Experienced information security professional with a strong background in risk assessment, privacy impact analysis, and IT security automation. Skilled in conducting internal audits, developing process documents, and evaluating supplier assurance processes. Proven track record in providing consultancy for compliance with data security and privacy frameworks, performing spot checks, and managing audit findings. Adept at interpreting technical findings for non-technical audiences and creating comprehensive reports. Successfully cleared ISO audits with no observations.
Overview
1824
1824
years of professional experience
5
5
years of post-secondary education
2
2
Certifications
Work History
Senior Consultant
PricewaterhouseCoopers, PWC
Bangalore
01.202 - Current
Risk Assessments:
Conducted thorough reviews and evaluations of organizational risks for compliance and acceptance.
Monitored findings and risk assessments, followed up with business units on action plans.
Developed process documents for new procedures.
Assessed RFPs/POCs for new assets.
Provided IT security consultations for newly onboarded applications.
Established and monitored controls based on associated risks.
Privacy Impact Assessment and Compliance:
Performed Privacy Impact Assessments in line with GDPR compliance.
Managed RFP/RFI processes from an Information Security perspective.
Conducted internal audits with various departments at Shell.
Automated IT Information Security processes.
Assessed supplier assurance processes and validated vendor-owned controls.
Reviewed assurance reports, including SOC II Type II reports.
Consultancy and Compliance:
Evaluated Information Security posture for specific projects and provided consultancy for compliance with Shell's Data Security & Privacy framework.
Reviewed and analyzed Master Service Agreements/Contracts, Statements of Work, Inter-Departmental Documents of Understanding, and third-party agreements to evaluate client security requirements.
Developed security plans and operating procedure documents for individual projects to ensure compliance with Data Security & Privacy framework.
Recorded data security risks for projects and advised project managers on appropriate mitigating controls.
Reviewed access control lists and separation of duties records, suggested appropriate mitigating controls for conflicting roles.
Audits and Reporting:
Performed spot checks/audits and reported findings to senior management.
Ensured timely closure of open audit findings by reporting and escalating issues to project managers and executives.
Interpreted technical security findings for non-technical audiences and provided coaching to mitigate findings.
Developed comprehensive reports to track audit status, open findings, escalations, and data analysis.
Successfully cleared ISO, SOX audits, and Key Control over Operations assessments without any observations.
Risk Advisor (Worked With PWC)
US Software Groups
Bangalore
02.2022 - 01.2023
Company Overview: Contracted with PwC and acting as a consultant for Shell Information security & Risk management
Performed the assessment on the application security, which involves in Access, authentication, data storage, data transmission
Proactively review information security and related risks, threats, and vulnerabilities, legal and regulatory
Proven ability to engage with business partners, establish effective working relationships, and deliver results
Assessing application from data localization aspects
Reviewing Assurance reports like SOC II type II reports
Recorded Data Security Risks for applications and advised Project Managers about appropriate mitigating controls
Collaborate with key stakeholders at all levels of organization to confirm, verify and address audit findings, control deficiencies and remediation plans
Contracted with PwC and acting as a consultant for Shell Information security & Risk management
Subject Matter Expert
Cognizant Technology Solutions
02.2017 - 02.2022
Perform the role of a functional specialist for IT Information Risk Management (IRM) within application and infrastructure projects
Performing the Business Impact Assessment, Legal & Regulatory Assessment
Proactively review information security and related risks, threats, and vulnerabilities, legal and regulatory
Execute IT Projects reviews - guide projects towards project stage gate signoffs so that the projects deliver secure, reliable, and compliant IT solutions
Led the POC on the application used by the major client and sub-contractors, this involves is assessment on the vulnerability in the applications used across countries
Assessing the Supplier Assurance Process & validate the Vendor owned Controls
Associate
Layfield & Barrett APC
Bangalore
10.2016 - 02.2017
Monitors project scope, schedule, costs, resources, quality, and risk to ensure project activities/tasks are occurring as planned and any variances are identified
Applies project management methodology, tools, techniques, and terminology - Is able to demonstrate a theoretical understanding and can identify the application of each in driving successful project execution
Documents changes to project scope, schedule, quality, and cost - Documents changes to the project scope, schedule, quality, and costs to keep the project plan accurate, updated, reflective of authorized project changes as defined in the change management plan
Documents project risks, assumptions, issues, and decisions - Document's project risks, assumptions, issues, and decisions, and as applicable, under the direction of a project manager
Monitors project work - Measure's performance using appropriate tools and techniques to monitor the progress of the project, identifies and quantifies any variances to the approved plan, and as applicable, works with the project manager to identify and communicate corrective actions
Senior Process Associate
AGS Health (P) Ltd
07.2011 - 05.2016
Monitoring process around the Continuous Demand Management Process (CDMP)
Managing and supporting IT program portfolios
Setting up the program structure in all effected tools in cooperation with a program manager
Creating and publishing regular and ad hoc reports
Supporting senior managers with follow-up clarification/questions
Gathering data from onshore partners and Subject Matter Experts as well as various databases
Conducting analysis and graphical presentation of the data
Senior Process Associate
Ajuba Solutions (P) Ltd
06.2008 - 07.2011
Supporting and coordinating project management tasks (Quality Control checks, RAID & RAG Reporting)
Project financials (resources planning, resource management and reporting, budget planning, controlling, and reporting)
Milestones / Deliverables tracking and reporting
Updating resource actuals/ forecasts and monthly reconciliation
Support ad-hoc clean-up and bulk modification requests in SharePoint database
Initial quality assurance on received data inputs based on given guidelines
Education
M.Sc. - Computer Science
TUK Arts & Science College
Thanjavur
06.2003 - 04.2005
B.Sc. - Computer Science
Ponnaiyah Ramajayam College
Thanjavur
07.1999 - 04.2002
Skills
Information Security & Cyber Security
IT Security Policies & Procedures Development and Implementation
Risk Assessment and Business Impact Analysis
ISO27001: 2022 Lead Auditor & ISMS Implementation
IT General Controls (ITGC) Assessment
IT & Internal Audits
IT Risk Advisory
Information Risk Management
Vendor Risk and Third-Party Security Reviews
Project Management
IT Compliance Management
Certification
ISO/IEC 27001:2022 Lead Auditor
Timeline
Risk Advisor (Worked With PWC)
US Software Groups
02.2022 - 01.2023
Subject Matter Expert
Cognizant Technology Solutions
02.2017 - 02.2022
Associate
Layfield & Barrett APC
10.2016 - 02.2017
Senior Process Associate
AGS Health (P) Ltd
07.2011 - 05.2016
Senior Process Associate
Ajuba Solutions (P) Ltd
06.2008 - 07.2011
M.Sc. - Computer Science
TUK Arts & Science College
06.2003 - 04.2005
B.Sc. - Computer Science
Ponnaiyah Ramajayam College
07.1999 - 04.2002
ISO/IEC 27001:2022 Lead Auditor
ISO 42001 Artificial Intelligence Management System (AIMS)
Senior Consultant
PricewaterhouseCoopers, PWC
01.202 - Current
Similar Profiles
Lavwinya SreedharanLavwinya Sreedharan
External Auditor at PricewaterhouseCoopers, PWCExternal Auditor at PricewaterhouseCoopers, PWC