
Timeline
About me
Senior Manager | IT Audit, Risk Consulting, Info Security, Compliance | I Help companies identify risk, design, implement controls, perform IT Audit.
Education

Sikkim manipal university, gangtok
2011 - 2013Master’s degree msc a
Educational Institution
2009 - 2011Bachelor's degree
Experience

Hcltech
Nov 2005 - May 2011Senior technical support officer
Iyogi
May 2011 - Oct 2012Technical specialist
Hcltech
Oct 2012 - Jun 2014Senior specialist
Ibm
Jul 2014 - Nov 2021Conduct Audits on Information Technology General Controls (ITGCs) and determine if controls are designed and operating effectively.Manages audit activities and work on various audits and projects in different phases.Review Audit evidence when received to verify accuracy and completeness.Articulating audit findings and remediation activity to senior management.Review ISAE 3402 report on company's “ITGCs” and on the suitability of the Design and Operating Effectiveness of Controls. Show less
Senior Information Technology Auditor
Jul 2019 - Nov 2021Security Delivery Specialist
Jul 2017 - Jul 2019Audit and Compliance Focal
Jul 2014 - Jul 2017

Pwc
Dec 2021 - nowAssistant managerResponsible for the IT risk and controls deliverables, part of operational Risk Management performing advisory/assurance activities which includes Risk assessment (Applications, interfaces and processes), control design, control implementation, control operation and control documentation. Supports projects with the categorization (PIRA), assessments (BIA/LRA) and mitigation of risks through Selection/Design of Controls.Reviewing Project charter, Project tier rating in Archer tool.Assessing the business impact of the identified risks through the risk assessment process (Business Impact Assessment) and Legal and regulatory assessment). Performing Service classification.Determine the likelihood by assessing threat and vulnerabilities.Response to identified risks and mitigation through control objectives.Documenting actual control procedure and work instructions.Performing continuous risk identification and evaluation.Performing Interface assessment, SAHLD assessment.Review of assurance reports (ISAE 3402, SOC2 Type2, SOC2 Type1, SOC1 Type2, ISO27001 and PCI AOC).Validating the use of production data in NPE environment.Performing Privacy Impact Assessment (PIA) and Deep level assessment (DLA).Decision on security assessment like Pen test, Vulnerability assessment and Code scanning.Track finding closure, obtaining risk acceptance, action plan to close finding.Generating control set based on risk profiles and selection and deployment of relevant controls to ensure acceptable risk mitigation.Delivers on-boarding and compliance validation services for Suppliers providing 3rd party services.Providing expert advice on the selection, design, implementation and operation of actual controls based on risk assessment outcome.Implementation of designed controls and handover to relevant organization for agreement to operate sign-off.Ensuring controls are designed and operated effectively.Project handed over to BAU and agreed to deploy. Show less
Licenses & Certifications

Diploma in information system

Mcp

Mcsa

Mcse
- View certificate

Certified information systems auditor® (cisa)
IsacaJun 2022 - View certificate

Ibm mentor
IbmJul 2021 - View certificate

Bluemix essentials
IbmMay 2018 - View certificate

Cyb002x: the ciso's view (cybersecurity series)
University of washingtonJan 2018 - View certificate

Business continuity champion
IbmApr 2021 - View certificate

Ibm security essentials 2017
IbmSept 2017 - View certificate

Cism cert prep: 4 information security incident management
LinkedinJun 2022 - View certificate

Information risk and protection
IbmOct 2017 
Iso 31000:2018 lead implementer
IntertekAug 2023
Iso 20000 master - it service certification lead implementer
IntertekSept 2023
Iso 27701:2019 lead implementer for privacy information management system
IntertekAug 2023- View certificate

Security operations and response
IbmOct 2017 
Iso 27001 lead implementer
IntertekAug 2023
Iso 27001 lead auditor - information security certification
Bscic certifications pvt. ltd.Jul 2023
Iso 27001 lead implementer - information security certification
IntertekSept 2022
Iso 22301 li
IntertekMay 2023- View certificate

Cism cert prep: 3 information security program development and management
LinkedinJun 2022
Languages
- enEnglish
- hiHindi
Recommendations

Dias p.g.
Sr.Executive - Shipping and Logistics at Olam Agro India LtdErnakulam, Kerala, India
Jolene c.
You have a problem, I'll solve itFederal Territory of Kuala Lumpur, Malaysia
Karthik manjunath
Technology Strategy at EY-P || ERP and IT Strategy || ERP Implementation || Chemical Engineer || Sto...Bengaluru, Karnataka, India
Alejandro l.
Entrenador personal en AutónomoCidade do México, México
Sabbiruddin khan, mba
Financial Planning Analyst @Accenture || Ex - KPMG || FP&A || Financial Modeling|| SQL || TABLEAU ||...Bengaluru, Karnataka, India
Gourav sharma
Manager, RCSC-Used Car, HDFC Bank | ex- Mahindra FinMumbai, Maharashtra, India
Syed wajid
Airline Security Assistant Manager at IndiGo (InterGlobe Aviation Ltd)Hyderabad, Telangana, India
Adawia safitri
MelbourneGreater Melbourne Area
Haruka kubo
株式会社LITALICO - Engineer Recruiter/Branding/PRJapan
Laura baudoin
Audencia student searching for an internship from December 19th to March 3rd 2023Nantes, Pays de la Loire, France
Loreto valenzuela tapia
Químico farmacéuticoSantiago Metropolitan Area
Edward wilks
Project Delivery Manager at GHDGreater Perth Area
Reza afrazmanech
Lead GeoscienceLondon, England, United Kingdom
Antonio yongao, p.eng., cet
Senio Engineer at Candu Energy - Member of the SNC-Lavalin GroupMississauga, Ontario, Canada
Elodie brocas
Known as The Good Life Specialist - Certified Nutritionist (MCO), Wellness Coach & Yoga Instructor. ...Oberägeri, Zug, Switzerland
Ryan natsch
Vice President at CitiNew York City Metropolitan Area
Santiago gonzalez gutiérrez
Experto en Cooperación Internacional y gestión de ONG´s. Gestión de Proyectos de Cooperación para el...Greater Sevilla Metropolitan Area
Ragini sen
Hardware Engineer| VLSI | Gate Qualified |Ahmedabad, Gujarat, India
Ghada khalifa
ConsultantEgypt
Natasha toeteberg-harms, cpa, cfe
Advisory Manager specializing in Fraud Investigation and Risk Management Services at Ahuja & Consult...Iowa City, Iowa, United States
...