V ASHOK KUMAR
Hyderabad, India ~ +91-900******* ~ *******@*****.**.**
Objective
Seeking a mid to senior level position with a well established and globally
reputed organization in
IT/BFSI/Consulting sectors, by utilizing 14+ years of experience in
Information Systems Auditing, Information Security Management, Risk
Management, Project Management and Product development.
Information Security professional - Summary
Information Security
. Implemented Information Security across the Organization.
. Conducted Risk Assessment and Information Systems Audits of Operation
centres, Data Center and Disaster Recovery sites.
. Audited the Infrastructure and Applications in accordance with
Regulations, Framework and
ISO 27001 Standard.
. Established processes to safeguard the Information system assets.
. Liaised with external Auditors for providing Assurance on Information
Security.
. Crafted Information Systems Security Policy, Disaster Recovery and
Business Continuity plans.
. Imparted training in information Systems Security.
Information Technology
. Established ATM and IVRS centres of the Bank.
. Managed ATM, Tele-banking, Online Banking and Debit Card operations of
the Bank.
. Managed Data Center activities.
. Implemented IT security policy in Core Banking Solution branches.
Professional Certifications & Academics
. CISA - Certified Information Systems Auditor, ISACA, USA - 2006
. CISM - Certified Information Security Manager, ISACA, USA - 2009
. ISO 27001 LA - Information Security Management System, Lead Auditor,
DNV, India - 2012
. CPISI - Certified Payment Card Industry Security Implementer, SISA,
India-2014
. PMP - Project Management Professional, PMI, USA - 2009
. CAIIB - Certified Associate of Indian Institue of Bankers - IIBF,
India - 2000
. Six Sigma - Green Belt Certification, Covansys-CSC, India - 2007
. MBA (IT) - S M University - 2008
. BSC (MPC) - Osmania University - 1984
Professional Experience
VSoft Technologies, India (SEI CMMI Level 3 Company)
Domain Consultant
Dec'07 - May'14
Responsible for managing Information Security, Information Systems
Auditing, Risk Management, Business Analysis and Product development.
. Participated in crafting Risk Management strategy initiated by the Top
Management
. Crafted Information Systems Security Policy, Disaster Recovery and
Business Continuity plans.
. Implemented Information Security across the Organization.
. Conducted Risk Assessment and Information Security Audits of Data
Center and Disaster Recovery sites.
. Defined Control Objectives and implemented Information System
Controls.
. Established processes to safeguard the Information system assets and
devised several Templates.
. Imparted training to personnel in information Systems Security.
. Participated in VAPT and Application Security.
. Liaised with external Auditors for providing Assurance on Information
Security.
. Worked as a Project Manager to execute US Banking Compliance project
based on FDIC guidance.
. Reviewed, analyzed and evaluated RFPs and Software.
. Contributed in achieving CMMI Level 3 for VSoft by preparing policies,
standards and templates.
Covansys-CSC, India/ Netherlands (SEI CMMI Level 5 Company)
Senior Consultant
Feb'07 - Dec'07
Responsible for assessing key banking applications for compliance with
security requirements in a major Bank at Netherlands.
. Performed information security compliance audits in accordance with
Regulations, Framework and ISO 27001 Standard.
. Conducted assessment of Application controls from the domains of
Account Management, Authentication, Access Control, Data Handling, and
Application Lifecycle, assuring product reliability and security.
. Conducted gap analysis and recommended SMART actions to ensure
Regulatory compliance
. Appraised stakeholders about various Risk mitigation and remediation
plans through independent audit reports.
Syndicate Bank, India
Manager - IT
May'84 - Jan'07
Responsible for carrying out IT operations at Data Center and Controlling
offices of the Bank.
. Implemented IT security policy of the Bank and promoted process
compliance.
. Reviewed audit reports of branches and supported them in the
rectification & closure of audit reports.
. Managed the Data Center activities by resolving issues and attaining
SLAs.
. Established IVRS Center and functioned as Nodal Officer for Tele-
Banking & ATM operations of the Bank.
. Managed Debit Card operations.
. Reviewed Internal, Statutory & RBI audit reports of operational units.
. Member of Channel Management Committee, handling Cards, Tele-banking
and Online banking activities.
Professional Development
. PCI DSS V3.0 Implementation Workshop and Certification course, SISA
. Practical workshop on COBIT 5 framework, Hyderabad Chapter of ISACA
. ISO 27001 Lead Auditor Certification course, DNV
. Train the Trainer Program for imparting Project Management skills,
PMIPCC
. Project Management Professional training, Aspen School of Business
. Software Quality training, Aspen school of Business
. Effective Management, Decision Making, Group Dynamics, Team Building
and Time Management, VSoft
. Information Security Management System, Presentation skills, Lateral
thinking skills, Covansys-CSC
. Participated in Project Management Conferences, AGMs, Workshops,
Webinars and Network meetings
. Mentoring PMP and CSQA aspirants
. Authored a book on the UNIX Operating System.
Technical Skills Set
. Operating System: UNIX, Windows
. Database: Oracle 9i, SQL Server, MS-Access, dbase
. Application Package: MS Office-Word, Excel, PowerPoint, MS Outlook
. Database Query tools: Aqua Data Studio
. Software development activities: Agilefant
. Defect Tracking System: Bugzilla
. Helpdesk monitoring tool
Professional Affiliations
. Active member of Hyderabad Chapter of Information Systems Audit and
Control Association (ISACA).
. Active member and Volunteer of Pearl City Chapter of Project
Management Institute (PMI).
. Life member of Indian Institute of Banking and Finance (IIBF).
Awards
Awarded 'Outstanding Employee' in VSoft Technologies.[pic][pic][pic]