Summary
Overview
Work History
Education
Skills
Certification
Work & Exploration (Recognition, Innovation & Ongoing Pursuits)
Professional Engagement: Active ISACA Delhi Chapter Member
Courses & Training:
EARLY VENTURES
Timeline
Generic

SANDEEP KUMAR

https://www.linkedin.com/in/sandeep-kumar-0742ba21/

Summary

Strategic Cybersecurity GRC, Risk & Architecture Lead (CRISC, CISM, ISO 27001 LA, CEH, CCNA Security, RHCE) with extensive experience delivering enterprise security, GRC, risk, and architecture initiatives across On-Prem to Cloud transformation environments.

Expertise in Enterprise Security Architecture (ESA) Operating Models, Zero Trust, Threat Modeling, risk-based controls, security governance, and target-state architecture, aligned with NIST 800-53, NIST CSF, CIS, and ISO 27001. Strong knowledge of PCI DSS, HIPAA, SOC 1/2, SOX, GLBA, and GDPR, with proven experience in control assurance, risk treatment, exceptions, and audit readiness.

Seeking opportunities to lead cybersecurity programs end-to-end—from strategy, risk assessment and architecture through implementation, governance, and operational transition—delivering measurable and resilient security outcomes.

Overview

1
1
Certification
16
16
years of professional experience

Work History

Security Managed Services Associate Manager – Cybersecurity GRC & IT Risk

ACCENTURE
09.2023 - Current

HIGHLIGHTS

  • Built and operationalized the Enterprise Security Architecture (ESA) operating model: Defining target-state security architecture, governance, RACI, capability-to-component mappings, reference architectures, secure design standards, and architectural guardrails across AWS, Azure, SaaS, containerized, and hybrid environments to enable scalable security-by-design and repeatable control coverage.
  • Led architecture risk assessments, threat modeling, and secure design reviews: For cloud and enterprise platforms, aligning security controls with NIST CSF, NIST SP 800-53, ISO 27001, CIS, SOC 2, and PCI DSS while driving risk-based remediation, exception governance, Zero Trust architecture, identity, encryption, and data protection standards across business-critical environments.
  • Enabled secure cloud transformation and audit-ready delivery across Healthcare, FMCG and Financial programs Partnered with delivery and architecture teams on on-prem to cloud migrations — bringing AI-assisted STRIDE and PASTA threat modeling into PoC and target-state evaluations, and closing out residual risks, exceptions, and regulatory embedding to land clean, audit-ready handovers. (Healthcare & FMCG)

Key Deliverables:

  • Led AWS Security Data & Anaytics (DnA) Governance Operations for a major healthcare client, driving access governance, compliance coordination, stakeholder engagement, and operational process optimization across shared services teams.
  • Designed and operationalized the Enterprise Security Architecture (ESA) Operating Model, establishing governance structures, RACI ownership, and engagement frameworks across Security, Enterprise Architecture, GRC, and Operations.
  • Conducted enterprise and application security architecture reviews across on-premises and AWS cloud platforms, identifying design gaps, control deficiencies, and security risks while recommending secure-by-design improvements.
  • Led and performed complex cyber and technology risk assessments aligned with NIST 800-53, NIST CSF, CIS Controls, ISO 27001, and organizational policies to evaluate control effectiveness and regulatory compliance.
  • Partnered with architecture and engineering teams to embed secure-by-design principles into cloud migration and modernization initiatives, strengthening governance across hybrid cloud environments.
  • Ensured security architecture alignment with enterprise standards, regulatory requirements, and risk management frameworks .
  • Led security risk reviews during platform transitions, transformation initiatives, and SOC operating model changes, identifying risks and defining mitigation plans across vulnerability management, incident response, endpoint, network, and data security domains.
  • Managed go-live security readiness assessments, validating security controls, documenting residual risks, and obtaining governance approvals before production deployment and operational handover.
  • Governed residual risks and security exceptions, enabling leadership to make informed risk acceptance, mitigation, and remediation decisions across enterprise and cloud initiatives.

Manager -Tech. Risk Oversight

Fidelity International
12.2022 - 09.2023
  • Delivered enterprise technology risk assessments, thematic risk reviews, and executive risk reporting, identifying emerging trends, concentration risks, and systemic control issues to support senior leadership decision-making.
  • Assessed and challenged technology incidents and operational risk events through root cause analysis, validating issue credibility and driving corrective and preventive actions to reduce recurrence.
  • Reviewed and enhanced the technology control environment by identifying opportunities to strengthen preventive, detective, and monitoring controls, improving overall risk visibility and control effectiveness.
  • Monitored & reported technology risk KPIs, KRIs, and external risk indicators, providing early warning of operational and cyber risk exposures and enabling proactive risk oversight.
  • Facilitated & Communicated risk governance and issue management by tracking remediation plans, validating control improvements, and providing regular updates on risk posture, audit findings, and regulatory commitments.
  • Partnered with engineering, security, and business stakeholders to evaluate technology risks across application, infrastructure, and cloud initiatives, ensuring alignment with enterprise risk appetite and governance standards.

Consultant | Finance Project Risk Assurance, Compliance & Governance

HCL Technologies
01.2018 - 12.2022
  • Supported Risk Assurance and Compliance functions technologically end-to-end — ensuring adherence to governance, reporting, and regulatory review obligations across enterprise engagements.
  • Managed ITGC controls and activities, ensuring the business operated within the agreed risk appetite through close collaboration with stakeholders across POCs, implementation, compliance, privacy, and pre-sales.
  • Delivered system hardening reviews and security posture assessments on 3,000+ servers (Unix, Windows, DB, VMs) against MAS, NIST SP 800-53, and ISO 27001 baselines.
  • Acted as backup to the Compliance Officer, leading vendor risk planning, issue escalation, and resolution with business, security, privacy, legal, and IT teams to embed a risk-based approach.
  • Performed cybersecurity risk assessments (technology + third-party) using NIST 800-53, NIST CSF, and CIS, evaluating controls across customer environments and vendors to protect business information and assets.
  • Applied hands-on expertise in vulnerability management, endpoint security, data privacy, and classification to strengthen the enterprise control environment.
  • Built and delivered executive-grade dashboards and reports — communicating program state, framework adherence, and gap closure to a wide audience of technical and business stakeholders.
  • Participated in daily client incident management huddles, staying aligned on weekly issues, upcoming projects, change requests, and the evolving security posture of the organization.

Associate Consultant | Information Security, Audits & ISMS Governance

TATA Consultancy Services, India
06.2015 - 01.2018
  • Delivered end-to-end information security services — including security audits, risk assessments, gap analyses, corrective action plans, and policy/procedure development — aligned to ISO 27001:2013 and ISO 31000 risk frameworks.
  • Represented the organization in ISMS audits (ISO 27001:2013), ensuring enterprise-wide compliance and continuous improvement of governance, risk, and control effectiveness.
  • Contributed to ISMS initiatives focused on strengthening service delivery, operational effectiveness, and customer experience.
  • Risk Assessments, VA/PT & Compliance Assurance
  • Performed vulnerability assessments and penetration testing (VA/PT) on business-critical applications and servers, driving remediation of high-risk exposures.
  • Conducted internal assessments, control reviews, and compliance validation against PCI-DSS and HIPAA, ensuring sustained regulatory alignment.
  • Facilitated incident response activities, coordinating across teams to contain, investigate, and close security events.
  • SOC Build, Security Operations & Client Leadership
  • Led end-to-end SOC build and implementation (domestic and global) covering SIEM platform deployment, use-case development, and best practice onboarding to ensure operational readiness and successful delivery.
  • Acted as a client-facing point of contact, addressing queries on security policies, procedures, and operational controls with clarity and confidence.

Specialist

HCL Technologies , India
03.2011 - 05.2015
  • Operated and administered SIEM platforms (ArcSight / Net Forensics) by tuning correlation rules, creating custom use cases, and monitoring security events to improve proactive threat detection and reduce false positives.
  • Performed continuous SOC monitoring and incident triage, investigating security alerts across SIEM, DLP, firewall, proxy, and endpoint security tools, and escalating high-severity incidents in line with defined SLAs.
  • Executed vulnerability assessments and coordinated patch remediation with infrastructure and application teams, tracking closure of identified security gaps and improving overall vulnerability compliance.
  • Monitored and optimized Data Loss Prevention (DLP) controls using Websense, analyzing policy violations, reducing false positives, and supporting data protection requirements across enterprise environments.
  • Managed web security and URL filtering through Websense and Palo Alto, implementing policy updates and access controls while balancing business requirements with security standards.
  • Administered Cisco ASA / FWSM firewalls and Cisco ACS authentication services, performing firewall rule reviews, access provisioning, VPN support, and periodic security policy housekeeping.
  • Owned end-to-end change management for security infrastructure, conducting impact assessments, coordinating testing, validating rollback plans, and implementing approved security changes through ITIL processes.
  • Delivered shared security services support by collaborating with Network, Server, Endpoint, Identity, and Application teams to resolve security requests, onboard new services, and maintain operational governance across multiple business units.
  • Provided Cisco TAC technical support to enterprise customers across the US and Canada, troubleshooting network and security incidents, performing root cause analysis, and restoring services within contractual SLA commitments.

Education

Master of Computer Applications (MCA) -

Punjab Technical University

Post Graduate Diploma - Computer Application “A Level”

NIELIT (formerly DOEACC)

Diploma - Computer Application “O level”

NIELIT (formerly DOEACC)

BSc -

Mumbai University

Skills

  • IT & Technology Risk Management
  • Enterprise Security Architecture & Secure-by-Design Governance
  • AI & Emerging Technology Risk Oversight
  • Regulatory Compliance & Advisory (SOX, PCI DSS, HIPAA, GDPR, ISO 27001)
  • NIST 800-53 / NIST CSF / CIS Control Frameworks
  • Enterprise & Third-Party Risk Assessment & Zero Trust Security
  • Cybersecurity Maturity & Resilience Frameworks
  • Risk Scoring & Visualization
  • Control Assurance, Risk Treatment & Exception Management

Certification

CISM | CRISC | CEH | ISO 27001 LA | CCNA | CCNA Security | RHCE | Pursuing CISSP | CLAUDE Fundamentals

Work & Exploration (Recognition, Innovation & Ongoing Pursuits)

  • GRC Innovation : Built a GenAI-powered Cyber GRC solution with reusable frameworks, playbooks and risk assets adopted across teams.
  • AI & Emerging Tech : Advancing in AI Risk, Agentic AI, GenAI Risk & AI-TRiSM through risk visualization, scoring and governance concepts.
  • Security Architecture : Built Capability-to-Component models enabling Zero Trust coverage, architecture reviews and enterprise/cloud gap analysis.
  • Risk & Compliance : Embedded NIST CSF, CIS & regulatory controls into transformation plans, strengthening audit readiness and control effectiveness.
  • Business Impact : Supported governance and process improvements contributing to a USD 300M healthcare portfolio.
  • Leadership Mentored consultants/architects and led knowledge-sharing initiatives; SPOT Award for / Best Team – Risk Workshop recognition.

Professional Engagement: Active ISACA Delhi Chapter Member

Contributed to professional cybersecurity networks and supported the “Cyber Safe” community initiative.

Courses & Training:

LinkedIn Learning | Coursera | Udemy (AI & Cybersecurity) | ISACA CISM and CRISC | ISC2 CISSP Prep | Advanced Training in AI Governance Frameworks.

EARLY VENTURES

  • Technical Support Officer at | HCL Technologies BPO Services, British Telecom, Noida, India
  • Computer Technical Lab Assistance at Amity University | Lucknow
  • Faculty at UPTEC Computer Consultancy Lucknow

Timeline

Security Managed Services Associate Manager – Cybersecurity GRC & IT Risk

ACCENTURE
09.2023 - Current

Manager -Tech. Risk Oversight

Fidelity International
12.2022 - 09.2023

Consultant | Finance Project Risk Assurance, Compliance & Governance

HCL Technologies
01.2018 - 12.2022

Associate Consultant | Information Security, Audits & ISMS Governance

TATA Consultancy Services, India
06.2015 - 01.2018

Specialist

HCL Technologies , India
03.2011 - 05.2015

Master of Computer Applications (MCA) -

Punjab Technical University

Post Graduate Diploma - Computer Application “A Level”

NIELIT (formerly DOEACC)

Diploma - Computer Application “O level”

NIELIT (formerly DOEACC)

BSc -

Mumbai University
SANDEEP KUMAR