Seasoned Vice President at CSIPL with a proven track record in risk management and cross-functional team leadership. Expert in controls testing and project management, demonstrated through significant improvements in compliance and operational efficiency at CITI. Skilled in analytics and reporting, with a talent for mentoring teams towards achieving excellence in audit and compliance.
Overview
19
19
years of professional experience
Work History
Vice president
CSIPL
Chennai
01.2020 - Current
Driving risk culture and governance across APAC regional Payment and Receivables applications
Partner with technology teams and stakeholders to ensure technology risk and control related matters are addressed timely and within the risk appetite, including but not limited to issue and corrective action plans monitoring and tracking, as well as leading / participating in internal or cross-functional risk and control initiatives
Identify & assess technology risks and engage stakeholders to determine corrective action plans (CAPs) to remediate them in a timely manner
Manage internal, external, regulatory, and other audits end-to-end, providing proper perspective on risks and issues
Work with partners in-region across all the technology sectors, and globally within Citi Technology Infrastructure to manage technology and infra related risks and compliance to regulatory requirements
Analyzes a multitude of scorecards to mitigate Technology Risks
Serves as a subject matter expert for Issues / CAP Management
Develop and deliver reports and metrics for management
Operational Risk Events (OREs): Support the global team in monitoring / tracking of regional (APAC) technology OREs, perform trend analysis and drive actions to address identified gaps
Identifying thematic or specific control gaps and partnering to develop action plans to drive risk mitigation and remediation
Ensure compliance to regulatory requirements like MAS 610, MAS 644, and MAS 655, MAS TRM guidelines
Managing risk appetite metrics to ensure successful delivery of mitigating actions
Ensures project completion, special assignments, and other ad hoc activities as required
Conduct technology risk assessment for new project and major technology enhancement
Evaluates the control environment by ensuring appropriate controls are in place
Host the Country Technology Risk and Control forums for the country technology managers and country risk leads region wise
Conduct independent compliance assessment and gap analysis of technology risk and cyber security regulatory requirements whenever required
Assistant Vice president
CSIPL
Chennai
01.2017 - 12.2019
Independently assess the effectiveness of controls and determine the potential impact of any control failures and corrective actions required
Identify control gaps/weaknesses and provide practical recommendations to improve the quality and effectiveness of the control environment
Review escalations of dashboard deviations (Project Quality Control, Issue and CAP management, End of Vendor Support, Production Access Control, Vulnerability assessments, SDLC documentation compliance, Engagement Form submission, FID management, CoB tests of applications, entitlement reviews - EERS, DB compliance exceptions in FortiDB, SSH trust public key exceptions, Citi SSO, Export license, Employee Due Diligence reviews, Third Party management, and Cross Border Data Clearance) after evaluating preliminary assessments
Produce periodic management reports to appraise management of the status of risk and control issues and reviews
Perform and report on trend analysis & find opportunities for process improvements and raise CAPs accordingly
Manage internal and external audits and regulatory examinations/inspections by acting as audit liaison / interface, as required
Work with SMEs of various Technology related processes to create documents for Senior Technology Managers focused on audit and regulatory readiness
Co-ordinate periodic reporting; analyze self-assessment and audit results; and assist in formulating effective remedial solutions
Perform the information security review of Application and verify their compliance to the Citi Information Security Standards
Perform Managers Control Assessment (MCA) testing of IT General Controls
Analyze test results and open corrective action plans as needed
Identify emerging risks and prepare Quarterly Risk Assessment (QRA) documents to summarize overall MCA results
Investigate how non-compliant items can be remediated or how risk could be mitigated
Schedule, host and drive meetings with multiple levels of management
Support Technical Information Security Officers in their work for remediating any non-compliant items
Embracing new technologies, actively seeking out opportunities for improving efficiency of the Information Security Review Process and seek out possibilities for implementing automation for any manual efforts
Receive manually defined issues, review for completeness and accuracy
Manager- Infrastructure Security Analyst
CITI
Singapore
01.2014 - 01.2017
Company Overview: CITI Singapore
Schedule expedited and emergency requests during the shift (CCR/CMP/INC) and update request with scheduling (i.e
Global block list)
Escalate scheduling of BAU changes as requested (see emails/IMs for escalation)
Review/accept Change Admin tasks
Escalate rejections and expirations to requesters/change coordinators, rescheduling or correcting the change as necessary
Represent Cyber SecOps PSO changes in regional/business CAB meetings
Chase task acceptance/approvals
Answer emails/IMs regarding scheduling
Assist in scheduling BAU requests
Close Change Admin tasks
CITI Singapore
Manager- Infrastructure Security Analyst
CITI
Singapore
03.2013 - 01.2014
Company Overview: CITI Singapore
Monitor and investigate Violations and Security breaches on Wintel, Unix and databases using Arc sight
Work with business units and audit to perform Event Monitoring testing as needed
Establishing baseline and assessing impact when new activity/Work introduced
Cyber SecOps Ticket handling
Executing corrective action plan to review Firewall rules
Develop and maintain Process Control Manuals
Coordinate with Information Security officer on Security incident report filings associated with Event Monitoring activity
Perform Monthly/Quarterly/Semiannual Risk assessment test
CITI Singapore
Senior Project Engineer
WIPRO Technology Services
06.2006 - 02.2013
Company Overview: formerly CITI technology services
Review of daily activities performed by SEM Tier 1 Analyst in Arc sight monitoring tool
Perform final closure of all Tier 1 analyst cases
Research/perform validation on breaches and violations
Captures and tracks violations and breaches through the review of daily audit logs in Arc sight and follows up with the business to ensure timely return of reviews
Escalation of audit log issues to Sr
Management
Weekly review of SEM Tier 1 activity with VP of Event Monitoring
Data gathering for external and internal audits
Work with business units and audit to perform Event Monitoring testing as needed
Email research/data gathering/review as requested by business
Develop and maintain all Enterprise SEM's Process Control Manuals
Coordinate with BISO with SIRT filings associated with Event Monitoring activity
Perform Asset Reconciliation on various global regions feeding Arc Sight Environments
Lead a Team of 15 members which reviews the changes/logs done in Oracle, SQL and Sybase production databases on daily basis and ensures that all changes are done as per the defined policies and standards
Escalation of deviations and track it to closure
Providing Audit deliverables whenever required
Single point of contact for transition of projects and implementing the same in BAU
Delivered Structured documents as per the standards required by the client such as PCM, PLSD, SOW etc
Ensure all activities carried out in Databases/Servers are in compliance with CITI standards & policies
Ensure that SLA is met for the reviews
Ensure that Monthly reports are being sent to the client with all the details Incorporated
Business recovery Coordinator For two years in Security Analysis group
Prepared BIA and BRP
Single point of contact for the respective projects during Audits
RCSA tester
Coordinate with the client to define the process and to ensure that it is in accordance with the CITI standards
Ensure that the process has been updated whenever there is change
To train the Team members and to ensure that the process has been followed without any deviations
To provide details to the management about the progress and productivity of the team
Providing monthly metrics to client and for the Management
Monitor violations and recommend for SIRT when it is required
Active member of the entertainment & sports wing of the employee's activity council which organizes and conducts events
PRAISE Award winner
RAVE award winner
Technical Associate
CITI Bank
06.2006 - 12.2006
Review the changes done in SQL, Oracle databases on daily basis and ensures that all changes are done as per the defined policies and standards for EMEA countries
Monitor violations and recommend for SIRT when it is required
Escalation of deviations and track it to closure
Providing Audit deliverables whenever required
Ensure that SLA is met for the reviews
Ensure that Monthly reports are being sent to the client with all the details Incorporated