Varinder Kumar
Information & Product Security Consultant @VamiSec GmbH
Signup · Get unlimited contacts
WORK HISTORY
Information & Product Security Consultant @VamiSec GmbH
EDUCATION
CT Institute of Technology, Shahpur
Diploma of Education, Computer Science
CT Institute of Engineering, Management and Technology, Shahpur
Computer Science and Engineering, Computer Science
Offenburg University of Applied Sciences
Master's degree, Enterprise and IT security
ABOUT VARINDER KUMAR
I am an Information Security Consultant and Product Security Consultant specializing in regulated industries. I work across enterprise governance and product-level cybersecurity, helping organizations build security programs that are technically sound, regulator-ready, and aligned with business goals.In product security, I support connected systems in medical device and automotive environments. I translate regulatory and cybersecurity requirements such as EU MDR, the Cyber Resilience Act, IEC 81•••51, IEC 62443, MDCG guidance, and ISO 21434 into concrete technical and architectural controls. My work includes defining secure design principles, conducting structured threat modelling using STRIDE and attack trees, performing security architecture reviews, and supporting penetration testing and remediation validation. I integrate security gates into the Secure Software Development Lifecycle and prepare technical documentation for audits and regulatory submissions, ensuring security is embedded from design through release and post-market phases.Earlier, I supported a Cybersecurity Management System aligned with TISAX and ISO 21434, conducted vulnerability analysis using SCA tools, maintained SBOMs with CVE and CVSS traceability, developed remediation guidance, contributed to risk assessments, and supported audit preparation. I also built reporting dashboards to improve vulnerability visibility for management.On the enterprise side, I design and operationalize ISO 27001-aligned ISMS frameworks. My experience includes risk and asset management, policy development, internal audits, and compliance alignment with GDPR, DORA, NIS2, and the EU AI Act. I also implement cloud security controls in Microsoft 365 environments using Microsoft Purview capabilities such as DLP, Information Protection, and Insider Risk.I hold a master’s degree in enterprise & IT Security and certifications as an ISO 27001 Lead Implementer and ISO 27001 Auditor. My long-term focus is to advance in both product security and information security by embedding secure-by-design principles into connected products and building risk-driven, audit-ready ISMS programs that support sustainable business growth.
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.