CISO / dyCISO Track | Principal Cybersecurity & IAM Architect - IAM, Digital Security, Directory Entitlements | Former SVP, Goldman Sachs
Transforming enterprise security posture through Zero Trust Architecture, Scalable IAM Governance & AI-Driven Risk Resilience. 21+ years protecting Fortune 100 infrastructures across Goldman Sachs and global tech leaders.
- 21+ Years directing enterprise defense, identity architecture, and security governance across Tier-1 financial institutions.
- 5M+ Identities Protected: Scaled modern identity fabrics across workforce, multi-cloud workloads, and machine/non-human identities.
- Unblemished Regulatory Record: 0 audit findings across SOX 404, GLBA, and GRC controls over 3+ consecutive years.
- Zero Standing Privilege: Engineered JIT PAM modernization driving a 98.4% reduction in privileged credential exposure.
- Executive Strategy & Board Governance: C-suite cyber governance, $18.5M modernization budgets, Architecture Review Board (ARB) leadership, and regulatory audit compliance.
- Identity Fabric & Access Architecture: OAuth 2.0, OIDC, SAML 2.0 federation, hybrid Entra ID / Active Directory Tier-0 hardening, SailPoint IGA, and privileged access workflows.
- Zero Trust Architecture (NIST 800-207): Continuous verification, phishing-resistant FIDO2 WebAuthn authentication, micro-segmentation, and zero standing privilege (ZSP / JIT).
- Hybrid Multi-Cloud Security: Enterprise PKI / Hardware Security Modules (HSMs), AWS & Azure Cloud Security Posture Management (CSPM), and high-frequency trading enclaves.
- Autonomous Threat Detection: Real-time operational intelligence, SIEM/SOAR automation, and dynamic perimeter deny lists.
- Node.js: v18.0.0 or higher (v20+ recommended)
- npm or bun
# Clone the repository
git clone https://github.com/mdhimancs/portfolio.git
cd portfolio
# Install dependencies
npm install
# Start local development server (runs on port 3000)
npm run devOpen http://localhost:3000 in your browser.
# Compile and build the production bundle
npm run build
# Run TypeScript linting verification
npm run lintThe application incorporates strict defense-in-depth measures:
- Content Security Policy (CSP): Hardened CSP restricting script, object, and style evaluation.
- Mandatory HTTP Headers: HSTS, X-Content-Type-Options:
nosniff, X-Frame-Options:SAMEORIGIN, and strict Permissions-Policy. - Zero-Trust Resource Gate: Protected executive blueprints, case studies, and patents gated by Firebase Authentication and Firestore allowlist RBAC.
- Time-Bound Sessions: Cryptographically signed access links valid for 8 hours for executive search partners and board committees.
- Anti-Abuse Safeguards: Form honeypot defense, client-side submission rate limiting, and server-side IP throttling.
For complete architectural specifications, see PROJECT_GUIDE.md and 4_webSecurity.md.
- PROJECT_GUIDE.md: Master deployment, security, and architectural documentation.
- 2_DEPLOYMENT.md: Hosting guides for GitHub Pages, Vercel, Netlify, and Cloud Run.
- 4_webSecurity.md: Web security policies, HTTP headers, and access control specs.
- 3_Ideas.md: UI/UX design blueprints and segmented tab design systems.
- Ideas.md: Future capabilities and strategic feature roadmap.
- Email: munish.world@gmail.com
- LinkedIn: linkedin.com/in/munishd
- GitHub: github.com/mdhimancs
- Location: Bengaluru, India