Journey
Education
Certifications & Skills

Vik Soni

CISSP, CISM, ISO 27001 Lead Auditor

I have spent the better part of two decades where technology gets genuinely complicated: the place security frameworks collide with real engineering, and compliance stops being a box-ticking exercise and starts demanding craft.

The ground runs from hands-on systems and network engineering, through security consulting and architecture, to leading end-to-end security functions across industries and geographies. There is a Master’s and a stack of certifications below. None of that is what keeps me interested. What keeps me interested is the problem of making a complicated idea usable by the person who actually has to act on it.

Right now that means AI. I am building the tools and the corpus on this site around the frameworks that govern it, writing a book about why security leaders are the right people to do that work, and taking the argument to conferences. There is no product here and nothing for sale. All of it exists because I wanted to know the answer.

Outside work I am a husband and a father to two boys who keep the house happily loud. I raced on the velodrome for years, which taught me more about calculated risk than any framework has. I no longer race, but the bike is still in my life, mostly for the company and the coffee stop. When we are not on wheels we are usually somewhere outdoors, well off the beaten track.

Journey

2022 – Present
Product Security Manager
Bupa, Melbourne
• Application security, vendor risk, penetration testing and secure design across Health Insurance and Corporate Services.
• Translate security risk into executive language and embed it into product and strategic decisions.
2020 – 2022
Advisory Practice Lead & Principal Security Consultant
Triskele Labs, Melbourne
• Built and led the advisory practice: vCISO engagements, board presentations, PCI DSS audits, and risk frameworks for banking, insurance, and retail.
2019 – 2020
Senior Cyber Risk Consultant
BDO, Melbourne
• Risk frameworks, ISO 27001 implementations, cyber risk assessments, and BCP across government, financial services, and commercial clients.
2018 – 2019
Security Consultant
Superloop, Melbourne
• End-to-end ISO 27001 implementation for Cloud Managed Services, building the ISMS from the ground up.
2014 – 2018
System Administrator & Security Engineer
Perks, Adelaide & Local MSP, Melbourne
• End-to-end IT and security management across enterprise and SMB environments: infrastructure, Cisco networking, VMware and AWS.
2012 – 2014
Service Delivery Manager
IBM, Bangalore, India
• Managed Diageo's global IT infrastructure across 80 countries and tens of thousands of employees.
2010 – 2012
IT Manager
Hinduja Group, London, UK
• IT operations across multiple locations. Broad remit, first leadership role, and where the security focus began.
2008 – 2009
MSc, Computer and Information Networks
University of Essex, UK
• Networking principles, IP services and programming, as academic grounding to complement hands-on experience.
2004 – 2008
System Engineering
CSC & Dell, India
• System engineering and support for UK and US customers. The technical foundation, and the habits that stuck.

Education

University of Essex, UKMSc, Computer and Information Networks, 2008 to 2009
Manipal Academy of Higher Education, IndiaBSc, Information Technology, 2000 to 2004

Certifications & Skills

Certifications• Certified Information Systems Security Professional, CISSP (ISC2)
• Certified Information Security Manager, CISM (ISACA)
• Certified Information Systems Auditor, CISA (ISACA)
• PCI Qualified Security Assessor, QSA (PCI Security Standards Council)
• ISO/IEC 27001 Lead Auditor (IRCA)
• Cyber Leadership Program (Cyber Leadership Institute, 2024)
• AWS Certified Solutions Architect, Associate (Amazon Web Services)
• ITIL V3 Foundation
• Cisco Certified Network Associate, CCNA
• Microsoft Certified Systems Engineer, MCSE
Security & ComplianceSecurity architecture, threat modelling, risk management, ISO 27001, PCI DSS, security frameworks, audit and assurance
Cloud & InfrastructureAWS, Azure, systems engineering, network engineering, infrastructure as code, service delivery management
AI & Machine LearningRetrieval-grounded AI tooling for security frameworks, AI-assisted security work, and NIST CSF and ISO 27001 model development. LLM fine-tuning and local inference as lab and research work, not in the production path.