Summary
Overview
Work History
Education
Skills
Certification
Timeline
Personal Information
DECLARATION
PERSONAL DETAILS
Generic
Kumar B R

Kumar B R

Deputy Manager
Chennai

Summary

Data Privacy and Governance, Risk & Compliance (GRC) professional with over 17+ years of experience in Information Technology, including extensive experience in Information Security, Risk Management, Third-Party Risk Management, Governance, Compliance and Data Privacy. Experienced in facilitating and monitoring Data Protection Impact Assessments (DPIAs), Records of Processing Activities (ROPAs), Data Flow and Data Inventory management, Privacy Risk Assessments and privacy compliance activities. Hands-on experience in supporting privacy governance, regulatory compliance, privacy documentation, awareness programs and audit activities. Strong exposure to ISO 27001, ISO 27701, SOC 2, HIPAA and Data Protection regulations including GDPR and the Digital Personal Data Protection Act (DPDPA). Skilled in collaborating with project teams, business stakeholders, Information Security teams and external auditors to identify privacy risks, monitor remediation activities and strengthen organizational privacy compliance.

Overview

1
1
Language
1
1
Certification
18
18
years of professional experience

Work History

Manager in Infosec

Hexaware Technologies
06.2023 - Current
  • Conducted DPIAs, privacy risk assessments, and data mapping exercises to identify and mitigate privacy risks across business initiatives, applications, and third-party integrations.
    Managed RoPA, data inventory, and Data Principal Rights processes in compliance with GDPR and the DPDP Act.
    Performed privacy compliance assessments, gap analyses, and control reviews against ISO 27001, ISO 27701, GDPR, DPDP Act, and SOC 2 requirements.
    Conducted internal audits, control testing, evidence validation, and remediation tracking to strengthen privacy, security, and compliance programs.
    Supported privacy incident management, breach assessments, root cause analysis, and corrective action tracking.
    Performed third-party privacy and vendor risk assessments, including due diligence reviews and contractual compliance verification.
    Developed privacy policies, procedures, standards, and governance documentation to support regulatory compliance.
    Utilized GRC platforms for compliance monitoring, risk management, audit support, and control assessments.
    Conducted Business Impact Analysis (BIA) and supported the development, testing, and maintenance of Business Continuity and Disaster Recovery Plans (BCP/DRP) aligned with ISO 22301.
    Facilitated business continuity exercises, resilience testing, and cross-functional collaboration with IT, Security, Legal, HR, and business stakeholders.
    Delivered privacy and security awareness programs and mentored team members to promote a culture of compliance and continuous improvement.

Technical Lead in Information and Cyber Security

Tech Mahindra Limited
Chennai
02.2022 - 05.2023

Client: Standard Chartered Global Business Services
Role: Information Security Risk Manager
Project: Third-Party Risk Management (TPRM)

Managed end-to-end third-party risk assessments, including onboarding, due diligence, reassessments, monitoring, and offboarding activities.
Conducted information security risk assessments and control reviews for third parties across the South Asia region, identifying security and compliance gaps.
Evaluated financial, operational, regulatory, and information security risks and provided risk mitigation recommendations to stakeholders.
Performed vendor due diligence, evidence validation, and periodic reassessments to ensure ongoing compliance with organizational and regulatory requirements.
Collaborated with third parties, business owners, and risk teams to resolve assessment issues and drive timely remediation of findings.
Escalated high-risk and non-compliant cases, supporting risk acceptance, remediation, and contractual decision-making processes.
Monitored key risk metrics, assessment status, and remediation progress, providing management reporting and risk insights.
Maintained vendor risk records and ensured accuracy of assessment documentation, risk data, and supporting artifacts.
Facilitated stakeholder meetings and promoted continuous improvement of third-party risk management practices.

Team Leader in Information Security and Compliance

Yalamanchili Software Exports Private Ltd
09.2021 - 02.2022

Planned and conducted internal audits for ISO 27001 and PCI DSS, including audit planning, evidence review, reporting, and corrective action tracking.
Coordinated external certification, client, and compliance audits, facilitating evidence collection, auditor interactions, and observation closure.
Performed information security risk assessments, vendor audits, and control reviews to identify risks and strengthen compliance.
Managed ISMS documentation, including policies, procedures, records, and compliance artifacts within the Document Management System (DMS).
Supported security incident management, including incident tracking, investigation coordination, documentation, and SLA-based closure.
Conducted firewall rule reviews and compliance validations to ensure adherence to security and change management requirements.
Facilitated Information Security Steering Committee (ISC) and Management Review Meetings (MRM), including reporting, action tracking, and governance support.
Coordinated audit evidence reviews, root cause analysis, corrective actions, and remediation activities to ensure timely closure of findings.
Developed management dashboards, risk reports, and presentations for senior leadership and governance forums.
Conducted facility, safety, and third-party audits to evaluate operational, security, and compliance controls.

Senior Executive in Information Security

Enerji Systems Private Ltd (Enerji Group of Companies)
12.2016 - 09.2021

Planned and conducted internal audits for ISO 9001 and ISO 27001, including audit planning, evidence review, reporting, and corrective action tracking.
Coordinated external certification and surveillance audits with certification bodies, supporting audit execution, evidence collection, and closure of findings.
Performed information security, third-party, and vendor audits to evaluate compliance with organizational and regulatory requirements.
Managed ISMS and QMS documentation, including policies, procedures, records, and compliance artifacts within the Document Management System (DMS).
Supported information security incident management, risk assessments, risk register maintenance, and implementation of risk treatment plans.
Conducted firewall review activities, security control validations, and tracked remediation of VAPT findings to strengthen security posture.
Facilitated Information Security Steering Committee (ISC) and Management Review Meetings (MRM), including governance reporting, action tracking, and management presentations.
Supported Business Continuity Management activities by coordinating BCP documentation, stakeholder inputs, evidence collection, compliance metrics, and audit follow-ups.

System Engineer

TekFlair Systems Private Ltd
01.2013 - 09.2016
  • Developed, maintained, and supported LAN/WAN, Internet connectivity, and wireless communication networks to ensure reliable network availability.
  • Planned and implemented network infrastructure using routers, switches, hubs, and other networking hardware and software.
  • Provided end-user support for Microsoft Outlook configuration, email connectivity, and troubleshooting.
  • Coordinated with field engineers and technical teams, assigned support activities, and monitored timely completion of IT tasks.
  • Performed Windows operating system installation, maintenance, configuration, customization, troubleshooting, and issue resolution.
  • Provided end-to-end desktop and laptop hardware and software support, including installation, configuration, repair, maintenance, and troubleshooting.
  • Supported computer networking, Internet configuration, Remote Assistance, and Remote Desktop connectivity for end users.
  • Installed, configured, and supported Windows-based applications and Microsoft Office tools.
  • Diagnosed and resolved hardware, software, network, and end-user issues using structured troubleshooting and problem-solving approaches.
  • Performed PC assembly, hardware upgrades, peripheral installation, and device driver installation and configuration.
  • Coordinated with hardware and software vendors for the procurement, installation, maintenance, and replacement of computers and IT peripherals.
  • Prepared and submitted daily IT support and operational status reports to the IT Manager.
  • Installed, configured, and administered the Quick Heal Administration Console to support endpoint security management and monitoring.

System Admin

R V Techno Solutions Pvt. Ltd
06.2011 - 12.2012
  • Installed, configured, administered, and troubleshot Windows Server 2008 environments.
  • Managed user and group accounts, access permissions, and security settings, including file sharing and access control.
  • Performed file system backup and recovery activities, disk administration, and storage management.
  • Installed, configured, and managed local and network printers, including troubleshooting printing and connectivity issues.
  • Supported the specification, procurement, installation, and configuration of IT hardware, software, and related equipment.
  • Diagnosed, troubleshot, and resolved a wide range of technical, hardware, software, and operating system issues.
  • Installed, configured, and troubleshot networking equipment, including routers and switches.
  • Supported the installation, configuration, and maintenance of Windows operating systems and desktop applications.
  • Set up and configured desktop computers, installed required software, and provided technical support to end users.

Networking Engineer (Coordinator)

Tikona Digital Networks Ltd
04.2010 - 05.2011

Organization: Mother Concern – Planman HR Pvt. Ltd.

  • Supported wireless network operations using 4G technologies, including OFDM (Orthogonal Frequency Division Multiplexing) and MIMO (Multiple Input Multiple Output) technologies.
  • Supported point-to-point wireless connectivity using 5.8 GHz frequency bands for tower-to-tower communication and 2.4 GHz connectivity for last-mile customer connections.
  • Performed preventive maintenance, fault management, troubleshooting, and issue resolution to maintain network availability and service continuity.
  • Monitored Internet bandwidth utilization, identified usage and performance issues, and prepared regular bandwidth monitoring reports.
  • Installed and configured Customer Premises Equipment (CPE), Nano devices, and Wi-Fi modems to establish and maintain customer connectivity.
  • Conducted site-level signal strength testing and connectivity validation to ensure optimal wireless network performance and service quality.

Hardware & Debugging Engineer

Aforeserve Company Limited
10.2008 - 02.2010
  • Performed repair, servicing, and troubleshooting of Intel-based motherboards, including component-level fault identification and basic hardware diagnostics.
  • Gained hands-on experience with motherboard components, chipsets, and hardware architecture, performing chipset-level analysis and fault diagnosis.
  • Assisted with the installation, configuration, maintenance, and troubleshooting of workstations, networking equipment, and other IT hardware.
  • Installed and configured Windows operating systems, including Windows 7, 8, 10, and 11, along with required software and applications.
  • Performed testing and troubleshooting of peripheral and expansion cards, identifying hardware faults and supporting timely issue resolution.

Education

Master of Science (M.Sc.) - Cyber Forensic and Information Security

Madras University
Chennai
01-2021

Bachelors of Engineering (B.E.) - Electronics & Communication Engg

Jaya Engineering College, affiliated to Anna University
Chennai
01-2008

Skills

Data Privacy Program Governance & Operating Model

RoPA, Data Discovery, Mapping & Classification

Privacy by Design / Default; SDLC Integration

DPIA, DSAR, Consent & Cookie Governance

DPDP Act, GDPR, CCPA/CPRA, etc

Cross-border Transfers: SCCs, TIAs, Localization

Privacy Risk Assessments & Gap Analysis

Privacy Platforms: OneTrust, TrustArc etc

Stakeholder Engagement (CISO/Legal/DPO)

Team Leadership & Consulting Delivery

ISO/IEC 27001:2013 Lead Auditor Course

Third-party risk assessments

Incident management

Firewall log review

Vendor due diligence

Risk assessments

Control testing

Compliance monitoring

Policy review

Audit reporting

Remediation tracking

Management reporting

Stakeholder coordination

Evidence validation

Certification

Successfully completed and certified in ISO/IEC 27001:2013 Lead Auditor Course – June 2021

Timeline

Manager in Infosec

Hexaware Technologies
06.2023 - Current

Technical Lead in Information and Cyber Security

Tech Mahindra Limited
02.2022 - 05.2023

Team Leader in Information Security and Compliance

Yalamanchili Software Exports Private Ltd
09.2021 - 02.2022

Senior Executive in Information Security

Enerji Systems Private Ltd (Enerji Group of Companies)
12.2016 - 09.2021

System Engineer

TekFlair Systems Private Ltd
01.2013 - 09.2016

System Admin

R V Techno Solutions Pvt. Ltd
06.2011 - 12.2012

Networking Engineer (Coordinator)

Tikona Digital Networks Ltd
04.2010 - 05.2011

Hardware & Debugging Engineer

Aforeserve Company Limited
10.2008 - 02.2010

Bachelors of Engineering (B.E.) - Electronics & Communication Engg

Jaya Engineering College, affiliated to Anna University

Master of Science (M.Sc.) - Cyber Forensic and Information Security

Madras University

Personal Information

  • Date of Birth: 19th May 1987
  • Gender: Male
  • Marital Status: Married

DECLARATION

I hereby declare that the details furnished above are true and complete to the best of my Knowledge.

PERSONAL DETAILS

  • Father’s Name : K S Ramalingam
  • Native Place : Chennai T.N
  • Overall Experience : 17+ Years
Kumar B RDeputy Manager