Work Preference
Summary
Overview
Work History
Education
Skills
Certification
Timeline
CORE COMPETENCIES
Generic
Brijesh Kumar Pandya

Brijesh Kumar Pandya

Ahmedabad

Work Preference

Desired Job Title

vCISO

Work Type

Consulting

Location Preference

Remote

Summary

Results-driven GRC and Information Security leader with 18+ years of experience and 8+ years of dedicated GRC specialization across Pharmaceutical, Banking, and Manufacturing sectors. CISSP-certified with hands-on expertise in ISO 27001:2022 ISMS implementation, ITGC compliance, VAPT program management, third-party risk management, BCP/DR, and regulatory compliance (DPDP 2023). Proven track record protecting ₹50Cr+ IT assets, managing 3,000+ endpoints across 90+ locations, and achieving zero major security incidents. Recognized for translating complex regulatory requirements into actionable security programs and building security-first cultures. Seeking a Senior GRC Manager, Information Security Manager, or Deputy CISO role to deliver enterprise-level risk and compliance leadership.

Overview

1
1
Certification
20
20
years of professional experience

Work History

Deputy General Manager -IT

Hester Biosciences Ltd.
Ahmedabad, Gujarat
05.2026 - Current
  • Directed strategic initiatives to enhance operational efficiency and product quality.
  • Implemented process improvements resulting in reduced production downtime and increased output.
  • Led cross-functional teams to develop and launch innovative bioscience products.
  • Fostered collaborative relationships with key stakeholders to align project goals and objectives.
  • Oversaw compliance with regulatory standards, ensuring adherence across all operations.
  • Mentored junior managers, promoting professional development and operational excellence.
  • Enhanced team productivity by providing ongoing coaching and mentoring to staff members.
  • Coordinated efforts between departments for seamless execution of projects, increasing overall success rates.
  • Ensured compliance with relevant regulations by developing robust policies and procedures.
  • Mitigated risks proactively by conducting thorough analyses of potential threats.
  • Achieved cost savings through strategic negotiation with vendors and suppliers.

Information Technology Manager

Torrent Pharmaceuticals Ltd.
Ahmedabad, Gujarat
07.2021 - 05.2026
  • Managed IT infrastructure projects, improving system reliability and performance across multiple departments.
  • Managed cross-functional teams to implement software solutions, aligning with business objectives.
  • Developed and executed IT policies, ensuring compliance with industry regulations and best practices.
  • Streamlined IT operations through process improvements, reducing response times for support requests.
  • Negotiated software support contracts to drive Rs. 1.5 million in cost savings.
  • Led IT infrastructure projects to enhance system reliability and performance.
  • Developed and implemented IT policies to ensure data security and compliance standards.
  • Managed cross-functional teams to optimize technology solutions and project delivery timelines.
  • Streamlined processes through automation, resulting in improved operational efficiencies across departments.
  • Mentored junior staff in technical skills and project management best practices.
  • Collaborated with stakeholders to align IT strategies with organizational goals and objectives.
  • Oversaw vendor relationships to ensure quality service delivery and cost-effectiveness of solutions.
  • Analyzed system performance metrics to identify areas for improvement and implement corrective actions.
  • Streamlined helpdesk operations, reducing response times and increasing end-user satisfaction levels.
  • Researched and recommended innovative and automated approaches to routine tasks.
  • Managed large-scale IT projects, ensuring on-time completion within budget constraints.
  • Trained staff on new software applications and hardware installations, boosting productivity across departments.

IT Manager

Electrotherm India Ltd.
10.2018 - 07.2021
  • Led ₹7 Crore IT infrastructure security upgrade across 3 manufacturing sites — secure OS migration, Exchange deployment, and SCCM patch management for 1,000+ endpoints.
  • Executed data center migration with security-focused architecture redesign, implementing redundancy, backup strategies, and defense-in-depth controls.
  • Established information security policies, IT risk management frameworks, and internal control assessment processes for manufacturing environments.

Senior System & Domain Administrator

VAM Systems Inc.
Doha, Qatar
08.2011 - 10.2018
  • Delivered enterprise security and infrastructure services for Qatar’s largest banking institutions, managing ISO 27001 compliance, Qatar Central Bank regulatory requirements, VAPT, BCP/DR, and large-scale endpoint security operations.
  • Led BCP/DR compliance initiative per Qatar Central Bank mandate — conducted DR simulations, parallel testing, and full interruption tests for core banking systems, achieving successful regulatory sign-off.
  • Managed enterprise VAPT program in partnership with EY — coordinated remediation workflows, CAB firewall change approvals, rollback procedures, and Director IT-signed closure documentation.
  • Directed OS migration for 3,000+ endpoints across 90 branches and 3 international offices using SCCM zero-touch deployment — delivered on schedule with zero data loss.
  • Maintained ISO 27001 compliance across 200+ Microsoft servers, ensuring GIA policy adherence and security configuration standards for all server implementations.
  • Served on Incident Response Team for critical banking security incidents — led identification, analysis, containment, recovery, and post-incident reporting.
  • Administered MDM and DLP (GFI Endpoint Protection) across enterprise, securing data in transit, at rest, and in use.
  • Achieved 98.9% SLA uptime through comprehensive patch management via SCCM 2012 R2 and MS-SCOM across mission-critical banking infrastructure.
  • Led a team of 10–12 engineers delivering 24/7 infrastructure support across Windows Server, Exchange, SQL, Oracle, and SAN environments.

System Administrator

Electrotherm India Ltd.
Ahmedabad, Gujarat
10.2010 - 08.2011
  • Managed IT infrastructure and systems administration across manufacturing sites, supporting network operations, server maintenance, and end-user support.
  • Assisted in implementing security policies and IT controls across plant operations, coordinating with cross-functional teams for system reliability.

System Administrator

Cygnet Infotech Pvt. Ltd.
Ahmedabad, Gujarat
04.2008 - 09.2010
  • Administered Windows Server infrastructure, Active Directory, and network services for a growing software services company.
  • Managed endpoint security, patch management, and helpdesk operations — first exposure to IT security policies and access control frameworks.
  • Supported IT compliance activities and internal audit readiness across software delivery teams.
  • Implemented monitoring tools to proactively identify and resolve system issues.
  • Coordinated data backups and recovery processes, minimizing downtime risks.
  • Managed system upgrades and patches to enhance security and functionality.
  • Administered network infrastructure, ensuring optimal performance and reliability across systems.

Technical Support Engineer

Hutchison Essar (now Vodafone India)
Ahmedabad, Gujarat
09.2006 - 05.2007
  • Provided L1/L2 technical support for GPRS and mobile data services, resolving network and connectivity issues for enterprise and retail customers.
  • Collaborated with network operations teams on fault identification, escalation management, and SLA-driven resolution for telecom customers.

Education

Bachelor of Computer Applications - BCA

SJE College of Management Studies
Bangalore, India
01-2025

Diploma - Computer Science

S.J.E.S. Polytechnic
Bangalore
01-2002

Skills

  • GRC & Compliance Tools: RSA Archer, ManageEngine ServiceDesk, Nessus, SIEM Platforms, Phishing Simulation Tools
  • Security Tools: Symantec Endpoint Protection, GFI Endpoint Protection, MS Defender, Checkpoint Encryption, IDS/IPS, DLP, Firewalls, VAPT Tools
  • Frameworks & Standards: ISO 27001:2022, ISO 27002, ISO 42001 (AI RMS), NIST CSF, CIS Controls, ITIL v4, SOX-ITGC, DPDP 2023
  • Cloud & Infrastructure: AWS (SAA), Windows Server 2012–2019, Active Directory, MS Exchange, SCCM, VMware, Linux RHEL, SAN Storage
  • Security Domains: GRC, Risk Management, Threat & Vulnerability Management, Cloud Security, Data Protection, Cryptography, IAM, Network Security

Certification

  • CISSP – Certified Information Systems Security Professional (ISC)²
  • CISA - Certified Information Systems Auditor (ISACA)
  • CEH – Certified Ethical Hacker EC-Council |
  • PMP – Project Management Professional PMI
  • CCSK v5 – Certificate of Cloud Security Knowledge Cloud Security Alliance
  • AWS Certified Solutions Architect – Associate Amazon Web Services
  • DPDP 2023 Certified India Data Protection
  • ITIL Foundation Axelos
  • CCNA Cisco
  • MCITP – Windows Server 2012 Microsoft
  • RHCE – Red Hat Enterprise Linux 5 Red Hat
  • JNCIA-ER / JNCIA-EX Juniper Networks

Timeline

Deputy General Manager -IT

Hester Biosciences Ltd.
05.2026 - Current

Information Technology Manager

Torrent Pharmaceuticals Ltd.
07.2021 - 05.2026

IT Manager

Electrotherm India Ltd.
10.2018 - 07.2021

Senior System & Domain Administrator

VAM Systems Inc.
08.2011 - 10.2018

System Administrator

Electrotherm India Ltd.
10.2010 - 08.2011

System Administrator

Cygnet Infotech Pvt. Ltd.
04.2008 - 09.2010

Technical Support Engineer

Hutchison Essar (now Vodafone India)
09.2006 - 05.2007

Bachelor of Computer Applications - BCA

SJE College of Management Studies

Diploma - Computer Science

S.J.E.S. Polytechnic

CORE COMPETENCIES

  • GRC Strategy & Governance
  • ITGC Compliance
  • Vulnerability Assessment & VAPT
  • BCP / Disaster Recovery Planning
  • Endpoint Security & DLP
  • Data Classification & Protection
  • ISO 27001:2022 ISMS Implementation
  • Regulatory Compliance (DPDP 2023)
  • Incident Response & Management
  • Security Awareness & Phishing Simulation
  • Identity & Access Management
  • Audit Management & Evidence Collection
  • Risk Management & Treatment
  • Third-Party Risk Management (TPRM)
  • Security Policy Development (25+ Policies)
  • Cloud Security Governance (AWS, CCSK)
  • SIEM & Security Operations
  • ISO 42001 AI Risk Management
Brijesh Kumar Pandya