Summary
Overview
Work History
Education
Skills
Hobbies and Interests
Languages
Certification
Timeline
Generic

Ramkumar Chandramohan

Bangalore,

Summary

Experienced Information Security, Risk, and Compliance professional with 19 years in SOX, IT security, privacy, and AI risk management. Led internal and external SOX audits, while managing teams to enhance compliance strategies. Certified in CISSP, CIPP/E, CIPT, and AIGP, with strong expertise in GDPR, the EU AI Act, and ISO/IEC 27001:2013. Proficient in automating compliance and audit tasks with Microsoft VBA and Python.

Overview

2
2
Languages
1
1
Certification
20
20
years of professional experience

Work History

Senior IS Security, Risk & Compliance Specialist

ABB
Bangalore
06.2023 - Current
  • Managed enterprise-wide roll-out of NIS 2 regulatory requirements across ABB business areas, ensuring compliance and alignment with new regulations.
  • Designed the governance control framework to support NIS 2 regulatory compliance.
  • Advised HR Transformation Program on design and implementation of IT general controls for Workday platform, strengthening overall security posture.
  • Advised risk and control owners on using Privileged Access Management tools to mitigate privileged access risks across servers and databases.
  • Automated IT general control execution activities, delivering approximately 200 FTE hours of efficiency gains for control executors.
  • Advised business stakeholders in identifying and mitigating AI-related risks during onboarding of AI applications into enterprise landscape, enhancing risk management processes.
  • Developed an AI agent to support Information Security consultants in researching security policies, standards, and guidelines, reducing research fatigue and improving consulting turnaround time.
  • Published enterprise guidelines for designing secure and responsible AI systems.
  • Major projects undertaken: NIS 2 Regulation roll-out, HR Transformation Program

IT Risk/Compliance Manager

Philips Health tech Ltd
Bangalore
10.2015 - 05.2023
  • Deployed the Philips IT compliance management framework across IT programs, supporting IT strategic objectives while ensuring alignment with internal policies, external regulations, and accreditation standards.
  • Conducted IT, cybersecurity, privacy (GDPR), and SOX assessments, identifying potential risks and defining effective mitigation controls.
  • Coordinated external SOX audits with business, IT, and external audit stakeholders, ensuring timely evidence submission and remediation of control deficiencies.
  • Managed compliance KPIs, delivering insights to executive stakeholders for informed decision-making.
  • Managed third-party risks through the review of SOC reports from outsourcing partners and cloud service providers.
  • Led a team of two compliance officers.
  • Planned and drove quarterly internal control evaluations across IT controls, reporting outcomes to IT management through the RSA Archer eGRC tool.
  • Ensured IT compliance risks were appropriately disclosed to IT management, the audit committee, and relevant stakeholders.
  • Major projects undertaken: Implemented SOX controls for Master Data Hub solutions and finance systems, Upgraded the Consumer Master Data Hub to comply with GDPR requirements, Implemented privacy controls across e-commerce and digital platforms, Automated IT change management control execution and SOX audit activities.

Information Security Lead

Philips Health tech Ltd
Bangalore
04.2011 - 09.2015
  • Performed threat and vulnerability assessments for IT solutions, including SAP BI and Informatica MDM, to identify security risks, define mitigation controls, and embed controls into solution design.
  • Assessed IT solution architectures for security vulnerabilities and guided solution architects to embed security controls during the design phase.
  • Reviewed proposed IT solutions to assess security implications and specify required security controls.
  • Managed vulnerabilities and closed open issues through collaboration with software vendors, IT technical leads, and testers.
  • Advised IT delivery project teams on security testing activities, including web application and infrastructure penetration testing.
  • Ensured vulnerability and risk reports were communicated to Information Security Management.
  • Supported security incident response activities and reviewed the risk and impact of breaches affecting protected systems.
  • Major projects undertaken: Implemented role-based authorizations on the Teradata Data Warehouse platform. Implemented security controls for the cloud-based C2FO payment optimization solution.

SAP Security Consultant

Tata Consultancy Services (Client : Johnson & Johnson and Eli Lilly)
Bangalore
09.2006 - 04.2011
  • Designed and implemented role-based access control for SAP ECC systems, ensuring compliance with FDA and SOX regulatory requirements for healthcare and medical device environments.
  • Designed and built role-based access controls for SAP R/3 systems and data-level security for SAP BI systems.
  • Conducted security assessments and designed IT controls within SAP systems, reinforcing compliance with SOX requirements.
  • Executed segregation of duties (SoD) risk analysis prior to market rollouts, ensuring adherence to SOX compliance.
  • Led and mentored a team of six security consultants, delivering training on SAP Security concepts to enhance team capability.

Education

Bachelor of Engineering - Mechanical Engineering

PSG College of Technology
Coimbatore, India
01-2006

Skills

  • Regulatory compliance
  • Audit management
  • Information Security risk assessment
  • Artificial intelligence risk management
  • ITGC control automation
  • Third-party security risk management
  • Stakeholder engagement

Hobbies and Interests

  • Classical music
  • Computer programming and automation
  • Personal finance
  • Cycling and travel

Languages

English
Proficient (C2)
C2
Tamil
Native
Native

Certification

  • CISSP – Certified Information Systems Security Professional ((ISC)², 2015)
  • CIPP/E – Certified Information Privacy Professional / Europe (IAPP, 2016)
  • CIPT – Certified Information Privacy Technologist (IAPP, 2019)
  • AIGP – Artificial Intelligence Governance Professional (IAPP, 2025)

Timeline

Senior IS Security, Risk & Compliance Specialist

ABB
06.2023 - Current

IT Risk/Compliance Manager

Philips Health tech Ltd
10.2015 - 05.2023

Information Security Lead

Philips Health tech Ltd
04.2011 - 09.2015

SAP Security Consultant

Tata Consultancy Services (Client : Johnson & Johnson and Eli Lilly)
09.2006 - 04.2011

Bachelor of Engineering - Mechanical Engineering

PSG College of Technology
Ramkumar Chandramohan