Akshatha M

Associate Consultant

Bengaluru, Karnataka, India9 yrs 6 mos experience
Highly Stable

Key Highlights

  • Led successful GRC initiatives at Ola, transforming compliance culture.
  • Achieved zero major findings in regulatory compliance audits.
  • Implemented automated security awareness programs, reducing manual efforts by 90%.
Stackforce AI infers this person is a Governance, Risk, and Compliance expert in the SaaS industry.

Contact

Skills

Core Skills

Governance, Risk Management, And Compliance (grc)Project ManagementCyber Risk ManagementThird Party Risk Management (tprm)Threat & Vulnerability ManagementWeb Application SecurityApplication Security

Other Skills

Android pen testingBurp SuiteCross-functional Team LeadershipData PrivacyInformation SecurityInformation Security AwarenessInformation Security Management System (ISMS)Information Security PolicyManagementMobile SecurityPenetration TestingProduct SecurityProgram DevelopmentRational AppScanSecure Code Review

About

I'm Akshatha, an experienced professional in Governance, Risk, and Compliance (GRC), specializing in developing and implementing frameworks that ensure a holistic approach to risk management and regulatory compliance. - Over the past few years, I've played a pivotal role in transforming Olacabs through strategic GRC initiatives. From revamping policies and procedures to spearheading the implementation of automation tools, my focus has been on efficiency, accuracy, and encouraging a culture of compliance awareness. - I played a key role in the development and implementation of the Ola's GRC framework ensuring holistic approach to Risk and Compliance. - Established and maintained strong relationships with internal and external stakeholders, fostering a collaborative approach to GRC initiatives. - I led the implementation of Automated Employee Security Awareness Program resulting in a 90% reduction in manual efforts. Developed and delivered security training programs on compliance, policies tailored to the organization's needs and industry regulations to enhance organizational awareness. - Additionally, I've successfully orchestrated regulatory compliance audits, achieving zero major findings and ensuring adherence to applicable laws and standards. My proficiency extends to ISO 27001, PCI DSS, RBI, IRDAI, and GDPR compliance, where I've not only guided my organization through audits but also implemented fixes and improvements aligning with the standards. šŸ’” Highlights of my expertise: **ISO 27001**: Successfully navigated external audits with no significant issues, earning praise for ISO 27001 compliance. **PCI DSS**: Collaborated closely with QSAs, resolved compliance gaps, and ensured alignment with PCI DSS 4.0 standards. **RBI and IRDAI**: Demonstrated a strong grasp of cyber security guidelines, leading the organization in self-assessments for strict adherence. **GDPR**: Maintained meticulous documentation, collaborated with auditors, and upheld the organization's commitment to GDPR compliance. **Third-Party Risk Assessment**: Assisted in the development of security assessment criteria, conducted vendor reviews, and provided recommendations for security improvements. šŸ¤ Let's connect! If you share a passion for elevating GRC standards, navigating compliance landscapes, or simply want to exchange insights, feel free to reach out.

Experience

Nxp semiconductors

Senior Lead Information Security Business Analyst

May 2025 – Present Ā· 10 mos Ā· Bengaluru, Karnataka, India Ā· Hybrid

Ola

5 roles

GRC Lead

Promoted

Apr 2023 – Mar 2025 Ā· 1 yr 11 mos Ā· On-site

Secure Code ReviewWeb Application SecurityPenetration TestingGovernance, Risk Management, and Compliance (GRC)Product SecurityTeam Building+2

Assistant Manager GRC

Promoted

Apr 2022 – Apr 2023 Ā· 1 yr Ā· On-site

Cyber Risk ManagementInformation Security Management System (ISMS)Third Party Risk Management (TPRM)Information Security AwarenessInformation Security Policy

Security Engineer III

Dec 2021 – Apr 2022 Ā· 4 mos Ā· On-site

Threat & Vulnerability ManagementThreat ModelingSecurity Training

Security Engineer II

Dec 2020 – Dec 2021 Ā· 1 yr Ā· On-site

Secure Code ReviewWeb Application SecurityPenetration TestingThreat Modeling

Security Engineer I

Dec 2018 – Dec 2020 Ā· 2 yrs Ā· On-site

Secure Code ReviewApplication SecurityVulnerability Assessment and Penetration Testing (VAPT)Mobile Security

Cigital, inc (a part of synopsys)

Associate Consultant

Jul 2016 – Dec 2018 Ā· 2 yrs 5 mos Ā· Bengaluru, Karnataka, India

  • Identify security vulnerabilities and articulate the business risks to customers.
  • Perform Source code review for various types of application such as Web, Web Services, Mobile and Thick Client.
  • Familiarity in source code review for different languages such as Java, .NET, PHP, Javascript, Typescript, Objective C.
  • Perform web application Penetration Testing of all types and Hybrid Android Mobile Applications testing.

Education

Dayananda Sagar College of Engineering, BANGALORE

Bachelor's Degree — Information Technology

Jan 2012 – Jan 2016

MES Chaitanya PU College

Jan 2010 – Jan 2012

Lions English High School, Sirsi

High School

Jan 2009 – Jan 2010

M R Sakhare English Medium School, Hubli

High School

Jan 2006 – Jan 2009

MHPS Balikoppa, Siddapur

Jan 2001 – Jan 2006

Stackforce found 100+ more professionals with Governance, Risk Management, And Compliance (grc) & Project Management

Explore similar profiles based on matching skills and experience