Detail-oriented Information Security Analyst with a proven track record of ensuring compliance with Information Security & Data protection regulations and standards. Experienced in regulatory compliance, data protection compliance, and ISO 27001 compliance, seeking to leverage my skills to contribute to the security posture of the organization.
Overview
3
3
years of professional experience
1
1
Certification
Work History
Associate Security Consultant- Audit & Compliance
Varutra Consulting Pvt. Ltd.
Mumbai
07.2022 - Current
Deployed at client- DHL Express Pvt. Ltd. as Information Security Analyst..
Conducted various IT security and data protection user awareness programs, including mailers, posters, and quizzes, on a regular basis.
Proficient in conducting phishing simulations using platforms like Cofense PhishMe, resulting in a 41% increase in employee awareness and reporting of phishing attempts.
Proficiency in analyzing data from phishing simulations to assess employee susceptibility, and improve training programs.
Developed security playbooks, policies, and process documents to enhance the organization’s security posture.
Created third-party vendor security checklists and IT security audit checklists, review decks, and reports for monthly review and management review meetings.
Assisted in GDPR implementation and collaborated with cross-functional teams to ensure organizational compliance.
Maintained risk register to support risk assessment activities related to IT security.
Collaborated with vendors and cross-functional teams to conduct security assessments of third-party applications, including BIA, TVA, DPR, and PIA.
Analyzed security incident tickets to identify root causes of security incidents, and develop preventive actions and remediation plans.
Regular review of information security risks, vulnerabilities, and the patching process.
Regulatory Compliance Intern
Wellthy Therapeutics
Mumbai
09.2021 - 05.2022
Created, reviewed, and updated Standard Operating Procedures (SOPs) and the Risk Register.
Co-created the ISO 27701 standard manual and the Personal Data Protection Act (PDPA) manual for the organization; updated the ISO 27001 and ISO 13485 manuals.
Participated in ISO 27001 and 27701 certification audits.
Created audit checklists for ISO 27001, 27701, 13485, and EU MDR 2017/745.
Prepared Non-Conformance (NC) reports for the ISO 13485 audit, including Root Cause Analysis (RCA), and Corrective and Preventive Actions (CAPA).
Acquired basic knowledge of CE marking for Class II-A medical devices, US HIPAA compliance, 21 CFR Part 11, and Part 820.
Created templates for Data Subject Access Requests and Data Correction Requests in accordance with GDPR and PDPA requirements.
Reviewed all cross-functional documents (risk register, SOP, information handling schedule, departmental KPIs, asset inventory) to ensure compliance with ISO 13485 and ISO 27001 standards.
Conducted Data Protection Impact Assessments (DPIAs) for critical vendors.
Education
Master of Science - Nutraceuticals
G.N. Khalsa College
Matunga, Mumbai
01-2021
Bachelor of Science - Zoology
B.N. Bandodkar College
Thane
01-2019
Skills
NIST
ISO 27001
ISO 27701
ISO 27002
ISO 22301
ISO 14971
Risk Management
Data protection
GDPR
PDPA
DPDP Act
US HIPAA
Governance, Risk, and Compliance
Drafting Policies and Procedures
ISMS Implementation
Presentation skills
Communication skills
Collaborative
Adaptive
Problem solving
Proficient in Excel and PowerPoint
Data analysis
Attention to detail
Languages
Hindi
First Language
English
Proficient (C2)
C2
Marathi
Intermediate (B1)
B1
Certification
Completed Systems Security Certified Professional (SSCP) training.
Training in Manufacturing (Level 2) & COVID- Food Safety Supervisor conducted by SafeFoodz Solutions.
On-line training in HACCP Internal Auditing. Training Content: Codex HACCP, Pre-requisite Programs, Risk Assessment, Internal Auditing Skills.
Online Internal Auditor Training to FSSC 22000 version 5.0 Requirements.
Completed training program on ICP- OES & ICP- MS.
Completed Certificate course in Food Testing and Product Formulation.
Accomplishments
SOC Ticket Analysis & Improvement
Successfully identified the root cause and analysis of SOC tickets and implemented preventive and corrective measures resulting in a 50% reduction in security incidents.
Phishing Awareness Initiative
Conducted a company-wide Phishing awareness campaign and training program, increasing employee response rate by 41% and reducing the susceptibility rate from 12.5 to 1.8%.
Affiliations
Participated in Annual Extension Activities under the Department of Lifelong Learning & Extension (DLLE).
Volunteered in Nutrazest, Nutrition Week and Eat Right Mela.
Timeline
Associate Security Consultant- Audit & Compliance
Varutra Consulting Pvt. Ltd.
07.2022 - Current
Regulatory Compliance Intern
Wellthy Therapeutics
09.2021 - 05.2022
Completed Systems Security Certified Professional (SSCP) training.
Training in Manufacturing (Level 2) & COVID- Food Safety Supervisor conducted by SafeFoodz Solutions.
On-line training in HACCP Internal Auditing. Training Content: Codex HACCP, Pre-requisite Programs, Risk Assessment, Internal Auditing Skills.
Online Internal Auditor Training to FSSC 22000 version 5.0 Requirements.
Completed training program on ICP- OES & ICP- MS.
Completed Certificate course in Food Testing and Product Formulation.
Master of Science - Nutraceuticals
G.N. Khalsa College
Bachelor of Science - Zoology
B.N. Bandodkar College
Similar Profiles
NITIN SRIVASTAVANITIN SRIVASTAVA
Manager-Sales & Business Development at Varutra Consulting Private LimitedManager-Sales & Business Development at Varutra Consulting Private Limited