continuity activities within SLA, to ensure flawless and quality delivery of services.

Security Consultant

Barclays – United States

Aug 2014 – Nov 2017 · 3 yrs 3 mos

Responsibilities:

  1. Responsible for aligning security initiatives with enterprise programs and business objectives, ensuring that information assets and technologies are adequately protected.
  2. Assist in execution of procedures to monitor and maintain compliance with the Company’s Security Policies and Standards.
  3. Monitor compliance and ensure enforcement with all SOX, PCI DSS, COBIT, and NIST requirements as applicable to the application.
  4. Provide oversight on PCI DSS compliance and completes annual PCI DSS Self-Assessment Questionnaire.
  5. Responsible for tracking all risks on Plan of Action and Milestones POA &M
  6. Conducts recurring Physical and Systems Assessments across third-party vendors.
  7. Advises Senior Management on risk issues that are related to information security and recommends actions in support of the organization’s wider Risk Management Program.
  8. Develop and implement processes to ensure the timely identification of information Cyber Security incidents.
  9. Establish and maintain processes to investigate and document information Cyber Security incidents to be able to respond appropriately and determine their causes while adhering to legal, regulatory, and organizational requirements.
  10. Establish and maintain incident escalation and notification processes to ensure that the appropriate stakeholders are involved in incident response management.
  11. Organize, train, and equip teams to effectively respond to information Cyber Security incidents in a timely manner. 
  12. Test and review the Incident Response Plan periodically to ensure an effective response to information security incidents and to improve response capabilities.
  13. Establish and maintain communication plans and processes to manage communication with internal and external entities.
  14. Conduct post-incident reviews to determine the root cause of information security incidents, develop corrective actions, reassess risk, evaluate response effectiveness and take appropriate remedial actions.
  15. Establish and maintain integration among the Incident Response Plan, disaster recovery plan and business continuity plan.
  16. Evaluate and communicate control strengths and weakness with audit, IT management and business unit staff to plan an effective and efficient integrated audit approach and remediation plan
  17. Responsible for deployment and configuration of entire cloud environment for Apple Pay solution using Jenkins, GIT.
  18. Acted as Security architect for multiple projects few being payment gateway migration project, Apple pay, Bpay/Btap, Diners, BIN migration from On US to VISA, Payment and Issuer Mandates, Housekeeping of Obsolete bins, Cloud Migration etc.
  19. Perform Infrastructure review during peak season and provide several technical recommendations for service improvements.
  20. Used tools such as GIT, Jenkins to support development activity and created CI/CD pipeline.
  21. Building policies for access control and user profiles using AWS IAM, S3 controls with bucket policies.
  22. Experience in security technologies including VPC, IAM, KMS in AWS.
  23. Managing offshore and onshore teams and took ownership and accountability for the offshore technical team’s deliverables in all phases of the development lifecycle.

Project Lead

Walgreens – Chicago, United States

Sep 2009 – Aug 2014 · 3 yrs 3 mos

Responsibilities:

  1. Liaised with business clients to understand the requirements and provide sign off to requirements documents.
  2. Develop and reviewed the unit test plans and scripts with UAT team and execute test scripts to ensure correctness.
  3. Support changes/applications post implementation by debugging, fixing, and participating in maintenance releases as needed by adapting DevOps model.
  4. Took ownership and accountability for the offshore technical team’s deliverables in all phases of SDLC.
  5. Responsible for implementing 3rd party mandates to adhere to compliance and create documentation for custom development products.
  6. Drive MIM call with relevant and impacted teams during major incidents and provide regular updates to Management and relevant teams.
  7. Publish official internal major incident report and root cause analysis.
  8. Drive status meetings and represent CAB meetings for production changes.
  9. Provide Disaster Recovery support in the event of failover.

Module Lead

ING Bank N.V – Singapore

Mar 2006 – Feb 2008 · 3 yrs 3 mos

Responsibilities:

  1. Handling client queries, support day-to day production issues, system monitoring, EOD batch support.
  2. Cater the new requests from different branches of ING Singapore.
  3. Involved in migration of applications based on vendor new release.
  4. Create functional and technical documents, set up and lead an offshore team for round the clock support model.
  5. Liaise with onshore and offshore counterparts in prioritizing, coordinating, and reviewing the delivery, represent production release meetings and provide approvals, training and create reusable documents.

Educational Qualifications

Master’s degree

Master’s in Cyber Security Operations and Leadership

University of San Diego – California United States

May 2020 – Apr 2022

Bachelor of Engineering in Electronics and Communication

Anna University – India

Jun 2001 – Apr 2005