Summary
Overview
Work History
Education
Skills
Certification
Accomplishments
Timeline
Generic

Twinkle Chakraborty

Bengaluru

Summary

Skilled GRC Consultant with over 14+ years of experience in Governance, Risk, Compliance, IT Audit, Security, PCI Compliance, Vulnerability Reviewer, ITGC, DRP & BCP, maintenance and support in the IT sector. Expert in SOC1 / SOC2 audits, SOX, GDPR audits and PCI-DSS. Proficient in ISO 27001, ITGC, NCA and GRC processes to streamline operations, improve efficiency and reduce risk across the organization. Detail-oriented compliance analyst familiar with conducting research and compliance investigations. Productive, responsible and insightful professional with an organized approach. Ready to leverage several years of experience to take on new position at successful organization.

Overview

1
1
Certification
16
16
years of professional experience

Work History

Staff Product Compliance Specialist

Ivanti Technology
06.2023 - Current
  • Own the technical heavy lifting of audits and after audits perspective: control implementation, 3PAO engagement, POA&M management and continuous monitoring
  • Led SOX audits following the PCOAB accounting standards with BDO US - Where the effectiveness of ITGC was measured and been a part of the gap findings and remediation.
  • Developed RACM templates and control placemats during GAP assessments for all systems under SOX audits, including SAP, Concur, Workday, Salesforce, and Informatica, to ensure compliance with relevant standards and regulations.
  • Led SOC II Type 2 audits as Product SME with external auditors A-lign and Deloitte for products including MDM, Pulse Secure, Cherwell, Risk Sense, ITSM, and Neurons, verifying artifacts from control owners for audit accuracy.
  • Risk lifecycle management: risk identification, assessment, scoring, monitoring, remediation, and vendor collaboration workflows
  • Built compliance-as-code: evidence collection and continuous control monitoring tied into our existing security telemetry.
  • Collaborated with stakeholders to present PowerPoint presentations, conduct audit kick-offs, and manage audit remediation processes.
  • Created bridge letters and engagement letters with auditors after audits concluded.
  • Acquired understanding of GAAS frameworks to support compliance efforts. and working on its implementation.
  • Extensive experience with tools like Archer, ADO, ITSM, JIRA, Neurons for tasks related to audit, A-Scend for updating before and after audit data
  • Studied new regulatory / legal requirements / the impact of these on the organization's security posture & ensured privacy compliance with the requirements and implementation of privacy controls/policies.
  • Monitor product metrics (as a part of Continuous Monitoring), Stakeholder's feedback and usage patterns to identify areas for improvement (if any), validating their ideas with our internal team's.

IT Security Officer

Sequential Technology
Bangalore
10.2022 - 06.2023
  • Conducted ISMS audits with auditors like PWC and DNV including ISO 27001, PCI-DSS, and QMS, to ensure compliance with information security standards & regulations.
  • Led re-certification efforts to maintain compliance with information security standards and regulations like SOC 2, TL9000, ISO27001, ISMS/QMS
  • Conducted vendor due diligence assessments to evaluate third-party risks and ensure compliance with company policies and regulations.
  • Developed and implemented effective governance frameworks to manage risks and ensure compliance with regulatory requirements.
  • Conducted GAP assessments, including PCI audits & ISMS audits, to identify areas for improvement and ensure compliance with relevant standards / regulations.
  • Developed and delivered information security awareness training programs to educate employees on best practices and reduce security risks.
  • Maintained GDPR privacy policy strategies to enhance operations and minimize risk of data breaches across the organization.

GRA Lead Consultant

Tecplix Technologies
04.2022 - 10.2022
  • Conducted IT General Controls (ITGC) audits to assess IT control effectiveness and pinpoint improvement areas.
  • Facilitated SOC II certification renewal to maintain compliance with industry standards.
  • Participated in external audits with PwC, provided information & guidance to ensure a smooth audit process and timely resolution of any identified issues.
  • Reviewed internal policies and controls prior to presentation to external auditors, ensuring compliance and facilitating audit success.
  • Ensured compliance with relevant regulations and standards, including developing policies and procedures to address compliance gaps and conducting regular assessments to ensure ongoing compliance.
  • Maintained risk register, identified and evaluated potential organizational risks, and developed strategies for effective mitigation.
  • Documented SOX audit procedures, findings, and recommendations in accordance with internal and external auditing standards

GRC Lead Consultant

Wipro
10.2021 - 04.2022
  • Managed MLPS (Multi-Level Protection Scheme) data, ensured compliance with data security regulations, and implemented controls to safeguard data from unauthorized access.
  • Maintained risk register, identified and evaluated potential risks for renowned Japanese medtech manufacturer, and developed mitigation strategies to enhance organizational resilience.
  • Maintained GDPR privacy policy strategies across Europe to streamline operations, improve efficiency in handling customers' data processing and reduce risk of data breach across the organization.
  • Collaborated with Saudi clients on GRC initiatives, utilizing regulations from the NCA (National Cyber Security Authority) to create a risk assessment template.
  • Conducted JSOX audits to ensure compliance with Japanese regulations and standards, reviewed and tested internal controls and processes to identify weaknesses and recommend improvements.
  • Participated in SOC 2 audits, guided audit process, and facilitated timely resolution of issues related to security, availability, processing integrity, confidentiality, or privacy.

IT Risk Security Administrator

Mouser Electronics, Inc. Ltd
12.2019 - 10.2021
  • Conducted access reviews to ensure compliance with company policies & regulatory requirements, reviewing Active Directory & HR reports to identify and remove any vulnerabilities or unauthorized access.
  • Conducted risk assessments in accordance with NIST standards.
  • Executed GAP assessments to identify deficiencies in controls and processes, recommending improvements to achieve compliance with regulatory requirements and industry best practices.
  • Performed Active Directory audits for compliance with company policies and regulations, identifying and remediating vulnerabilities and unauthorized access.
  • Participated in end-to-end PCI-DSS audits, provided information and guidance to ensure a smooth audit process and timely resolution of any identified issues related to payment card data security.
  • Created strategies for GRC processes to streamline operations, improve efficiency, and reduce risk across the organization.
  • Maintained a thorough privacy policy across the organization to reduce risk involved in customer data breach
  • Developed and maintained GDPR compliance policies, procedures and controls.
  • Conducted internal audits to evaluate controls and processes, identifying weaknesses and recommending improvements for compliance with regulatory requirements.
  • Conducted risk assessments to identify and evaluate potential risks, recommending strategies to mitigate identified vulnerabilities.
  • Conducted warehouse auditing to ensure compliance with regulations and standards, including identifying and evaluating potential risks.
  • Validated ITGC issues, identified and assessed potential risks and recommended improvements to controls and processes to mitigate them.
  • Conducted universe tool audits to ensure compliance with regulatory requirements.
  • Assessed auditing processes related to termination policies to ensure thoroughness.
  • Extensive experience on Cherwell Termination Auditing according to Fusion tool.
  • Involved in CSV-Computer systems validation and prepared policies.
  • Created, maintained, / reviewed policies and frameworks.
  • Reviewed policies and published them in Share point tool, ensuring that they were up-to-date, accurate, and accessible to all relevant stakeholders.
  • Used tools like Enterprise Reckon for scanning the CHD entries.

APAC IT Security Specialist

EPIROC MINING
09.2019 - 11.2019
  • Access Reviews - User, Privileged and SOD's
  • Firewall/Skybox reviews (Create rules so ensure zero Risks involvement)
  • Executed immediate risk assessments for identified vulnerabilities during third-party risk assessments.
  • Conducted internal audits to gather data across teams, ensuring audit readiness for external assessments (Security Operations Centre, SIEM, IAM, Application Security, Network Security).
  • Developed security awareness modules aligned with GRC framework to enhance team compliance and knowledge.
  • Managed Disaster Recovery Plans while adhering to the company's BCM policies.
  • Had been a crucial part in- Privacy policy developing and implementing phase
  • Utilized tools such as Snow (Service Now) and Jira for project management.
  • Travelled internationally (Onsite- Sweden) and finished a short project on Disaster Recovery Planning

IT Security Analyst

Hudson's Bay Services Private Ltd
07.2017 - 08.2019
  • Reviewed access controls by checking Active Directory against HR reports, removing identified vulnerabilities to enhance security posture.
  • Reviewed Firewall / Skybox (Rules review to ensure zero Risks involvement)
  • Implemented ISO 27001 (Phase 1 completed)
  • Received data across the team / kept the team audit ready in case of external audits (Security Operations Centre, McFee, SIEM, Venafi, IAM, Application Security, and Network Security teams)
  • Created Security awareness training modules as per the GRC framework.
  • Worked on Internal Auditing
  • Used Tools like Skybox and Jira
  • Managed project activities during my tenure as Project Coordinator from May 2018 to August 2019, overseeing Venafi, Application Security, Business Continuity Plan, and OMS database.
  • Updated the Jira tool to reflect project progress.
  • Coordinated with stakeholders to clarify technical terms for business understanding, facilitating meetings and presentations to streamline communication.
  • Contributed to portfolio management efforts to ensure alignment with strategic goals and improve project outcomes.
  • Scheduled jobs as per project requirements and available resources

IT Security and Vulnerability Analyst

Boeing International
07.2017 - 10.2017
  • Developed and maintained IAM policies and procedures, including access controls, authentication mechanisms, and identity verification processes.
  • Worked on Access Control Policy using TFS (Team Foundation Server) and Access Validations using TFS (Team Foundation Server)
  • Assisted in SOC II certification.
  • Developed and maintained disaster recovery plans and procedures, ensuring robust backup and recovery processes, data retention policies, and system redundancy requirements.
  • Oversaw management of network infrastructure, operating systems, and database systems, ensuring optimal performance and reliability.
  • Produced technical documentation to enhance system understanding and usability for end users.
  • Involved in project management using the waterfall method.
  • Contributed to evaluation of portfolio strategies to enhance overall investment outcomes.

Security Delivery Specialist

IBM India Pvt Ltd
Bangalore
04.2010 - 11.2016
  • Conducted firewall reviews to identify and rectify redundant and shadowed rules, collaborating with stakeholders to enhance network security.
  • Reviewed user access permissions within the Identity Access Management system, ensuring alignment with security policies and compliance requirements.
  • Collaborated with the information security manager to address audit deficiencies by implementing corrective actions.
  • Initiated remediation actions to resolve deficiencies pointed out as part of audit fieldwork.
  • Interacted with the Information Technology Team & all Staff to Perform risk analysis for all the raised queries by different stakeholders and Implementation of security products.
  • Experience with tools usage like Skybox for Firewall reviews and QRadar for log monitoring purposes
  • Conducted, tested and reviewed controls to ensure compliance with SOC1 & SOC2 standards and participated in the development and implementation of policies and procedures to meet NIST standards
  • Performed assessments and audits to identify HIPAA compliance gaps and developed action plans to address any issues.
  • Worked with Kaiser Permanente Account--- one of IBM's biggest clients with more than 35,000 servers-HIPAA projects, Disney and Astellas Pharmaceuticals and worked under security frameworks like ISO 27001 and CoBit.
  • Administered and monitored Windows 2003 servers.
  • Prepared the backup and restore data.
  • Windows Base image verification pre-& post deployment
  • Participated in service and server "Activation and de-activation".
  • Worked on troubleshooting of servers not reporting to the VSA site, Patch Management (APARS), / Health Checking (NCIs) of over 35000+servers on different OS like NT4/2000/2003/2008 (event log checks, performance monitoring, and checks disk, etc.)
  • Actively participated in GSD331 / ISeC implementations for clients like Kaiser, Disney, Astellas etc.
  • Reviewed, documented and maintained security policies and standards as per the business requirement across the organization using technology and appropriate controls.
  • Involved in the maintenance of CIRATS and updated the missing and expired health check reports in the ECM tool
  • Reviewed contracts of clients which we have signed and implemented the same in the IBM environment to deliver the services.
  • Developed / maintained health check policies & procedures, including performance monitoring, analysis, and optimization.
  • Maintained comprehensive BCP to ensure continuity of critical business functions for client Disney during service disruptions and strategic renewals.
  • Experience in maintaining patch management policies and procedures, including vulnerability scanning, patch testing, and deployment strategies.
  • Involved in quality check of servers before delivery to the customer and server activation / de-activation.
  • Attended audits like SOX / AUP & carried them out efficiently with zero defects and escalations.
  • Maintained records of all SSAE 16 related activities and ensuring they are up to date.
  • Attended audits like SOX / AUP & carried them out efficiently with zero defects and escalations.
  • Maintained records of all SSAE 16 related activities and ensuring they are up to date.

Education

Bachelors - business administration (Finance)

WBUT

Skills

  • Audits - SOX ITGC, SOC II Type 2, PCI-DSS
  • Compliance Management & auditing
  • Risk Management
  • Control testing
  • Regulatory compliance
  • Information security
  • Framework Knowledge: ISO27001, PCI-DSS, NCA, JSOX, MLPS, NIST, ITGC
  • Gap assessment
  • Compliance monitoring
  • Incident Management
  • Policy Management
  • Patch Management
  • Cybersecurity protocols
  • Product management -ITSM, Neurons, MDM, Pulse Secure zTA, Cherwell
  • OS & Network
  • Due diligence
  • Internal auditing
  • Documentation management
  • Document review
  • Project management
  • Reporting skills
  • Communication effectiveness
  • Presentation skills
  • Powerpoint presentations
  • Training facilitation
  • Information gathering
  • Collaborative teamwork
  • Problem resolution
  • Analytical problem solving
  • Critical thinking
  • Influencing skills
  • Industry awareness
  • Organizational effectiveness
  • Excellent communication
  • Excellent communication

Certification

  • CISM Certified
  • MCSE (Microsoft Certified Systems Engineer)
  • CCNA (Cisco Certified Network Associate)
  • IBM certified ITIL Professional
  • Cloud Burst Certified

Accomplishments

  • Efficiently ramped up different projects on multiple platforms and conducted security risk assessments, risk management, security audits, and developed/implemented security policies using NCA, ISO 27001, NIST, and PCI-DSS frameworks and standards.
  • Effectively designed and implemented GRC process strategies to streamline operations, improve efficiency, and reduce risk across the organization.
  • Successfully developed security processes and procedures as per standards and best practices.
  • Worked on ISO 27001 assessments, Compliance Security Management, and Process Improvement in adherence to PCI-DSS, SOX, HIPAA regulations, and PCOAB.
  • Effectively planned, executed, and implemented projects in compliance with quality standards and policies (ISO 27001), SOC II Type 2 Privacy policies, PCI-DSS, and SOX audits following the PCOAB standards.
  • Handled projects like vulnerability assessments, internal and external audits, and incident management using tools.
  • Developed and implemented effective governance frameworks to manage risks and ensure compliance with regulatory requirements, including monitoring and reporting on compliance activities to senior management and stakeholders.

Timeline

Staff Product Compliance Specialist

Ivanti Technology
06.2023 - Current

IT Security Officer

Sequential Technology
10.2022 - 06.2023

GRA Lead Consultant

Tecplix Technologies
04.2022 - 10.2022

GRC Lead Consultant

Wipro
10.2021 - 04.2022

IT Risk Security Administrator

Mouser Electronics, Inc. Ltd
12.2019 - 10.2021

APAC IT Security Specialist

EPIROC MINING
09.2019 - 11.2019

IT Security Analyst

Hudson's Bay Services Private Ltd
07.2017 - 08.2019

IT Security and Vulnerability Analyst

Boeing International
07.2017 - 10.2017

Security Delivery Specialist

IBM India Pvt Ltd
04.2010 - 11.2016

Bachelors - business administration (Finance)

WBUT
Twinkle Chakraborty