Over 12 years of experience in IT and 7+ years in Information Security, specializing in Governance, Risk Management, Compliance (GRC), and security audits. Expertise includes ISO 27001:2013/2022, SOC 2, GDPR, and NIST SP 800-53 frameworks., Led and performed over 50+ vendor assessments for clients in the US across pharmaceutical, BFSI, and IT sectors. Hands-on with TPRM tools such as LogicManager, ComplyScore, Coupa, MetricStream, and ServiceNow., 5 years of experience as an ISO 27001:2022 Lead Auditor and SOC 2 assessor. Proficient in planning, executing, and reporting internal/external audits. Skilled in identifying security gaps, managing corrective action plans, and ensuring regulatory compliance., Implemented enterprise security controls, risk assessments, and remediation strategies aligned with business and regulatory needs. Conducted access reviews, gap analysis, data protection reviews, and policy audits., Practical knowledge of vulnerability assessments and tools including Nessus, Nexpose, Tenable SC, SanerNow, Wireshark, and Nmap. Strong foundation in infrastructure security and network device configuration (Cisco L2/L3 switches, routers, ASA firewalls)., Designed and delivered security awareness programs and technical training sessions for internal users, enhancing InfoSec maturity across departments., Led diverse teams across multiple client projects, ensuring on-time deliverables. Strong interpersonal skills with experience in stakeholder management, cross-functional collaboration, and end-user support.