Summary
Overview
Work History
Education
Skills
Languages
Certification
Accomplishments
Affiliations
Timeline
Generic

Nida Qureshi

Mumbai

Summary

Detail-oriented Information Security Analyst with a proven track record of ensuring compliance with Information Security & Data protection regulations and standards. Experienced in regulatory compliance, data protection compliance, and ISO 27001 compliance, seeking to leverage my skills to contribute to the security posture of the organization.

Overview

3
3
years of professional experience
1
1
Certification

Work History

Associate Security Consultant- Audit & Compliance

Varutra Consulting Pvt. Ltd.
Mumbai
07.2022 - Current

Deployed at client- DHL Express Pvt. Ltd. as Information Security Analyst..

  • Conducted various IT security and data protection user awareness programs, including mailers, posters, and quizzes, on a regular basis.
  • Proficient in conducting phishing simulations using platforms like Cofense PhishMe, resulting in a 41% increase in employee awareness and reporting of phishing attempts.
  • Proficiency in analyzing data from phishing simulations to assess employee susceptibility, and improve training programs.
  • Developed security playbooks, policies, and process documents to enhance the organization’s security posture.
  • Created third-party vendor security checklists and IT security audit checklists, review decks, and reports for monthly review and management review meetings.
  • Assisted in GDPR implementation and collaborated with cross-functional teams to ensure organizational compliance.
  • Maintained risk register to support risk assessment activities related to IT security.
  • Collaborated with vendors and cross-functional teams to conduct security assessments of third-party applications, including BIA, TVA, DPR, and PIA.
  • Analyzed security incident tickets to identify root causes of security incidents, and develop preventive actions and remediation plans.
  • Regular review of information security risks, vulnerabilities, and the patching process.

Regulatory Compliance Intern

Wellthy Therapeutics
Mumbai
09.2021 - 05.2022
  • Created, reviewed, and updated Standard Operating Procedures (SOPs) and the Risk Register.
  • Co-created the ISO 27701 standard manual and the Personal Data Protection Act (PDPA) manual for the organization; updated the ISO 27001 and ISO 13485 manuals.
  • Participated in ISO 27001 and 27701 certification audits.
  • Created audit checklists for ISO 27001, 27701, 13485, and EU MDR 2017/745.
  • Prepared Non-Conformance (NC) reports for the ISO 13485 audit, including Root Cause Analysis (RCA), and Corrective and Preventive Actions (CAPA).
  • Acquired basic knowledge of CE marking for Class II-A medical devices, US HIPAA compliance, 21 CFR Part 11, and Part 820.
  • Created templates for Data Subject Access Requests and Data Correction Requests in accordance with GDPR and PDPA requirements.
  • Reviewed all cross-functional documents (risk register, SOP, information handling schedule, departmental KPIs, asset inventory) to ensure compliance with ISO 13485 and ISO 27001 standards.
  • Conducted Data Protection Impact Assessments (DPIAs) for critical vendors.

Education

Master of Science - Nutraceuticals

G.N. Khalsa College
Matunga, Mumbai
01-2021

Bachelor of Science - Zoology

B.N. Bandodkar College
Thane
01-2019

Skills

  • NIST
  • ISO 27001
  • ISO 27701
  • ISO 27002
  • ISO 22301
  • ISO 14971
  • Risk Management
  • Data protection
  • GDPR
  • PDPA
  • DPDP Act
  • US HIPAA
  • Governance, Risk, and Compliance
  • Drafting Policies and Procedures
  • ISMS Implementation
  • Presentation skills
  • Communication skills
  • Collaborative
  • Adaptive
  • Problem solving
  • Proficient in Excel and PowerPoint
  • Data analysis
  • Attention to detail

Languages

Hindi
First Language
English
Proficient (C2)
C2
Marathi
Intermediate (B1)
B1

Certification

  • Completed Systems Security Certified Professional (SSCP) training.
  • Training in Manufacturing (Level 2) & COVID- Food Safety Supervisor conducted by SafeFoodz Solutions.
  • On-line training in HACCP Internal Auditing. Training Content: Codex HACCP, Pre-requisite Programs, Risk Assessment, Internal Auditing Skills.
  • Online Internal Auditor Training to FSSC 22000 version 5.0 Requirements.
  • Completed training program on ICP- OES & ICP- MS.
  • Completed Certificate course in Food Testing and Product Formulation.

Accomplishments

SOC Ticket Analysis & Improvement

  • Successfully identified the root cause and analysis of SOC tickets and implemented preventive and corrective measures resulting in a 50% reduction in security incidents.

Phishing Awareness Initiative

  • Conducted a company-wide Phishing awareness campaign and training program, increasing employee response rate by 41% and reducing the susceptibility rate from 12.5 to 1.8%.

Affiliations

  • Participated in Annual Extension Activities under the Department of Lifelong Learning & Extension (DLLE).
  • Volunteered in Nutrazest, Nutrition Week and Eat Right Mela.

Timeline

Associate Security Consultant- Audit & Compliance

Varutra Consulting Pvt. Ltd.
07.2022 - Current

Regulatory Compliance Intern

Wellthy Therapeutics
09.2021 - 05.2022
  • Completed Systems Security Certified Professional (SSCP) training.
  • Training in Manufacturing (Level 2) & COVID- Food Safety Supervisor conducted by SafeFoodz Solutions.
  • On-line training in HACCP Internal Auditing. Training Content: Codex HACCP, Pre-requisite Programs, Risk Assessment, Internal Auditing Skills.
  • Online Internal Auditor Training to FSSC 22000 version 5.0 Requirements.
  • Completed training program on ICP- OES & ICP- MS.
  • Completed Certificate course in Food Testing and Product Formulation.

Master of Science - Nutraceuticals

G.N. Khalsa College

Bachelor of Science - Zoology

B.N. Bandodkar College
Nida Qureshi