

Data Privacy and Governance, Risk & Compliance (GRC) professional with over 17+ years of experience in Information Technology, including extensive experience in Information Security, Risk Management, Third-Party Risk Management, Governance, Compliance and Data Privacy. Experienced in facilitating and monitoring Data Protection Impact Assessments (DPIAs), Records of Processing Activities (ROPAs), Data Flow and Data Inventory management, Privacy Risk Assessments and privacy compliance activities. Hands-on experience in supporting privacy governance, regulatory compliance, privacy documentation, awareness programs and audit activities. Strong exposure to ISO 27001, ISO 27701, SOC 2, HIPAA and Data Protection regulations including GDPR and the Digital Personal Data Protection Act (DPDPA). Skilled in collaborating with project teams, business stakeholders, Information Security teams and external auditors to identify privacy risks, monitor remediation activities and strengthen organizational privacy compliance.
Client: Standard Chartered Global Business Services
Role: Information Security Risk Manager
Project: Third-Party Risk Management (TPRM)
Managed end-to-end third-party risk assessments, including onboarding, due diligence, reassessments, monitoring, and offboarding activities.
Conducted information security risk assessments and control reviews for third parties across the South Asia region, identifying security and compliance gaps.
Evaluated financial, operational, regulatory, and information security risks and provided risk mitigation recommendations to stakeholders.
Performed vendor due diligence, evidence validation, and periodic reassessments to ensure ongoing compliance with organizational and regulatory requirements.
Collaborated with third parties, business owners, and risk teams to resolve assessment issues and drive timely remediation of findings.
Escalated high-risk and non-compliant cases, supporting risk acceptance, remediation, and contractual decision-making processes.
Monitored key risk metrics, assessment status, and remediation progress, providing management reporting and risk insights.
Maintained vendor risk records and ensured accuracy of assessment documentation, risk data, and supporting artifacts.
Facilitated stakeholder meetings and promoted continuous improvement of third-party risk management practices.
Planned and conducted internal audits for ISO 27001 and PCI DSS, including audit planning, evidence review, reporting, and corrective action tracking.
Coordinated external certification, client, and compliance audits, facilitating evidence collection, auditor interactions, and observation closure.
Performed information security risk assessments, vendor audits, and control reviews to identify risks and strengthen compliance.
Managed ISMS documentation, including policies, procedures, records, and compliance artifacts within the Document Management System (DMS).
Supported security incident management, including incident tracking, investigation coordination, documentation, and SLA-based closure.
Conducted firewall rule reviews and compliance validations to ensure adherence to security and change management requirements.
Facilitated Information Security Steering Committee (ISC) and Management Review Meetings (MRM), including reporting, action tracking, and governance support.
Coordinated audit evidence reviews, root cause analysis, corrective actions, and remediation activities to ensure timely closure of findings.
Developed management dashboards, risk reports, and presentations for senior leadership and governance forums.
Conducted facility, safety, and third-party audits to evaluate operational, security, and compliance controls.
Planned and conducted internal audits for ISO 9001 and ISO 27001, including audit planning, evidence review, reporting, and corrective action tracking.
Coordinated external certification and surveillance audits with certification bodies, supporting audit execution, evidence collection, and closure of findings.
Performed information security, third-party, and vendor audits to evaluate compliance with organizational and regulatory requirements.
Managed ISMS and QMS documentation, including policies, procedures, records, and compliance artifacts within the Document Management System (DMS).
Supported information security incident management, risk assessments, risk register maintenance, and implementation of risk treatment plans.
Conducted firewall review activities, security control validations, and tracked remediation of VAPT findings to strengthen security posture.
Facilitated Information Security Steering Committee (ISC) and Management Review Meetings (MRM), including governance reporting, action tracking, and management presentations.
Supported Business Continuity Management activities by coordinating BCP documentation, stakeholder inputs, evidence collection, compliance metrics, and audit follow-ups.
Organization: Mother Concern – Planman HR Pvt. Ltd.
Data Privacy Program Governance & Operating Model
RoPA, Data Discovery, Mapping & Classification
Privacy by Design / Default; SDLC Integration
DPIA, DSAR, Consent & Cookie Governance
DPDP Act, GDPR, CCPA/CPRA, etc
Cross-border Transfers: SCCs, TIAs, Localization
Privacy Risk Assessments & Gap Analysis
Privacy Platforms: OneTrust, TrustArc etc
Stakeholder Engagement (CISO/Legal/DPO)
Team Leadership & Consulting Delivery
ISO/IEC 27001:2013 Lead Auditor Course
Third-party risk assessments
Incident management
Firewall log review
Vendor due diligence
Risk assessments
Control testing
Compliance monitoring
Policy review
Audit reporting
Remediation tracking
Management reporting
Stakeholder coordination
Evidence validation