Summary
Overview
Work History
Education
Skills
Websites
Certification
Awards
Languages
Timeline
Generic

AMAN DEEP SINGH CHAWLA

Kanpur

Summary

Risk and compliance professional with expertise in SOC 2 and ISO 27001 initiatives. Proven track record in GRC automation and resilience assessments, driving compliance excellence and achieving audit readiness. Skilled in enhancing security posture through collaboration with diverse teams and effective security strategies. Strong ability to partner with sales leaders to optimize pipeline closure.

Overview

5
5
years of professional experience
1
1
Certification

Work History

Senior Risk & Compliance

ChargePoint Technologies Private Limites
Gurgaon
04.2025 - Current
  • Led SOC 2 and ISO 27001 compliance initiatives across the parent organization and multiple locations, ensuring full adherence to standards.
  • Managed customer compliance assessments and annual security audits, ensuring risk mitigation and audit readiness.
  • Oversaw third-party vendor risk management program for 40+ vendors, streamlining evaluation and remediation processes to enhance compliance.
  • Collaborated with cross-functional teams such as IAM, Cloud Security, Privacy, Legal etc. to refine compliance strategies, aligning them with organizational policies and industry standards for improved effectiveness.
  • Built and scaled the Business Continuity & Resilience program from inception, delivering a mature end-to-end resiliency framework.
  • Engineered end-to-end GRC automation tools, including audit evidence automation, SaaS Integrations, and real-time audit-ready dashboards.

Manager-Information Security

Signzy Technologies Private Limited
Bangalore
11.2022 - 02.2025
  • Led compliance, infrastructure security & product security vertical for team of 5, ensuring alignment with regulatory standards.
  • Optimised Infosec processes for Products and Infrastructure teams to align with Security Frameworks.
  • Collaborated with CISO Teams of Banks & Fintech Players to ensure adherence to RBI, SEBI, IRDAI & other regulatory security guidelines.
  • Presented and reported high-level Information Security initiatives, risk posture, and compliance updates to CXO leadership and the Board.
  • Managed yearly budget for infosec team, optimizing resource allocation for security initiatives.
  • Evaluated and implemented end-to-end GRC compliance automation solution, enhancing compliance efficiency.
  • Served as the primary lead for security audits and due diligence, securing audit clearances for key clients including American Express, Emirates NBD, Amazon Payments (UAE), HDFC Bank ICICI Bank, Paytm, State Bank of India, Indusind Bank, Citibank, and other fintech & NBFC customers.

Associate Manager - Information Security

Signzy Technologies Private Limited
Bangalore
11.2021 - 10.2022

Built and implemented the SOC 2 Type I & II framework from scratch, achieving certification within 8 months.

  • Led information security and compliance audits across Cyber Security Framework, SAR Data Localization, VKYC, NSDL eSign, NPCI, SEBI, Application Security, BCP & DR, Vendor Audits & Cloud Security Posture to ensure adherence to security standards.
  • Conducted comprehensive risk assessments and business impact analyses aligned with ISO 27001 and NIST, enabling effective remediation tracking and management reporting.
  • Performed internal and privacy impact assessments (PIAs) to mitigate data protection and regulatory compliance risks.
  • Hands-on experience with cloud environments and security technologies including SIEM, EDR, DLP, NAC, AV, and email security solutions.

Security Engineer 1

Signzy Technologies Private Limited
Bangalore
11.2020 - 10.2021
  • Conducted end-to-end security testing for three full-stack products, identifying critical vulnerabilities and improving overall security posture.
  • Executed Vulnerability Assessments (VA) across multiple products and environments using Nessus professional.
  • Performed penetration testing on 300+ APIs.
  • Conducted cloud security audits across AWS and Azure platforms.
  • Executed phishing simulation exercises to assess and enhance employee security awareness and readiness.
  • Delivered employee training on Information Security Awareness, Privacy, and Secure Coding practices to foster a culture of security compliance.
  • Led ISO 27001 re-certification with the external auditor, achieving zero non-conformities.

Education

Masters of Computer Applications -

Dr. APJ Abdul Kalam Technical University
Lucknow, Uttar Pradesh
06.2021

Bachelors in Computers Application -

Chhatrapati Shahu Ji Maharaj University
Kanpur, Uttar Pradesh
06.2019

Skills

  • Risk assessment
  • SOC 2 compliance
  • ISO 27001 certification
  • Security audits
  • Incident response
  • Business impact analysis
  • GRC automation
  • Cloud security
  • Resiliency assessments
  • Employee training and awareness

Certification

  • Certified Information Security Auditor-CISA
  • ISO 27001 Lead Auditor
  • Web Application Penetration Tester Xtreme eWPTX
  • Data Protection Officer CDPO-DPDPA by DPO Club<>Quality Austria Central Asia

Awards

  • Achieved 10x Top Rated Manager 2022
  • Recognized as Superstar Employee 2021 at Signzy Technologies

Languages

  • Hindi
  • Punjabi
  • English, Native
  • Hindi, Native
  • Punjabi, Native

Timeline

Senior Risk & Compliance

ChargePoint Technologies Private Limites
04.2025 - Current

Manager-Information Security

Signzy Technologies Private Limited
11.2022 - 02.2025

Associate Manager - Information Security

Signzy Technologies Private Limited
11.2021 - 10.2022

Security Engineer 1

Signzy Technologies Private Limited
11.2020 - 10.2021

Masters of Computer Applications -

Dr. APJ Abdul Kalam Technical University

Bachelors in Computers Application -

Chhatrapati Shahu Ji Maharaj University
AMAN DEEP SINGH CHAWLA