Summary
Overview
Work History
Education
Skills
Hobbies and Interests
Languages
Timeline
Generic
Pratishi Rastogi

Pratishi Rastogi

Gurgaon

Summary

Seasoned Cyber Security Professional with more than 7 years of experience in the industry, specializing in security auditing, risk assessment, and the implementation of security controls in accordance with organizational policies and procedures. Proficient in adhering to industry standards and regulations, including ISO/IEC 27001, 31000, NIST CSF with experience in GDPR, PCI DSS, COBIT, FedRAMP CMS. Skilled in executing programs and initiatives that strengthen the company's standing and contribute to its success. Demonstrates a solid history of effectively managing cyber security frameworks that align with organizational missions and objectives. Authors detailed reports on security audits and organizational risks in communication with relevant stakeholders and board members. Offering knack for building productive working relationships.

Overview

7
7
years of professional experience

Work History

Asst. Manager (Lead Solution Advisor)

Deloitte Touche Tohmatsu Limited
Gurgaon
08.2021 - Current
  • Contribute and communicate significantly to the development and review of IT security policies for prominent business entities globally.
  • Focused in internal and external technological security auditing through Testing of Controls (ToC) and Testing of Effectiveness (ToE).
  • Execute and lead product, infrastructure and enterprise risk mamagement (ERM) initiatives through design of Key Risk Indicators (KRIs) against defined Objectives and Key Results (OKRs), aiming to maximize benefits and deliver optimal value to stakeholders.
  • Well-versed in implementing security controls for safeguarding personal and sensitive information, aligning with industry-recognized Cyber Security Standards/Framework such as ISO/IEC 27001, ISO 31000, OWASP Foundation, NIST CSF and 800-53, experience with COBIT, FedRAMP CMS.
  • Knowledgeable about regional Data Privacy regulations including GDPR, HITRUST, HIPAA, CCPA, DCIA, and PCI DSS.
  • Advocate for the importance of user-centric design principles, ensuring solutions are accessible and meet end-user needs.
  • Participated in incident response process for business centric risks and assisted with remediation and corrective action plan through risk management initiatives.
  • Maintain an extensive professional network, leveraging contacts for business development and collaborative opportunities through mamagement and representation of risks to Enterprise Risk Management Committee (EMRC) and Information Security Committee (ISC).
  • Provide expert advice and consultancy on complex security issues, establishing credibility with key clients.
  • Foster strong client and business partner relationships through regular communication, ensuring satisfaction with delivered solutions and services.
  • Collaborate with various third-party organizations, evaluated their security solutions and strategies.
  • Established processes to ensure efficient workflow throughout the organization.
  • Ensured compliance with regulatory requirements and industry standards.
  • Analyzed customer feedback data to develop action plans for improving services offered.
  • Coached, mentored and trained team members in order to improve their job performance.
  • Developed and implemented strategies to increase customer satisfaction and loyalty.
  • Conducted regular meetings with staff to discuss progress and identify areas of improvement.
  • Created monthly reports for senior management summarizing operational performance metrics.

Cyber Security Specialist

AstraZeneca PLC
Chennai
03.2018 - 07.2021
  • Engaged in the design and implementation of security measures for patient-focused solutions, thereby facilitating effective IT support in sustaining the supply chain of the CoviShield vaccine throughout the Covid-19 pandemic.
  • Developed collaborative relationships across various sectors with the organization's non-technical business units and vendors that provide services or solutions.
  • Conducted security evaluations on both internal and external solutions/services that handled the organization's data.
  • Ensured compliance with the organization's security policy framework, which aligned with industry best practices.
  • Managed the complete risk management lifecycle, from identifying and detailing risks along with their severity, to offering mitigation strategies and recommendations, while also monitoring the progress of risk resolution and supporting business units in aligning with the organization's risk appetite.
  • Orchestrated security architecture reviews, optimizing infrastructure for enhanced protection against cyber threats.
  • Advised senior management on emerging cyber security trends and recommended strategic adjustments.
  • Negotiated with vendors to procure cutting-edge cyber security technologies at cost-effective rates.
  • Developed and implemented robust information security policies and procedures, aligning with industry best practices.
  • Collaborated with IT teams to secure cloud-based environments, employing encryption and access control measures.
  • Authored and reviewed cyber security policies, standards and procedures to implement new innovations and regulatory compliance requirements.
  • Applied appropriate internal controls to address and circumvent security risks without reducing system performance.

Education

Post Graduate Diploma in IT Infrastructure, Systems & Security -

CDAC (Centre for Development of Advanced Computing) ACTS
Pune, Maharashtra, IN
02.2018

Bachelors in Electronics and Communications Engineering - B.Tech

Dr. A.P.J. Abdul Kalam Technical University
IN
07.2017

Skills

  • Governance, Risk and Compliance
  • Internal and External Audit
  • Enterprise Risk Assessment
  • Information Security Controls and Processes
  • Security Auditing
  • Control Testing
  • Communication Skills
  • Leadership

Hobbies and Interests

  • Travelling
  • Reading
  • Sports

Languages

  • English
  • Hindi

Timeline

Asst. Manager (Lead Solution Advisor)

Deloitte Touche Tohmatsu Limited
08.2021 - Current

Cyber Security Specialist

AstraZeneca PLC
03.2018 - 07.2021

Post Graduate Diploma in IT Infrastructure, Systems & Security -

CDAC (Centre for Development of Advanced Computing) ACTS

Bachelors in Electronics and Communications Engineering - B.Tech

Dr. A.P.J. Abdul Kalam Technical University
Pratishi Rastogi