Summary
Overview
Work History
Education
Skills
Personal Information
Certification
ACHIEVEMENTS
Languages
Timeline
Generic

SANCHI MEHTA

Summary

A dedicated Cybersecurity and IT Governance Professional with extensive experience in risk assessment, regulatory compliance, and governance frameworks. Proven expertise in ISO 27001 implementation, CERT-In policy reviews, IT GRC, and third-party risk management. Strong analytical and leadership capabilities with the ability to strengthen security controls and conduct maturity assessments.

Overview

1
1
Language
1
1
Certification
10
10
years of professional experience

Work History

Assistant Manager

KPMG INDIA
04.2024 - Current
  • Lead cybersecurity governance, risk, and compliance (GRC) engagements, ensuring alignment of cybersecurity programs with business objectives, regulatory requirements, and organizational risk appetite.
  • Conduct risk assessments, cybersecurity maturity assessments, and governance reviews to identify vulnerabilities, control gaps, and enterprise cybersecurity risks across business processes, applications, cloud environments, and technology functions.
  • Develop, review, and implement information security policies, standards, procedures, and governance frameworks in line with industry best practices and regulatory expectations.
  • Support clients in establishing and enhancing Information Security Management Systems (ISMS) aligned with ISO/IEC 27001:2022, including risk assessments, Statement of Applicability, control implementation, and readiness assessments.
  • Conduct compliance and gap assessments against frameworks and regulations such as ISO 27001, NIST Cybersecurity Framework (CSF), CERT-In guidelines, PCI-DSS, GDPR, PDPP Act, and other applicable security and privacy requirements.
  • Perform policy and process reviews against CERT-In directions and regulatory standards, identifying compliance gaps and recommending remediation measures.
  • Develop and deliver cybersecurity awareness and training programs to promote a strong security culture across client organizations.
  • Work closely with client technology, security, and business teams to develop incident response processes, cyber crisis management procedures, and support tabletop exercises to validate response readiness.
  • Evaluate third-party and vendor security posture through due diligence assessments, review of security certifications, control validation, and risk analysis.
  • Track, monitor, and report cybersecurity risks, observations, remediation plans, and exceptions through governance forums, dashboards, and senior management reporting.
  • Provide advisory support to internal and client stakeholders on cybersecurity governance, risk management, compliance requirements, and emerging topics including AI governance aligned to ISO/IEC 42001:2023.
  • Support and independently lead project work, client deliverables, workshops, assessments, and retainer engagements while managing stakeholder communication and project timelines.
  • Contribute to business development activities including proposal preparation, engagement letters, scope definition, effort estimation, and client presentations.

Consultant

ERNST & YOUNG (EY INDIA)
06.2022 - 03.2024
  • Conducting Third Party Risk Management process for a global company client where key responsibilities included assessing vendor policy and procedure documents for information security, asset management, data privacy, application security and antivirus protection; assessing vendor applications against ISO 27001:2022 standards and providing recommendations.
  • Conduct Inherent Risk Assessment (IRA) and Information Security Risk Assessment (ISR) on suppliers who have access to data or assets.
  • Prepare and present TPRM information security assessment reports.
  • Conducted gap analysis and data mapping with privacy regulations, providing remediation solutions to enhance compliance.
  • Conduct interviews with the client to ascertain the current state of compliance in line with in-scope applicable regulations.
  • Conduct data privacy impact assessments and develop policies/procedures such as data protection policy, data subject rights, supplier relationship, privacy by design, breach notification, etc.,
  • Analyzed risks and issues, proposing mitigating plans to safeguard information against unauthorized access or disclosure.
  • Review and improve governance, risk and compliance framework for one of the largest product-based companies, including review of network and data security controls and access management including user access reviews.
  • Support in conducting control testing of ISMAP and European Cloud Code of Conduct along with gap analysis and providing remediation of identified gaps.

Senior Associate Attorney

INTEGREON
09.2019 - 06.2022
  • Assisted Project Manager with data privacy gap assessment, developing data privacy framework, policies, and procedures in compliance with applicable laws, including GDPR, HIPAA, PIPEDA, and CCPA.
  • Analyze complex legal documents including emails, contracts, spreadsheets and other financial documents.
  • Perform risk assessments and determine prevention and mitigation measures to reduce risks to an acceptable level.
  • Analyzed complex legal documents, including emails, contracts, spreadsheets, and financial documents to support litigation and compliance efforts.
  • Code documents as per project requirements and ensure client review instructions are followed by the review team.
  • Performed quality control on reviewers' work, ensuring adherence to client specifications and maintaining high standards for deliverables.
  • Shared and drafted daily status reports to communicate project progress to stakeholders. including query logs and example documents to get document coding confirmed.
  • Work in tandem with project managers to support completion of active client projects.

Company Secretary Trainee

NEERAJ GUPTA & ASSOCIATES
07.2016 - 10.2017
  • Company law requirements such as conversion of a public company into a private company.
  • Drafted legal documents and petitions to support corporate governance and regulatory compliance.
  • Conduct secretarial audits of various companies.
  • Liaised with department officials to facilitate incorporation of companies and ensure adherence to statutory compliance.
  • Draft legal documents and petitions.
  • Facilitated communication with department officials to ensure smooth incorporation of companies and adherence to statutory compliance requirements.

Education

LLM - Corporate Law

School of Law and Legal Studies, GGSIPU
Delhi

LLB -

Lloyd Law College, CCSU
Greater Noida

ICSI - Foundation and Executive Programme (Semi-Qualified Company Secretary)

B.Com Programme -

University of Delhi

Skills

  • ISO 27001:2022 gap assessment and implementation Third-Party Risk Assessment Cybersecurity Risk Assessment IT GRC Cybersecurity Audit CERT-In Policy & Process Review
  • Cybersecurity GRC
  • ISO 27001
  • Risk assessment
  • ServiceNow Jira MS Office Relativity Canopy

Personal Information

Title: ASSISTANT MANAGER | CYBERSECURITY & IT GOVERNANCE

Certification

ISO 42001:2023 Lead Auditor – Artificial Intelligence Management Systems, ISO 27001 Lead Implementor – Information Security Management Systems

ACHIEVEMENTS

Title: ASSISTANT MANAGER | CYBERSECURITY & IT GOVERNANCE

Languages

English, Hindi
First Language

Timeline

Assistant Manager

KPMG INDIA
04.2024 - Current

Consultant

ERNST & YOUNG (EY INDIA)
06.2022 - 03.2024

Senior Associate Attorney

INTEGREON
09.2019 - 06.2022

Company Secretary Trainee

NEERAJ GUPTA & ASSOCIATES
07.2016 - 10.2017

LLM - Corporate Law

School of Law and Legal Studies, GGSIPU

LLB -

Lloyd Law College, CCSU

ICSI - Foundation and Executive Programme (Semi-Qualified Company Secretary)

B.Com Programme -

University of Delhi
SANCHI MEHTA