Asha N

Associate Consultant

Chennai, Tamil Nadu, India13 yrs 5 mos experience
Most Likely To SwitchHighly Stable

Key Highlights

  • Expertise in ISO 27001 implementation and audits
  • Strong background in Information Security Management
  • Proven track record in Risk Assessment and Mitigation
Stackforce AI infers this person is an Information Security Architect with extensive experience in compliance and risk management.

Contact

Skills

Core Skills

Information Security Management System (isms)Information Security

Other Skills

Information Security Standards and PoliciesISO 27001PCI DSSSOXSSAE/ISAERisk Assessment MethodologyRisk Treatment PlanInformation Security Policy ManualSecurity ArchitectureBusiness Continuity Management PlanSecurity AdministrationActive DirectoryUser account managementTicket tracking toolsUser access management

About

Working as an Information Security Architect with good experience in the security domain.

Experience

13 yrs 5 mos
Total Experience
2 yrs 8 mos
Average Tenure
2 yrs 10 mos
Current Experience

Daimler truck innovation center india (dtici)

Principal Consultant

Jul 2023Present · 2 yrs 10 mos · India

Deloitte india

Assistant Manager, Cyber Risk Services

Dec 2020Apr 2023 · 2 yrs 4 mos · India

Grm technologies private limited

3 roles

Assistant Manager Information Security

Jul 2020Dec 2020 · 5 mos

Senior Information Security Consultant

Jul 2019Jul 2020 · 1 yr

IT Security Consultant

Aug 2017Jun 2019 · 1 yr 10 mos

  • Information Security Standards and Policies
  • Affluent with ISO 27001, PCI DSS, SOX, SSAE/ISAE ensuring IT and application security compliance with organization’s security policies
  • Performed ISO 27001 Internal audits, driven surveillance audits and re-certification audits.
  • Involved in ISO 27001-based internal, supplier and third party audits.
  • Implemented ISO 27001-based ISMS at mid and large sized firms. Written Information Security Policies, Procedures and Guidelines.
  • Information Security Risk Governance and Implementation
  • Created Information Security Policy Manual aligned to ISO 27001:2013
  • Created and implemented Risk Assessment Methodology for entire ISMS Program
  • Created Risk Treatment Plan and methods for the various risks identified in the Risk Assessment
  • Develop Asset and Risk Register
  • Developed a road-map for roll-out and implementation of ISO 27001 controls
  • Designing the various IS related Policies and procedures
  • Preparing of Risk Register and Risk Tracker
  • Designing and preparing the Statement of Applicability
  • Participated in designing the Security Architecture and formulating the Risk Mitigation Strategy
  • Designing and conducting Information Security Awareness programs
  • Security review of IT Infrastructure and IS operations in accordance with ISO 27001, at Operational office and Data center;
  • Assessment of IS controls for RFP compliance
  • Review of Business Continuity Management Plan for the entire program.
  • Review of the Security policies and procedures
  • Creation and review of SOA (Statement of Applicability)
  • Review of the IS processes
  • Assessment of the physical and environmental controls at operational office, data center and communication rooms
  • Review of the logical access Controls
  • Review of the Security Incidents
  • Review of the Disaster Recovery Plan
  • Preparation of the Audit findings report and mitigation plans
Information Security Standards and PoliciesISO 27001PCI DSSSOXSSAE/ISAERisk Assessment Methodology+6

Wipro technologies

Senior Systems Engineer

Jul 2008Mar 2012 · 3 yrs 8 mos · Chennai Area, India

  • 3.8 yrs of experience in Security Administration
  • Handled Ticket tracking tools- Service Manager 7, Remedy, IDM, Peregrine,
  • Has experience working with Active Directory on Windows 2003/2008 server, Mainframe- RACF, Unix, Exchange Server 2010, Manual online form testing in SUN Identity Manager and RSA Console
  • Roles and Responsibilities mainly included User account creation, termination, role cleansing activities, maintenance of Ids (reactivation and extension of Ids), creation of User and Generic mailbox, Distribution list, Security groups, Home folder, network shared folder. Granting/Denying permissions to network file share folders, drive access and troubleshooting issues with user account and RSA using key-fobs
  • Got online transition on the customized client application from the client; contributed document and trained the entire offshore team on the same
  • Responsibility to collect daily efforts of the team in order to review and maintain SLA of the tickets processed and also sends weekly and monthly efforts to the client
  • Responsibility for implementing the policies and procedures of user ID management and the security policies
Security AdministrationActive DirectoryUser account managementTicket tracking toolsInformation Security

Aviva 24/7 / wns

Technical Analyst

Mar 2007Jul 2008 · 1 yr 4 mos · Chennai Area, India

  • Worked as Technical Analyst
  • Worked in user access management- Security Administration profile
  • RACF Id and RACF group creation for the users accessing various systems across the company.
  • Connecting User with the RACF group based on his role and the requirement and granting access to Datasets.
  • Maintenance of RACF Id such as Resuming the revoked Id, resetting password, replacing department groups
  • User access provisioning, amendment and maintenance of various systems including lotus notes
  • To perform Role cleansing activity
  • Setting up/Deleting user accounts, administration and amending user access on Active
  • Directory
  • Efficiently use the Tracking tool- ASSYST 6.5version
  • Maintain client operating standards and SLA including documentation, form processing and internal procedures
  • Handled the projects ITAEXP (Extension of Id’s), Name change.
  • Troubleshooting issues related to user profiles and accesses in various applications
User access managementRACFActive DirectorySecurity AdministrationInformation Security

Education

St. Peter's Engineering College

Bachelor of Engineering (BE) — Electronics and Instrumentation Engineering

Jan 2001Jan 2005

Stackforce found 100+ more professionals with Information Security Management System (isms) & Information Security

Explore similar profiles based on matching skills and experience