USAA Classification: Internal
Jharna Jan
Certified Lead Auditor and CISSP trained consultant
Texas
https://www.linkedin.com/in/jharna-jan-004a0a20
An enthusiastic, flexible, self-disciplined individual seeking an opportunity to play a challenging position in an organization that offers high-end technical exposure and an opportunity for personal and professional enhancement with full commitment in company. Having 8+ years of overall experience mostly related to internal risk management and assessment with Business Process Management.
Tools and Frameworks
• Certified Lead Auditor ISO/IEC 27001:2013 from The British Standards Institution (BSI)
• ITIL Version 4 training
• CISSP Training completed from (ISC)2
• Basic Knowledge on HIPPA,GDPR, GLBA, SOX, FISMA, FEDRAMP,SABSA
• Advance Excel
• ITGC Audit training
• PCI-DSS
• Certified Salesforce Administrator
Education
Bachelor of Computer Application, D.A.V. College, Yamunanagar Core skill
• CISSP Trained
• Certified Lead Auditor ISO/IEC 27001:2013 from The British Standards Institution (BSI)
• ITIL Version 4 training
• ITGC Audit training
• Able to conduct security assessments with ISO 27001 requirements.
• Thorough understanding of ISO 27001 clauses and control.
• Experience in supporting ISO 27001 or related audits
• Proficient knowledge of information security management best practices, governance, and risk/compliance assessment methodologies. Proficient understanding of security tools, frameworks, and processes
• Knowledge on BCM, Privacy, and Vendor risk management, Legal and Regulatory requirements in relation to Information Security and IT.
• Knowledge of performing Risk Assessment/ IT Audits on Third Party vendor and collaborate to remediate findings.
• Knowledge on GDPR, HIPPA & SOC.
• Basic Knowledge on ITIL 4.
• Knowledge of Conducting the Audit in PDCA cycle manner for the organizations to fulfill the requirements of ISMS implementation according to the standard of ISO27001.
• Ability to or learn to conduct periodic risk assessments and drive integration of remediation efforts with the risk management process.
USAA Classification: Internal
Project Details
HCLAmerica (Client USAA)
Description: - Sr. Business Process Analyst (Risk &Compliance)
• Managing the Process Engineer partners with cross functional team, in the application of Process engineering principles to design and/ or optimize Business process and their overall performance.
• Executing the BPM strategy across the enterprise.
• Conducting the Gap Assessments before reviewing.
• Presenting Deliverables for Q1, Q2, Q3 & Q4.
• Deriving % increase and % Decrease on YOY Reports data for the compliance reconciliation.
• Identify and managing the risk that stem from the business process.
• Conducting the Risk mitigation (Involves identifying, measuring, monitoring & Controlling).
• Regularly following the Risk and compliance policies, standards and procedures for business activities.
• Analyze and identify the process improvement opportunities.
• Interacts with key Stakeholders to scope & ensure alignment with strategic priorities.
• Working with Stakeholders to ensure project achieve intended results, where risk is proactively identified and mitigated and benefits are validated.
• Experience in reviewing the Customer Disclosures according to rules and regulation.
• High level understanding of the Consumer Financial Products including the saving, credit, deposits and loans.
• Facilitate Client Meetings, performing Data Analysis, Document Reviewing and articulating findings in written reports.
• Maintain proactive communication with third parties to manage expectations ensuring and gaining customer satisfaction and trust.
• Worked on tools like SQL, Tableau, Salesforce, and Advance Excel. Panacea InfoSec Pvt Ltd
Description: Conducting ISMS 3rd party audits
• Able to conduct security assessments with ISO 27001 requirements.
• Thorough understanding of ISO 27001 clauses and control, BCM, Privacy, and Vendor risk management,
• Legal and Regulatory requirements in relation to Information Security, Coordinating with company management to identify potential risks
• Gap assessments
• Coordinate vulnerability scans, and penetration tests on campus systems, document findings, and recommend risk mitigation strategies.
• Conducting due diligence on third parties with the Inherent Risk Questionnaire (IRQs)
• Regularly auditing company procedures, practices, and documents to identify possible weaknesses or risks
USAA Classification: Internal
• Risk Analysis(Qualitative, Quantitative), Sensitive Data Management.
• Basic Knowledge of PCI-DSS, ITIL, SDLC, SOC.
• Prepare reports and action plans.
• Implementing policies and procedures to uphold laws and regulations Biju's & WhiteHatJunior (Business Analyst Operations)
• Was part of Risk and compliance team.
• Assessing company operations to determine compliance risk.
• Developing and implementing an effective legal compliance program
• Identify Risk, Assess, Develop strategies, Implement Control, establish policies & procedures, Training employees, Continuous Monitoring the risk indicators to be compliant.
• Technical Vendor Compliance, managing team SLA and represent team during reviews.
• Working with Stakeholders to ensure project achieve intended results, where risk are proactively identified and mitigated and benefits are validated.
• Coordinate proactively auditing processes, practices and documents
• Providing insights into risk assessment outcomes and risk management strategies. Delhi Public School (Vendor & Stakeholder Compliance)
• Vendor Management and coordination
• Collaborate with external auditors and HR when needed
• Compliance management
• Risk management, Risk Analysis,
Pacific IT Consulting (Business Operation Analyst- Risk & Compliance)
• Vendor Compliance, SLA Maintenance,
• Plan vendor governance and invite the vendor for supply of IT manpower.
• Providing insights into risk assessment outcomes and risk management strategies. Eschool Buddy Retail PVT. L.T.D (Operational Analyst- Vendor Compliance)
• Bi-Weekly planning for conducting the audits according to the customers.
• Coordinating with managers/operations head for fault reduction.
• Helping in conducting the internal audits.
• Assist in the development of audit programs for operational and compliance audits and execute testing accordingly
• Working with Stakeholders to ensure project achieve intended results, where risk are proactively identified and mitigated and benefits are validated.