Santosh Nandakumar

Co-Founder

Bengaluru, Karnataka, India16 yrs 4 mos experience
Most Likely To SwitchHighly Stable

Key Highlights

  • Mentored over 1000 professionals in cybersecurity certifications.
  • Executed over 100 cybersecurity projects across multiple countries.
  • Expert in implementing international security standards.
Stackforce AI infers this person is a Cybersecurity Consultant with extensive experience in compliance and risk management.

Contact

Skills

Core Skills

Information Security ManagementRisk Management

Other Skills

PCI DSSISO 27001ISO 20000ISO 22301IS AuditCyber Security Framework AssessmentRisk AssessmentIT Service ManagementBusiness ContinuityCertified Chief Information Security Officer (CCISO) Online Training & Certification CourseSecurity AuditsIT AuditInformation TechnologyServersCybersecurity

About

As a CISM trainer, I help candidates prepare for CISM exam by providing them with a deep understanding of the CISM framework which includes training on topics such as information security governance, risk management, incident management, and disaster recovery. As the Head of Content at Ministry of Security, I lead the development and delivery of high-quality and engaging content on various topics related to cybersecurity, such as information security governance, risk management, incident management, and disaster recovery. I also help organizations build and strengthen their information security management capabilities by providing customized training and consulting services. Do you have any specific questions about the CISM certification or information security management in general, Please inbox me for a blazing-fast response. In my track record, I have mentored more than 1000+ professionals on cybersecurity certifications and seen huge positive results. From a professional standpoint, I have overall 17+ years of experience in Cyber Security Consulting, Pre Sales & Delivery, and executed more than 100+ cyber security projects. Implementations: ISO 27001, ISO 27701, ISO 29100, ISO 20000, ISO 31000, ISO 22301, ISO 27799, BS 10012, ISO 9001 International Standards: NIST CSF, ITIL V3, NIST SP 800, EU General Data Protection Regulation (GDPR), PCI DSS, HIPAA, HITRUST, Regulatory: RBI GKC Guidelines, RBI CSF, IRDAI CSF, SEBI Cyber Security Certifications CISA CISM Certified ISO 27001-2013 Lead Auditor Certified ISO 27001-2013 Lead Implementer Certified ISO 20000 Certified BS 10012 -2017 PIMS Certified ITIL V3 Foundation Certified Six Sigma Yellow Belt Domain Exposure: Banking, BFSI, IT, Insurance, Telecom, NBFC, Manufacturing, Retail & Pharmacy. Projects Executed Onsite: Multiple Cities in India, Qatar, Riyadh, Malaysia, Vietnam, Jamaica, and Dubai

Experience

16 yrs 4 mos
Total Experience
2 yrs 8 mos
Average Tenure
4 yrs 4 mos
Current Experience

Ministry of security

Founder

Jan 2022Present · 4 yrs 4 mos · India

Pwc india

Manager & Principal Consultant

May 2018May 2020 · 2 yrs · Bengaluru, Karnataka, India

  • Manage Entire South India Security Operations

Paladion

2 roles

Assistant Vice President & Senior Solutions Architect

Promoted

Jan 2017Apr 2018 · 1 yr 3 mos

  • Aid in the pre-sale stages of engagements, specifically supporting the sales team with activities such as proposal writing and assisting with client presentation Create and own responses to Request for Proposal (RFPs), POCs, SoWs.
  • Development of new services/solutions and enhance existing services portfolio
  • Work with respective Regional Sales Team members and be their extended arm for any ongoing Sales Engagements/Discussions and Pipeline Tracking.

Senior Consultant & Project Manager

May 2013Dec 2016 · 3 yrs 7 mos

  • Managing and executing multiple projects on information security & compliance, IT Risk & Assurance for India, MEA & US regions on areas such as
  • a) PCI DSS version 3.2 – GAP Assessment & QSA Audits
  • b) Implementing ISO27001 (ISMS) framework & Conducting ISO27001 risk assessment, Gap Assessment and Internal Audits for 27001:2013(Including recertification audit and surveillance audit.)
  • c) Implementing ISO 20000 (ITSMS) standard
  • d) Implementing ISO 22301 (BCMS) standard
  • e) Data Flow Analysis (DFA)
  • f) IS Audit
  • g) Cyber Security Framework Assessment
  • h) Extensive third-party audits as part of vendor risk management services
  • i) Develop security policies, standards and procedures.
  • j) Design, review and recommend security controls for application and infrastructure systems.
  • Managing Regional Teams – Project Managers and Team Members across different client locations to facilitate and assisting them for the project execution.
PCI DSSISO 27001ISO 20000ISO 22301IS AuditCyber Security Framework Assessment+2

Ibm

2 roles

Data Security Consultant

Promoted

Nov 2011May 2013 · 1 yr 6 mos

  • Was part of the IBM Global Business Service and the primary role and responsibilities were to continue elevating data security and privacy practice of various projects undergoing and Assist Project Managers and Leads in developing Data Security and Privacy and Data Protection solutions for the projects.
  • The implementation & audit work involves conducting a risk assessment of the each project by evaluating different aspects like access to client systems – production and non production, access to client’s environment – whether production or development, requirements of regulatory compliance, access to personal information, access to business sensitive information etc. Based on the assessment, controls like documented Data Security Plan, Risk Log, User Access Management, Training & Awareness, and Separation of Duties.
  • Verifying DOU (Document of understanding), SOW (statement of work), CTA to ensure the client stated security controls are in place.

IT Security Analyst

May 2009Oct 2011 · 2 yrs 5 mos

  • Was part of Compliance Testing to perform audit of a system carried out against a known criterion in which the Servers Security Configurations are periodically health checked in order to meet the Security standards requested by the customer. Each server is manually health checked including the Applications and operating systems running on the server by retrieving the settings from the servers and comparing it with GSD331 Settings (Which are agreed by both the customer and the Company).

Manthan

Level 2 Engineer

Sep 2008Apr 2009 · 7 mos

Convergys

Level 1 Engineer

Aug 2007Apr 2008 · 8 mos

Education

Manipal Academy of Higher Education, Manipal

MBA — Human Resources

Jan 2008Jan 2010

Visvesvaraya Technological University

BE — Computer Science

Jan 2003Jan 2007

Stackforce found 100+ more professionals with Information Security Management & Risk Management

Explore similar profiles based on matching skills and experience