S

Sumitra Ghatge

Associate Consultant

Pune, Maharashtra, India12 yrs 5 mos experience

Key Highlights

  • Over a decade of experience in cybersecurity and networking.
  • Expert in translating technical risk into actionable insights.
  • Proven track record in strengthening governance and oversight.
Stackforce AI infers this person is a Cybersecurity and Risk Management expert with a focus on enterprise technology.

Contact

Skills

Core Skills

Cyber & Technology Risk ManagementAudit & Assurance (technology / Cyber)Third-party / Vendor Risk (tprm)Grc (governance, Risk & Compliance)Information Security OperationsSecurity Controls ImplementationNetwork Infrastructure OperationsNetwork Troubleshooting & Root Cause AnalysisNetwork Infrastructure Implementation (lan / Wan / Wlan)Network Troubleshooting & Incident Resolution

Other Skills

LinkedIn Learning AI-powered CoachingCybersecurity StrategyCyber Threat Intelligence (CTI)Zero Trust ArchitectureCloud Security ArchitectureAPI SecurityAI for CybersecurityNetwork Documentation & DiagramsNetwork Performance MonitoringInformation Security ConsultingManaged Security ServicesRemediation Governance / Issue ManagementExecutive-level CommunicationCloud Security GovernanceSenior Stakeholder Management

About

With over a decade of experience across cybersecurity and networking, I shape cybersecurity and technology risk oversight in complex organizations, translating ambiguity into clear priorities, accountable execution, and resilient outcomes. Across internal audit and Big4 environments, my work has focused on evaluating cloud and enterprise technology landscapes to determine whether controls and operating models materially reduce risk or provide limited assurance. I translate technical risk into decision-ready insights that inform risk-based prioritization, strategic trade-offs, and remediation sequencing across stakeholders. I operate across security, technology, engineering, risk, and business teams to clarify ownership, establish follow-through mechanisms, and strengthen oversight cadence. I am known for constructive challenge, calm communication, and consistent, evidence-based follow-through. My work has contributed to earlier risk visibility, clearer accountability, and more consistent remediation across complex technology environments. I am focused on advancing governance maturity and supporting the evolution from point-in-time assurance toward more continuous, risk-aligned oversight models, so security and technology efforts remain aligned to business priorities and resilience outcomes. Framework familiarity: NIST CSF, ISO/IEC 27001, ISO/IEC 42001, PCI DSS, FedRAMP; threat-informed control thinking using MITRE ATT&CK and MITRE D3FEND.

Experience

12 yrs 5 mos
Total Experience
--
Average Tenure
--
Current Experience

Akamai technologies

Senior Internal Auditor

Apr 2024Present · 2 yrs 2 mos · India · Remote

  • Turning Cyber Risk into Board-Ready Oversight and Business Confidence
  • In my current role, I have been strengthening cybersecurity and technology risk oversight by making it board-ready, practical, and execution-focused. I have led cyber audits, and I present key themes to senior leadership for Audit Committee discussions. I have also been driving control testing and building audit test plans, so assurance becomes faster, more consistent, and easier to evidence. My approach is simple: clarify the real risk, align ownership, and drive follow-through through governance. The outcome is clearer accountability, stronger remediation momentum, and leadership decisions that are informed by evidence and risk context, not noise.
Cyber & Technology Risk ManagementAudit & Assurance (Technology / Cyber)

Ey technology solutions

Senior Security Consultant

Oct 2021May 2024 · 2 yrs 7 mos · Pune, Maharashtra, India · Hybrid

  • Strengthening Secure Business Scale through Security Oversight and Risk Capability Development
  • As organizations expanded their cloud footprint and global vendor ecosystems, consistent and reliable visibility into third-party security posture became essential to supporting secure operations, brand trust, and customer confidence. The need was not only to assess risk, but to do so in a way that could scale, remain credible, and inform decisions.
  • In this context, I served as a Lead Assessor and performed QA reviews for third-party security assessments across complex vendor ecosystems, covering domains including cybersecurity, IT and network security, identity and access management, secure SDLC, physical and environmental security, and operational controls. I worked across multi-location environments to align scope, evidence expectations, and assessment sequencing with operational realities, enabling effective execution without disrupting BAU activities.
  • Beyond assessment delivery, I contributed to research and capability development initiatives focused on strengthening how cybersecurity risk is evaluated and monitored at scale. This included work on Cyber Risk Quantification (CRQ) to support more informed, decision-ready risk discussions beyond qualitative assessments, and Continuous Control Monitoring (CCM) to enable regular, data-driven visibility into control performance rather than reliance on point-in-time assessments. The emphasis was on practicality, scalability, and alignment with governance expectations.
  • Also, developed RFPs, SOWs, and POVs, translating security and risk concepts into clear, outcome-oriented proposals that supported delivery alignment and client decision-making.
  • The outcome was stronger consistency in security assessments, improved confidence in risk visibility, and more reliable inputs for governance and decisions, enabling organizations to scale securely while protecting brand value and customer trust.
Third-Party / Vendor Risk (TPRM)GRC (Governance, Risk & Compliance)

Shubhankar associates

Security Operations Analyst

Jan 2017Oct 2021 · 4 yrs 9 mos · Pune, Maharashtra, India · On-site

  • Building Practical Security Foundations through Information Security Operations
  • As organizations increasingly relied on digital systems to support daily operations, the immediate need was to establish basic information security hygiene, meet compliance expectations, and respond effectively to operational security issues. In a small-scale organization, security work required hands-on involvement across multiple areas to keep systems stable and risks manageable.
  • In this role, I supported information security operations by assisting with security assessments, basic incident handling, and implementation of baseline security controls. I worked closely with infrastructure and network teams to help identify vulnerabilities, support remediation actions, and ensure essential controls were in place to protect systems and data.
  • I contributed to compliance-aligned security activities by supporting control implementation and documentation in line with standards such as PCI DSS and ISO/IEC 27001, helping the organization build structured security practices. I also supported business continuity activities, assisted with patching and endpoint protection, and contributed to maintaining security documentation, policies, and procedures.
  • Exposure to early cloud and application security concepts helped me understand how security risks emerge at the operational level and how practical controls are applied in real environments. I also supported solution design and pre-sales activities where required, gaining visibility into how security requirements are translated into implementable solutions.
  • The outcome was a solid grounding in information security operations, control implementation, and incident readiness. This role provided the practical, hands-on foundation that later enabled me to work effectively in cybersecurity governance, audit, and risk oversight roles with an execution-aware perspective.
Information Security OperationsSecurity Controls Implementation

Shubhankar associates

2 roles

Data Network Engineer

Oct 2015Dec 2016 · 1 yr 2 mos · Pune, Maharashtra, India · On-site

  • Ensuring Reliable Connectivity and Operational Stability through Network Engineering
  • At an early stage of my career, reliable network connectivity was essential to keeping business operations running smoothly and meeting customer expectations. Network disruptions directly affected productivity, service delivery, and trust, making stability and performance critical priorities.
  • In this role, I supported the core network infrastructure for client environments, working on installation, configuration, and day-to-day management of network devices. I handled escalated site-down incidents in coordination with service providers, focusing on timely restoration of services and minimizing business impact.
  • I worked on monitoring and improving network performance, investigating recurring issues through log analysis, diagnostics, and root cause assessment. I followed defined change control procedures when implementing configuration updates and maintained accurate documentation, network diagrams, and vendor information to ensure operational clarity and continuity.
  • The outcome was improved network reliability, faster resolution of connectivity issues, and stronger operational discipline around change and documentation. This role built my foundational understanding of infrastructure stability, incident handling, and operational risk.
Network Infrastructure OperationsNetwork Troubleshooting & Root Cause Analysis

Network Engineer

Nov 2013Sep 2015 · 1 yr 10 mos · Pune, Maharashtra, India · On-site

  • Establishing Reliable Network Foundations for Business Continuity
  • In the early phase of my career, stable and well-designed network connectivity was fundamental to supporting business operations and customer service. Organizations depended on reliable LAN, WAN, and WLAN environments to ensure uninterrupted access to systems, applications, and services.
  • In this role, I worked as a Network Engineer, supporting the implementation and maintenance of LAN, WAN, and WLAN solutions, including IPv4 addressing for customer environments.
  • I handled day-to-day network troubleshooting across a range of issues such as intermittent connectivity, slow network performance, routing problems, site-down incidents, quality-of-service challenges, and firmware upgrade activities. I focused on identifying root causes and restoring connectivity efficiently to minimize operational impact.
  • I also supported disaster management activities, including backup and restore operations, contributing to the organization’s ability to recover from outages and maintain service continuity.
  • The outcome was improved network reliability, quicker resolution of connectivity issues, and stronger operational discipline.
Network Infrastructure Implementation (LAN / WAN / WLAN)Network Troubleshooting & Incident Resolution

Education

Indian Institute of Technology, Kanpur

Executive Certificate Program in Cyber Security — Computer and Information Sciences and Support Services

Aug 2025Mar 2026

TC College

Bachelor of Science — Information Technology

Stackforce found 100+ more professionals with Cyber & Technology Risk Management & Audit & Assurance (technology / Cyber)

Explore similar profiles based on matching skills and experience