Summary
Overview
Work History
Education
Skills
Websites
Certification
Timeline
Generic
Saravanan Swaminathan

Saravanan Swaminathan

Cyber Security Professional
CHENNAI,Tamil Nadu

Summary

Experienced professional with a proven track record in risk advisory, specializing in technology compliance and audit functions. Demonstrated expertise in conducting comprehensive compliance audits, leading design and operating effectiveness testing, and driving process improvement initiatives. Skilled in collaborating effectively with cross-functional teams to ensure alignment with regulatory requirements and business objectives. Holds esteemed certifications including CISA, GSNA, CISSP, CCSP, CISM, and PCI ISA, underscoring a deep understanding of industry standards and best practices. Proficient in navigating complex regulatory landscapes and designing robust security frameworks to mitigate risks effectively. Strong communicator with excellent interpersonal skills, dedicated to delivering impactful results in dynamic environments.

Overview

16
16
years of professional experience
8
8
years of post-secondary education
8
8
Certifications

Work History

Senior Manager GRC

ServiceNow
10.2023 - Current

Developed and implemented a comprehensive technology compliance strategy tailored for ServiceNow, ensuring alignment with regulatory frameworks such as PCI DSS, SOC2 and SOX.

Led a team responsible for assessing, monitoring, and reporting on compliance with regulatory requirements, maintaining a high standard of adherence across ServiceNow initiatives.

Collaborated closely with cross-functional teams including Legal, IT Security, and Risk Management to interpret and apply compliance requirements effectively within ServiceNow projects and operations.

Established and maintained effective relationships with external auditors and regulatory bodies, facilitating smooth audits and ensuring compliance validation.

Conducted regular audits and assessments of ServiceNow configurations, workflows, and data handling practices to identify and mitigate compliance risks.

Provided expert guidance to project teams and stakeholders on compliance-related matters, ensuring alignment with organizational goals and regulatory requirements.

Stayed informed about emerging compliance trends, technologies, and best practices within the ServiceNow ecosystem, integrating new insights to enhance compliance strategies and operational efficiency.

Manager - Risk & Compliance

PayPal India Private Limited
12.2020 - 10.2023

Oversaw and managed security portfolios, ensuring robust protection measures and adherence to PCI DSS compliance standards for PayPal and its subsidiaries.

Implemented and maintained rigorous technology controls to safeguard sensitive data and mitigate cyber threats across organizational systems and platforms.

Collaborated with cross-functional teams to develop and enforce security policies, procedures, and best practices, ensuring alignment with industry standards and regulatory requirements.

Led initiatives to enhance cybersecurity posture, conducting regular audits and assessments to identify vulnerabilities and implement proactive remediation measures.

Provided strategic guidance and technical expertise to stakeholders on security and compliance matters, fostering a culture of security awareness and accountability within the organization.

Played a key role in maintaining effective relationships with regulatory bodies and external auditors, facilitating successful audits and ensuring continuous compliance with industry regulations

Manager - Audit & Assurance

MKPSG
10.2017 - 12.2020
  • In my role at MKPSG, I undertook diverse responsibilities that aligned with the organization's mission: Conducted successful compliance audits for technology and financial service firms, evaluating adherence to standards like PCI DSS, SSAE 18, and SOX
  • Offered strategic insights to bolster security measures
  • Led comprehensive technology risk assessments for multiple tech companies, aligning their security practices with industry frameworks to assess security and risk landscapes
  • Played a key role in evaluating information security controls and related process to uplift various compliance programs as per rapidly changing risk landscape
  • Innovatively sought automation opportunities, streamlining processes in line with security best practices
  • Conducted training sessions on security awareness, controls lifecycle management, and tech compliance audits, fostering a security-conscious culture
  • Specialized in PKI audits, meticulously evaluating root and certifying authorities' compliance with local regulations and standards
  • Exhibited adaptability through involvement in special projects, thriving in a dynamic environment and driving positive contributions amid change
  • Overall, my tenure at MKPSG centered on ensuring compliance, bolstering security practices, and executing effective risk assessments.

GRC Consultant

Secure Logic PTY
04.2017 - 10.2017
  • In my role as a GRC Consultant at Secure Logic, I've taken a proactive stance in leading and executing various compliance-related engagements
  • Some of my key contributions include: Assuming a central role in scoping, designing, implementing, and executing technology compliance audits
  • This has encompassed the orchestration of audit test work and ensuring that the resulting audit documentation is not only comprehensive but also aligned with established methodologies
  • Conducting thorough technology compliance Gap Analysis for significant compliance frameworks such as SOC, and PCI DSS
  • My involvement has extended to collaborating closely with organizations to aid them in achieving compliant status, proactively addressing any existing gaps
  • Engaging in Internal Audits, which necessitates a comprehensive assessment of organizations against their internal information security risk policies, procedures, as well as industry benchmarks
  • Maintaining an unwavering focus on compliance and controls, with continuous monitoring at the core of my responsibilities
  • This vigilance has been instrumental in promptly identifying any potential drift or emerging changes within the dynamic technology risk landscape
  • Throughout my tenure at Secure Logic, I've been entrusted with multifaceted responsibilities that span scoping, design, implementation, and continuous monitoring of technology compliance initiatives.

Consultant - Technology Compliance Audit

MKPSG
06.2014 - 03.2017
  • Conducting in-depth Gap Analyses for significant compliance frameworks such as SOX, SOC, and PCI DSS
  • Collaborating closely with organizations to guide them towards compliance, addressing gaps proactively
  • Engaging in thorough Internal Audits, assessing organizations against internal risk policies, procedures, and industry benchmarks
  • Maintaining a vigilant focus on compliance and controls, with continuous monitoring as a cornerstone
  • Swiftly identifying potential deviations or emerging changes within the dynamic tech risk landscape
  • Providing crucial support in implementing measures aligned with regulatory frameworks like PCI DSS, SOC, and SOX
  • Guiding organizations through the intricate process of achieving compliance with these robust standards
  • Throughout my role at MKPSG, I've demonstrated a commitment to comprehensive compliance management.

Audit Manager

Nelson & Jegannathan
05.2008 - 05.2014
  • As an Audit Manager at Nelson & Jegannathan, I've undertaken a comprehensive range of responsibilities to fortify compliance within the Information Security Program
  • Key highlights of my contributions include: Supervising diverse internal audits within the Information Security Program, ensuring adherence to internal security policies and relevant regulations
  • Spearheading the development and execution of compliance monitoring and enhancement activities, proactively aligning with internal policies and external regulations
  • Leading the planning and execution of control design and operating effectiveness testing
  • Ensuring meticulous documentation and clear communication of test outcomes
  • Defining tactical steps, addressing control criteria, and rigorously testing control operating effectiveness
  • Maintaining a precise system and control inventory, including identifying supporting roles, crucial for effective compliance management
  • Actively contributing to enhancing internal controls through analytics and automation, fostering adaptive controls in response to evolving risk landscapes
  • Throughout my tenure as Audit Manager, I've showcased a resolute commitment to compliance, robust internal controls, and continuous improvement.

Education

CA INTERMEDIATE -

ICAI - The Institute of Chartered Accountants of India
05.2006 - 05.2011

Bachelor of Commerce - undefined

DG VAISHNAV COLLEGE
05.2005 - 05.2008

Skills

Effective Communication and Leadership

Product Security

Control Testing & Automation

Regulatory & Exam Management

Compliance Assessment

Technology Risk & Compliance

Effective Communication and Leadership

Certification

ISACA: Certified Information Systems Auditor (CISA)

Timeline

Senior Manager GRC

ServiceNow
10.2023 - Current

Manager - Risk & Compliance

PayPal India Private Limited
12.2020 - 10.2023

Manager - Audit & Assurance

MKPSG
10.2017 - 12.2020

GRC Consultant

Secure Logic PTY
04.2017 - 10.2017

Consultant - Technology Compliance Audit

MKPSG
06.2014 - 03.2017

Audit Manager

Nelson & Jegannathan
05.2008 - 05.2014

CA INTERMEDIATE -

ICAI - The Institute of Chartered Accountants of India
05.2006 - 05.2011

Bachelor of Commerce - undefined

DG VAISHNAV COLLEGE
05.2005 - 05.2008
Saravanan SwaminathanCyber Security Professional