Summary
Overview
Work History
Education
Skills
Accomplishments
Certification
Music, Travel
Languages
Tools
Timeline
Generic

Sanjay Palle

Summary

Knowledgeable Risk Manager equipped with strategic planning and program leadership abilities honed in IT industry environments. Establishes strong and successful policies to mitigate risk at each level and establish clear procedures for assessments, prevention and containment. Led clients through successful IT External Audits, ensuring all requirements were met within compliance frameworks. Ensuring compliance and efficiency are met as per client requirements.

Overview

9
9
years of professional experience
1
1
Certification

Work History

Manager, Risk Management

Deloitte
03.2019 - Current

- Conducting Internal ISO 27001 Audits and Handling External Audits for the Organizations and projects.

- Managing external client IT audit engagements at Deloitte, ensuring client needs are met throughout the process.

- Identifying Potential Risks: Threats, vulnerabilities and risks that the system might encounter. Natural occurrences such as calamities or power outages should be taken into consideration in addition to malware attacks.

- Perform vendor risk assessments (includes AWS, Azure, GCP), addressing security questionnaires, assessing the adequacy of policies, procedures, processes, and compliance and operational controls in a significantly large and complex organization.

- Implementation of ISO 27001.

- Effortlessly adheres to Information Security Practices under ISO27001 framework and identify risks and executing Business Continuity Plans to avoid Business Disaster.

- Demonstrated abilities in conducting Information Security Audits, Security Planning and Management for streamlining Information Security Operations.

- Mapping Risk assessments reports to Confidentially, Integrity and Availability, NIST frameworks ISO27001-ISMS standards and controls.

- Review SOC reports, penetration test reports, BitSight reports, ISAE reports

- Responsible for Security Awareness

- Responsible for answering client questionnaires

Senior Operations Professional

IBM
04.2015 - 03.2019

- Led clients through successful IT External Audits, ensuring all requirements were met on time.
- Guided clients in preparing for IT External Audits, helping them achieve timely completion within compliance frameworks.

- Contributed to the development of well-organized and easy-to-understand IT External Audit reports for clients.
- Drafted clear and concise IT External Audit reports, effectively communicating findings to stakeholders.

- Global process lead for Patch Management, Vulnerability Assessment

- Defining Policies and Ensuring relevant process/procedures are adopted by the teams.

- Ensuring corporate & program risk registers up to date with accurate information.

Education

MBA - Operations Management

Sikkim Manipal University
Gangtok, India
06.2017

Bachelor of Engineering Technology - Computer Engineering Technology

Aurora - JNTU
Hyderabad, India
04.2011

Skills

  • Operational risk management
  • Enterprise risk management
  • Innovation and Creativity
  • Audit Coordination
  • Compliance Monitoring
  • IT risk management
  • Information Security
  • Risk advisory
  • Customer Service
  • Team Building Leadership

Accomplishments

    - Developed a game with the help of developers for a security awareness event at Deloitte where I was successful in spreading security awareness across the firm.

    - Possess extensive experience in navigating audits successfully.
    - Proven ability to prepare for and excel in IT audits.

    - Conducted various sessions within the firm on Risk Management, Patch & Vulnerability Management, Penetration test reports, SOC reports which led me as a trainer.

    - Designed the process metrics for the new process (In Security Patching, Vulnerability Management) according to client needs.

    - Received numerous appreciations from clients and the customers from different locations.

    - Transitioned many new projects to India.

    - Recovering delinquent accounts

Certification

- CISA

- SANS (Managing Human Risk)

- ISO 27001 Lead Auditor (2013)

- Qualys Guard (VM & PC)

- CCSK (perusing)

Music, Travel

I would love to travel to different places, explore their traditions, culture, food. Music is a powerful tool for relaxation and stress relief which I strongly believe.

Languages

English
Bilingual or Proficient (C2)
Telugu
Advanced (C1)
Hindi
Intermediate (B1)

Tools

- Archer (RSA)

- TPRM (Aravo)

- ServiceNow

- IEM BigFix

- Qualys Guard

- QRadar

Timeline

Manager, Risk Management

Deloitte
03.2019 - Current

Senior Operations Professional

IBM
04.2015 - 03.2019

MBA - Operations Management

Sikkim Manipal University

Bachelor of Engineering Technology - Computer Engineering Technology

Aurora - JNTU
Sanjay Palle