Results-driven Sr. Consultant specializing in PCI DSS compliance and information security governance. Led compliance initiatives and improved third-party risk management, contributing to organizational security objectives. Recognized for contributions through awards, showcasing analytical skills and effective collaboration with stakeholders.
Overview
1
1
Certification
14
14
years of professional experience
Work History
Sr. Consultant
HDFC Bank
07.2023 - Current
Drive payment card security, governance, and regulatory compliance initiatives within the Information Security Group.
Lead the Merchant Compliance team, managing PCI DSS compliance for merchant onboarding, annual assessments, remediation, and ongoing compliance activities.
Manage compliance with PCI DSS, PCI PIN, PCI P2PE, and ISO/IEC 27001, ensuring adherence to regulatory and industry requirements.
Successfully lead the bank's transition to PCI DSS 4.0 and ISO/IEC 27001:2022, ensuring seamless implementation of updated security standards.
Coordinate certification audits, compliance assessments, and gap remediation activities with internal teams, QSAs, and auditors.
Manage third-party vendor security compliance and collaborate with business, technology, risk, and regulatory teams to strengthen the bank's security posture.
Serve as the primary point of contact for merchants, internal stakeholders, and auditors to ensure timely delivery of compliance requirements.
Achievements
Received the Extra Miler Award for exceptional ownership and contributions to critical information security and compliance initiatives.
Awarded the Gold Star Award for outstanding performance and excellence in driving payment card security and regulatory compliance.
Sr. Consultant
Aujas Cyber Security Limited
08.2021 - 07.2023
Performed Third-Party Risk Assessments (TPRA) and vendor security assessments for BFSI clients to ensure compliance with regulatory and security standards.
Delivered Application Security Architecture Reviews, including for Morgan Stanley, to identify security gaps and recommend remediation.
Conducted Application Threat Modeling for internal and internet-facing applications, identifying risks and recommending compensating controls.
Implemented ISO/IEC 27001 security controls, performed risk assessments, and developed security policies, procedures, and documentation.
Collaborated with clients to remediate security findings and strengthen their overall security posture.
Achievements
Awarded the Star Performer Award for consistently delivering high-quality client engagements.
Received the Rising Star Award for outstanding performance and contributions to information security initiatives.
Deputy Manager
Euronet Worldwide Ind. Pvt. Ltd.
10.2017 - 08.2021
Managed end-to-end delivery of RBI, PCI DSS, ISO/IEC 27001, third-party, and internal audits, ensuring compliance with regulatory standards.
Coordinated PCI DSS and ISO/IEC 27001 certification audits, achieving timely completion and maintaining certification status.
Conducted enterprise risk assessments and third-party vendor security assessments based on PCI DSS and ISO/IEC 27001 requirements.
Managed Information Security policies, standards, and procedures throughout their lifecycle.
Performed IT General Controls (ITGC), internal, and departmental security assessments.
Delivered security awareness and training programs, enhancing organization-wide understanding of security protocols.
Ensured quarterly compliance for vulnerability assessments, penetration testing, and other mandatory security scans.
Performed periodic user access reviews to ensure compliance with access control policies.
Assistant Manager
Reliance Communications Ltd.
10.2016 - 09.2017
Audit new and existing information systems and technologies.
Supported information security strategy, governance, and policy management to enhance compliance and risk management.
Perform security assessment, including process reviews as well as technical analysis based on ISO 27001.
Conducted training and awareness programs for end users to promote security best practices and awareness.
Collaborated with external auditors to streamline audit process and ensure thorough examination of systems.
ISMS Analyst
Mahindra Special Services Group Ltd.
11.2014 - 10.2016
Information Security Audit for leading company.
ISMS transition implementation and sustenance. Defining and implementing Risk assessment methodology. Facilitate Risk assessment and risk treatment. Reviewing ISMS policy, procedures and guidelines.
Conducted an audit for the corporate IT department at Mahindra & Mahindra to assess compliance and security protocols.
Delivered information security training to end users and specialized training for higher management and technical team to enhance security practices.
Designed and deployed security frameworks that addressed risks across people, processes, and technology to enhance organizational security posture.
Developed and implemented a comprehensive awareness program to promote information security best practices across the organization.
Reviewed client's information security program and provided actionable recommendations for enhancement.
Contributed to the auditee team during the certification audit performed by STQC and BSI.
RMS Trainee
Allied Digital Services Ltd.
05.2014 - 11.2014
Monitored system logs for security incidents, generating detailed reports to inform response strategies.
Hands on working with SIEM tools (ECOP, Alien Vault).
Assisted Static Malware Analysis Team by analyzing malware samples and providing actionable insights to enhance threat detection.
Handled phone calls and mailbox for IT security operations, ensuring timely communication and issue resolution.
Knowledge of tools like Malware Byte, Process Explorer, All-in-one-key logger, Hide my IP, Nessus, TCP view etc.
Imaging Associate
Ocwen Financial Solutions Pvt. Ltd.
11.2012 - 05.2014
Executed automated processing of mortgage documents, enhancing operational efficiency and accuracy.
Collaborated with Automation Team to support process automation initiatives for mortgage servicing operations.
Conducted training sessions for employees on automation tools and workflows, facilitating knowledge transfer on operational processes.
Education
Bachelor of Science - IT
Mumbai University
Mumbai
01-2012
12th -
Mumbai University
Mumbai
01-2009
10th -
Maharashtra state Board
Maharashtra
01-2007
Skills
PCI DSS compliance
Regulatory compliance
Information security governance
Risk assessment and management
Third-party risk management
Application security review
Certification
CISSP
CISA
ISO 27001:2022 Lead Auditor | Lead Implementor
CPISI certified
ISC2 CC
Pronouns
She
Her
Disclaimer
I hereby declare that the above written particulars are accurate to the best of my knowledge and belief.