Overall experience in Compliance, Application security, IT Specialist, IT Audits, Risk management, Operational excellence, Business consulting, Business Continuity Management, Third Party Assessment, Client relationship management and robust business documentation. Proficiency in handling overall risk & exposures of customers, risk assessment, internal/ external rating. Experience in setting up Compliance function for the organization and run it successfully with enhanced due diligence. Contributed to enhancing organizational processes through initiatives geared towards lowering risk, heightening productivity & improving internal controls An effective communicator & negotiator with strong analytical and organizational abilities
Overview
12
12
years of professional experience
1
1
Certification
Work History
Consultant Specialist-IT Risk and Control Analyst
HSBC Software Development (India) Pvt Ltd
08.2019 - Current
Extended exposure to external ISAE 3402 Audits in terms of managing and validating evidence related to Controls
Delivery of Risk and Control Dashboard for all Business Divisions to Department Heads about the most significant risks to the business; ensuring business heads understand the risks that might affect their departments; ensuring individuals understand their own accountability for individual risks.
Managing Application related issues on different Risk Managing platforms. (I.e., Jira) and reconciliation of issues with multiple Source System.
IT security audits (e.g., network, operating system, and data center), including evaluating if security vulnerabilities are properly identified and mitigated. Coordinate the scope and performance of these reviews with business units and external security experts
Third party Application Security review and to work with Risk owners to work on the findings.
Worked with developer in creating Automation tool (MRCS) for Risk and Compliance space to manage/track all KCIs effectively from different source system to one place.
Collaborating with more than 30 clients belonging to different geographies and communicate the concept of risk management and building measures to mitigate inherent risks
Monthly Risk review meetings with IT service owners to discuss issues related to their applications and provide solutions to mitigate risk.
Plans and executes corporate information technology (IT) audit projects designed to provide assessment of internal control processes and operational performance, in accordance with department and professional standards
Participated in reviews of internal controls and security of systems under development as well as major IT projects and initiatives
Closure of risk identified in the processes by recommending various process improvement ideas and initiate projects for the same.
Work with the technology team for the implementation of various tools and techniques for process improvement and efficiency. Suggesting enhancement of the current tools for building in further efficiency in the system.
Perform Manual re-certifications of the user's access for the listed applications.
Assessing the risk and control for various clients and devising frameworks for effective risk management.
Application security assessment and mitigating the related vulnerabilities.
Setting up Compliance functions and devise parameters for compliance testing. Regulate monitoring basis internal and regulatory compliance.
Perform various other reviews of IT management policies and procedures such as change management, business continuity planning / disaster recovery and information security to ensure that controls surrounding these processes are adequate.
Handling overall risk operations involving risk assessment & internal / external rating and monitoring risk for various clients.
Tools/Applications used: Helios, Cyberport, Kulakeep, Jira, confluence, Kenna, Qlik Sense, Qlik View, EIM, SCOTT, BRETT, COMET, Service Now etc, Microsoft Share Point, PWC Connect.
Senior Software Engineer-Production L1 Support
HSBC Software Development (India) Pvt Ltd
02.2016 - 08.2019
Optimizing Daily Alerts on the Servers and Extensive Investigation of Issues.
Thorough knowledge of Scheduling tool like Control-M and investigating on the job sysouts.
Worked within a team, collaborate, and added value through participation in peer code reviews, by providing comments and suggestions, work with cross functional teams to achieve goals.
In Depth Knowledge of File transfer protocols such as FTP, SFTP.
Support applications for different business requirements in project.
Ability to prioritize and multi -task to meet deadlines.
Applying SQL Patches and Deploying SQL queries on Server.
Proactive incident reduction powered by data tools.
Preparing article in Confluence Knowledge Management Site for global knowledge share.
Monitoring global Geneos for applications.
On any failure of batch, take appropriate action.
Coordinating with Vendors/external systems for data related issues.
Creating Incidents using e-RTC tool on daily basis for tracking the day-to-day issues.
Supporting portfolios and websites for external customers used for fund prices, investment options and career information.
Responsible for fixing issues in case of websites down.
Raising Change Request with the help of GSD tool for deployment of any production changes.
Raising access request via GSR tool for a new business joiner or existing business user if any. (Drive access, software access, Application access, Hardware, Laptop configuration etc.)
Coordinating with ISR teams to implement the request and chasing them.
Follow standard Service Desk operating procedures; accurately log all Service Desk tickets using the defined tracking software.
Performing access related audit for a team via Cognos Tool.
Escalate issues and involve experts wherever required to resolve issues as quickly as possible.
(Client Name HSBC)
Education
M.Com -
B.com - undefined
Higher Secondary - undefined
Maharashtra
Secondary - undefined
Maharashtra
Skills
Governance risk management
Data Privacy
GDPR compliance expertise
Data transfer management
ISAE 3402 compliance audit
Capacity Management
Cyber Issues
Cryptography reviews
Data backup & Recovery
Disaster recovery planning
IT Service Management
Logging & Monitoring
Identity & Access Management
Stakeholder engagement
Management of privileged accounts
Certification
CSX Cybersecurity Fundamentals, ISACA
Certified Information Systems Auditor (CISA), Trained
Languages
English
Hindi
Marathi
Disclaimer
I consider myself familiar with information technology aspects. I am also confident about my ability to work in a team. I declare that the information furnished above is true to the best of my knowledge.
Storage & Data Protection Services at HSBC Software Development (India) Pvt. Ltd.Storage & Data Protection Services at HSBC Software Development (India) Pvt. Ltd.