Summary
Overview
Work History
Education
Skills
Certification
Languages
Timeline
Generic
Hemalatha C

Hemalatha C

Hyderabad

Summary

Dynamic Information Security Analyst with a proven track record at Tata Consultancy Services, excelling in ITGC testing and SOX compliance. Expert in GRC controls assessment and vendor risk management, I effectively bridge stakeholder communication and reporting. Adept at utilizing OneTrust and BitSight, I drive compliance initiatives and enhance organizational security posture.

Overview

4
4
years of professional experience
1
1
Certification

Work History

Information Security Analyst

Tata Consultancy Services
02.2022 - Current
  • Conducted ITGC testing for Access, Change Management, and IT Operations for multiple business applications.
  • Performed SOX controls testing (TOD & TOE) and documented results in line with audit requirements.
  • Executed ITAC (IT Application Controls) testing to ensure accuracy and integrity of automated system controls.
  • Supported internal and external audits by preparing evidence, walkthrough documents, and control narratives.
  • Evaluated GRC controls and identified control gaps with remediation recommendations.
  • Performed enterprise-wide risk assessments and facilitated remediation tracking.
  • Implemented ISO 27001 aligned security controls across client environments.
  • Developed and maintained compliance dashboards, risk registers, and audit documentation.
  • Managed end-to-end third-party risk assessments, including scoring, evidence collection, and reporting.
  • Conducted vendor due diligence using platforms such as OneTrust, BitSight, and SecurityScorecard.
  • Drafted and updated security policies, procedures, and process documents.
  • Participated in incident response, evidence collection, and RCA support.
  • Conducted training and awareness programs on IT governance and compliance.

Education

Bachelor of Technology -

JNTU
Ananthapuram, India

Skills

  • ITGC testing and SOX compliance
  • GRC controls assessment
  • Vendor risk management
  • Policy governance
  • Risk analysis and gap assessment
  • Audit readiness and evidence management
  • Stakeholder coordination and reporting
  • OneTrust and AuditBoard proficiency
  • BitSight and SecurityScorecard expertise
  • JIRA and ServiceNow ITSM usage
  • Microsoft 365 and SharePoint skills
  • Scrut automation knowledge

Certification

  • OneTrust Certified TPRM Specialist, 2025
  • ISO 27001:2022

Languages

English

Timeline

Information Security Analyst

Tata Consultancy Services
02.2022 - Current

Bachelor of Technology -

JNTU
Hemalatha C