Initialising secure portfolio…
HomeAboutExperienceSkillsCertificationsHighlightsContact
Network Security Architect · Zero-Trust · SASE/SSE · Cloud & AI · 9 Years

Engineering Zero-Trust
for Cloud & AI Infrastructure.

I architect zero-trust access fabrics (NIST 800-207), SASE/SSE controls, and cloud posture management for global enterprises — securing 35,000+ users across 190+ locations. Aligned to NIST AI RMF 1.0, OWASP LLM Top 10, and MITRE ATLAS so AI adoption never compromises identity, data, or posture.

0Years Exp.
0Users Secured
0Locations
0% Less Incidents
AS
Network Security Architect

Anubhav Srivastava

Security Delivery Associate Manager · Accenture · Gurugram

Zero-Trust, End-to-End.

I'm a Network Security Architect with 9 years securing global enterprise infrastructure — architecting zero-trust (NIST 800-207), SASE/SSE (SWG, CASB, DLP), cloud posture (CSPM/CNAPP), identity, and data-egress controls that protect both traditional and AI-enabled workloads at enterprise scale.

At Accenture, I own the zero-trust access fabric for 35,000+ users across 190+ locations on Zscaler (ZIA & ZPA), Palo Alto, Cisco ISE, Entra ID, and Azure CSPM — governing access to enterprise, cloud, and AI-hosted services with ZTNA and micro-segmentation. At Deloitte, I federated 250,000+ users via Entra ID & Google Cloud Identity and migrated 200+ applications across 26 VPCs to AWS.

I align architecture to NIST AI RMF 1.0, OWASP LLM Top 10, and MITRE ATLAS so enterprises can adopt GenAI without compromising posture, data, or identity. Directing 30+ engineer teams across BFSI, healthcare, telecom, and FMCG clients.

🛡️

Zero-Trust & SASE/SSE

NIST 800-207, ZTNA, micro-segmentation, SWG/CASB/DLP, lateral-movement containment.

☁️

Cloud & AI Infrastructure

AWS, Azure, GCP — CSPM/CNAPP/CWPP, API security, inference-endpoint protection.

🔐

Identity Governance

Entra ID, Okta, Azure B2B, conditional access — human, service, and AI-agent identities.

🤖

AI Security Alignment

NIST AI RMF 1.0, OWASP LLM Top 10, MITRE ATLAS, Google SAIF — LLM access governance.

Experience & Architecture

Tap through each role to see the work, the diagrams, and the impact.

Accenture

Security Delivery Associate Manager
Mar 2024 – Present
Enterprise · Multi-Cloud · Zero-Trust · AI Workloads

Architecting the zero-trust access fabric and cloud security posture for global enterprise infrastructure — governing access to on-prem, cloud, and AI-hosted services, and directing a 26–28 engineer security operations team.

Zero-trust access for 35,000+ users across 190+ locations on Zscaler ZIA/ZPA, Palo Alto, Cisco ISE, Entra ID, Azure CSPM
Engineered end-to-end Zscaler tenant with the Zscaler engineering team — cut incidents 70%; designated project Zscaler SME
Azure CSPM on Microsoft Defender for Cloud — continuous posture, risk ID, automated remediation for AI & critical workloads
WAF & DDoS strategy across AWS and Azure — tuning native controls for app, API, and inference-endpoint protection
Enterprise identity modernization & Entra ID transformation — SSO, federation, conditional access for human, service & AI-agent identities (team of 30–32)
Zscaler ZIA/ZPAPalo AltoPrismaCisco ISEForescoutEntra IDAzure CSPMDefender for CloudAWS WAFAzure WAFNIST 800-207NIST AI RMF
aws-security-governance.arch
AWS SECURITY GOVERNANCEAWS CLOUDIAM GOVERNANCERole ApprovalsAccess ReviewsGUARDRAILSSCPs · CloudTrailLambda RemediationIDENTITYEntra ID · SSOB2B FederationWIZ CSPM — POSTURE MONITORINGAlerts · Risk Rules · Dashboards · Multi-CloudCOMPUTEEC2 · ECS · LambdaDATAS3 · RDS · DynamoDBNETWORKVPC · WAF · ShieldCOMPLIANCENIST 800-53 · ISO 27001 · CIS · SOC 2

Deloitte Consulting USI

DC Engineer 2 — Cloud Network Security
Jun 2022 – Mar 2024
Enterprise SaaS · AI-Ready Cloud · Identity

Architected the segmented AWS cloud network foundation for SaaS and AI workloads, and the identity backbone federating SSO for a quarter-million users.

Migrated 200+ apps incl. 50+ business-critical workloads from on-prem to AWS across 26 VPCs in multiple waves
HA, scalable AWS network — VPC, subnets, route tables, security groups, ELB, Route 53 (multi-region, micro-segmentation)
AWS network security — NACLs, Security Groups, Palo Alto Network Firewall; site-to-site & client VPN via AWS VPN + Direct Connect
Deployed AWS WAF, Shield (DDoS), CloudFront, Global Accelerator to secure content, API, and service delivery
Entra ID ↔ Google Cloud Identity federation via Azure B2B — SSO for 250,000+ users across Google Marketing Platform (POC → Prod → Hypercare)
AWS VPCELBRoute 53Network FirewallWAFShieldCloudFrontGlobal AcceleratorDirect ConnectEntra IDAzure B2BGoogle Cloud Identity
aws-landing-zone.arch
AWS LANDING ZONEAWS ORGANIZATIONS + SCPsSECURITYLOG ARCHIVESHARED SVCSNETWORK26 VPCs · 200+ AppsVPC-PROD-01VPC-PROD-02VPC-STG···VPC-26ENTRA ID — SSO 250K+MIGRATION WAVES

Accenture

Security Senior Analyst
Sep 2021 – Jun 2022
BFSI · Healthcare · Hospitality · Petroleum · Public Sector

Network security architecture consulting across CMHC, Grant Thornton, Nature's Bounty, and Illinois Tollway — engineering complex changes, DR projects, and multi-OEM firewall policy at SLA.

Operated Checkpoint, Cisco FMC, ASA 5500/5500-X, Firepower 4100 in standalone & HA with virtual Threat Detection
Firewall policy across Checkpoint, Cisco ASA (multi-context), FortiGate, Palo Alto — access rules by IP/port/protocol for segmentation
Site-to-site VPN migrations to AWS and Azure; evaluated Cisco NG Firepower 4100 with vTD/ASA modules for production
Coordinated vendor TAC for issue resolution within SLA; junior analyst mentoring & KT
CheckpointCisco FMCASA 5500-XFirepower 4100FortiGatePalo AltoAnyConnect VPNSIEMIDS/IPSSolarWinds
mss-soc.arch
MSS SOC OPERATIONSFIREWALLSCP·ASA·FG·PALOGSIDS/IPS·NPMSIEMSplunk·QRadarRESPONSETAC·IRUS ENTERPRISE — BFSI · HC · PETRO · GOVTeam Enablement · Mentoring · KT

Birlasoft Limited

Network Analyst
Aug 2019 – Aug 2021
Healthcare · Petroleum · Insurance

Network and security operations across Invacare, Weatherford International, and Allstate — Azure firewall deployment, IAM migration, SIEM rollout, and enterprise vulnerability & compliance monitoring.

Deployed firewalls on Azure Cloud; migrated apps from Okta to OneLogin — redesigning DC for improved posture & access control
Engineered Blusapphire SIEM across 8 data centres; rolled out Tenable for continuous vulnerability & compliance monitoring
Governed change processes — site commission/decommission, NCM backup, IOS upgrades
Root-caused bad links, CPU utilization, port errors, and device outages
Azure CloudOktaOneLoginBlusapphire SIEMTenableFortinetCisco ASAF5 LTMZscalerMPLS
azure-security.arch
AZURE SECURITY STACKAZURE FWIAM MIGRATIONSIEM/EDR · 8DCFortinet · Cisco ASA · F5 LTM · ZscalerTenable SC / Nessus — Enterprise Vuln Mgmt

Vodafone India

AM — Service Management (IP)
Feb 2019 – Aug 2019
Telecom · IP Service Ops

Owned IP service management operations for Vodafone India's telecom network — incident, change, and availability governance across the IP services stack.

Managed IP incident/change/availability for the Vodafone India telecom infrastructure
Coordinated cross-functional NOC teams to maintain SLA-aligned IP services stack
ITILIP OpsIncident MgmtChange MgmtTelecom NOC

Evolve Technologies · Data Link Consultancy

Senior NLD/VAS Engineer → Network Engineer (Vodafone India)
Sep 2016 – Feb 2019
Telecom · L1/L2 Support · Backbone

L1/L2 support and network engineering for Vodafone VAS-LAN, NLD/ILD voice, E-TOPUP, and IN networks — routing/switching, firewall ops, and critical MOP execution.

Configured routers/switches/firewalls across RIP, OSPF, BGP, MPLS with VLAN, STP, HSRP, VRRP, EtherChannel
Operated Cisco ASA 5585 and Juniper NetScreen ISG-1000; ACL policy implementation on ASA 5585
Troubleshot packet loss, SCTP path failures, latency; monitoring via WANDLE, TEMIP, ASDM, Cisco Prime Infra
Designed & implemented new solutions improving resilience and segmentation of Vodafone infrastructure
BGPOSPFMPLSJuniper M/MXCisco CatalystASA 5585Juniper ISG-1000VLAN/STP/HSRP
telecom-backbone.arch
VODAFONE TELECOMVAS-LANIN NetworkROUTINGBGP·MPLS·OSPFROUTERSJuniper·CiscoFIREWALLSASA·ISGNLD/ILD BACKBONE — VODAFONE INDIA

Skills & Technologies

Full-stack security across zero-trust, cloud, identity, detection, and AI infrastructure.

☁️

Cloud Platforms

AWS VPCELBRoute 53WAFShieldCloudFrontGlobal AcceleratorDirect ConnectNetwork FirewallAzure CSPMDefender for CloudAzure WAF
🌐

Proxy · Web · CASB · DLP

Zscaler ZIAZPASWGCASBDLPForcepoint ONEMimecastAPI Security
🔐

IAM & Identity

Microsoft Entra IDAzure B2BGoogle Cloud IdentityOktaOneLoginCyberArkSAMLSSO/FederationConditional AccessPrivileged AccessCisco ISECisco ACSForescoutForti NAC
📊

SIEM · SOAR · XDR

Splunk ESIBM QRadarLogRhythmArcSight ESMRSA NetWitnessRapid7 InsightIDRBlusapphireSOAR AutomationThreat HuntingXDR
⚙️

Routing, Switching & NAC

BGPOSPFMPLSRIPVLANSTP/RSTPHSRP/VRRPEtherChannelCisco Nexus 5K/7K/9KJuniper MX960/240Arista 70xxT
🔎

Vulnerability, Endpoint & Tools

Tenable SC/NessusSolarWinds NCM/NPMSentinelOneTrend MicroMcAfee ePOWiresharkSAML TracerVirusTotalAbuseIPDBServiceNowHPSM

Certifications

Industry-recognized across Azure and AWS.

Azure Solutions Architect Expert

AZ-303 / AZ-304

Azure Administrator Associate

AZ-104

AWS Solutions Architect — Associate

Amazon Web Services

AWS Advanced Networking — Specialty

Amazon Web Services

Measurable, Enterprise-Scale Impact.

Quantified outcomes across zero-trust, cloud, identity, and AI-ready infrastructure.

70%

Security Incidents Cut

End-to-end Zscaler tenant architecture, build, and deployment for 35,000+ users across 190+ locations at Accenture.

35K+

Users Secured

Zero-trust access (ZIA/ZPA, ZTNA) across 190+ locations for the global enterprise footprint.

250K+

Federated SSO

Migrated 250,000+ end-users via Entra ID + Google Cloud Identity federation across Google Marketing Platform at Deloitte.

200+

Apps to AWS

Migrated 200+ applications incl. 50+ business-critical workloads across 26 VPCs — the segmented cloud network foundation for SaaS and AI workloads at Deloitte.

30+

Engineers Directed

Cross-functional security operations teams (firewalls, NAC, Zscaler, IAM) governing incident response & compliance posture.

AI

Secure GenAI Adoption

Architecture aligned to NIST AI RMF 1.0, OWASP LLM Top 10, MITRE ATLAS & Google SAIF — enabling enterprise AI without posture drift.

Let's Build Something Secure.

Zero-trust architecture, cloud & AI security, identity governance — open to opportunities and collaborations.

STATUS · Available for consulting·TZ · IST (UTC+5:30)·SLA · < 24h
anubhav@security-arch:~/contact — zshSECURE · TLS 1.3
encrypted-in-transitzero spam · zero recruiter blastsreplies within one business day