SUMMARY OF QUALIFICATIONS
Senior Executive with Fortune 500 and Consulting Experiences Accomplished, dynamic and tenacious Executive-Level professional with almost two (2) decades of extensive experience spearheading and implementing information security, risk, compliance and audit services that significantly enhance technology capability and business performance.
Expertise in GRC, Information Security, IT Audits, BCP/DR and Security Consulting Services Expertise in GRC Advisory Services, Cybersecurity, IT Governance, Information Security Advisory, Security Governance, Information & Application Security, Audit and Risk Consulting, Cloud Managed Hosting Services, and Regulatory Compliance across various industry domains.
Strong Orientation in Delivery Excellence, Product Management, Operations and Business Development Senior Global Leader with expertise in developing high performing teams and building strategic partnership across different countries, organizational levels and cultural background. Proficient in leading global teams through complex initiatives that advance organizational objectives whilst optimizing technologies and systems. Equipped with outstanding ability to plan, coordinate and implement practices and procedures to bring significant improvements in efficiency, productivity & business processes towards the successful attainment of organizational goals.
AREAS OF EXPERTISE AND COMPETENCIES
Project Management Office Leadership & Program Management Strategic Planning & Financial Acumen
Risk & Change Management Program & Portfolio Governance Interpersonal Communication
Stakeholder Engagement Facilitation & Presentation Skills Quality & Vendor Management
Strategic Vision & Implementation Business Development Sales & Pipeline Management Product Management Consulting Delivery Excellence P&L Management Fortune 500 and Big 4 Experience BISO/CISO Go-to Market Strategies Budgeting & Financial Planning Strategic Alliances, Partnerships & Analyst Relations
-Threat Vector Identification
-PCI Compliance Audits, Assessments, Implementation, Monitoring and management
-Vendor Outsourcing Security Reviews
-Data Privacy Frameworks
-Privacy/Data Privacy Impact Assessments
-NIST CSF Posture Assessment
-IT Governance Frameworks, CoBIT & Val IT
-3rd Party Vendor Risk Assessments
-BC/DR Strategy
-GRC Advisory Assessments
-IT Governance & Reporting Metrics
-Risk & Compliance Monitoring
-ROI & TCO
-Network & Database Security
-Information Risk & Compliance Assessments
-Data Masking/Encryption
-Cyber Security Strategy
-Vulnerability Assessments & Penetration Testing
-Cyber Security Maturity Assessment
-Application Threat Modelling
-Issues, Remediation & Exception Management
-System Hardening Standards
-Data Loss Prevention (DLP)
-Continuous Compliance Monitoring
-Content Integrity Monitoring
-GxP Compliance
-SOX/NERC/PCI/HIPAA/NERC/GLBA/FFIEC/GDPR/CCPA etc.
-Security Program & Metrics
-Information Security Policies & Procedures
-CISO/CSO/BISO Advisory Role
-ISO 27001 Controls Reviews
-SDLC Security Reviews
-BC/DR Plan Creation and Implementation
-BC/DR Drill Management
-GRC Platform Strategy & Roadmap
-GRC Platform Implementation
-AI/RPA in Risk Management
-Security Training & Awareness
-IT Audit Planning
-HiTrust Assessments & Certification
-IT Audit Execution and Reporting
-Cyber Defence / Cyber Resilience
-Technology Risk Management
-Enterprise Risk Frameworks (COSO)
-Architecture Standards
-OT Security, Risk & Compliance
-SCADA Systems Compliance
-IT Risk Assessments & Remediation
CAREER PROGRESSION AND ACHIEVEMENTS
HCL AMERICA INC. AUG 2010 – TILL DATE
A $ 8.8 billion IT Services firm with worldwide presence (www.hcltech.com)
General Manager – Governance Risk & Compliance Services
In this role, I currently direct and manage the north America business for governance risk & compliance function, which includes providing governance and oversight to more than 40+ large engagements with ~ 100 million USD Project budget.
Day-to-day responsibilities include managing the overall pre-sales support, delivery assurance, product management, practice and people management, direct project involvement and excellence, quality assurance and security service management, financial and cost management, operations management, recruitment and on-boarding of new staff, competency and talent management, up-selling of new services, vendor management, training and development, client satisfaction management and internal stakeholder management..
Key responsibilities include:
Directly responsible for P&L, Product, Promotion, Sales, Pre-sales and delivering Customer Success working closely with Sales and Service Delivery organization; and Partner with customer executive stakeholders for designing service strategy and new investment areas for existing and new prospective business
Partner with customer executive team and North America sales leadership for providing consultative solutioning for new business and investment ideas for the customer
Develop and implement a comprehensive Enterprise GRC Cyber Security strategy, to establish Cyber Security Program for Clients
Ensure overall security program resiliency by benchmarking against industry trends, GRC security frameworks and thought leadership and continuously research and review latest cyber security trends, emerging technologies, threats to incorporate appropriate safeguards
Executing advisory & consulting engagements around regulatory risk & compliances such as SOX ITGC, PCI-DSS, HIPAA, Data Privacy, FFIEC etc.
Involved with prospect qualification (pre-sales cycle); diagnostic study; custom proposal development, estimation & pricing, proposal development and commercial negotiations.
Attend Business Planning meetings with HCL’s Executive leadership team and propagate the vision to the North America team
Work with the Regional Sales Leadership team to cross sell GRC services for their existing as well as new customers
Provide Pre-sales support through the onsite-presales GRC team; and Conduct enablement sessions with the sales team to walk them through our services offering and give them collaterals to position GRC services in their respective accounts
Forecast the operating budget and manage the existing engagements based on the pre-allocated budgets
As part of GRC leadership team, provide inputs and review changes for budget forecasting and cost allocation
Manage product vendor alliance management initiatives and strategic product vendor partnerships for RSA Archer, MetricStream, Open Pages & Service Now which included developing pricing agreement, organizing joint marketing campaign, meeting and go-to-market strategy.
Provide client consultations about GRC’s products (Archer, MetricStream, Service Now) and services and guide team to develop customized programs to meet client needs and close business
Attend QBR’s (Quarterly Business Reviews) with the Customer Executive team & provide Escalation management for critical new business and current resourcing needs
Participate and share thought leadership in different customer discussion forums to share best practices
Work with HCL Corporate Marketing team and Customer Executive team to position the GRC services in the right forums and invest on marketing activities by sponsoring or participating in industry leading seminars and conferences jointly with our customers
Do timely reviews to measure success of the customer projects and participate in mentorship program with key business and delivery managers to provide insights
Enhance and grow our investment by setting up a GRC Lab in the US to further leverage and build GRC frameworks locally in North America for our customers
Define and executing Go-To-Market strategies through the existing partnership with various GRC Platform vendors and including it in resource and investment planning
Hire and build a team of top notch GRC sales/pre-sales and consulting professionals with strong domain knowledge, passion and intelligence to be a part of this rewarding journey
Manage business processes, and orient related tools needed for all the new employees to enable them for performing their roles and responsibilities effectively
Manage aspirations, career development, reward and recognition programs and timely address employee concerns
Work with HR to create special programs for retention of key talents including variable pay management of Senior Business leaders linked to their Key Performance Parameters (KPP)
Implement employee engagement and capability enhancement programs within the GRC practice
Drive setting up knowledge base, re-usable components for GRC advisory services
CONCENTRIX INC. APR 2009 – AUG 2010
A $3 billion global business and knowledge process outsourcing firm (www.concentrix.com)
Sr Analyst Systems – GRC Consulting
As an Asia Pacific GRC Lead, I was responsible for ensuring that the Convergys IT organization achieves appropriate levels of compliance with corporate policies, client contractual agreements and adherence with the industry regulations.
Overall responsibility and accountability for directly delivering, leading, directing, managing and contributing to Information Risk, Cyber Risk, cybersecurity and periodic audit, across a very an account base of ~ 40 extremely large global engagements with diverse industry verticals.
Key responsibilities included:
Lead IT compliance tasks and gap remediation efforts using IT Governance tools and proactively address non-compliant findings with IT operation and application teams and ensure appropriate remediation is executed in reasonable timeframe.
Govern procedural and operational review of IT policies, processes and systems against corporate, government, and internal compliance standards.
Review Vulnerability Matrices and interpret the findings to customer areas.
Lead IT Risk assessment activities as part of assessments conducted by internal and external areas.
Conduct Audits and Review for the customer engagements and publish reports to executive management
Document and implement a risk & compliance framework for the existing engagements
Work with IT & other support teams for gap tracking and remediation
Drive a large IT Standards optimization program for alignment to industry standards and best practices
Continuously research and review latest cyber security trends, emerging technologies, threats to incorporate appropriate safeguards
Develop, implement, and oversee enforcement of security policies, procedures and work plans based on industry best practices
Develop and implement cyber security awareness and training program for the operations team
Provide advice, educate management teams of latest breaches and security threats
Work with corporate information security group for implementation of best practices in the region
FORD MOTOR COMPANY JUN 2007 – APR 2009
$160 billion Fortune 100 Automobile firm with worldwide presence (www.ford.com)
Security & Controls Champion – IT Security & Risk Services
Provide Security and Controls support to all IT projects and IT processes in Asia Pacific Region
Participate and liaison with internal and global audit teams in audit scope discussions, determine areas of risk.
Facilitate distribution and discussion of audit findings and remediation with the respective stakeholders
Monitor & manage status of major audit comments and report to management.
Assess and review control deficiencies and provide guidance, direction, and consultation for Security regulations and compliance requirements of applications and infrastructure as per Policies and standards
Support annual internal compliance activities, monitor and report status to Management
Conducted 3rd party assessment and review for our vendors
Participate in S-Ox efforts (application and infrastructure compliance as per S-OX 404) as a control’s advisor.
Provide guidance and attestation of security controls to application developers during application design and development.
Led an extremely large program for implementation of generic ID management process to remediate 3 major audit comments across different lines of business.
Provided strategic consulting & advisory to the IT Services and development team for best practice and secure implementation of their projects in alignment to the defined policies and procedures.
Promoted strategic control & risk review services across top executives by providing leadership and subject matter expertise.
Established “Centre of Excellence” for Security & Controls in alignment to SOX – ITGC control testing inviting participation from the control owners to bring in culture of accountability.
IBM GLOBAL SERVICES LTD. OCT 2004 – JUN 2007
$79 billion Fortune 100 IT firm with worldwide presence (www.ibm.com)
Team Leader – Risk & Controls
Served as Team Leader for company’s Global delivery services organization, supervising more than 25 risk leads and managing a delivery portfolio of ~ $10 million
Setup a Risk & Control Unit to implement and monitor and a risk averse and compliant operations for more than 30 engagement delivered from the Global Delivery Services Unit.
Key responsibilities included:
Identifying Key Risks and mapping them to the process to identify the Key Controls for the delivery accounts
Providing the Risk/Controls process charts to the process owners for a regular check
Working closely with the Focal Point(s) for various key aspects for business compliance for the day to day compliance activities been affectively met and amend or propose changes for the same.
Acting as Focal point for the India Competencies during a Corporate Audit and ensure we have all green for every audit which goes through the IT Infrastructure.
Driving Audit readiness project across whole of IBM EMEA for all the competencies involved in IT Infrastructure Management
Assisting the Audit Team to get them an insight into the business overview and IT governance state for every competency, and addressing the Audit results with the findings with every competency to address the shortcomings
Communicating inefficiencies and deficiencies related to the process to the Process Owner
Continuously researched and reviewed latest Info security trends, emerging technologies, threats to incorporate appropriate safeguards with Gartner, Forrester and teams and work with business leaders for implementation
Developed, implemented, and oversaw enforcement of security policies, procedures and work plans
Provided daily strategic leadership which includes practice and people management, delivery excellence, quality assurance and security service management, financial and cost management, operations management, recruitment and on-boarding of new staff, competency and talent management, training and development client (internal and external) satisfaction management for the Risk & Control team.
CONCENTRIX INC. MAR 2003 – OCT 2004
A $3 billion global business and knowledge process outsourcing firm (www.concentrix.com)
Sr Technical Support Officer
Worked as a Network Services Subject Matter Expert providing technical services support to Enterprise Customer and helping them troubleshoot their Operating System and Network Issues.
Provide L3 level escalation support for complex issues and document the knowledge base for re-usability
Mentored a team of 15 technical support officers in groom them both in technical and functional aspects of operations to achieve the goals and objectives
Maintain day to day reports for each individual of the team and handle escalations as required
Worked as In-team trainer for the process providing technical training on the process to the new hires
Work with client counterparts to refine the knowledge base based on quick learning and enhance the FTR ratio
Provided help to management for new transitions/projects and quick onboarding per our delivery model
Leveraged Six Sigma tools and methodologies to help reduce the average call handling time for the entire organization which was appreciated by the Country Manager
ATS INFOTECH PVT.LTD. MAR 2001– MAR 2003
Large IT Educational Institute
Business Development Officer
Performed a multifaceted role of business development and technical trainer to guide and groom students from colleges and help them go through a defined career-based programs
Interfaced with client team to understand the role skill requirements and build that as part of the training curriculum
Visit Tier 2 & 3 colleges and plan educational and career awareness sessions with the student counselling team.
Execution of business plans for creation of more business in the assigned area as per defined strategy from management.
Schedule interviews/seminars in assigned areas for prospective students.
EDUCATION AND PROFESSIONAL DEVELOPMENT
MS in Cybersecurity & Information Risk Management 2018 - Ongoing
Western Governors University Salt Lake City, UT
Bachelor of Management (BBA) 1998-2001
GGD University Bilaspur, India