Summary
Overview
Work History
Education
Skills
Certification
Recognition
AREAS OF EXPERTISE
Timeline
Generic

ANKIT LATH

Gurgaon

Summary

Experienced Governance, Risk, and Compliance (GRC) Professional and Certified RSA Archer Expert with 15 years of expertise in designing and optimizing Third-Party Risk Management (TPRM) frameworks across physical and SaaS environments. Led vendor lifecycle programs from onboarding to offboarding, utilizing automated workflows and advanced Archer integrations. Focused on aligning third-party ecosystems with regulatory mandates and enhancing enterprise resiliency.

Overview

1
1
Certification
15
15
years of professional experience

Work History

Senior Associate

Rackspace Technology
Gurgaon, India
01.2021 - Current
  • Vendor Risk & Issue Management: Spearheaded the design and implementation of comprehensive Vendor Risk Management and Vendor Issue Management solutions in Archer to track third-party findings and remediation plans, including Standard Information Gathering (SIG) framework integration.
  • Archer Engage Portal & Vendor Portal Services: Designed, implemented, and installed the RSA Archer Engage Portal and vendor portal services to streamline external stakeholder collaboration.
  • PCI DSS Assessment (v3.0 & v4.2) Implementation: Led the end-to-end implementation of PCI programs in RSA Archer, covering scoping, automated evidence gathering, and auditor assessment workflows within the PCI module.
  • ISO Frameworks & Internal Audit Integration: Architected and deployed end-to-end programs for ISO 27001, ISO 45001, ISO 9001, and ISO 14001 inside Archer to streamline internal audit processes.
  • Risk Tickets & Quarterly Assessment Automation: Conducted requirement analysis and implementation for Risk Tickets applications to handle final assessments, alongside executing quarterly risk assessments and evidence collection for all PCI applications.
  • Authoritative Sources Onboarding & Harmonization: Mapped and onboarded diverse regulatory and standard frameworks into Archer Authoritative Sources, including Cyber Essentials Plus, TISAX, SOC, ISO programs, and ISO 42001.
  • Information Security Policy Mapping: Centralized and onboarded enterprise infosec policies, mapping them directly against controls across multi-framework compliance standards such as TISAX, ISO 27001/14001/9001/42001, Cyber Essentials, Cyber Assurance, HITRUST, and HIPAA.
  • Enterprise Platform Upgrades & SaaS Migration: Successfully engineered the technical upgrade of an RSA Archer instance from version 6.8 to 6.11, while leading the complex migration from an in-house Archer deployment to RSA Archer SaaS.
  • Custom On-Demand Change Management Solution: Developed a bespoke, on-demand application within Archer to track internal change requests and platform enhancements.
  • Award & Leadership Recognition: Honored with the prestigious Rackspace Powerhouse Award.

Associate

JP Morgan Chase
Hyderabad, India
08.2018 - 01.2021
  • Performance & Usability Optimization: Enhanced existing application performance and usability for end-users, alongside simplifying advanced workflows for optimum results.
  • Third-Party Risk Management (TPRM): Expanded TPRM capabilities specifically for process assurance, and designed/built data feeds for integrating engagements, projects, and supplier assessments.
  • Core Logic & Architecture: Redesigning existing logic for legacy or dynamic Control Effectiveness (CE) score calculations.
  • Enablement & Training: Facilitated targeted training and learning programs for RSA Archer.

Information Security Consultant

Intel Corporation
04.2017 - 08.2018
  • Architected and presented high-impact RSA Archer Business Continuity and Disaster Recovery proofs-of-concept (POCs) to executive stakeholders, securing strategic buy-in.
  • Collaborated with HCL leadership to design, develop, and deploy a robust RSA Archer Business Resiliency solution.
  • Spearheaded the successful implementation of RSA Archer Third-Party Risk Management (TPRM), streamlining vendor risk assessment lifecycles.
  • Reengineered legacy event-based exception and extension request applications into fully automated Advanced Workflow systems, reducing manual intervention.
  • Led comprehensive training and enablement initiatives for RSA Archer 6.2 following a complex migration from version 5.x.
  • Executed the technical upgrade of RSA Archer from version 6.2 to 6.4, ensuring seamless platform stability and minimal downtime.
  • Engineered enterprise integrations connecting RSA Archer with ServiceNow, SEAL, and diverse third-party applications via REST APIs.
  • Partnered with HCL to develop and implement Windows PowerShell automation scripts, optimizing custom Archer administrative workflows.

Associate

JP Morgan Chase
03.2015 - 04.2017
  • Architected and deployed custom On-Demand Applications (ODAs) using RSA Archer to support complex Legal and Compliance business requirements.
  • Maintained and optimized enterprise IT Risk and Compliance (ITRC) policies and procedures portals to ensure seamless regulatory lifecycle management.
  • Spearheaded the onboarding and configuration of the KPMG Vision 360 project for JPMC India internal policies.
  • Engineered a secure, automated integration between RSA Archer and Enterprise Password Vault (EPV-AIM) for fortified credential management.
  • Implemented Privacy Management on-Demand applications within the Incident Management framework to streamline privacy governance and incident response.
  • Executed rigorous Risk and Control Self-Assessments (RCSA) and application risk classifications for Legal & Compliance technology systems.
  • Collaborated with LCS IRMs to review and validate RCSA findings against strict organizational control standards and procedures.
  • Received a Certificate of Appreciation from the Chief Technology Control Officer for driving the firm-wide success of the enterprise "Controls" program.

Senior Application Developer

BNY Mellon
07.2014 - 02.2015
  • Integrated Vulnerability Management: Spearheaded the end-to-end integration of RSA Archer with McAfee Vulnerability Manager and QualysGuard environments, automating vulnerability data feeds to streamline risk posture visibility across infrastructure.
  • Custom Exception Framework Enhancement: Enhanced and supported a customized Exception Request application within Archer, optimizing workflow approvals, dynamic record permissions, and SLA tracking for risk exceptions.
  • Financial Attestation Process Automation: Designed and developed an on-demand financial attestation solution in Archer to track, manage, and audit the compliance of multi-regional financial reports.
  • Advanced UI Customization & Scripting: Implemented robust JavaScript and custom objects within Archer to extend core application capabilities, enforce validation logic, and deliver dynamic user experiences.

Systems Engineer

Tata Consultancy Services
09.2011 - 06.2014
  • Engineered and maintained one of the largest enterprise RSA Archer implementations, ensuring high availability and seamless platform performance.
  • Resolved high-severity incidents and technical bottlenecks by leveraging deep expertise in Archer server configurations, job engines, and core backend services.
  • Managed end-to-end data integrity by configuring, executing, and monitoring complex Data Imports and automated Data Feeds.
  • Executed comprehensive bug fixes and streamlined workflows to efficiently handle day-to-day user requests and operational inquiries.
  • Spearheaded training programs for incoming freshers, successfully mentoring and guiding them to achieve official RSA Archer certification and technical proficiency.
  • Completed an intensive 3-month TCS Initial Learning Program, earning formal certification and specialized mastery in RSA Archer.

Education

Bachelor of Technology - AE&I

ITER College
Bhubaneshwar, Odisha, India

Skills

  • Microsoft Office
  • ISO 27001:2022
  • Agile Methodologies
  • ServiceNow
  • Agile Project Management
  • JIRA
  • Risk assessment
  • Rally
  • Fortify
  • Vulnerability Assessment
  • ISO certification

Certification

  • RSA Archer 5.x Certified.
  • ISO 27001:2022
  • COBIT 5.0
  • Certified third party risk practitioner

Recognition

  • Power House Award | Rackspace
  • Certificate of Appreciation | Chief Technology Control Officer, JPMC
    Recognized for outstanding contribution to the firm-wide success of the Controls Program.

AREAS OF EXPERTISE

RSA Archer, Archer Engage, Proofpoint, Knowbe4, Business Continuity and Disaster Recovery, Business Impact Analysis, Third Party or Vendor Risk Management, IT Risk Management, Enterprise Risk Management, Policy Management, ServiceNow, Jira, Rally

Timeline

Senior Associate

Rackspace Technology
01.2021 - Current

Associate

JP Morgan Chase
08.2018 - 01.2021

Information Security Consultant

Intel Corporation
04.2017 - 08.2018

Associate

JP Morgan Chase
03.2015 - 04.2017

Senior Application Developer

BNY Mellon
07.2014 - 02.2015

Systems Engineer

Tata Consultancy Services
09.2011 - 06.2014

Bachelor of Technology - AE&I

ITER College
ANKIT LATH