
Timeline
About me
Information Security Associate at athenahealth | CISA | MBA | ISO 27001:2022 Lead Auditor
Education

University of mumbai
2012 - 2016Bachelor of engineering (b.e.) computer engineeringBachelors Degree in Engineering (Computer)

Symbiosis international university
2019 - 2021Master of business administration - mba information technology business management (itbm)
Experience

Air india limited
Jun 2015 - Jul 2015Intern at department of information technologySentiment Analysis on Live Data: Developed a project on ‘Sentiment Analysis for Facebook posts by Air India using the ‘R’ language’ for categorizing posts into 3 broad segments – Positive, Negative, or Neutral and 6 segments based on emotions.

Larsen & toubro infotech ltd
Oct 2016 - Apr 2019• Implemented governance, risk analysis, and control processes in Microsoft SharePoint environments, web applications, ensuring compliance with operational risk management frameworks.• Conducted risk and control self-assessments (RCSA) for clients, ensuring proper governance mechanisms and internal controls were in place.• Reviewed remediation plans for significant risk events, achieving a higher success rate in control implementation.• Developed and implemented governance policies, enhancing decision-making for operational risk management.• Supported market mode adoption strategy of IT applications to ensure seamless scalability enhancements and security controls validation across the application development and integration pipeline.• Provided innovative solutions for secure data handling through SharePoint Online and on-premises platforms.• Implemented real-time analytical dashboards for problem-solving and monitoring enterprise IT systems.• Evaluated business requirements and provided risk classification and mitigation strategies for clients, enhancing service delivery through IT operations. Show less
Software Engineer
Oct 2017 - Apr 2019Graduate Engineer Trainee
Oct 2016 - Sept 2017

Ey
May 2020 - Jun 2020Summer intern - risk advisory (cybersecurity)Worked as a part of the Cyber Risk Advisory Consulting Practice responsible for the implementation and enhancement of an existing KPI measurement framework as per ISO 27001:2013 clauses aimed at measuring the effectiveness of ISMS. ❑ Contributed to enhancing Key Performance Indicators (KPI) metrics frameworks for ISO 27001:2013, improving the execution of cybersecurity performance assessments.❑ Analyzed cybersecurity risks and provided recommendations for Media & Entertainment consumers undergoing digital transformation, providing solutions for risk mitigation.❑ Supported the design of e-learning cybersecurity courses for educational institutions, promoting continuous learning growth and continuous improvement of cybersecurity awareness as per industry best practices.❑ Recommended alternative tools such as RSA Archer and PowerBI for better representation of KPIs. Show less

Axis bank
Jul 2021 - May 2022Deputy manager (information technology)❑ Led the implementation of Information & Cybersecurity controls in line with PCI DSS and other regulatory requirements related to the banking and finance industry, reducing issues and potential security vulnerabilities.❑ Performed qualitative and quantitative risk assessments and management activities for multiple fintech products, ensuring compliance with the flow of sensitive data protection and encryption standards.❑ Collaborated with cross-functional teams by providing feedback while implementing agile methodologies and validating cybersecurity controls for process improvement in a fast paced regulatory environment.❑ Assisted in the root cause analysis, research, review, and design of internal controls for emerging IT-related processes, ensuring compliance with standards related to customer data protection and financial transactions. Show less

Deloitte
May 2022 - Jul 2024Assistant manager - cyber strategy & transformation - technology & transformationIn a client-facing role, conducted multiple IT Audits, Information System Reviews, Readiness Assessments, and Cybersecurity Reviews for leading Banking & Financial Services Companies: ❑ Performed complete ITGC evaluation across IT platforms including operating systems, databases, and network components as per IT governance, policies and procedures (TOD), and effectiveness of controls (TOE). ❑ Performed system evaluation and audit IT and business process as a part of SOX 404, SSAE 18 and ICFR assessments in accordance with PCAOB/AICPA guidance. ❑ Performed third-party vendor risk assessments, SOC 2 Type II readiness assessments, and IT procurement process reviews. ❑ Performed Technology Risk Assessments in various Internal Audit and IT-themed engagements. ❑ Conducted compliance reviews in alignment with Regulatory guidelines related to System Audit, Cloud Adoption, Cybersecurity, and Cyber Resilience Frameworks. ❑ Performed IT infrastructure assessments for Data Centers and Backup sites. ❑ Reviewed network security posture of client’s intranet and internet-facing applications including firewall rule and security architecture reviews based on NIST Cybersecurity Framework. ❑ Conducted Application Security and Configuration Reviews including Security Operation Center (SOC) and Security Information and Event Management (SIEM). ❑ Facilitated strategic planning for regulatory compliance by developing real-time risk metrics, conducting trend analysis based on statistics, and implementing detail-oriented remediation plans.❑ Experienced in policy development, maintenance of standards, procedures, and governance frameworks tailored to ad-hoc projects and innovation initiatives as per client needs.❑ Developed over 30 project proposals (RFPs), audit work programs, project plans, documentation, and engagement deliverables, achieving measurable revenue growth and success in client acquisition & relationship management. Show less

Athenahealth
Jul 2024 - nowInformation security associate❑ Compliance: Worked with new & existing vendors to ensure initial and continued compliance with Information Security requirements related to PHI. Reviewed technical controls with vendors, developed risk mitigation & remediation plans, documented compliance, exceptions, & reported findings to leadership. ❑ Project planning and facilitation: Reviewed Information Security-related project plans that outlined deliverables, responsible parties, timelines, and other details for both athenahealth and third-party vendors. Conducted check-ins with stakeholders and SMEs to ensure that key security controls are monitored to prevent unauthorized access and protect against data damage or disclosure. ❑ Process reviews: Ensured that business stakeholders conducted periodic reviews of internal and vendor practices to maintain athenahealth's compliance with all regulatory requirements, including HIPAA and HITRUST. ❑ Reporting: Supported audits and tracked exceptions to athenahealth Information Security policies by vendors. Show less
Licenses & Certifications
- View certificate

Professional cloud security engineer
GoogleApr 2023 %C2%B2.webp)
Certified in cybersecurity (cc)
(isc)²May 2023- View certificate

Google cloud associate cloud engineer
GoogleJun 2023 - View certificate

Google cloud certified cloud digital leader
GoogleNov 2022 - View certificate

Certified information systems auditor (cisa)
IsacaJan 2025 
Iso 27001:2022 - information security management systems lead auditor
Bsi training academyJan 2024
Honors & Awards
- Awarded to Prathamesh MayekarRanked 42 at Online Quizzing Festival (OQF) Season 6 Dare2Compete Apr 2021 D2C Online Quizzing Festival (OQF) Season 6 is world’s largest quizzing festival where prestigious institutions come together on a common platform to set the quizzing stage on fire! Keeping up with its legacy, the D2C Online Quizzing Festival (OQF) broke all records in 2020 with 21,715 registered participants.
- Awarded to Prathamesh MayekarRanked 130 at Online Quizzing Festival (OQF) Season 5 Dare2Compete May 2020 D2C Online Quizzing Festival (OQF) Season 5 is world’s largest quizzing festival where prestigious institutions come together on a common platform to set the quizzing stage on fire! Keeping up with its legacy, the D2C Online Quizzing Festival (OQF) broke all records in 2020 with 21,715 registered participants.
- Awarded to Prathamesh MayekarRanked in Top 10 at “STEMQuiz” American Chemical Society - DTU, New Delhi, 2020. Apr 2020 American Chemical Society-DTU in collaboration with The Quiz Club of DTU: Delhi-42 organized The STEMQuiz: A Science, Technology, Engineering and Math Quiz.
- Awarded to Prathamesh MayekarRunner Up in the “PAN India GoCrackIt Challenge on Data Science” NSRCEL and IIM Bangalore, 2020. Jan 2020 GoCrackIt is a personalized career mentoring platform founded by IIM Ahmedabad and IIM Bangalore alumni.
- Awarded to Prathamesh MayekarRanked in Top 100 at “Parivartan - The Red Brick Summit” IIM, Ahmedabad, 2019 Oct 2019 Parivartan, the flagship event of the social and arts conclave of The Red Brick Summit, IIM Ahmedabad, seeks to empower young leaders to become change-makers paving the way for 'Parivartan of India's Social Sector'.
- Awarded to Prathamesh Mayekar1st Prize Winner, Technical Paper Presentation, Evolution2K16 - A national level technical paper presentation extravaganza S.S.P.M`s College of Engineering, Mumbai University Mar 2016 Topic: Automatic Speaker Recognition (An Approach to Extract Feature using MFCC on the Power Spectrum)Authors: Prathamesh M. Mayekar & Akshay Mhapankar
- Awarded to Prathamesh Mayekar2nd Prize Winner, Project Exhibition, Virtuosic 2016 - A national level technical festival S.S.P.M`s College of Engineering, Mumbai University Mar 2016 Project - Automatic Speaker Recognition(An Approach to Extract Feature using MFCC on the Power Spectrum)Team Members: Akshay Mhapankar, Prathamesh Mayekar & Prachi Dalvi
- Awarded to Prathamesh Mayekar3rd Prize Winner, Technical Paper Presentation, Evolution2K16 - A national level technical paper presentation extravaganza S.S.P.M`s College of Engineering, Mumbai University Mar 2016 Topic: Sentiment Analysis on Live-Data For Social Media using 'R' LanguageAuthors: Prathamesh M. Mayekar & Prachi M. Dalvi
- Awarded to Prathamesh Mayekar2nd Prize Winner, Project Exhibition, Virtuosic2K15 - A national level technical festival S.S.P.M`s College of Engineering, Mumbai University Mar 2015 Project - EVOLUTION 2015(Website) - For assessment & selection of technical papers under the event EVOLUTION 2015, National Level Paper Presentation Extravaganza organised under the Technical festival of the college known as the Virtuosic 2015.Link - http://www.sspmcoe.ac.in/evolution/
- Awarded to Prathamesh Mayekar3rd Prize Winner, Project Exhibition, Virtuosic2K14 - A national level technical fest S.S.P.M`s College of Engineering, Mumbai University Feb 2014 Project - DRIVE 2KX4(Game) - An application of Computer Graphics implemented in C Language.
Volunteer Experience
Member
Issued by ISACA Research Triangle Chapter on Jan 2025
Associated with Prathamesh MayekarMember of Institutional Social Responsibility Committee
Issued by SCIT - Symbiosis Centre For Information Technology on Jun 2019
Associated with Prathamesh MayekarMember of Reflections (Office College Newsletter) Committee
Issued by SCIT - Symbiosis Centre For Information Technology on Jun 2019
Associated with Prathamesh Mayekar
Languages
- enEnglish
- maMarathi
- hiHindi
Recommendations

Priyatosh kadam
IT '24 || GCP☁️ || MERN || Redux || Java || DSA || DevOps || DS & ML|| @LeetCode🚀 || @GeeksForGeeksPune, Maharashtra, India
Reema barai
Pre-Final year B.Tech Computer Science Student at UMIT | Passionate About Software Development | Kat...Mumbai, Maharashtra, India
Timothy lua
SMU Information Systems | GovTech Product Management InternSingapore
Mercedes dalia andia gutierrez durrer
"You are what you eat – bei ALEGRIA Restaurante Peruano servieren wir authentische peruanische Geric...Luzern, Lucerne, İsviçre
Aya bahri
Mobile DeveloperBerlin, Berlin, Germany
Habeeb waseem
Oracle DBA at King Abdulaziz University Hospital.السعودية
Jinkyu kim
QA Engineer at Tech MahindraUnited States
Tiago rocha alves
Service,support, customer experience Atendimento|Suporte|Experiência do cliente|Gestão |Performance ...Caruaru, Pernambuco, Brazil
Arthur mitaine-alberola
EntrepreneurMarseille, Provence-Alpes-Côte d'Azur, France
Andrew hall
Cloud, Systems/Applications Administrator, SRE and DevOpsColumbus y alrededores, Ohio
...