Surabhi S, CISSP

Business Analyst

Thiruvananthapuram, Kerala, India4 yrs 11 mos experience
Highly Stable

Key Highlights

  • Led global compliance and risk management programs.
  • Successfully implemented multiple ISO certifications.
  • Expert in AI governance and risk initiatives.
Stackforce AI infers this person is a seasoned Information Security and GRC professional with a focus on compliance in complex regulatory environments.

Contact

Skills

Core Skills

Information SecurityRisk Management

Other Skills

Third-Party Vendor ManagementVendor complianceInformation Security Management System (ISMS)Internal AuditsISO 27001 Lead AuditorBusiness ContinuityHITRUSTSOC 2HyperproofCloud SecurityIsms auditAuditingVendor ManagementBCMBCP

About

Information Security & GRC professional with 5+ years of experience leading global compliance, audit, and risk management programs across complex regulatory environments. I specialize in translating regulatory requirements into practical, scalable security programs that enable business growth. As a Global Compliance Lead, I have owned and delivered end-to-end ISO external audits across multiple geographies, strengthening organizational maturity through strategic planning, executive stakeholder alignment, and disciplined execution. I have successfully implemented and certified ISO 27001:2022, ISO 22301:2019, and ISO 27701:2019, directly supporting enterprise readiness, customer assurance, and regulatory commitments. My experience extends to SOC 2 and HITRUST assurance engagements, internal audits, and Third-Party Supplier Risk Management, where I work closely with cross-functional teams to identify, assess, and mitigate risk in real-world operational contexts. I am actively involved in AI governance and risk initiatives, contributing to ethical and compliance guardrails, and secure adoption strategies that align innovation with responsible security practices particularly at the intersection of GRC and emerging technologies. CISSP-certified, detail-driven, and collaborative by nature, I focus on building resilient, audit-ready security programs while fostering a proactive, business-aligned compliance culture.

Experience

4 yrs 11 mos
Total Experience
4 yrs 11 mos
Average Tenure
4 yrs 11 mos
Current Experience

Ust

6 roles

Senior Information Security Analyst

Promoted

Oct 2025Present · 7 mos · Trivandrum, Kerala, India

Information Security Analyst

Promoted

May 2023Oct 2025 · 2 yrs 5 mos · Trivandrum, Kerala, India

Third-Party Vendor ManagementVendor complianceInformation Security Management System (ISMS)Internal AuditsISO 27001 Lead AuditorInformation Security+1

Associate Information Security Analyst

Promoted

Jan 2023Apr 2023 · 3 mos · Trivandrum, Kerala, India

Developer I

Sep 2021Dec 2022 · 1 yr 3 mos · Trivandrum, Kerala, India

Associate Software Developer

Promoted

Jan 2021Sep 2021 · 8 mos · Trivandrum, Kerala, India

Full Stack Developement

Jul 2019Dec 2019 · 5 mos · Trivandrum, Kerala, India · Remote

Education

SCMS SCHOOL OF TECHNOLOGY AND MANAGEMENT (SSTM)

Master of Computer Applications - MCA — computer application

Jan 2016Jan 2019

University Institute of Technology Mulamkadakom Kollam

B.Sc. — Computer Science

Jan 2013Jan 2016

GHSS BHOOTHAKULAM KOLLAM

Higher Secondary — Computer Science

Jan 2011Jan 2013

Chinmaya Vidyalaya

Jan 2000Jan 2005

Stackforce found 100+ more professionals with Information Security & Risk Management

Explore similar profiles based on matching skills and experience