Summary
Overview
Work History
Education
Skills
Languages
Certification
Timeline
Generic
ANUSHA SUVARNA

ANUSHA SUVARNA

Bangalore

Summary

Information Security Senior Engineer skilled in analyzing data to find discrepancies, risk assessment, problem solving, strategic planning and discussing potential compliance issues along with solutions to management. Proven ability to develop improved methods of management and find areas of deficiency. Meticulous auditing professional with excellent communication skill, ability to work independently and as a team member to successfully achieve project goals and objectives.

Overview

7
7
years of professional experience
2
2
years of post-secondary education
1
1
Certification

Work History

Senior cyber security engineer

Flipkart
11.2022 - Current
  • Lead ISO27001 recertification program for Flipkart by conducting internal audit of SCM locations, updating policies and standards, closing out gaps, keeping track of KPI.
  • Perform TPRM/VRM assessments on all vendors getting onboarded to Flipkart and Flipkart group entities
  • Perform contract reviews and suggest security clauses to be included in the contract
  • Conduct information security awareness training to all new onboarded employees.
  • Conduct phishing awareness simulation campaigns using mimecast for all Flipkart and group companies
  • Perform VAPT assessments on all the Flipkart developed tools.
  • Conducted onsite audit in data centres, Warehouses against ISO27001 and NIST CSF standards.
  • Prepare a roadmap for the overall maturity of the group entities.

Cyber Security Consultant

KPMG Global Services
01.2021 - 11.2022

• Maintained company-wide compliance with industry standards and ISO27001 Directed in-house cyber security auditing program to detect flaws and weaknesses in Client Security Architecture.

• Identify gaps in policies and standards of clients using GDPR, NIST CSF, COBIT and recommend improvements in security systems and procedures

• Conducted Cyber security maturity assessments using ISO27001, NIST Cyber Security Framework

• Perform CMMC Control Testing of client enterprise on AWS cloud and application by verifying evidences

  • Conducted PCIDSS assessment on a payment gateway client to identify the gaps and provide recommendations
  • Reduced cyber threats by implementing robust security frameworks and incident response plans.
  • Creating weekly status reports to present to clients.

Compliance & Risk Analyst

Boeing India
07.2019 - 04.2021
  • Perform System Criticality Assessment on business needs and decide Cost, RTO, RPO and dependencies of the application
  • Co-ordinate with Application team and perform Risk Assessment on the application based on ISO27001 controls.
  • Work on Access Control Policies for the application.
  • List out all roles and check for SOD access violation.
  • Perform Access Validation for the application
  • If the application is used for Defense then based on the data types used by the application perform NIST 800-171 assessment on the application
  • Design Disaster Recovery plan for the application by taking note of the Servers and Databases of the application and Business Requirements.

Information Security Risk Analyst

Tata Consultancy Services
12.2016 - 05.2019
  • Check compliance of all infrastructure devices like Servers, Client and Developer machines by applying Centre for Internet Security Controls (CIS)
  • Identify reason for non-compliance by checking if there are any phantom accounts, guest accounts, vulnerabilities that require patching, OS version, Firewall and Antivirus in the end machine is out of date
  • Send the list of non-compliant assets to respective teams and guide them remediation process
  • Achieved 90% compliance


Education

B.E - Information Science

St. Joseph Engineering College

High School Diploma - Science

St. Agnes College
India
06.2010 - 04.2012

SSLC -

St. Gerosa High School
2010

Skills

  • Skills Business Impact Assessments
  • CIS Compliance
  • NIST CSF
  • PCIDSS
  • SOC2 assessment
  • ISO27001 Assessments
  • Control Testing
  • Risk mitigation strategies
  • Third party risk assessments
  • Disaster recovery
  • IT Internal Audit
  • Cloud Security (AWS and GCP)

Languages

English
Advanced
Hindi
Fluent
Kannada
Fluent
Tulu
Native

Certification

ISO27001:2013 LA

ISO27001:2022 LI

ISO31000

Timeline

Senior cyber security engineer

Flipkart
11.2022 - Current

Cyber Security Consultant

KPMG Global Services
01.2021 - 11.2022

Compliance & Risk Analyst

Boeing India
07.2019 - 04.2021

Information Security Risk Analyst

Tata Consultancy Services
12.2016 - 05.2019

High School Diploma - Science

St. Agnes College
06.2010 - 04.2012

B.E - Information Science

St. Joseph Engineering College

SSLC -

St. Gerosa High School
ANUSHA SUVARNA