A highly motivated and result-driven IT Risk Management professional with 5+ years of experience in GRC with ITGC control testing, SOX Compliance, Access Management, Change Management and Cloud Security. Seeking to leverage my expertise in IT Governance, risk assessment, compliance frameworks like COBIT, NIST and ISO 27001 to contribute to the security and operational resilience of a forward-thinking organization. Strong analytical and problem-solving skills with proven track record in mitigating IT risks, ensuring regulatory compliance, and implementing effective control measures. Demonstrated expertise in conducting thorough security assessments, developing and enforcing policies and proven ability to collaborate with cross-functional teams, communicate complex security concepts to non-technical stakeholders, and provide proactive solutions to ensure a secure and compliant environment. Committed to maintaining up-to-date knowledge in the field, pursuing relevant certifications, and contributing to the overall success of the organization through a proactive and hands-on approach to cybersecurity.
Successfully delivered multiple projects including Third- Party or Vendor Risk Management (TPRM), ITGC SOX Control Testing (TOD &TOE), Cloud AWS Security Assessments. Performed Internal Audits, Secondary Audits to validate compliance with internal and external audit findings, ensuring the effectiveness of remediation efforts.
Third-Party Risk management (TPRM)
Risk Management: Expertise in conducting risk assessments and developing risk management strategies to prioritize and address potential security threats. Proactive approach to identifying and mitigating risks through the implementation of risk mitigation measures and continuous monitoring.
● Executed Third-Party assessments, including Vendor Onboarding, Periodic Reviews, and Physical Security Audits, ensuring compliance with contractual and regulatory requirements.
● Performed due diligence checks, including reviews of Vendor Policies, Controls, and Certifications (e.g., ISO 27001, SOC2, PCI DSS, HIPPA), ensuring alignment with organizational and regulatory requirements.
● Conducted Risk-Assessments to evaluate third-party control environments across domains such as Information Security, Data Privacy, Business Continuity, and Physical Security.
● Reviewed third-party service agreements, SLAs, and risk documents to identify potential gaps and compliance issues.
● Performed onsite and remote vendor audits, including physical security checks, access controls and surveillance systems, ensuring adherence to established security standards.
● Monitored and reported key metrics related to vendor risk, including high-risk vendor statuses and remediation timelines, to stakeholders and leadership.
● Assisted in the development and implementation of TPRM frameworks, policies, and workflows to enhance third-party risk management processes.
● Collaborated with vendors to design and monitor risk mitigation strategies for identified control gaps and tracked the closure of findings through secondary reviews.
SOX (Sarbanes- Oxley ACT) ITGC Control Testing
Sox Control testing- Experience on SOX (Sarbanes-Oxley Act) ITGC controls testing in alignment with the COSO framework, focusing on Test of Design (TOD) and Test of Effectiveness (TOE) and led walkthrough with control owners to assess control processes and gathered samples based on sampling methodologies. Evaluated control effectiveness and provided actionable recommendations for areas of improvement.
● Conducted IT General Controls (ITGC) testing for SOX compliance, focusing on Access Management, Change Management, Segregation of Duties, And Backup and Recovery Controls.
● Performed Test of Effectiveness (TOD) to evaluate the adequacy and appropriateness of control designs, ensuring alignment with regulatory requirements and industry best practices.
● Executed Test of Effectiveness (TOE) by obtaining and reviewing evidence to validate the operational effectiveness of controls, identifying deficiencies, and recommending remediation plans.
● Reviewed key controls in the SDLC, including Source Code Management, Test Evaluation Reports, and approvals for system changes, ensuring compliance with SOX compliance with SOX requirements.
● Assessed Use Access Management Processes, including provisioning, de-provisioning, and periodic access reviews for critical systems, to validate adherence to established policies.
● Validated controls related to privileged access management (PAM) and password policies to ensure compliance with SOX ITGC standards.
● Collaborated with stakeholders to document control processes, test results, and identified deficiencies, providing detailed reports and recommendations for improving control environments.
Cloud Security Assessment (AWS)
● Conducted AWS Security Application assessments to ensure control effectiveness align with regulatory requirements such as (GLBA. HIPPA, GDPR, and PCI DSS)
● Assessed the implementation of AWS security controls, including identify and access management (IAM), data encryption, logging, monitoring, and vulnerability management, to ensure compliance with industry standards and frameworks.
● Evaluated Cloud-based controls and configured against leading benchmarks such as CIS AWS Foundation Benchmark to identify gaps and propose remediation measures.
● Designed and executed tailored audit procedures to validate compliance with multiple regulatory regimes, ensuring adherence to privacy and data protection mandates.
● Reviewed AWS environments for security misconfigurations and provided detailed recommendations to strengthen cloud security posture.
● Collaborated with cross-functional teams to develop and implement risk mitigation strategies for non-compliant AWS resources.
● Prepared detailed reports and dashboards to communicate assessment findings and recommendations to stakeholders, ensuring transparency and continuous improvement.
I hereby declare that all the information given above is true and correct to the best of my knowledge.
Signature
Vimala Erothi