Ankit Patel
**************@*****.*** Ontario, Canada +1-902-***-****
Summary
Cybersecurity and GRC leader with 10+ years of experience strengthening security governance, enterprise risk management, regulatory compliance, third-party risk, cloud and infrastructure security, and operational resilience across telecommunications and financial services. Proven success leading enterprise initiatives aligned with NIST CSF 2.0, ISF Benchmark/SOGP, SOC 2, ISO/IEC 27001, PCI DSS, OSFI B-13, and CMMC—reducing compliance gaps by 25%, assessing 150+ third parties annually, and enabling executive cyber- risk decisions across 10+ high-priority initiatives. Trusted advisor to senior leaders, translating complex security, audit, cloud, and vulnerability findings into prioritized remediation roadmaps, risk-treatment plans, KPI/KRI reporting, and measurable risk reduction. Skills
Cybersecurity Governance & Risk: Security Governance, Enterprise Risk Management, Enterprise Risk Assessments, Third-Party Risk Management, Security Policy Development, Risk Treatment Planning, Security Architecture Reviews, Audit Management, Vulnerability Management
Frameworks & Regulatory Compliance: NIST CSF 2.0, ISO/IEC 27001, SOC 2, PCI DSS, COBIT, ISF Benchmark/SOGP, OSFI B- 13, CMMC
Cloud & Infrastructure Security: AWS, Microsoft Azure, Cloud Security, IAM, Kubernetes, Linux, PKI, TLS, High Availability, Disaster Recovery
Security Operations & Incident Response: Incident Response, Threat Detection, Security Monitoring, Malware Analysis, Digital Forensics, Network Security, IDS/IPS, SIEM
DevSecOps & Automation: CI/CD Security, Terraform, Ansible, Python, PowerShell, Shell Scripting, SQL GRC Platforms & Reporting: ServiceNow GRC, Archer, Vanta, Microsoft Defender, Microsoft Sentinel, Nexpose, Kenna, BitSight, Black Kite, Power BI, Risk Dashboards, KPI/KRI Reporting Work Experience
Cyber Security Advisor Rogers Communications & Rogers Bank Jul 2022 – Present
• Reduced compliance gaps by 25% by establishing and maturing a cybersecurity governance program aligned with NIST CSF 2.0, ISF, SOC 2, ISO/IEC 27001, and OSFI B-13.
• Led enterprise security maturity assessments and translated control gaps into prioritized remediation roadmaps, risk-treatment plans, and accountable action plans.
• Orchestrated IT participation in SOC 2, ISF, NIST CSF, OSFI B-13, ISO/IEC 27001, and cyber insurance assessments, coordinating evidence submissions, walkthroughs, management responses, and remediation tracking.
• Assessed 150+ third parties annually across security, privacy, and operational risk domains, partnering with Legal and Procurement to strengthen contractual security requirements.
• Enabled executive cyber-risk decisions across 10+ high-priority initiatives through Power BI dashboards, KPI/KRI reporting, and consolidated risk insights from audits, assessments, and insurance reviews.
• Evaluated 40+ cybersecurity policy exceptions annually, advising leadership on approvals, rejections, compensating controls, and mitigation requirements.
• Strengthened audit readiness by standardizing evidence tracking stakeholder coordination, submission practices, and remediation follow-up across technology teams.
• Influenced cloud and infrastructure security priorities by advising engineering and IT teams on vulnerability remediation, secure configuration, regulatory compliance, and risk acceptance.
• Increased employee security-awareness completion rates by 40% by leading CyberSTARR and Leadership Chat Series initiatives that improved engagement and accountability.
• Developed three junior team members through coaching on risk assessments, audit readiness, cybersecurity frameworks, and consistent application of GRC practices.
Senior Production Support Specialist Rogers Communications Nov 2018 – Jul 2022
• Provided Jira and Confluence application health, operational risk, and change updates to directors and senior managers, improving visibility into platform performance and support priorities.
• Strengthened Jira and Confluence resiliency by implementing Dynatrace monitoring, coordinating remediation activities, and supporting AWS-hosted application environments.
• Managed incidents, problems, and change records through ServiceNow, ensuring production support activities aligned with enterprise change-management and operational-risk requirements.
• Reviewed solution designs and architecture specifications to validate Jira compatibility, resiliency, supportability, and operational readiness requirements.
• Investigated IDS alerts, network traffic, endpoint artifacts, disk analysis, and memory forensics to identify command-and-control activity, malicious artifacts, and targeted hosts.
• Supported security assessments using Metasploit, OWASP ZAP, and Burp Suite, identifying non-compliant assets, input-validation issues, and critical vulnerabilities requiring remediation.
• Developed SIEM correlation rules and documented incident-response activities aligned with PCI DSS requirements, contributing to zero findings in the related compliance review.
• Supported SOC investigations through Jira-based incident analysis, WAF policy updates, Microsoft Sentinel log collection, secure handling of sensitive log data, and AWS containment activities. Network Engineer Altumcore Technologies Jul 2014 – Dec 2016
• Maintained network availability across LAN and WAN environments supporting 150+ workstations and coordinated firmware and hardware upgrades to minimize disruption.
• Installed, configured, and supported Windows operating systems, applications, and peripherals for 200+ users while maintaining technical documentation and hardware standards.
• Analyzed packet captures to identify command-and-control activity, supporting containment of three threats and helping prevent lateral movement to point-of-sale systems.
• Reviewed 45+ Azure security findings and prioritized remediation actions, reducing resolution time for critical vulnerabilities by 30%.
• Performed web application security testing using Burp Suite, documented eight critical SQL injection and insecure direct object reference findings, and collaborated with developers on remediation.
• Developed 12 Splunk detection rules for suspicious data-access patterns, supporting detection and prevention of a potential 16 GB data-exfiltration event.
• Conducted memory forensics across five compromised endpoints, developed three YARA detection rules, and supported credential resets for 1,200 accounts.
• Identified unencrypted personally identifiable information across four retail platforms and implemented field-level encryption and access controls aligned with PCI DSS.
Education
Master of Engineering in Internetworking, Dalhousie University, Canada Certifications
CISM AWS Certified Security – Specialty CCNA
Fortinet NSE 1 & 2 SAFe Scrum Master 6.0 Cradlepoint Certified Network Associate