
Dynamic GRC leader with over 13 years of experience in Information Security Governance, Risk & Compliance (IS GRC), IT Risk Management, and Cybersecurity across diverse sectors, including BFSI, Telecom, NBFC, Consumer Markets, and Logistics. Proven success in establishing and scaling Third-Party Risk Management (TPRM) programs while ensuring regulatory compliance with RBI and SEBI standards. Expertise in implementing critical frameworks such as ISO 27001, SOC 2, and NIST, along with a strong track record of leading enterprise-wide risk initiatives and vendor governance audits. Skilled in driving security transformation efforts with effective stakeholder engagement across CISO, CIO, and CTO functions.
• Led enterprise-wide ISO/IEC 27001:2022 implementation across Allcargo entities, including first-time certification for Terminals.
• Designed and implemented a comprehensive TPRM framework covering onboarding, assessment, monitoring, and offboarding.
Assessed 50+ new vendors and established governance for existing vendors.
• Established a centralized Vendor Governance model, ensuring compliance for vendors with logical access.
• Built and trained the TPRM team to manage the vendor risk lifecycle.
• Revamped IT and InfoSec risks in ERM into measurable risk statements, with residual risk plans.
• Collaborated with the CISO, CIO, CTO, and Infra leadership for risk alignment.
• Expanded KRIs from 25 to 60+, improving risk visibility and compliance coverage.
Drove improvements in USB access, VAPT closure timelines, license and software management, and phishing simulations.
• Led internal and external ITGC audits across group entities.
Information Security (IS)/ Internal Audits/ISMS
Third Party Risk Management (TPRM)/ (VRM)
Risk Management & Exception Management
IS Governance Risk & Compliance (IS GRC)
IT Service Management
NIST Cyber Maturity Assessments
Phishing Simulation
SOC 2 Type I & II Audits
ITGC & ITAC audits
Certified Information Security Auditor (CISA), ISACA
ISO/IEC 42001 (AIMS)
Certified Information Security Auditor (CISA), ISACA
ISO/IEC 27001:2022
ISO/IEC 20000-1:2011
Lean Six Sigma Green Belt
ITIL V3 Certified