Summary
Overview
Work History
Education
Skills
Accomplishments
Software
Certification
Interests
Timeline
AccountManager
Swati Gaur

Swati Gaur

Information Security Analyst
New Delhi

Summary

To be an active part of an organization where my domain related knowledge and skillset developed overtime will be fully explored so that utmost contribution to success of the organization can happen. Also aiming to get ISO27001 certified to deliver value - added solutions.

Overview

4
4
years of professional experience
4
4
years of post-secondary education
1
1
Certification
2
2
Languages

Work History

Information Security Analyst

Ameriprise Financials
New Delhi
09.2021 - Current

ACHIEVEMENTS/TASKS

  • Conduct end to end third party vendor due diligence evaluating on the various stages of Risk management. Review of Third party audit documentation like ISO 27001, SSAE 16.
  • Reviewed violations of computer security procedures and developed mitigation plans.
  • Performed risk analyses to identify appropriate security countermeasures.
  • Recommend improvements in security systems and procedures.
  • Conducted security audits to identify vulnerabilities.
  • Prepared variety of different written communications, reports and documents.
  • Examine Application level Controls for third party owned application.
  • Recommend Security controls for high risk vendors.
  • Reviewed and conducted SOX compliance audit.
  • Assist in managing 3rd party vendor data security and physical security reports (audits).
  • Create follow-up actions and assign to appropriate parties.
  • Participate in the security audit process for all new vendors.
  • Assist in the management of assessment meetings and meeting documentation.
  • Interact with Ameriprise Line of Business partners and external vendors in all aspects of the process.
  • Ensure open audit findings are closed within designated timeframes.
  • Resource for Strategic Sourcing and internal business partners with questions regarding Ameriprise Audit Policies/Processes.
  • Specialties: Business Continuity Management,
    Disaster Recovery,
    Risk Management,
    Information Security Management,
    Governance Risk and Compliance.

Technology Risk Consultant

Ernst & Young
Gurugram
07.2019 - 08.2021
  • Identified issues, analyzed information and provided solutions to problems.
  • Conducted security audits to identify vulnerabilities.
  • Recommend improvements in security systems and procedures.
  • Completed paperwork, recognizing discrepancies and promptly addressing for resolution.
  • Conducts IT-SOX Audits,SOC Audits (SSAE16Reports)and overseeing IT integration of financial audits across a wide range of sectors (FAIT Audits)
  • Perform risk assessments on a variety of processes and functions and review documentation and final
    deliverables to the client;
  • Identify areas of process improvement and coordinate with client stakeholders to mitigate business risks
    Performing testing of IT- General Controls for multiple clients.
  • Responsible for ISO 27001 based Information Security Management System internal audit.
  • Creating remediation's and sending reports to developers/clients
    Researching on new vulnerabilities and creating test cases.
  • Reviewed and conducted SOX compliance audit

Associate Professional

DXC Technology
Noida
02.2018 - 07.2019
  • Perform Information Security Risk assessments on an ongoing basis and report critical risks.
  • Defining, implementing and maintaining security policies and procedures.
  • Review Information Security controls in areas as mentioned below:
    o Change management process
    o Incident management process
    o Backup process
    o User identity and access management
  • Perform SOX Audit for various manufacturing and Health industries.
  • Identified service improvements to increase customer satisfaction.
  • Maintained records of account specific service problems and assisted in prioritizing work requests.
  • Reported project status to drive on-time project deliverables.
  • Interpreted demand forecasts and planned and delivered end-to-end services.

Education

Bachelor of Science - Electrical, Electronics And Communications Engineering

Indraprastha EngineeringCollege
Ghaziabad
08.2013 - 08.2017

Skills

undefined

Accomplishments

  • Trained end users on proper security protocol to minimize cybersecurity attacks.
  • Performed comprehensive investigations of security breaches and implemented appropriate solutions.
  • Created daily database reports to identify and mediate potential vulnerabilities.
  • Multiple client appreciations on each feature deliveries.
  • Core member of “UDHBHAV 13-17” organizing Committee - an Inter cultural Fest organized by the college each year
  • National certificate for performing and securing first rank in Dance at “National Republic Day Parade 2007”
  • Secured First Position in Yoga and Band Group Girls (Junior) Organized by ”Delhi School Sports and Activities Board”.
  • Participated in Athletic Meet organized by “Ministry of Youth Affairs & Sports, Govt. Of India”. • Participated and won in multitude of events like – Debate, Dance, Theatre and Yoga.

Software

SQL

C, C#

Ms excel

DBMS

Certification

EY Bonze Cyber Security - No expiration date

Interests

Dance

Yoga

Poetry writing

Outdoor games

Timeline

Information Security Analyst

Ameriprise Financials
09.2021 - Current

EY Bonze Cyber Security - No expiration date

05-2020

Technology Risk Consultant

Ernst & Young
07.2019 - 08.2021

Associate Professional

DXC Technology
02.2018 - 07.2019

Bachelor of Science - Electrical, Electronics And Communications Engineering

Indraprastha EngineeringCollege
08.2013 - 08.2017
Swati GaurInformation Security Analyst