Anand Choksi, CISSP, CRISC, CDPSE, CISA, PMP

CEO

Bengaluru, Karnataka, India16 yrs 9 mos experience
Highly Stable

Key Highlights

  • 18+ years in Information Security leadership.
  • Expert in GRC and Cybersecurity compliance.
  • Certified in multiple security frameworks and standards.
Stackforce AI infers this person is a Cybersecurity expert with extensive experience in GRC across multiple industries.

Contact

Skills

Core Skills

Information SecurityGrcInformation Security ManagementData ProtectionPci DssIt AuditBusiness Continuity

Other Skills

Agile MethodologiesApplication SecurityBusiness Continuity PlanningBusiness IntelligenceCOBITCloud ComputingCloud SecurityComputer SecurityCybersecurityDLPData Loss PreventionData PrivacyData SecurityDisaster RecoveryEnterprise Risk Management

About

Anand is an experienced Information Security Leader with 18+ years of experience in designing and implementing Information Security solutions, having assisted client organisations across Canada, US, Europe, India, Africa and Middle-East achieve their business and regulatory objectives by reducing cyber risks while improving their security posture. Anand heads the Information Security Compliance function for Razorpay. Prior to his current role with the Razorpay, Anand headed the Cyber GRC function for Flipkart (A Walmart company). He has also worked extensively in the Information Security Consulting space with EY, Aujas, Deloitte and Tech Mahindra. His technical expertise is mainly in the field of IT Governance, Risk and Compliance (GRC) in the areas of Third Party Risk Management , ISO 27001 Implementations, NIST assessments and Cybersecurity Controls Testing, Business Continuity Management (BCM) Advisory, Standard Operating Procedures (SOP) development, Security Program Management, Cyber Security Assessments and Roadmap development , Data Protection Strategy development, Cyber Security Vendor Evaluation & Selection and PCI DSS Implementations. Anand has serviced clients across sectors including E-commerce, Consumer Products and Retail, Financial Services, Diversified Industrial Products and Technology. He is a Certified Information Systems Security Professional (CISSP), Certified in Risk and Information Systems Control (CRISC), Certified Data Privacy Solutions Engineer (CDPSE), Certified Information Systems Auditor (CISA), Project Management Professional (PMP), Certificate of Cloud Security Knowledge (CCSK) and ISO 27001 Certified Lead Implementor and Auditor. He holds a Bachelor's degree in Business Administration and a Master’s in Computer Applications.

Experience

Razorpay

Head - Information Security Compliance

Aug 2025Present · 7 mos · Bengaluru, Karnataka, India

  • Lead the Infosec Compliance charter for Razorpay and its group entities

Flipkart

2 roles

Group Head - Cyber GRC

Jul 2023Aug 2025 · 2 yrs 1 mo · Bengaluru, Karnataka, India · Hybrid

  • Lead the Cyber GRC charter for Flipkart (A Walmart company) and its subsidiaries - Myntra, Cleartrip, Yaantra, ANS Commerce, Supermoney and Flipkart Commerce Cloud.
  • Key Responsibilities:
  • Security GRC Strategy
  • Security Governance, Policy & Standards Management
  • Information Security Compliance
  • Third Party Risk Management
  • GRC Tooling & Process Integration
  • Information Security Risk Assessments & Reporting
  • Risk Register Management
  • Risk Treatment, Issue & Exception Management
  • M&A Security Due Diligence
  • Security Awareness and Training
Team ManagementInformation SecurityProblem SolvingIT Risk ManagementPresentationsMentoring+1

Head of Information Security at eKart, F1, Jeeves, Flipkart Wholesale and Flipkart Re-commerce

Jul 2023Aug 2025 · 2 yrs 1 mo · Bengaluru, Karnataka, India · Hybrid

  • Leading Infosec for FK group entities - eKart, F1, Jeeves and FK Re-commerce (Yaantra)
Team ManagementProblem SolvingMentoringInformation Security

Myntra

Head - Cyber GRC & Data Protection

Mar 2021Jun 2023 · 2 yrs 3 mos · Bengaluru, Karnataka, India

  • Heading Cyber GRC, Third Party Risk Management (TPRM) and Data Protection / Insider Risk for Myntra (A Walmart company). Also, lead Information Security for Ekart Logistics.
  • Overall Accountability for:
  • Security GRC Strategy
  • Security Governance, Policy & Standards Management
  • GRC Tooling & Process Integration
  • Information Security Risk Assessments & Reporting
  • Risk Register Management
  • Risk Treatment, Issue & Exception Management
  • Third-Party Risk Management
  • M&A Security Due Diligence
  • Security Awareness and Training
  • External Security Audit / Compliance
  • Internal Security Controls Assessment & Management
  • Data Protection Tooling and Enablement
  • Insider Threat Incident Management and Investigations
Team ManagementInformation SecurityProblem SolvingIT Risk ManagementMentoringGRC

Ey

Manager

Sep 2012Feb 2021 · 8 yrs 5 mos · Toronto, Ontario, Canada / Bangalore

  • As an Experienced Manager, led multiple engagements in the following areas while working in EY India and Canada. Clients included companies in the E-commerce, Consumer Goods, Technology, Manufacturing, Pharma and BFSI space:
  • NIST Assessments and Development of Cybersecurity Roadmaps
  • ISO 27001 Implementations / Readiness Assessments
  • Third Party Security Assessments
  • Drafting of Security Policies, Procedures and Hardening Standards
  • Third Party Assurance (SOC 2 / 1)
  • GRC Tool Implementations
  • Data Protection Strategy Development
  • GDPR Assessments
  • Security Program Management
  • Network Architecture Reviews
  • Internal / External IT Audit
Information Security ManagementTeam ManagementDLPIT Security AssessmentsISO 27001Internal Audit+8

Aujas

Senior Consultant

Apr 2010Aug 2012 · 2 yrs 4 mos · Mumbai Area, India

  • Risk Advisory Services
  • Service Delivery (Key Projects) :
  • PCI DSS Implementation for a marine travel company
  • PCI DSS Gap Analysis for a leading web hosting company
  • Application Data Flow Analysis for one of India’s leading private banks
  • Data Protection (DLP / DRM / DAM) Vendor Evaluation for India’s largest stock exchange
  • Data Flow Analysis and Data Protection Framework Development for a leading PSU bank
  • Incident Management Framework Development and Symantec Brightmail rules fine-tuning for India's leading Telecommunications Company
  • Websense DLP rules fine-tuning for a leading telecommunications company
  • Data Flow Analysis and Data Protection Strategy Development for a leading life insurance company headquartered in the Netherlands
  • Data Protection Operations Management for India's leading telecommunication company
  • ISO 27001 Implementation for a leading payment card processing company
  • ISO 27001 internal audit for a leading KPO
  • ISO 27001 internal audit for a leading consumer finance company
  • Interim information security management support for a leading stock broking company
  • Practice Development, Team management and Presales :
  • Developed winning proposals around Data Protection, PCI DSS, ISMS, BCP, IT Governance, RBI IS Guidelines Gap Assessment
  • Devised a reusable template for use in Application Data Flow Analysis engagements
  • Acted as a product manager for the Aujas Compliance Manager Tool and conducted demos on the tool for several banks in India
  • Developed a proposal for offering Cloud Computing Security risk services
  • Conducted interviews for potential hires
  • Mentored and developed a team of 4 people functionally reporting to me. Conducted appraisals and identified areas of Improvement for them
PCI DSSTeam ManagementData SecurityData Loss PreventionDLPISO 27001+4

Deloitte india

ERS Consultant

May 2009Apr 2010 · 11 mos · Mumbai Area, India

  • Service Delivery (Key Projects) :
  • Reserve Bank of India Special purpose IS Audit for a leading private bank
  • Network Security Audit/Architecture Review for a US based medical device manufacturer
  • Agreed Upon Procedures testing for a major global BPO
  • Physical Security Review for India’s largest Oil and Gas Company
  • IS Audit for a leading UK based insurance company
  • BCP framework development for a leading Indian life insurance company
  • Presales:
  • Developed proposals / approach notes around Cloud Computing use in Government, Cloud Computing Risks, Converged Security and SOP development
IT Security AssessmentsIT AuditBusiness Continuity PlanningProblem SolvingIT Risk ManagementPre-sales+1

Tech mahindra

Security Consultant

Oct 2006Feb 2009 · 2 yrs 4 mos · Mumbai Area, India

  • I joined Tech Mahindra fresh out of college. Worked across service lines on a number of engagements which included:-
  • BT Security Evaluation and Certification Scheme (BTSECS) Compliance/Vulnerability Management for a major platform in BT Retail
  • SOP manual development for BTSECS
  • Developing training material for inhouse use on BCP, ITIL, Network Security, PCI DSS, SOX, DPA et al.
  • Service provisioning/assurance workflow designing for BT Wholesale offerings such as WBC, IPStream, DataStream and FeatureNet
Information Security ManagementIT Security AssessmentsISO 27001Problem SolvingInformation Security StandardsGRC

Education

Gujarat University

Master of Computer Applications - MCA — Computer Applications

Gujarat University

Bachelor of Business Administration - BBA — Marketing and Finance

National Institute of Information Technology

DNIIT

St Xavier's High School Loyola Hall

HSC

Don Bosco High School - India

Primary Schooling

Stackforce found 100+ more professionals with Information Security & Grc

Explore similar profiles based on matching skills and experience