Responsible for firm-wide objectives focused on enhancing data protection, standardizing and securing critical infrastructure, and improving cyber visibility through Security Operations Centers (SOCs). Conducted third-party risk assessments, managed Vendor Risk Assessment (VRA) framework, and drove its enhancement to meet evolving cyber security needs. Acted as the Subject Matter Expert (SME) for assisting member firms in adopting and executing vendor risk management processes. Led efforts to ensure compliance with cyber security standards and best practices across the firm and its partners.
Overview
9
9
years of professional experience
1
1
Certification
Work History
Senior Vendor Risk Assessment Analyst
Deloitte Support Services India Private Limited
Hyderabad
2020.08 - Current
Project: Global Cyber Security Function
Description:
Responsible for firm-wide objectives focused on enhancing data protection, standardizing and securing critical infrastructure, and improving cyber visibility through Security Operations Centers (SOCs)
Conducted third-party risk assessments, managed Vendor Risk Assessment (VRA) framework, and drove its enhancement to meet evolving cyber security needs
Led efforts to ensure compliance with cyber security standards and best practices across the firm and its partners.
Roles and Responsibilities:
Conducted and oversaw thorough vendor risk assessments, collaborating with internal stakeholders to effectively manage and mitigate risks.
Prepared and completed risk assessments to ensure compliance and readiness during policy, regulatory, and accreditation audit preparations.
Managed the maintenance and administration of the Vendor Risk Assessment (VRA) platform, ensuring its seamless operation and utility
Collaborated with business units, procurement, and other stakeholders to ensure a holistic approach in understanding and implementing Vendor Risk Management (VRM) requirements.
Ensured thorough follow-up reporting and monitoring for effective resolution of risks.
Accelerated continuous improvements in vendor risk management by updating and refining procedures.
Stay current with the latest developments in vendor risk management for industry awareness and to incorporate best practices and emerging trends.
Enhanced operational risk management by raising awareness of potential risks associated with vendor failures or poor performance, and collaborating with Strategic Sourcing, Legal, and Business units to mitigate losses through effective contract management and vendor compensation.
Operational Risk Consultant
Wells Fargo
Chennai
2019.04 - 2020.07
Project: Third Party Operational Risk Management
Description:
Collaborated with US States team to ensure seamless Life Cycle Management of Third Party Risk Assessments utilizing the GRC tool
Managed end-to-end Third Party Risk Assessment process including - Engagement profile, IRQ(Inherent Risk Questionnaire), Due diligence, Contract execution, Monitoring oversight & Closure.
Roles and Responsibilities:
Initiated relevant risk assessments, including Information Security, Business Continuity, Third Party provider, Vulnerability assessments, Background Check, and Exit Strategy, coordinating with respective Enterprise teams for completion.
Performed Quality Assurance (QA) reviews on GRC Tool records and ensured compliance with Third Party Service Provider (TPSP) policy requirements.
Tracked and notified TPSPs on identified vulnerabilities, ensuring timely remediation.
Provided process improvement suggestions to enhance the efficiency of the Third Party Risk program.
Monitored vendor alerts from Google Alerts for moderate and high-risk TPSPs.
Liaised with Compliance Consultants, Information Security Officers, Anti-Bribery & Corruption (AB&C), and other relevant teams for assistance and approvals as required.
Analyst
Cognizant Technology Solutions
Chennai
2015.06 - 2019.04
Project: Vendor Risk Management.
Description:
Evaluating the risk of third-party suppliers processing, storing, transmitting, or accessing client information was a key responsibility in managing the Vendor Risk Assessment process.
Roles and Responsibilities:
Classified vendors based on scorecard reviews using client tier system.
Conducted supplier assessments in alignment with ISO 27001 standards.
Performed initial reviews of vendor-submitted reports, including PCI, ISO, SOC, ISAE 3402, and Information Security policies and procedures.
Contributed to the creation of a Vulnerability, Risk & Impact (VRI) database to aid in assessments.
Assisted in developing customized self-assessment questionnaires tailored to specific services provided.
Risk-rated and finalized identified gaps using the risk management framework.
Delivered final assessment briefings to business stakeholders.
Conducted quality checks on Risk Assessments
Maintained end-to-end status tracking and report generation using the GRC (Governance Risk and Compliance) tool.
Education
B.Tech in Information Technology -
SRM University
2015-05
Intermediate (11th and 12th Grade) -
Sri Chaitanya College
2011-05
10th Grade -
A Little Flower The Leader School
2009-05
Skills
Skills
Technical Skills:
Java, C and SQL
Tools:
GRC Tools
Archer
Standards/Regulations:
ISO 27001
SOC 1/2 Type I/II, SOC 3
PCI
ISAE 3402
Location
Hyderabad
Certification
CISA Certified (Certified Information Systems Auditor)
Certified ISMS Lead Auditor – ISO 27001:2013
CCSK Certified (Certificate of Cloud Security Knowledge)
<ul><li>Assist in preparing Subs Annual Budgets and reviewing Subs financial reports.</li><li>Provide support and training to partners to ensure adequate support for the program component.</li><li>Conduct partner technical supportive supervision on request basis from Grants & Compliance teams.</li><li>Coordinate grantee proposal review process and ensure compliance with solicitations and donor regulations.</li><li>Coordinate pre-award evaluations and assessments of potential grantees as needed.</li><li>Analyze, verify and review grantees proposal budgets to ensure donor compliance and reasonableness.</li><li>Coordinate the assessment of grantee risk and implement appropriate systems and agreements to minimize risk.</li><li>Ensure timely and appropriate close-out of sub-grants and coordinate the close-out of EGPAF prime grants.</li><li>Provide support and training to partners finance staff to build financial and accounting capacity to ensure adequate support for the program component.</li><li>Monitor partners’ spending patterns as part of the overall project budget to actual analytics.</li><li>Follow up on Grantee monthly invoices & supporting documents</li><li>Serve as an expert on applicable policies, procedures, rules, and regulations and assist staff with their interpretation and understanding of these.</li><li>Stays abreast of donor policies, procedures, rules and regulations and host country legal requirements and informs local and regional management of significant changes.</li><li>Perform internal departmental/grants reviews ensuring compliance with Foundation and donor requirements. Identify potential areas of compliance vulnerability and risk; assists with the development of corrective action plans for the resolution of problematic issues; and provides general guidance on how to avoid or deal with similar issues in the future</li><li>Conduct on-site financial compliance reviews which include: cash counts; review of accounts receivables including employee receivables; documentation of segregation of duties and internal control structure; document storage and retention</li><li>Document findings, propose improvements or change as relevant, disseminate findings and ensure follow up implementation of recommendations as well as resolution</li><li>Conduct random surprise checks and vendor verification reviews to ensure proper procurement procedures are being practiced and report on findings</li><li>Develops an effective Compliance & Ethics training program, including appropriate introductory training for new employees as well as ongoing training for all employees and managers</li><li>Assists with improving the awareness and understanding of compliance to assist employees with the establishment of a “culture of compliance”</li></ul> at Elizabeth Glaser Pediatric Aids Foundation<ul><li>Assist in preparing Subs Annual Budgets and reviewing Subs financial reports.</li><li>Provide support and training to partners to ensure adequate support for the program component.</li><li>Conduct partner technical supportive supervision on request basis from Grants & Compliance teams.</li><li>Coordinate grantee proposal review process and ensure compliance with solicitations and donor regulations.</li><li>Coordinate pre-award evaluations and assessments of potential grantees as needed.</li><li>Analyze, verify and review grantees proposal budgets to ensure donor compliance and reasonableness.</li><li>Coordinate the assessment of grantee risk and implement appropriate systems and agreements to minimize risk.</li><li>Ensure timely and appropriate close-out of sub-grants and coordinate the close-out of EGPAF prime grants.</li><li>Provide support and training to partners finance staff to build financial and accounting capacity to ensure adequate support for the program component.</li><li>Monitor partners’ spending patterns as part of the overall project budget to actual analytics.</li><li>Follow up on Grantee monthly invoices & supporting documents</li><li>Serve as an expert on applicable policies, procedures, rules, and regulations and assist staff with their interpretation and understanding of these.</li><li>Stays abreast of donor policies, procedures, rules and regulations and host country legal requirements and informs local and regional management of significant changes.</li><li>Perform internal departmental/grants reviews ensuring compliance with Foundation and donor requirements. Identify potential areas of compliance vulnerability and risk; assists with the development of corrective action plans for the resolution of problematic issues; and provides general guidance on how to avoid or deal with similar issues in the future</li><li>Conduct on-site financial compliance reviews which include: cash counts; review of accounts receivables including employee receivables; documentation of segregation of duties and internal control structure; document storage and retention</li><li>Document findings, propose improvements or change as relevant, disseminate findings and ensure follow up implementation of recommendations as well as resolution</li><li>Conduct random surprise checks and vendor verification reviews to ensure proper procurement procedures are being practiced and report on findings</li><li>Develops an effective Compliance & Ethics training program, including appropriate introductory training for new employees as well as ongoing training for all employees and managers</li><li>Assists with improving the awareness and understanding of compliance to assist employees with the establishment of a “culture of compliance”</li></ul> at Elizabeth Glaser Pediatric Aids Foundation