Summary
Overview
Work History
Education
Skills
Certification
Security Tools
Skills
Languages
Timeline
Generic
Arun Prakash

Arun Prakash

Bangalore

Summary

Dedicated and seasoned cybersecurity professional with almost 17 years of experience in developing and managing security governance, risk management, and compliance programs; all aspects of cloud security and compliance; cybersecurity strategy; vendor risk management; and change management.ement. Possess strong analytical skills to solve problems quickly and add value to stakeholder relationships, both internal and external to an organization.

Overview

17
17
years of professional experience
1
1
Certification

Work History

Senior Cyber Security Advisor (BISO)

Evernorth Health Services (The Cigna Group)
Hyderabad
12.2024 - Current
  • Led development and implementation of security policies in accordance with business goals and health standards.
  • Prioritized and identified security risks across various business units and technology platforms.
  • Conducted regular audits to ensure compliance with HIPAA, GDPR, ISO 27001 standards.
  • Enhanced system integrity and performance through thorough security architecture reviews.
  • Designed effective security controls to address identified vulnerabilities promptly.
  • Secured vendor relationships by managing supplier risks effectively.
  • Developed metrics for assessing effectiveness of organizational security initiatives.
  • Delivered executive updates on cybersecurity controls, associated risks, and remediation efforts.
  • Lead and manage cloud security compliance for AWS and other platforms, ensuring adherence to healthcare regulations, and safeguarding sensitive health data.
  • Oversee risk assessments, security controls, and incident response in cloud environments, driving continual improvement and executive reporting.
  • Educate and empower staff on cloud security policies and best practices to maintain a strong compliance posture.

AVP- Cyber Security

Standard Chartered Bank
Bangalore
09.2022 - 12.2024
  • Conducted risk assessments to identify and prioritize information security risks based on data sensitivity and vulnerabilities.
  • Developed and implemented security controls aligned with regulatory requirements and industry best practices.
  • Reviewed vulnerability data from various sources to assess risk ratings for business assets.
  • Evaluated third-party vendors' security postures to ensure adequate protection of shared data.
  • Established security metrics and KPIs to measure effectiveness of information security controls.
  • Created Cloud Security Policies and Frameworks to enhance compliance and risk management strategies.
  • Collaborated with stakeholders on security monitoring and incident response initiatives.
  • Designed controls to safeguard confidentiality, integrity, and availability of sensitive data.

Principal Engineer- Infosec

Acuity Knowledge Partners
07.2018 - 08.2022

Directed oversight of compliance and governance for vulnerability assessment and penetration testing programs.

  • Executed IT audits to evaluate adherence to risk management practices and compliance standards.
  • Managed information security risk functions while overseeing assessment and treatment plans.
  • Conducted thorough third-party risk assessments to ensure vendor compliance with security measures.
  • Led GRC portal implementation from planning through successful launch, facilitating smooth operations.
  • Analyzed SOC reports and ISMS documentation for control alignment with SOC frameworks.
  • Performed regular SIEM reviews and monitoring to enhance threat detection effectiveness.
  • Reviewed RFP/RFI submissions, contributing to strategic business development efforts.

Senior Consultant- Cyber Security

Capgemini
Bangalore
08.2015 - 07.2018
  • Identified unapproved and high-risk cloud services, collaborating with proxy team for blocking.
  • Conducted risk analysis of SaaS and IaaS cloud services using Skyhigh (McAfee) tool.
  • Managed enterprise-wide identification and mitigation of operational and regulatory risks.
  • Ensured compliance with HIPAA, PCI-DSS, SOC 2, ISO27001, and FedRAMP standards.
  • Assisted cloud service owners with Cloud Service Acquisition Request process.
  • Developed and maintained GRC framework, aligning policies with strategic objectives.
  • Led coordination of governance structure to enhance accountability across departments.
  • Reported on GRC initiatives and risk trends to executive leadership for informed decision-making.

Assistant Manager- Infosec

Jabil Global Service
Gurgaon
09.2013 - 07.2015
  • Ensure services are provided in accordance with ISO 27001: 2013 standards.
  • Perform VAPT activities.
  • IT Audit and Risk assessment.
  • Design and review ISMS process and Policies.
  • Security incident management (identify security events / incidents, conduct investigation, gather evidence, report to relevant authorities, suggest preventive measures and closures).
  • Security Awareness Training.

Senior Engineer- Infosec

Sasken
Bangalore
10.2009 - 09.2013
  • Conducting periodic security risk assessments: Work with Cross functional teams like Engineering, Infrastructure, IT, Legal and help minimize security risks.
  • Perform control assessment and ensure mitigation of gaps by effective governance and stakeholder engagement.
  • Vulnerability Assessment for Servers, desktops and Network devices.

Quality Analyst

Nokia Siemens Network
Kolkata
10.2008 - 09.2009
  • Internal Quality Audit.
  • RCA/Corrective action.
  • Implementation of TL9000 requirement & Measurement.

Education

Bachelor of Engineering - Electronics And Communication

Rajiv Gandhi Proudyogiki Vishwavidyalaya
Bhopal
06.2007

Bachelor of Science (BSc) - Science Education

Indira Gandhi National Open University (IGNOU)
06.2002

High School Diploma -

Purnia College
Purnia
04.1999

Skills

Cybersecurity & GRC
  • Risk Management Frameworks (RMF, ISO 27001, NIST CSF, COBIT)
  • Governance, Risk, and Compliance (GRC) Tools (eg, Archer, ServiceNow GRC, MetricStream)
  • Security Policies & Procedures Development
  • Security Audits & Assessments
  • Regulatory Compliance (HIPAA, GDPR, PCI-DSS, SOX)
  • Third-Party Risk Management
  • Business Continuity & Disaster Recovery Planning
  • Vulnerability Management & Remediation
  • Incident Response & Forensics
  • Data Privacy & Protection
Cloud Security & Compliance
  • Cloud Security Posture Management (CSPM)
  • Cloud Compliance (Azure, AWS, GCP)
  • Identity & Access Management (IAM)
  • Cloud Risk Assessment & Mitigation
  • Secure Configuration & Hardening (CIS Benchmarks)
  • DevSecOps Integration
Leadership & Strategy
  • Cybersecurity Program Management
  • Stakeholder Engagement & Communication
  • Cross-functional Team Leadership
  • Strategic Planning & Roadmapping
  • Budgeting & Resource Allocation
  • Executive Reporting & Dashboards
Project and process management
  • Agile and Scrum methodologies
  • Risk-based prioritization
  • Process improvement and automation
  • Change management
  • Metrics and KPIs development
Communication & collaboration
  • Policy and report writing
  • Training and awareness programs
  • Vendor management
  • Conflict resolution
  • Presentation and public speaking

Certification

  • ISO 27001: 2013 lead implementer
  • Certified Payment Card Industry Security Implementer V3.2
  • Certified Information Systems Auditor (CISA)
  • AWS Security Engineering
  • ISO/IEC 20000-1:2018
  • TL 9000: Quality Management

Security Tools

  • GRC Tool: RSA Archer, ServiceNow GRC
  • Vulnerability Assessment and Management: Qualys, Nessus
  • Cloud Security tool: AWS Security Hub, Skyhigh for CASB
  • Project Management tools: Jira, Microsoft Project, Confluence

Skills

Security Program Development, Security Team Leadership, Project Management, Crossfunctional Collaboration, GRC, Risk Management, Vulnerability Management, Policy & Procedure Development, Vendor/Third Party Risk Management, Incident Response, Data Loss Prevention, Vulnerability Assessment, Risk Assessment, Security Audit, Compliance review, Malware Analysis, Threat Intelligence, Network Security Monitoring, AWS Security, CASB, Cloud Risk assessment, Cloud Security Best Practices

Languages

Hindi
First Language
English
Advanced (C1)
C1

Timeline

Senior Cyber Security Advisor (BISO)

Evernorth Health Services (The Cigna Group)
12.2024 - Current

AVP- Cyber Security

Standard Chartered Bank
09.2022 - 12.2024

Principal Engineer- Infosec

Acuity Knowledge Partners
07.2018 - 08.2022

Senior Consultant- Cyber Security

Capgemini
08.2015 - 07.2018

Assistant Manager- Infosec

Jabil Global Service
09.2013 - 07.2015

Senior Engineer- Infosec

Sasken
10.2009 - 09.2013

Quality Analyst

Nokia Siemens Network
10.2008 - 09.2009

Bachelor of Engineering - Electronics And Communication

Rajiv Gandhi Proudyogiki Vishwavidyalaya

Bachelor of Science (BSc) - Science Education

Indira Gandhi National Open University (IGNOU)

High School Diploma -

Purnia College
Arun Prakash