Vinod Bavara

CEO

Mumbai, India28 yrs experience
Most Likely To SwitchHighly Stable

Key Highlights

  • Led multiple ISO 27001 implementation projects.
  • Expert in Information Security and Compliance Management.
  • Extensive experience in Cyber Security frameworks.
Stackforce AI infers this person is a Cyber Security expert with extensive experience in Information Security Management and Compliance.

Contact

Skills

Core Skills

Information Security ManagementIso 27001Compliance ManagementCyber Security ComplianceRisk ManagementIt GovernanceInformation SecuritySecurity OperationsIncident ManagementTechnical SupportNetwork Management

Other Skills

Application SecurityAudit FindingsAudit ReportBSEBusiness ContinuityBusiness Continuity PlanningCCNACEHCISACISSPCOBITCompliance RequirementsComputer ForensicsComputer SecurityCyber Security

About

Working with QRC Assurance and Solutions Pvt. Ltd. · Audit the management systems, ISO/IEC 27001:2013, 27001:2022 and 27701:2019. Analyse the controls effectiveness, Identify the control deficiencies, Prepare the Audit Report, Executive Summary Presentation etc. · Assessing the organizations independently and also as team member of the auditing team · Preparation of template documents for Information Security/Cyber Security Policy, Procedures, Guidelines · Conduct the Information System Audit for various regulatory requirements like RBI, SEBI, UIDAI. One Point One Solutions Ltd., Navi Mumbai - Information Security and Compliance Manager. • Manage information and cyber security and compliance requirements for ISO 27001 and BFSI Clients • SIEM management. • Vulnerabilities management. • To ensure audit findings, if any are closed within time frame. I was employed by BTP Consultants for Abu Dhabi Islamic Bank project, Abu Dhabi. • Maintain Bank's ITD Standards, processes, procedures and controls in support of ADIB’s business needs and compliance requirements. • Ensured risks, controls and KPIs are identified for each process. • Follow-up on remediation actions for internal and external audit findings related to IT. I have managed 4 ISO 27001 implementation projects and can manage its full life cycle. • Develop and implement ISO 27001 compliance documentation (Risk Assessments, Policies, Procedures etc.), • Vulnerability Assessments and remediation cycles I was part of e-Cop Security Operations Center (SOC), Singapore for 1 year and part of Allied Digital SOC, India for 3 years. I guided SOC team for the operational activities like monitoring and incident handling. I aligned Allied Digital SOC processes with ISO 27001 and ISO 20000 standards. Banking (BFSI) Experience: • Familiar with Reserve Bank of India Cyber Security Framework. Mapped ISO 27001 Clauses and controls against Reserve Bank of India requirements. • Business Process Outsourcing for SBI Bank, SBI Life Insurance, ICICI Bank, ICICI Securities, Kotak Securities, EdelweissTokio Insurance, Bharti AXA Insurance etc. • IT GRC Consultant at Abu Dhabi Islamic Bank • While at Allied Digital, part of team for implementation of LANDesk agent and PointSec (Hard Disk encryption) installation on 55000+ desktops at ICICI Bank. Oil and Gas Experience: • IT Security Consultant, Rasgas Company Limited, Qatar. • Secure wireless setup at Hindustan Petroleum Corporation Ltd, Mumbai using RADIUS server. • PC Network Engineer, EXPEC, Saudi Arabian Oil Company project.

Experience

Qrc assurance and solutions pvt ltd

VP - GRC

Jun 2022Present · 3 yrs 9 mos · Navi Mumbai, Maharashtra, India

  • · Audit the management systems, ISO/IEC 27001:2013, 27001:2022 and 27701:2019. Analyse the controls effectiveness, Identify the control deficiencies, Prepare the Audit Report, Executive Summary Presentation etc.
  • · Assessing the organizations independently and also as team member of the auditing team
  • · Preparation of template documents for Information Security/Cyber Security Policy, Procedures, Guidelines
  • · Conduct the Information System Audit for various regulatory requirements like RBI, SEBI, UIDAI.
ISO/IEC 27001:2013ISO/IEC 27001:2022ISO/IEC 27701:2019Audit ReportInformation Security PolicyCyber Security Policy+2

One point one solutions

Manager - Information Security & Compliance

Jul 2020Jun 2022 · 1 yr 11 mos · Mumbai Suburban, Maharashtra, India

  • Improving Information Security across 4 locations (Mumbai, Bangalore, Chennai, Gurugram).
  • Information Security Policy and Procedures Reviews and Improvements
  • ISO27001 Recertification
  • Meet customers’ (Banking, Insurance, Securities, Utilities) security and compliance requirements.
  • Vulnerability management
  • SIEM management
  • Conduct Security Awareness Training
  • Test the DR/BCP
  • Determine logging requirements as per customer information / cyber security requirement
Information SecurityISO 27001Vulnerability ManagementSIEM ManagementSecurity Awareness TrainingInformation Security Management+1

Northstar consulting

Cyber Security Consultant

Oct 2019Jul 2020 · 9 mos · Mumbai Metropolitan Region

  • Helping clients to be compliant to BSE / NSE / NCDEX Cyber Security and Cyber Resilience Framework.
  • Mapping of ISO 27001 clauses and Annex-A controls to Reserve Bank of India Cyber Security Framework.
Cyber SecurityISO 27001BSENSENCDEXCyber Security Compliance+1

@ btp for abu dhabi islamic bank

IT GRC Consultant

Jul 2018Apr 2019 · 9 mos · Abu Dhabi, United Arab Emirates

  • IT GRC Consultant @BTP for Abu Dhabi Islamic Bank
  • Responsible for maintaining, optimizing and improving ITD processes and documentation.
  • Maintain IT Standards, processes, procedures and controls in support of ADIB’s business needs and compliance requirements.
  • Optimize and improve ITD processes and documentation that meet best-practice (ITIL and COBIT) and audit requirements.
  • Follow-up on remediation actions for internal and external audit findings related to IT Governance.
  • Ensured RACI, risks, controls and KPIs are identified for each process.
  • Perform other IT Governance activities and duties as required.
IT GovernanceIT StandardsCompliance RequirementsRisk ManagementAudit FindingsCompliance Management

Northstar consulting india

Consultant

Feb 2016May 2018 · 2 yrs 3 mos

  • Prepaid Payment Instruments are (PPI) are used for digitized payment for procurement of goods and services and electronic banking for transfer of funds. I helped client become compliant with Prepaid Payment Instruments regulation from Reserve Bank of India.
  • Prepare Policies, Procedures and other required documentation.
  • Information Security Awareness Training
  • Teaching Information Technology - Chartered Accountant Course
Prepaid Payment InstrumentsInformation Security Awareness TrainingPolicies and ProceduresCompliance ManagementInformation Security

Aman

Sr. Information Security Consultant

Sep 2011Jan 2016 · 4 yrs 4 mos · Doha, State of Qatar

  • 3 ISO 27001 projects,
  • Manage development and implementation of the Information Security Management System, ISO / IEC 27001,
  • Conduct GAP Analysis to know the gaps that exist between the ISO 27001 / Qatar NIAP requirement and current security practices,
  • Perform risk assessments manually and using software (RM Studio),
  • Manage development and implementation of information security policies, procedures, forms and registers,
  • Develop and test BCP / DR process,
  • Develop and conduct information security awareness training,
  • Vulnerability Assessments using nmap, Nessus,
  • Network Risk Monitoring - RedSeal,
  • Information Security Governance - part of the team that developed an application for compliance with ISO 27001 and National Information Assurance Policy, a Qatar Government policy to safeguard Qatar Government and Industry information and related systems,
  • Assist the sales team with request for proposals and technical documentation,
  • Perform technical presentations, Proof of concepts and demo for customers and prospects.
ISO 27001Risk AssessmentsBusiness Continuity PlanningVulnerability AssessmentsInformation Security ManagementRisk Management

Rasgas, doha, qatar

IT Security Consultant - Contractor

Dec 2010Jun 2011 · 6 mos

  • Information Security Documentation
  • Updated Information Security related documents like Corporate Information Security Guide, classification of information etc. Educating users about how to secure confidential information using approved tools.
  • LOG Management
  • Based on Software event monitoring Gap Analysis and Remediation Plan, prepared events to be monitored in Security Devices like Firewall, Network Devices like Switches and Routers, OS like Windows and Linux. Regular review of LOGs from above plus Anti virus, Backup, SAP Servers etc. Analysed security events and logs from various network devices, security devices and Servers.
  • Vulnerability Assessment.
  • Prepared internal vulnerability assessment procedure. Prepared presentation and sample report to be given to various section heads. Clarified what will be done, What is the responsibility of security team and various Section Heads and Owners, what tools will be used, approximate time frame. Completed Vulnerability Assessment of DMZ network of RasGas. Researched various solutions for discovered vulnerabilities. Prepared concise report considering controls in place.
Information Security DocumentationLog ManagementVulnerability AssessmentInformation Security ManagementRisk Management

E-cop pte. ltd. singapore

Security analyst

Jan 2007Jan 2008 · 1 yr

  • Provision of 24 x 7 Managed Security Surveillance / Monitoring / Incident-Handling/Response services
  • Analyze the logs of the various systems.
  • Checking of security incident reports.
  • Analysis of security incidents and escalation of security events
  • Liaising with customers with regards to information security incidents,
  • Provision and performance of remedial actions to enhance customers' network security posture
Security MonitoringIncident HandlingLog AnalysisSecurity OperationsIncident Management

Allied digital services ltd.

Sr. Security Consultant

Jan 2004Oct 2010 · 6 yrs 9 mos

  • Provision of 24 x 7 Managed Security Monitoring / Incident-Handling/Response services,
  • Manage and monitor Firewall, IDS / IPS, VPN, Servers,
  • Escalation of security incidents,
  • Member of ISO 27001 implementation, maintenance, internal audit team,
  • Prepare Risk Assessment, Policies, Procedures and Guidelines,
  • Audit of Security devices, Network devices,
  • Firewall rule-set review, audit logging, monitoring,
  • Internal vulnerability assessment of client’s network and system components,
  • Creating security awareness among Allied Digital RMS staff,
  • IT Audit for Bombay Stock Exchange/NSE broker,
  • Assist the sales team with request for proposals and technical documentation.
Managed Security MonitoringIncident HandlingRisk AssessmentSecurity OperationsIncident Management

Al-jeraisy (jccs) for saudi aramco oil co.

PC Network Engineer

May 1999Jan 2001 · 1 yr 8 mos

  • Worked on Saudi ARAMCO Oil Co. project, EXPEC PC Contract # 41225/00. Coordinator for installations of new PCs from JERAISY in EXPEC, supervised five member team.
  • Installation of Windows NT, standard applications, Mainframe
  • connectivity software Personal Communicator, Drilling Information Systems [DIS] etc. Using Remedy action request, a helpdesk software to keep track of user reported problems and their solution. Providing Support to Users in remote locations including Gas and Oil Separation Plants [GOSPs] and DRILLING RIGS.
PC InstallationNetwork SupportUser SupportTechnical SupportNetwork Management

Newtech computer services pvt. ltd.

Sr. Customer Support Engineer

Jan 1993Jan 1999 · 6 yrs

  • Installation and support of heterogeneous network of WinNT, NetWare and Unix. Installation and Support of Server, Desktop Hardware and software. Installation, Maintenance and Troubleshooting of Peripherals like Printers, Modems, DATs, CTDs, HUBs and Switches
Network InstallationHardware SupportSoftware InstallationTechnical SupportNetwork Management

Education

Cybrary

MITRE ATT&CK Defender Fundamentals

Dec 2021Dec 2021

RSA Archer

Introduction to Archer — Governance Risk Compliance

Oct 2021Oct 2021

ISC2

Certificate - GDPR for Security Professionals

Jan 2018Jan 2018

Symantec Inc.

Symantec Endpoint Protection 11

Jan 2009Jan 2009

Symantec Inc.

Symantec Security Information Manager 4.5

Jan 2009Jan 2009

Symantec Inc.

Symantec Control Compliance Suite 9.0

Jan 2009Jan 2009

BSI Management Systems

ISO 27001:2005 Lead Auditor — ISO 27001 LA

Jan 2008Jan 2008

Websense Inc.

Websense Certified Web Security Engineer — WCWSE

Jan 2007Jan 2007

ISACA

Certified Information Systems Auditor — CISA

Jan 2005Jan 2006

ISC2

Certified Information Systems Security Professional (CISSP) — Information Security

Jan 2005Jan 2006

Madurai Kamaraj University

Bachelor of Science — Mathematics

Jan 2001Jan 2004

Shri Bhagubhai Mafatlal Polytechnic

Post Diploma in Computer Applications — Passed with second class.

Jan 1991Jan 1993

Shri Bhagubhai Mafatlal Polytechnic

Diploma in Digital Electronics — Pased with first class.

Jan 1987Jan 1991

Qualys

Certificate — Vulnerability Management

Nov 2021Present

CISCO

CCNA — Network

MICROSOFT

MCSE (Windows 2000) — Windows 2000 OS

NOVELL Inc.

CNE and CNA

Ramniwas Ruia Junior College

Class XII — Science

SUN Microsystems

SCSA-SOLARIS 7 — Solaris administrator

Sanskar Jyot High School

Class X — Passed wih Distinction.

Stackforce found 100+ more professionals with Information Security Management & Iso 27001

Explore similar profiles based on matching skills and experience