Summary
Overview
Work History
Education
Skills
Accomplishments
Certification
Timeline
Generic

Kartavya Parashar

GRC Consultant
Delhi

Summary

GRC Consultant with experience supporting a regulated fintech environment at Paytm as a third-party vendor. Hands-on expertise in SEBI CSCRF implementation, cyber and system audits, ITGC/ITAC audit support,Data Privacy audit support, policy development, compliance gap remediation, and quarterly security control reviews, with strong collaboration across IT, Security, and DevOps teams.

Overview

1
1
year of professional experience
4
4
Certifications

Work History

GRC Consultant

Info EShield - Cyber Solutions
09.2025 - Current

(Working as a GRC Consultant for Paytm through Info eShield - Cyber Solutions.)

  • Supported implementation and operationalization of the SEBI Cyber Security and Cyber Resilience Framework (CSCRF).
  • Performed SEBI Cyber and System Audits, including control testing, evidence validation, and audit support.
  • Acted as an auditee for ITAC and ITAC audits, coordinating responses and remediation with stakeholders.
  • Supported DPDP Act–aligned Data Privacy audits assisting in control assessment, evidence validation, stakeholder coordination, and remediation tracking for identified privacy compliance gaps.
  • Developed and implemented CSCRF-aligned policies and procedures across security and IT domains.
  • Conducted compliance gap assessments and supported closure of identified regulatory and audit gaps.
  • Executed quarterly Patch Management, Privileged Access Management (PAM), and Asset Management reviews.
  • Collaborated with IT, Security, and DevOps teams to strengthen governance and audit readiness.

Cyber Security Analyst - Intern

BQC Assessment Pvt. Ltd. (CERT-in)
02.2025 - 06.2025

Company Overview: (CERT-in) empanelled organization.

  • Led 50+ audits for ISO 27001, SOC 2 including SEBI Cyber, System and Cloud Audits.
  • Assisted in Third Party Risk assessments and GDPR audits.
  • Conducted Vulnerable Assessment and Penetration Testing (VAPT), Source Code Audit activities and (GRC).
  • Identified critical vulnerabilities and reported them to clients.

Education

Bachelor of Computer Applications - BCA - Cybersecurity

Bennett University
Greater Noida, UP, India
07-2025

Skills

Regulatory Compliance

Security Frameworks

Policy Development

Security awareness training

Risk Assessment

Incident Management

Audit & Assurance

Stakeholder Engagement

OWASP top - 10

Accomplishments

  • CSCRF framework
  • Cyber and System Audits
  • ISO Lead Auditor and Implementer
  • SOC -2 audit
  • ITAC and ITGC audits readiness
  • Gap Remediation
  • Policy Development and implementation
  • PortSwigger Labs
  • Addressed OWASP Top 10 issues

Certification

Ethical Hacking Essentials (EHE) - EC- Council.

Timeline

GRC Consultant

Info EShield - Cyber Solutions
09.2025 - Current

Cyber Security Analyst - Intern

BQC Assessment Pvt. Ltd. (CERT-in)
02.2025 - 06.2025

Bachelor of Computer Applications - BCA - Cybersecurity

Bennett University
Kartavya ParasharGRC Consultant