Dynamic Information Security Analyst with a proven track record at Tata Consultancy Services, excelling in ITGC testing and SOX compliance. Expert in GRC controls assessment and vendor risk management, I effectively bridge stakeholder communication and reporting. Adept at utilizing OneTrust and BitSight, I drive compliance initiatives and enhance organizational security posture.
Overview
4
4
years of professional experience
1
1
Certification
Work History
Information Security Analyst
Tata Consultancy Services
02.2022 - Current
Conducted ITGC testing for Access, Change Management, and IT Operations for multiple business applications.
Performed SOX controls testing (TOD & TOE) and documented results in line with audit requirements.
Executed ITAC (IT Application Controls) testing to ensure accuracy and integrity of automated system controls.
Supported internal and external audits by preparing evidence, walkthrough documents, and control narratives.
Evaluated GRC controls and identified control gaps with remediation recommendations.
Performed enterprise-wide risk assessments and facilitated remediation tracking.
Implemented ISO 27001 aligned security controls across client environments.
Developed and maintained compliance dashboards, risk registers, and audit documentation.
Managed end-to-end third-party risk assessments, including scoring, evidence collection, and reporting.
Conducted vendor due diligence using platforms such as OneTrust, BitSight, and SecurityScorecard.
Drafted and updated security policies, procedures, and process documents.
Participated in incident response, evidence collection, and RCA support.
Conducted training and awareness programs on IT governance and compliance.