Over 20 years of Consulting and Industry experience with top tier clients in Canada, India, US and Middle East.Top Areas of Experience and Expertise:a) Cyber Security• Policy, Procedures and Directives for a) Infrastructure/Network, b) Logical Access and c) Cloud Security.• Socializing Policies with a larger group of 100 plus stakeholders including Security Architects, Cloud Security teams, IT Operations team, IAM teams, CISO teams.• CISO/CIO Reporting– - Using multiple tools and data sources: End Point Detection and Response, Web Application Firewall, Advanced Malware detection, Data Science/Risk Based Vulnerability Management system, PAM, phishing tools, etc.- Establish trends and action plan based on the trends.- Mapping reports to areas of NIST – Identify, Protect, Detect, Respond and Recover.• Business Continuity Planning – Single point of contact for the Information Security Department covering 100 plus staff members across 5 locations. Updated the BCP in ‘Fusion’ software.b) Information Technology General Controls (ITGC/GITC)• Policy, Procedures and Directives• Identifying and documenting Risks and associated controls and test procedures (advisory)• Testing of Design Effectiveness and Operating Effectiveness of controls (audit capacity)• Expertise in PCAOB guidelines, Sarbanes Oxley Act (SoX), SOC assignments, PCI-DSSc) Identity and Access Management• Documenting Access Policy and Procedure• Identifying tools that would help manage the Privilege and other access• Integrating the tools with existing authentications and managing periodic recertificationsFrameworks and Standards used:NIST, ISF, COSO, COBIT, ISO 27001 and PCI-DSS
Listed skills include Internal Audit, Sarbanes Oxley Act, Auditing, Internal Controls, and 41 others.