Rajesh Kumar Gupta — Operations Associate
As an Information Security & GRC Leader at HCLTech, I drive enterprise audit, compliance, and technology risk programs for a major German global bank, aligning IT operations with ISO 27001, SOX, ITGC, BAIT, MaRisk, and DORA to enhance governance and operational resilience. Leveraging RSA Archer and ServiceNow, I have improved risk visibility, reduced compliance gaps by 30%, and streamlined regulatory reporting for executive stakeholders. At Sandoz Pharma (Switzerland) (HCL project), I led enterprise-wide IT risk assessments and risk-based control reviews across 14 IT security service lines (Database, Unix, Network, Cloud, etc.), ensuring compliance with ISO 27001, ISO 27005, ISO 27002:2013, 21 CFR Part 11, Eudralex Annex 11, NIST SP 800-53, ISO 27701, NIS2, GxP, and GDPR through the Sandoz IMF Controls Framework. I strengthened ISMS maturity and audit readiness by driving IMF control testing, implementing continuous control monitoring, enhancing third-party risk management, and maintaining complete regulatory documentation for inspections. At Blue Cross Blue Shield – North Carolina (Healthcare) (HCL project), I led HIPAA, NIST 800-53, SOC 2, and PCI DSS risk assessments for PHI systems, managed enterprise risk registers, and drove closure of high-risk findings. I improved overall compliance posture by executing security control testing, evaluating data-protection risks, and ensuring continuous adherence to healthcare regulatory requirements. Across previous roles at DXC and IBM, I delivered GDPR programs, led large-scale risk assessments, established governance frameworks, and supported incident response and audit remediation initiatives. I also lead Third-Party Risk Management programs, enforce SOC 2 compliance, and uplift supplier security across complex global ecosystems. Certified in CISM, ISO 27001 Lead Auditor, PCI DSS, AWS Architect, and RHCE, I am now expanding into AI-driven GRC, cloud-native security, and evolving EU regulatory frameworks. I recently published an industry article comparing ISO/IEC 42001 vs. NIST AI RMF, sharing practical insights on AI governance: https://www.linkedin.com/feed/update/urn:li:activity:7297578032033083392/ My focus is to bridge business and security through pragmatic governance, scalable risk management, and forward-looking leadership.
Stackforce AI infers this person is a seasoned Information Security and GRC expert in the Fintech and Healthcare sectors.
Location: Bengaluru, Karnataka, India
Experience: 17 yrs 3 mos
Skills
- Risk Management
- Information Security
- It Operations
- Training
- Linux Administration
Career Highlights
- Reduced compliance gaps by 30% across multiple projects.
- Led enterprise-wide IT risk assessments for major organizations.
- Certified in multiple security frameworks and methodologies.
Work Experience
HCLTech
Sr. GRC Manager Information Security (4 yrs 8 mos)
DXC Technology
Senior Information Security Manager (11 mos)
IBM
Senior Information Security SME Information and Data Privacy (2 yrs 6 mos)
Mphasis
Information Security Lead Engineer (1 yr 8 mos)
Vihaan Infrasystems India Limited
Information Technology Security Administrator (1 yr 1 mo)
Blue Imperial Engineers Pvt. Limited
Senior Unix System Administrator (3 yrs 6 mos)
Extramarks Education India Pvt. Ltd.
Security Administrator, Linux (1 yr 9 mos)
HCL Infosystems Ltd.
Technical Security Trainer - Redhat Linux (1 yr 3 mos)
Education
PGDM at Annamalai University
Graduation at Bundelkhand University