Srinivas Reddy M
Information Security Analyst
*********@*****.*** 965-***-****
Professional Summary:
In quest of a position in a an organization where I can utilize my experience eager to contribute to team success through hard work, attention to detail and excellent organizational skill. Incident Management, Vulnerability Assessments and threat Analysis. Motivated to learn, grow, and excel in the path of Assessments and Information Security Audit.
Skills:
CISA
NIST / GRC
Incident Response
SOX
HIPAA
Policies and Procedures
Demisto
Nexpose Rapid 7
Risk Management
ISO27001
SOC Type 2
Crowdstrike
Certifications:
Certified Information Systems Auditor (CISA)
ITIL V3Certified
Microsoft Certified Professional ( MCP )
Artificial Intelligence Governance Professional (AIGP) in learning phase.
Education:
Bachelor of Sciences from Sri Krishnadevaraya University.
Professional Experience:
Adecco India Pvt Ltd: (Project Rolled Out) April 2026– May 2026
Senior Risk and compliance Analyst
Performing internal audits, risk assessments, IT controls testing for ISO 27001 compliance.
Risk Assessment and selection of the issues that should be included and addressed in incident management process.
Plan and execute compliance monitoring review and set up management reporting.
Educate staff on compliance issues and procedures.
ITGC / ITAC controls testing as per the project requirements.
Tested and validated General Controls (ITGC) across user access management, change control, and IT operations to support management’s SOX Section 404 internal control assessments.
Support in facilitating the process and key controls selection including obtain process and controls understanding and directly responsible for ongoing controls validation and reporting.
Managed quarterly user access reviews (UAR) and Segregation of Duties (SoD) testing for SOX-critical systems, verifying that privileged access aligned with organizational policy.
Perform design effectiveness (TOD & TOE) and test internal controls as part of regular process audits.
Review SOC reports (SOC Type 2) reports and able to relate ITGC controls and uploaded the evidence in Archer tool for documentation.
HCL Technologies July 2024 to Jan 2025
Consultant. (Program Manager)
Coordinate vendors in review and third-party contracts.
Administer third-party risk with One Trust.
Manage the vendor onboarding process and report risk issues to senior management and the board.
Collaborated with cross-functional teams and external vendors to facilitate seamless coordination and successful execution of various activities.
Review vendor security posture and ensure defined controls are in place.
Access Management & Segregation of Duties (SoD)
Review activities to remediate control gaps and assess whether the risk has been fully mitigated and the implemented controls are sustainable.
Conduct risk evaluation and assessment of likelihood and impact of audit findings, and exceptions.
Evaluating TPRM controls and processes and defining evidence of compliance.
Satcon INC, Client: Cepheid, Sunnyvale Apr 2019 to Aug 2023
Information Security Analyst.
Coordination with Vendor risk management team through One Trust.
Conduct risk evaluation and assessment of likelihood and impact of audit findings, and exceptions.
Risk assessments by calculating inherent risk based on data asset value and threat impact, then determined residual risk after validating the design and effectiveness of existing IT controls.
Conducted initial inherent risk assessments across business applications and third-party vendors by evaluating data sensitivity.
Worked on both inherent and residual risks for our projects, making sure management clearly understood how much risk our security controls were actually reducing.
Evaluated third-party vendor applications by measuring their initial inherent risk to our network, applying control testing, and documenting the final residual risk to ensure it aligned with corporate risk appetite.
Incident Response: Evaluated the operational readiness of incident response playbooks specifically tailored for potential PHI data breaches.
Managed quarterly user access reviews (UAR) and Segregation of Duties (SoD) testing for SOX-critical systems, verifying that privileged access aligned with organizational policy.
Perform design effectiveness (TOD & TOE) and test internal controls as part of regular process audits.
Review SOC reports (SOC Type 2) reports and able to relate ITGC controls and uploaded the evidence in Archer tool for documentation.
Access Management & Segregation of Duties (SoD)
Experience in ITGC / ITAC testing, ISO 27001, and External/internal audits.
Tested and validated General Controls (ITGC) across user access management, change control, and IT operations to support management’s SOX Section 404 internal control assessments.
Quess Corp Ltd: Franklin Templeton Investments, India Sep 2016 to Apr 2018
Change Manager
Risk and Governance with Archer Tool.
Performing internal audits, IT SOX risk assessments, IT controls testing for ISO 27001 compliance.
Review activities to remediate control gaps and assess whether the risk has been fully mitigated and the implemented controls are sustainable.
Monitoring Assets on the Vulnerability Management tools and send the reports to the concern department for remediation.
Coordinate and work with different team users on phishing or suspicious emails.
Manually validating report findings to reduce false positives.
Analyzing scan reports and suggest remediation/mitigation plan.
Take security questions from the auditors and help engagement prepare evidence to showcase to auditors
Review the security access controls with AD team to fill the gaps with respect to security and audit.
Experience with change control policy and procedures.
Host CAB calls and document the decisions.
Facilitation of Finance, Database and HR teams Change Requests upgrades, break fixes.
Prioritize change requests, assess their impact, and accept or reject changes.
Document change management processes and change plans.
Was part of Global Internal audit team and ensure identifying risks in key areas of IT both Internal & External audit functions.
Quess Corp Ltd Aug 2014 to Sep 2016
Avaya Support Engineer
Coordinating cross-functional incidents, collaborating with stake holders and response teams for the timely response and resolution of incidents.
Perform Dynamic Assessment and verify false positives.
Experience in alert handling, standard availability and performance report generation.
Preparing the weekly and monthly Vulnerability scan reports as per the SLA and assigning the works.
Ensure incident records are appropriately documented with supporting evidence that is thorough, accurate, and complete.
Perform quality checks for change requests at all approval phases, reviewing the risk and impact analysis to verify this has been performed thoroughly.
Ensure the smooth process of change migrations and Incidents.
Handling customer complaints as per Customer Management Framework guidelines.
Experience with change control policy and procedures.
Host CAB calls and document the decisions.
Facilitation of Finance, Database and HR teams Change Requests upgrades, break fixes.
Prioritize change requests, assess their impact, and accept or reject changes.
Document change management processes and change plans.
Virtusa, India Feb 2013 to Aug 2014
Onsite Systems Engineer
Submission of Weekly & Monthly Stock Report to the IT Management.
Monitoring inventory of assets is always maintained.
Monitor and maintain the Asset Management System as computer input, asset condition renewals and upgrade.
Responsible for handling all incident notifications as per agreed process.
Ensure incident timeline Report is created immediately after resolution.
Check if the received assets are in good working order without any physical damage.
Handling user complaints as per Management Framework guidelines.
Coordination with vendors for warranty, Annual maintenance contract and related support.
Login2class.com, India Mar 2011 to Jan 2013
Linux Engineer
Installation and Maintenance of Software applications as per the client’s requirement.
Configure LDAP clients on server test and troubleshoot for maintaining network and data security.
Maintain software repositories and apply software updates.
Call technical support to clients on a regular basis.
Adding, removing, or updating user information such as logins and passwords.
Support the requests of the production and development teams to solve any problems related to the Linux servers.
Upgrading, installing, and configuring application software and computer hardware.