Summary
Overview
Work History
Education
Skills
Certification
Accomplishments
Languages
Timeline
Hi, I’m

Deepak Kushwah

Gurugram
Deepak Kushwah

Summary

Experienced IT risk and information security professional with over 9 years in banking and payments sectors. Developed and managed IT risk frameworks and remediation programmes aligned with COBIT, NIST, ISO 27001, and ITIL standards. Assessed IT risk in cloud environments and third-party providers, emphasising data integrity and governance. Certified Information Systems Auditor (CISA) and ISO 27001:2022 Lead Auditor, translating technical risks into actionable insights.

Overview

1
Language
1
Certification
10
years of professional experience

Work History

Airtel Payments Bank

Senior Manager - IS Audit
07.2024 - Current

Job overview

  • Lead risk-based audits of IT applications, databases, network infrastructure, cloud security, and endpoint security, ensuring alignment with industry standards (ISO 27001, NIST, CIS, ISF).
  • Tested critical applications against resilience and recovery objectives, performing root-cause analyses to identify IT-related control gaps and inform remediation strategies.
  • Conducted regulatory compliance reviews for RBI CSITE KRI submissions (Tranche III), ISMS, BCMS, and other ad hoc RBI reporting requirements, ensuring adherence to regulatory frameworks.
  • Manage external regulatory inspections (RBI, statutory auditors) and coordinate responses to audit findings and recommendations.
  • Oversaw vendor risk management and compliance with RBI guidelines for IT outsourcing by conducting thorough third-party/vendor audits and on-site security assessments.
  • Review and assess cloud architecture, configurations, and security controls, ensuring adherence to best practices for data protection and regulatory compliance.
  • Assess data integrity and reconciliation controls within core banking and payment data flows as part of application and technology control reviews supporting regulatory and financial reporting.
  • Collaborate with cross-functional teams to strengthen IT risk posture and implement remediation plans for identified gaps.
  • Leading security governance, information assurance and third-party cyber security programmes for one of India's largest payments banks, serving over 150 million customers.

Paytm Payments Bank

Information Systems Auditor
02.2023 - 07.2024

Job overview

  • Conducted IT audits of IT General Controls across applications, information security, cloud security, network security, vulnerability management, branch operations, vendor risk assessments, and regulatory submissions, ensuring comprehensive coverage of data processing and reconciliation controls.
  • Delivered information assurance, security governance, compliance and third-party risk management across Paytm's digital banking and payments infrastructure.
  • Ensured compliance with relevant laws, regulations, and organizational policies, providing expertise in regulatory requirements.
  • Contributed to development and enhancement of information security policies and procedures, aligning them with industry best practices.
  • Documented audit findings, risk assessments, and security measures for internal and external reporting, facilitating informed decision-making and compliance.

AU Small Finance Bank

Information Systems Auditor
04.2022 - 02.2023

Job overview

  • Conducted IT audits assessing IT General Controls, Information Security Controls, Cloud Security, Network Security, vendor risk, and regulatory submissions, ensuring compliance and risk mitigation.
  • Delivered information assurance, security governance, compliance and third-party risk management across one of India's leading Small Finance Banks, supporting secure digital banking operations and regulatory compliance initiatives.
  • Validated ITGC and application-specific controls, reinforcing data integrity and regulatory compliance.
  • Prepared audit documentation (risk assessment, working papers, audit program checklist, evidence gathering, report writing) and ensured resolution of non-compliance issues through proactive follow-up.

HDFC Bank

Risk Manager - Information Security Group
09.2019 - 04.2022

Job overview

  • Managed end-to-end Third-Party Risk Management (TPRM) lifecycle including pre-onboarding security due diligence, onboarding information assurance reviews, periodic assessments and annual assurance activities for 50+ service providers across cloud, technology and operational domains.
  • Performed cyber security evaluations of suppliers and service providers prior to onboarding, assessing governance, security controls, cloud security, compliance posture and risk exposure.
  • Managed cyber security risk, information assurance, supply-chain security and technology evaluation for India's largest private sector bank.
  • Led proof-of-concept evaluations and vendor selection for enterprise security solutions, defining requirements, conducting vendor demonstrations, assessing technical capabilities, and facilitating implementation.
  • Collaborated with business, technology, procurement and vendor management teams to embed cyber security and information assurance requirements throughout supplier onboarding, solution selection, and service delivery lifecycles.
  • Conducted cloud security architecture reviews and supported migration initiatives from on-premises environments to cloud platforms, advising on secure-by-design principles and information assurance control frameworks.
  • Delivered security risk assessments, gap analyses and remediation recommendations aligned with ISO 27001, NIST CSF and regulatory requirements; presented findings to senior management and governance committees.
  • Supported security policy development, compliance assessments and incident response activities across a complex, heavily regulated environment.

eSage IT Services Ltd.

System Engineer
07.2017 - 02.2019

Job overview

  • Implemented a range of information security controls and technologies, including DLP, IDS, IPS, Firewalls, Antivirus, and Antimalware.
  • Enhanced access control for applications and networks by implementing NAC/IDS/IPS solutions and authentication protocols.
  • Undertook regular system maintenance, facilitating hardware and software upgrades, and executing migrations from on-premises (VMware ESXi) to cloud (AWS/Azure).
  • Performed operational troubleshooting for servers and networks, resolving L1/L2 issues across remote locations to maintain system reliability.
  • Designed and deployed SOHO networks for clients, supporting around 1000 users, while ensuring PCI DSS compliance through domain scanning.

OIEPL Jaipur

Desktop Support Engineer
09.2016 - 07.2017

Job overview

  • Delivered infrastructure and end-user support across Windows/Linux environments, networking devices, and security technologies to ensure seamless operations.
  • Diagnosed and resolved hardware, software, and network connectivity problems efficiently.
  • Delivered remote support using desktop-sharing software to assist off-site users.
  • Configured network printers and resolved printing issues to ensure smooth operation.

Education

CDAC-ACTS
Pune, India

PG Diploma from IT Infrastructure, Systems & Security
08-2019

Rajasthan Technical University
Kota, India

Bachelor of Technology from Electrical & Electronics
07-2016

Skills

  • IT Risk Management Frameworks
  • Risk management
  • Regulatory compliance
  • IT governance
  • Information assurance
  • Data protection
  • Risk assessment
  • Cloud security
  • Cloud security assessments
  • Security architecture
  • COBIT
  • NIST CSF
  • ISO 27001
  • CIS Controls
  • PCI-DSS
  • DORA
  • Vendor risk management
  • Supplier security diligence
  • General IT controls
  • Application Controls
  • Enterprise security assessments
  • AWS
  • Azure
  • GCP
  • Hybrid Cloud
  • Cross-functional collaboration
  • Project Management
  • Team leadership
  • Strategic decision making
  • Strategic planning
  • Strategy execution

Certification

  • Certified Information Systems Auditor (CISA)
  • ISO 27001:2022 Lead Auditor
  • ISO 27001:2013 Lead Implementer
  • Elements of AI
  • Cisco Certified Network Associate (CCNA)
  • Fortinet NSE 1, 2 & 3
  • ICSI Certified Network Security Specialist (CNSS)

Accomplishments

  • Contributed to the design, implementation and maintenance of IT risk management frameworks and control environments across cloud, application, network and third-party domains for two regulated financial institutions.
  • Assessed data quality and data integrity controls within core banking and payment platforms as part of ITGC and technology audit reviews, validating data processing, reconciliation and monitoring controls supporting financial and regulatory reporting.
  • Managed cyber security due diligence and information assurance reviews for 50+ third-party service providers supporting critical banking operations and cloud environments (AWS, Azure, GCP).
  • Tested critical banking and payment applications against resilience and recovery objectives, and performed risk-based deep dives to identify root causes of IT-related control and loss events.
  • Led evaluation and selection of enterprise security technologies (NGFW, NAC, Email Security, CSPM, SOAR) - defining requirements, running PoCs, scoring vendors and overseeing implementation.
  • Developed a secure GenAI-powered Regulatory & Audit Assistant on AWS, automating regulatory interpretation, policy comparison and audit checklist generation using RBI, NPCI and internal policy knowledge bases.

Languages

English
Upper Intermediate
B2

Timeline

Senior Manager - IS Audit

Airtel Payments Bank
07.2024 - Current

Information Systems Auditor

Paytm Payments Bank
02.2023 - 07.2024

Information Systems Auditor

AU Small Finance Bank
04.2022 - 02.2023

Risk Manager - Information Security Group

HDFC Bank
09.2019 - 04.2022

System Engineer

eSage IT Services Ltd.
07.2017 - 02.2019

Desktop Support Engineer

OIEPL Jaipur
09.2016 - 07.2017

CDAC-ACTS

PG Diploma from IT Infrastructure, Systems & Security

Rajasthan Technical University

Bachelor of Technology from Electrical & Electronics
Deepak Kushwah