Summary
Overview
Work History
Education
Skills
Certification
Custom
Timeline
Generic

Gunum Anushya Giftlin A

Chennai

Summary

Cybersecurity professional with 12 years of relevant experience in implementing and auditing standards such as ISO/IEC 21434, ISO 42001, ISO 62443, ISO 27001. Skilled in leading security initiatives, influencing without authority, and collaborating across business functions. Strong at translating technical and process concepts into effective, compliant security solutions.

Overview

1
1
Certification
14
14
years of professional experience

Work History

Manager – Cyber: Emerging Technologies

Deloitte Touché Tohmatsu India LLP
Chennai
11.2022 - Current
  • Delivered consulting and implementation engagements across enterprise cybersecurity, AI governance, cloud security, Operational Technology (OT), and automotive cybersecurity, with expertise in ISO 27001, ISO 42001, ISO 27017, ISO 27018, IEC 62443, and ISO/SAE 21434.
  • Conducted cybersecurity maturity assessments and gap analyses against IEC 62443 and ISO/SAE 21434, developing risk-based remediation roadmaps to strengthen cybersecurity capabilities and operational resilience.
  • Drove OT security initiatives for manufacturing and industrial environments by performing risk assessments, implementing security controls, and establishing governance aligned with industry standards .
  • Designed and executed supplier cybersecurity assessments based on IEC 62443 evaluating automation vendors, OEMs, and system integrators for secure development and supply chain compliance.
  • Assessed product development lifecycles, including Automotive SPICE (ASPICE) processes, against ISO/SAE 21434 and IEC 62443 requirements, identifying gaps and recommending remediation measures.
  • Performed security architecture reviews and threat modelling for connected vehicle platforms, ECUs, embedded systems, automotive applications, and connected solutions to identify and mitigate cybersecurity risks.
  • Executed hardware and vehicle-level cybersecurity testing, including penetration testing, fuzz testing, and vulnerability assessments, in collaboration with engineering and product development teams.
  • Developed OT cybersecurity policies, incident response processes, risk management frameworks, and awareness programmes to strengthen cyber resilience across manufacturing environments.
  • Collaborated with cross-functional global teams to embed cybersecurity throughout the product development lifecycle, ensuring compliance with regulatory requirements, industry standards, and client expectations.
  • Delivered AI governance engagements by designing governance frameworks, policies, and risk management processes to enable responsible AI adoption and compliance with ISO 42001 and emerging AI governance requirements.

Lead - Security and Privacy compliance

BORN Group ltd (A subsidiary of TechM)
Chennai
06.2019 - 11.2022
  • Reported to the Practice Head and CISO, leading ISO 27001:2013, SOC 2 Type II, and privacy compliance initiatives across India, the US, and the UK, supporting content production, software development, maintenance, and support services.
  • Managed a team of four, overseeing planning, task allocation, and quality reviews to ensure timely delivery, while providing the tools, guidance, and training required to achieve team objectives.
  • Maintained and continually enhanced the Information Security Management System (ISMS), ensuring compliance with ISO 27001 requirements and effective communication of updates to stakeholders.
  • Planned and conducted internal audits in accordance with ISO/IEC 27001:2013, including compliance assessments, health checks, reporting, and presenting findings and recommendations to senior management.
  • Led enterprise and third-party security and privacy risk assessments, developing mitigation plans and supporting risk governance activities.
  • Conducted ISO 27001 gap assessments for subsidiaries and developed remediation roadmaps to strengthen compliance across the parent organization.
  • Drove the implementation and continual improvement of security governance processes, ensuring alignment with organizational policies and industry best practices.
  • Performed Business Impact Analysis (BIA) for critical business functions and reported outcomes to leadership to support business continuity and resilience planning.
  • Reviewed Secure Software Development Lifecycle (Secure SDLC) processes and participated in application security reviews to ensure security requirements were integrated throughout the software development lifecycle.
  • Coordinated and supported application security testing activities, including vulnerability assessments, penetration testing, and remediation tracking, to strengthen the security posture of business applications.
  • Embedded Privacy by Design principles into system and application development processes, ensuring compliance with GDPR, PDPA, CCPA, and other applicable privacy regulations.
  • Delivered security and privacy awareness initiatives, including onboarding sessions, periodic training, newsletters, and internal campaigns to strengthen organizational awareness and compliance culture.

Quality Executive

Sify Technologies Limited
Chennai
01.2016 - 06.2019
  • Delivered ISO 27001 and ISO 20000-1 audits and implemented ISO 27018, ensuring compliance and readiness for certification.
  • Independently managed the implementation and audit cycles of ISO 27001, ISO 20000-1, ISO 27017, ISO 27018, and PCI DSS standards, as well as SSAE 18 SOC 2 compliance for data centers, cloud, and managed services environments.
  • Coordinated with senior and middle management to identify and address security concerns and risks, enhancing organisational security posture.
  • Led risk reviews with internal teams and external customers to mitigate risks to objectives.
  • Managed and maintained information security management system covering risk, continuity, audits, continual improvement.
  • Maintained security and service management policies and procedures aligned to business and regulatory requirements.
  • Developed security policies, standards, procedures, and guidelines with CISO and committee approvals.
  • Delivered ISO training and awareness sessions for internal stakeholders on information security.
  • Presented audit findings and security performance reports, providing actionable improvement recommendations for governance reviews.

Senior Engineer

Mindtree Limited
Chennai
05.2015 - 11.2015
  • Ensure that activities within a process are being performed at a high level of quality and that it meets its associated Service Level Agreements or Operational Level Agreements.
  • Collaborated with Project Manager of Dutch-based telecom customer to ensure incident, problem, and change management processes met customer requirements.
  • Generated daily, weekly, and periodic reports on incident and problem records to support decision-making and improve service delivery.
  • Logged incidents for review at risk of breaching Service Level Agreement/Operational Level Agreement to the Incident Process Coordinator.
  • Monitored incidents for potential issues and/or increasing trend of repetitive Incidents.
  • Contributed to incident reviews after major incidents.

Customer Engineer

HCL Services Limited
Pondicherry
09.2012 - 05.2015
  • Lead a DC service transition project comprising of DC monitoring, management and process conformance based on Customer agreement.
  • Implemented ITIL processes and fostered awareness among teams for improved process adherence.
  • Reported to Project Manager of IT Operations Center, implemented ISO 9001, 27001, 20000-1 and CMMI-SVC, managed risk and enhanced process governance.
  • Implemented and conducted internal audits for ISO 9001, ISO 27001, ISO 20000-1 and CMMI for Services (SVC).
  • Collaborated with Corporate Quality Team to advance quality initiatives.

Education

Bachelor of Engineering - ECE

Karpaga Vinayaga College of Engineering and Technology
Chennai
01-2012

Skills

  • Cybersecurity strategy
  • Information security
  • Cybersecurity management system
  • Risk assessment
  • Security architecture
  • Threat modelling
  • Operational technology
  • AI governance frameworks
  • Project management
  • Training delivery

Certification

  • SABSA Chartered Foundation (SCF)
  • PECB Certified ISO 42001:2023 Lead Implementer
  • IRCA Certified ISO 22301 Lead Implementer by BSI Group
  • IRCA Certified Risk Professional (CRiSP) by BSI Group
  • IRCA Certified ISO 27001 Lead Auditor by DNV GL
  • CSA STAR Auditor
  • ITIL V3 Foundation Certified

Custom

  • HCL, Star of the Month for Quality - Process Implementation, 2013
  • Mindtree, Spot On Award for Notable Performance, 2015
  • Sify, Awarded as one of the “Learning Enablers in Sify”, 2017
  • Sify, Recognized for Implementing ISO 27017:2015 and ISO 27018:2014 Certifications, 2018
  • Born Group, BORN Imprint Award, 2020
  • Deloitte, “Live the Dot” for Client centricity, 2023
  • Deloitte, “Move the Dot” Team for Information security architecture review, 2023
  • Deloitte, “Impact Day Team Lead” for CSR, 2024
  • Deloitte, “Move the Dot” Team for TARA engagement, 2024
  • Deloitte, Cyber CSR Dream Team, 2024
  • Deloitte, “Move the Dot” Individual” for managing ISA engagement, 2025
  • Deloitte, “Move the Dot” Team” for managing Vehicle Security engagement, 2025
  • Deloitte, "Move the Dot" for Contribution to Deloitte ConnectSafe Lab, 2026

Timeline

Manager – Cyber: Emerging Technologies

Deloitte Touché Tohmatsu India LLP
11.2022 - Current

Lead - Security and Privacy compliance

BORN Group ltd (A subsidiary of TechM)
06.2019 - 11.2022

Quality Executive

Sify Technologies Limited
01.2016 - 06.2019

Senior Engineer

Mindtree Limited
05.2015 - 11.2015

Customer Engineer

HCL Services Limited
09.2012 - 05.2015

Bachelor of Engineering - ECE

Karpaga Vinayaga College of Engineering and Technology
Gunum Anushya Giftlin A