Summary
Overview
Work History
Education
Skills
Accomplishments
Certification
Interests
Timeline
Generic
Ritu Raj

Ritu Raj

Information Security And Data Privacy (DPO)
Bengaluru,Karnataka

Summary

Insightful Manager with experience directing and improving operations through effective employee motivational strategies and strong policy enforcement. Proficient in best practices, threat landscape trends and regulatory requirements of industry operations. Strong leader and problem-solver dedicated to streamlining operations to decrease costs and promote organizational efficiency. Uses independent decision-making skills and sound judgment to positively impact company success.

Overview

13
13
years of professional experience
10
10
Certificates

Work History

Manager- Information Security & Data Privacy (DPO)

TheMathCompany Pvt. Ltd.
Bengaluru
11.2021 - Current

Information Security Manager
• Plan, implement and review IT Governance, Risk, Compliance program, ensuring compliance within organization.
• Drive regulatory and industry guidelines into existing policies and standards.
• Review new services and initiatives from IT security and risk perspective and provide recommendations/mitigation measures.
• Oversee and perform Internal and External Audits capabilities like SOC2, ISO27001.
• Manage Enterprise Risk Management and IT Risk Register to report compliance review activity, tracking all actions and risks arising from review.
• Manage Information Security Steering Committee and Change Advisory Board, Incident Response Team, and Information Security & Privacy awareness training.
• Develop Third-Party Risk Management Program, incorporating most recent guidance and conduct on-site and off-site audits of vendor control environments.
• Drive threat and vulnerability management program to include data loss prevention, penetration testing, vulnerability scanning and threat assessment.
• Drive organization wide risk awareness training programs and security initiatives in cyber defense strategy.
• Oversee of Information/Cyber Security development and trends and work with industry to evaluate potential security offerings, including product evaluations, proof of concept and pilots.

Data Privacy as Data Protection Officer (DPO)
• Fulfill tasks of designated role of DPO to CISO.
• Inform and advise organization of their obligations.
• Implement DPO Center's established processes and practices.
• Create and implement strategies to ensure compliance with data protections laws.
• Perform DPIAs, PIAs and LI assessments and build/maintain client's Records of Processing Activities (RoPA).
• Draft and manage data protection policies, guidelines and processes.
• Maintain record of processing activities and impact assessments.
• Manage processes for breach response, complaints, claims and notifications.
• Advise on identifying, assessing and mitigating risks.
• Prepare recommendation reports and corresponding Master Service Agreements (MSA) and Schedule of Works (SoW).
• Devise, facilitate and deliver training and awareness workshops.
• Support client in responding to individuals' rights requests.
• Consistently inform and advise client on governance, accountability, and risks.
• Keep up to date with changes in data protection law and regulations.
• Ensuring organization gets attested to Global regulatory compliance frameworks like: GDPR/DPDPA/CCPA/GLBA/HIPAA.
• Conduct periodic compliance applicability audits.
• Actively contribute to building overall knowledge base within centralized team.

Lead-Cybersecurity and Third Party Risk Management

Northern Trust Corporation
Bengaluru
10.2017 - 11.2021
  • Worked with various Risk Advisors across the organization.
  • Conduct detailed Third-Party/Vendor Risk assessments and ensure that Risk assessments and outputs are recorded in enterprise tools and are in full compliance of defined policies and common standards, including the Third-Party Risk Management Framework.
  • Identify IT risk issues or issues that are common across the landscape and help implement preventative controls across IT&S.
  • Partner with other risk groups to assess, implement and communicate new/updated risk controls, frameworks, policies, risk indicators, metrics, and limits.
  • Ensure implementation of a strong IT risk culture in partnership with various IT Risk Advisors and Risk Owners.
  • Review the Contracts/Master Service Agreement between Third Party and Bank and ensure all the IS terms and conditions are covered.
  • Engaging with different stake holders globally for procuring new tools for Cybersecurity.
  • Perform Enterprise Compliance Risk Management (eCRM), Privacy (GDPR), and Information/Cyber Security risk assessments on Information Security, Sub-Advisory and Sub-Custodians for the bank.
  • Develop the Third-Party Risk Management Program, incorporating the most recent guidance from Federal Reserve Board (SR-1319).
  • Conducted the on-site and off-site audits of vendor control environments.

IT Security Specialist

IBM India Pvt. Ltd.
Bengaluru
10.2014 - 10.2017
  • Participating in Application Risk Assessment and involved in the remediation of gaps identified as part of the assessment.
  • Enterprise Program / Project Risk Management - Technology Risk Project Risk Analysis, Risk Log Reviews, Third Party reviews, Project Status Reviews.
  • Manage transition & steady state compliance risks of Monitoring and Tracking.
  • End to End involvement in all the account related projects & IT Governance.
  • Worked closely with Service Lines and ensure all documented roles & responsibilities are adhered to.
  • Ensure that Compliance requirements such as employee on/off boarding, Data Privacy Education (especially linked to regulatory Compliance), Infrastructure Security Requirements are tracked and monitored.
  • Conduct regular reviews on Compliance/Regulatory requirements, to ensure account is compliant with requirements defined by the Customer, Regulatory body, and the internal standards.
  • Provide education and awareness to the account regarding all C&C Policies & procedures.
  • Worked as audit response focal for external audits.
  • Provide pre-audit and post-audit support for both internal audits and external audits to understand and fulfill data requests, understand findings/conditions and to establish rightful ownership of the issues.

Service Delivery Consultant

Hewlett Packard Enterprise
Bengaluru
06.2012 - 10.2014
  • Provide analysis and investigation of security related data from a wide range of security devices and customer environments
  • Active participation in facing client audits, researching trends and current countermeasures for cyber security vulnerabilities, exploits, and other malicious activity
  • Reviewing Customer Security Document (CSD) and SOP
  • Functioned as service line Compliance owner and responsible for maintaining the agreed SLA with Customer
  • Any Risk / GAP identified during Audit and periodic review, will raise Mitigation action plan, and follow up for the Closure
  • Coordinate and prepare Supporting staff and documentation in response to customer Audits
  • Identification, analysis, and response to a variety of threats and vulnerabilities to the security of the company.

System Analyst- Security and Risk Management

IBM India Pvt. Ltd
Bengaluru
03.2011 - 06.2012
  • Security and Risk Management, Administration of user’s accounts (Creation/deletion and amendment) in Windows/Unix.
  • Creation of shared Drives and granting correct level of access to the Shared Drive as per Client's Request.
  • Account migration from one region to another region (cross domain or inter domain).
  • Mailbox migration from one server to another server including taking mailbox backup.
  • Profile/My Docs Migration from one server to other server/ Inter and Intra Domain Moves.
  • Worked on Root Cause Analysis (RCA), Process Behavior Analysis (PBA).

Education

MBA - Information Systems

Manipal Academy of Higher Education
Manipal, India
09.2011 - 09.2013

Bachelor of Engineering (B.E) - Information Science and Engineering

Visvesvaraya Technological University
Bengaluru, India
08.2005 - 08.2009

Skills

GDPR/DPDB/SOC2/ISO27001/CCPA

undefined

Accomplishments

  • Successfully established, implemented, and managed information security, risk management and data privacy initiatives across multiple organizations.
  • Developed and executed strategic plans for improving information security and data privacy.
  • Led cross-functional teams to achieve project goals and objectives.
  • Developed and implemented policies and procedures for ensuring compliance with regulations and standards.
  • Collaborated and worked closely with Global teams to build and implement strategies across the organization’s client and vendors.
  • Established the SaaS solution for client data handling.
  • Conducted successful internal and external audits onsite and offsite to identify the gaps/risks and worked towards mitigation plans.
  • Awarded for Value awards for outstanding work in all organizations.
  • Helped organizations get new client projects by working closely with potential clients and ensuring they get best customer experience and trust in their data hosting with organization.

Certification

ISO27001 Lead Implementation

Interests

Travelling, Driving, Photography, Communicating

Timeline

Data Protection Officer and Certified Information Security Management Professional (CISM) from EXIN

11-2023

HIPAA Compliance Complete Course from Udemy.

07-2023

Digital Forensic Investigator from Alison, UK.

06-2023

GDPR from Alison, UK

05-2023

CompTIA Security+ from Alison, UK.

05-2023

Implementing Privacy, Risk and Assurance Program from LinkedIn Learning

11-2022

Manager- Information Security & Data Privacy (DPO)

TheMathCompany Pvt. Ltd.
11.2021 - Current

Certified Network Security Specialist - ICSI (International Cybersecurity Institute), UK

06-2020

ISO27001 Lead Implementation

07-2018

Lead-Cybersecurity and Third Party Risk Management

Northern Trust Corporation
10.2017 - 11.2021

IT Security Specialist

IBM India Pvt. Ltd.
10.2014 - 10.2017

Microsoft Certified Technology Specialist: Windows Server 2008 Active Directory Configuration - Microsoft

06-2013

Service Delivery Consultant

Hewlett Packard Enterprise
06.2012 - 10.2014

Microsoft Certified Professional (MCP) - Microsoft

10-2011

MBA - Information Systems

Manipal Academy of Higher Education
09.2011 - 09.2013

System Analyst- Security and Risk Management

IBM India Pvt. Ltd
03.2011 - 06.2012

Bachelor of Engineering (B.E) - Information Science and Engineering

Visvesvaraya Technological University
08.2005 - 08.2009
Ritu RajInformation Security And Data Privacy (DPO)