I am an experienced information security professional with 16 years of experience in various domains of information security. Involved in the Internal audit UER activities Highlighting non-conformity findings from internal audits to senior management & provide corrective suggestions. Performing Vulnerability Assessment of APAC traders based systems on a periodic interval. Involved in UAT testing of to be on boarded applications & identify the security risks to the Application Development teams Perform analysis of the Vulnerability of Windows, Unix servers & databases & application before it's implemented on live environment Risk assessment of all newly developed applications from the administrative & business perspective & capture them in Compliance registers. Review High privilege admin access used by the business operations and ensure the monitoring of the actions performed by the staff. Periodical review of the application administration to mitigate the risk. Provided Training to people for CISA, CISSP and ISO 27001 LA. Currently working as Senior auditor and handling audit activities for various deliverables for Cyber Security Team.
Part of cyber security audit team. Handling government sector projects
Involved with audit of deliverables : Change Management, ITGC, security AUDIT, IMS, BCP.
Documentation of Policies and Procedures as per ISO 27001:20013 and ISO 22301:2012 controls and requirements.
Risk Assessment and Treatment Evaluation as per ISO 27001 and ISO 22301.
Designed business continuity framework, including the corresponding policies and procedures based on ISO 22301
Conducted Business Impact Analysis, Risk Assessment and prepared risk treatment plans.
Prepared checklists based on ISO 22301 and CBDT policies and procedures to ensure compliance.
Conducted Internal Audit as per requirement of ISO 27001 and ISO 22301 requirements and advisory for closure of findings.
Analysis of problematic areas to provide recommendations and solutions.
Determined areas for improvement and implemented processes to alleviate problems.
Assessing needs for projects and made proposals to senior management.