Rajesh Kumar Gupta — Operations Associate
As an Information Security & GRC Leader at HCLTech, I drive enterprise audit, compliance, and technology risk programs for a major German global bank, aligning IT operations with ISO 27001, SOX, ITGC, BAIT, MaRisk, and DORA to enhance governance and operational resilience. Leveraging RSA Archer and ServiceNow, I have improved risk visibility, reduced compliance gaps by 30%, and streamlined regulatory reporting for executive stakeholders. At Sandoz Pharma (Switzerland) (HCL project), I led enterprise-wide IT risk assessments and risk-based control reviews across 14 IT security service lines (Database, Unix, Network, Cloud, etc.), ensuring compliance with ISO 27001, ISO 27005, ISO 27002:2013, 21 CFR Part 11, Eudralex Annex 11, NIST SP 800-53, ISO 27701, NIS2, GxP, and GDPR through the Sandoz IMF Controls Framework. I strengthened ISMS maturity and audit readiness by driving IMF control testing, implementing continuous control monitoring, enhancing third-party risk management, and maintaining complete regulatory documentation for inspections. At Blue Cross Blue Shield – North Carolina (Healthcare) (HCL project), I led HIPAA, NIST 800-53, SOC 2, and PCI DSS risk assessments for PHI systems, managed enterprise risk registers, and drove closure of high-risk findings. I improved overall compliance posture by executing security control testing, evaluating data-protection risks, and ensuring continuous adherence to healthcare regulatory requirements. Across previous roles at DXC and IBM, I delivered GDPR programs, led large-scale risk assessments, established governance frameworks, and supported incident response and audit remediation initiatives. I also lead Third-Party Risk Management programs, enforce SOC 2 compliance, and uplift supplier security across complex global ecosystems. Certified in CISM, ISO 27001 Lead Auditor, PCI DSS, AWS Architect, and RHCE, I am now expanding into AI-driven GRC, cloud-native security, and evolving EU regulatory frameworks. I recently published an industry article comparing ISO/IEC 42001 vs. NIST AI RMF, sharing practical insights on AI governance: https://www.linkedin.com/feed/update/urn:li:activity:7297578032033083392/ My focus is to bridge business and security through pragmatic governance, scalable risk management, and forward-looking leadership.
Stackforce AI infers this person is a seasoned Information Security and GRC expert in the Fintech and Healthcare sectors.
Location: Bengaluru, Karnataka, India
Experience: 17 yrs 5 mos
Skills
- Risk Management
- Information Security
- It Operations
- Training
- Linux Administration
Career Highlights
- Reduced compliance gaps by 30% across multiple projects.
- Led enterprise-wide IT risk assessments for major organizations.
- Certified in multiple security frameworks and methodologies.
Work Experience
HCLTech
Sr. GRC Manager Information Security (4 yrs 10 mos)
DXC Technology
Senior Information Security Manager (11 mos)
IBM
Senior Information Security SME Information and Data Privacy (2 yrs 6 mos)
Mphasis
Information Security Lead Engineer (1 yr 8 mos)
Vihaan Infrasystems India Limited
Information Technology Security Administrator (1 yr 1 mo)
Blue Imperial Engineers Pvt. Limited
Senior Unix System Administrator (3 yrs 6 mos)
Extramarks Education India Pvt. Ltd.
Security Administrator, Linux (1 yr 9 mos)
HCL Infosystems Ltd.
Technical Security Trainer - Redhat Linux (1 yr 3 mos)
Education
PGDM at Annamalai University
Graduation at Bundelkhand University