I work across information security, risk management and data privacy: ISO 27001 and ISO 27701 implementations, internal audits, NIST CSF assessments, access and vendor risk reviews, and DPDP Act programs. Lately, I also explore how AI can make GRC work less manual.
Experience
- Implementing India's Digital Personal Data Protection Act 2023 for manufacturing, medical device and oil companies.
- Internal audits for FMCG clients covering endpoint security, logical access and SoD reviews, IT asset management, Microsoft 365 configuration, firewall rules, patch management and backups.
- ISO 27001 and ISO 27701 sustainment across healthcare and financial services companies, and ISO 27001 internal audits for a retail and apparel company.
- NIST CSF maturity and gap assessment for a pharmaceutical and biotech organization.
- Led an internal audit of user access reviews, incident management and data protection for a media and entertainment organization.
- Drafted policies and procedures aligned to SAMA CSF and NCA ECC.
- Helped validate a cloud assessment model and framework through a successful finance sector pilot.
- Security awareness sessions, lock screen posters and email campaigns for metals and financial services employees.
- Risk assessments, vendor risk evaluations, risk closure plans and technical proposals.
- Access control, authorization and exposure findings in commercial programs, plus coordinated disclosures to Dutch public sector organizations.
Certifications
- ISO/IEC 27001:2022Information Security Lead Auditor
- ISO/IEC 42001:2023AI Management Systems Lead Implementer
- CISACurrently studying
Education
- MSc Cyber SecurityNational Forensic Sciences University, Gandhinagar. 2022 to 2024, first with distinction
- BE Computer ScienceJhulelal Institute of Technology, Nagpur. 2019 to 2022, first with distinction
Frameworks and languages
ISO/IEC 27001ISO/IEC 27701ISO/IEC 42001NIST CSFDPDP Act 2023SAMA CSFNCA ECC
English, Hindi, Sindhi, Gujarati and Marathi.