Summary
Overview
Work History
Education
Skills
Certification
Affiliations
Accomplishments
Date
Timeline
Generic

Saurabh Saroha

Ghaziabad

Summary

Capable professional offering around 13 years of experience, mainly into information security, Governance, operational compliance and internal audits with a flavor of software development and testing. Creative and dynamic individual with experience of internal audits, implementation and sustainability of different standards & compliance requirements. Someone who leverages effective communication and in-person meetings to establish presence and build a positive rapport while fostering continuous client engagement. Adept at working effectively to achieve goals both as a cross-functional team member and individual contributor.

Overview

13
13
years of professional experience
1
1
Certification

Work History

Senior Manager - Information Security

Teleperformance
Noida
01.2022 - Current

Currently leading a small team within corporate information security function of Teleperformance India which involves regular interaction with business operations, clients, vendors and global counterparts. The Key responsibilities of this role include:

  • Managing information exception approvals as per global policy
  • Driving annual review and updates of information security and IT policy & process documents as per ISO 27001 and global policy
  • Running vendor risk assessment program for Teleperformance India
  • Leading software compliance initiative for TP India
  • Preparing and publishing key risk management reports including IT risk register and ensuring closures
  • Preparing CIO dashboard and business CXO decks on monthly basis

Senior Manager - Compliance

EXL services
Noida
06.2018 - 01.2022

Worked as key resource in compliance team of Corporate InfoSec function at EXL, responsible for managing InfoSec and technology aspects of all internal as well as external audits and representing EXL in all those audits. Also, acting as the governance SPOC & program manager of few external audit engagements to ensure timely completion of audit program.

  • Program management of PCIDSS & ISO 27001 certification covering all major delivery centers
  • Driving central governance program for InfoSec and Tech for improvements & compliance
  • Managing multiple SOC audit engagements with Big-4
  • Managing internal audit tracks as per the audit calendar
  • Contractual reviews and advising teams like data privacy & business continuity for compliance
  • Tracking and ensuring closure of all reported observations in internal / external audits
  • Driving pre-audit readiness exercise before any internal / external audit
  • Managing budgeting & vendor management aspects of external audit program
  • Actively collaborating with tech / InfoSec sub-teams and enabling teams for timely completion of audi

Assistant Manager - Compliance

Genpact
Noida
11.2015 - 05.2018

Served as a key member of the corporate compliance team charged with formulating strategic direction and devising compliance initiatives consistent with overall vertical strategy.

  • Leading and managing initiative of email restriction policy through DLP right from implementation, awareness and sustenance
  • Representing Genpact in multiple client audits/vendor assessments
  • Working on following up and ensuring remediation of audit observations
  • Helping business in responding to RFI questionnaire by drafting/collating responses
  • Driving internal assessments for prioritized accounts; MSA with client and internal compliance control checklist being the criteria
  • Managing end to end incident cycle for all incidents reported by DLP team for our vertical
  • Leading remediation & reporting of endpoint compliance issues monthly
  • Collaborating with multiple cross-functional teams for audit activities

Consultant

Financial Technologies India Ltd.
Mumbai
11.2014 - 10.2015

Financial Technologies group offers technology solutions to trade on next-generation financial markets, across asset classes including equities, commodities, currencies and bonds. I worked for ESG (Enterprise Solutions Group) which is a part of FTIL corporate structure and provides Information security risk consulting & audit services. My responsibilities at FTIL were:

  • Conducting both sets of internal audits (ISO 27001, 9001, 14001 combined and ISO 20000) for more than 20 departments as per organization policy
  • Reviews, updates and maintenance of all policy, procedure and other documentation
  • All arrangements related to external audits of ISMS, ITSM, QMS & EMS
  • Coordinating with all departments & ensuring closure of all internal & external audit findings
  • Resolving all issues/queries related to ISMS, ITSM, QMS & EMS for all FTIL departments
  • Training and awareness of ISMS, ITSM, QMS & EMS
  • Attending CAB meetings and providing inputs for major changes
  • Providing inputs while in-house development of tools like Change master & asset master
  • Consulting assignment of ISMS audits for one of the leading Legal Process Outsourcing firm

Associate Consultant

Fluxonix Security Solutions & Mitkat Advisory Services
Mumbai
12.2013 - 10.2014

Both Fluxonix and MitKat Advisory are couple of startups in consulting space providing Information security & risk consulting services. Immediately after graduating from PGDBM from Symbiosis, I joined Fluxonix Security Solutions followed by Mitkat services few months later, worked with both for brief periods as intern. My responsibilities at both firms are listed henceforth:

  • Worked with top stock exchange of India, part of team who did ISMS/BCMS implementation, network & application VA scans and internal review
  • Did an assignment of ISMS transition for India's leading payment card service provider
  • Worked on a systems audit and cleanup project for an IT product and services client and also provided recommendations for preventive controls

Software Engineer

Accenture
Hyderabad
04.2011 - 05.2013

Worked for mainly 2 clients, one was Top US OS developer and another was South African banking and insurance firm. My role and responsibilities there were:

  • Understanding the business need of application which was partly on cloud
  • Gathering, understanding and reviewing the requirements
  • Performing test planning activities
  • Designing and creating test artifacts
  • Logging and reporting the defects, representing the team in triage and other meetings
  • Assisting UAT (user acceptance test) team from client side and resolving their queries

Education

Post Graduate Diploma in Management - Information Security And IT Business Management

Symbiosis Center For Information Technology
Pune, India
05-2014

Bachelors of Engineering - Electronics And Communication Engineering

Maharshi Dayanand University
Haryana, India
05-2010

Skills

  • ISO 27001 audit and implementation
  • SSAE18 / PCIDSS audit
  • Policy & process management
  • Governance & compliance
  • MSA review
  • Client RFI responses
  • Audit representation
  • Vendor risk assessments
  • Exception Approvals
  • Software Compliance
  • Endpoint compliance
  • CXO dashboard
  • End user awareness
  • Incident Management
  • Data Privacy

Certification

  • ISO 27001 2013 lead auditor by BSI
    Cloud Security Alliance STAR Certification - Lead Auditor by BSI
    ITIL V3 Foundation

Affiliations

  • Was among top 14% (86 percentile) all over India in 6th IT Aptitude Test by NIIT in 2010.
    Secured 87 percentile in pH test conducted by eLitmus Evaluation Private Limited in 2011

Accomplishments

  • Awarded top performer of the quarter (Q2'23) in Information Security Team at Teleperformance
  • Awarded Top Performer thrice at EXL in annual awards

Date

11-Aug-2024                                                                                                    Saurabh Saroha

Timeline

Senior Manager - Information Security

Teleperformance
01.2022 - Current

Senior Manager - Compliance

EXL services
06.2018 - 01.2022

Assistant Manager - Compliance

Genpact
11.2015 - 05.2018

Consultant

Financial Technologies India Ltd.
11.2014 - 10.2015

Associate Consultant

Fluxonix Security Solutions & Mitkat Advisory Services
12.2013 - 10.2014

Software Engineer

Accenture
04.2011 - 05.2013

Post Graduate Diploma in Management - Information Security And IT Business Management

Symbiosis Center For Information Technology

Bachelors of Engineering - Electronics And Communication Engineering

Maharshi Dayanand University
Saurabh Saroha