AI Security | GRC | Cloud Security | Cybersecurity Engineering
Assistant Manager – Cybersecurity @ Uniqus Consultech | Ex-PwC | Ex-HSBC
M.Eng. Cybersecurity, University of Maryland (RSA Conference Security Scholar '24)
I work at the intersection of GRC, cloud security, and nation-state cyber threats — because security policy without technical depth, and technical security without policy context, are both incomplete.
Currently leading enterprise GRC audits at Uniqus Consultech, advising clients on ISO 27001, NIST CSF 2.0, and the RBI Cyber Resilience Framework. Previously at PwC (Atlanta & Gurugram) and Cyble building security programs from scrathc, and before that building secure authentication modules at HSBC.
I research how cyber threats intersect with geopolitics and critical infrastructure — currently working on US pipeline attack surface. I was selected as an RSA Conference Security Scholar ‘24, one of a small cohort chosen from across the universities in USA each year.
AI threat modeling tool for AI-enabled products. Implements deterministic OWASP LLM Top 10 evaluators grounded in real-world GRC and audit experience. Built with Python, Groq, and Streamlit — outputs automated PDF and Markdown reports.
Built an open-port attack surface dashboard for Maryland county government websites
using Python, ElasticSearch (ELK), and Censys APIs.
📄 Published at OSF · Harry, Sivan-Sevilla,
McDermott, Yadav, Daley (2023)
CISSP GSEC CCSK GCP-ACE AZ-900
I write about security, AI risk, and the gap between policy and practice.
→ NotYourCISO on Medium
📍 Gurugram, India
🌐 rishipalyadav.github.io ·
LinkedIn
