Services

Video meeting . 15 mins
FREE

About me

A Seasoned professional with about 6 years of demonstrated experience in key areas such as Security Architecture, Risk Advisory, Third-Party Risk Management, and Cybersecurity Strategy. Skilled in implementing robust security frameworks, managing risk for supply chain, conducting security audits, and ensuring compliance with industry regulations to synchronize security objectives with business goals. Committed to ongoing development, evidenced by professional certifications such as CISSP, CISA, ISO 27001:2013 LA, Cloud etc. Key Competencies: Proficient in Security Assessments, Cloud Security, Information Systems Governance, Risk Management, Supply Chain Risk Management (Technology). Experienced in IT Audits, Product Security, RCSA, M&A Security Due Diligence, Investor/Vendor due diligence. Skilled in using GRC tools, conducting Proof of Concept testing's, managing Projects and Resources. Pointed Details 1. Information Security / Product Security and compliance reviews involving PCI-DSS, ISO 27001, GDPR, NIST 800 series, various unified controls frameworks and key controls 2. Third party risk management across organisation's diverse tech portofolio, involving API, Web, and Mobile application security, data and perimeter security controls 3. Technology audits and control testing across APP/DB/OS layers. 4. SOX 404 control testing 5. Problem management and issue monitoring & remediation 6. Skilled in using GRC tools such as Coupa, MetricStream, Bitsight. 7. Security capability and maturity assessments across industries 8. Experience with designing policies and procedures for information & data security, vulnerability management etc. 9. Experience with SOC 1 and SOC 2 reports and PCI-DSS 10. Experienced in IT audits and Cloud security 11. M&A security due diligence 12. Policy governance and lifecycle management 13. Engaged in Proof of Concept testing's, managing Projects and resources. I can be contacted through LinkedIn or email me at:-cg250389@yahoo.com (7009029890)