Summary
Overview
Work History
Education
Skills
Accomplishments
Languages
Websites
Personal Information
Certification
Timeline
Generic
Hemanath  Ravi

Hemanath Ravi

Chennai

Summary

Results-driven Information Security Analyst with 5 years of expertise in implementing and managing robust Information Security Management Systems (ISMS) and ensuring compliance with PCI DSS and ISO standards. Skilled in conducting risk assessments, internal audits, and incident management to safeguard organizational assets. Strong problem-solving abilities, analytical skills, and a proactive approach to continuous improvement. Effective communicator and collaborator, committed to enhancing security measures and staying abreast of evolving cybersecurity landscapes.

Overview

6
6
years of professional experience
1
1
Certification

Work History

IT Associate

Anantara Solutions Pvt Ltd
Chennai
03.2022 - Current

Responsibilities

TGC and ISO 27001 Implementation:

  • Actively engaged in the implementation of IT General Controls (ITGC) and adherence to ISO 27001 standards for both product and project teams.

Third-Party Risk Management:

  • Conducted third-party risk assessments in accordance with company security policies and industry standards.
  • Developed and managed a comprehensive third-party risk management monitoring and reporting process.

Controls Review and Compliance:

  • Reviewed systems to ensure compliance with IT general controls, identified risks, and ensured adherence to policies and regulations.

Security Incident Management:

  • Monitored and reported security incidents, conducted root cause analysis, and ensured follow-up actions until the closure of incidents, maintaining a robust incident management process.

Policy Implementation:

  • Identified outdated process controls and implemented the organization’s policy or procedure documents, aligning them with industry best standards.

Risk Evaluation and Control Establishment:

  • Evaluated the IT infrastructure, DevOps, and Development teams to identify potential risks to the organization.

PCI DSS Compliance:

  • Ensured compliance with PCI DSS (Payment Card Industry Data Security Standard) by implementing and monitoring security controls for payment processing systems.
  • Conducted regular PCI DSS assessments, identified gaps, and implemented corrective measures.
  • Coordinated with external auditors for PCI DSS certification and recertification processes.

Quality Management System (QMS):

  • Supported the development and maintenance of the Quality Management System (QMS) in accordance with ISO 9001 standards.
  • Conducted internal quality audits and worked with teams to address non-conformities and enhance process efficiencies.
  • Assisted in the preparation of QMS documentation and process improvement initiatives.

Incident Management:

  • Developed and implemented incident management procedures to respond to security incidents.
  • Conducted investigations and root cause analyses of security incidents.
  • Coordinated response and recovery efforts to minimize the impact of security incidents on business operations.
  • Maintained an incident log and produced post-incident reports with recommendations for future prevention.

Compliance Intern

KLENTY INDIA PVT LTD
Chennai
06.2021 - 12.2021

Responsibilities

Assist in SOC 2 Audits:

  • Support the preparation and execution of SOC 2 audits using Vanta.
  • Gather and organize documentation required for audits within Vanta.
  • Participate in audit meetings and discussions.

Documentation and Reporting:

  • Help maintain and update SOC 2 documentation, including policies, procedures, and controls, using Vanta.
  • Assist in preparing reports and presentations on SOC 2 compliance status generated by Vanta.

Control Testing:

  • Conduct and document tests of internal controls within Vanta to ensure they are operating effectively.
  • Identify and report any control deficiencies or weaknesses flagged by Vanta.

Risk Assessment:

  • Participate in risk assessments and help identify potential security risks using Vanta’s risk assessment features.
  • Assist in developing and implementing mitigation strategies.

Policy and Procedure Review:

  • Review and suggest improvements to IT security policies and procedures.
  • Ensure that all documentation aligns with SOC 2 requirements.

Training and Awareness:

  • Assist in developing and delivering SOC 2 training and awareness programs for employees.
  • Help create training materials and conduct training sessions.

Collaboration:

  • Work closely with various departments, including IT, Legal, and Operations, to ensure compliance with SOC 2 standards.
  • Collaborate with external auditors and consultants as needed.

IT Associate - Help Desk

Sutherland Global Services
Chennai
06.2018 - 05.2021

Responsibilities

  • Actively implemented the ISO 27001:2013 (Information Security Management Systems) and SOC 2 Type 2 were certified with good flags.
  • Performed all stages of the audit including, planning preparing the audit program, fieldwork executing, reporting and follow up.
  • Performing internal audit for security compliance and taking the lead in external security audits, with a focus on supporting various security aspects, include ISO 27001 and SOC 2 Type 2
  • Policy, Procedure, Guidelines, SOP creation and Review.
  • Ongoing vendor monitoring, including coordination with the first line Business Unit for completion of required TPRM program documentation
  • Develop and maintain supplier risk and control monitoring plans, performing monitor activities and analysis of evidence to determine controls are operating effectively
  • Responding to client security concerns, answering security queries via call, and preparing documents
  • Responsible for handling RFP an

Education

Master of Science - Computer Applications

SRM UNIVERSITY
Chennai
05-2017

High School Diploma -

Vijayanta Senior Secondary School
Chennai
05-2012

Skills

  • ISO 27001 and ITGC
  • Risk management
  • Incident Management
  • Third-party risk management
  • SOC 2 Type 2
  • Firewall – Fortinet and Palo Alto
  • Antivirus – Sophos and McAfee
  • BCP – Resilience One and MIR3
  • System Upgrades & Optimization
  • Security, Backup & Recovery Solutions
  • Endpoint Security
  • Microsoft Active Directory – AD Server
  • Problem and Change Management
  • SIEM – Splunk and ManageEngine
  • RFP – Loopio
  • GRC - Archer and OneTrust

Accomplishments

● Have got appreciation for achieving 100% target.

● Have been recognized many times as Star of the Quarter and Month. Most importantly, our team has constantly won the “Team of the Quarter” throughout the year.

Languages

Tamil
First Language
English
Advanced (C1)
C1

Personal Information

Date of Birth : 24/11/1994

Nationality : Indian

Marital Status : Married

Certification

Udemy Certified

  • ISO/IEC 27001:2022 (ISMS)
  • PCI DSS Standard and Compliance
  • ISO 9001:2015 Quality management system auditor

Timeline

IT Associate

Anantara Solutions Pvt Ltd
03.2022 - Current

Compliance Intern

KLENTY INDIA PVT LTD
06.2021 - 12.2021

IT Associate - Help Desk

Sutherland Global Services
06.2018 - 05.2021

Master of Science - Computer Applications

SRM UNIVERSITY

High School Diploma -

Vijayanta Senior Secondary School
Hemanath Ravi