Kuchal (Kush) CISM, CRISC, AIMS, CPISI, GRC, ISMS,BCMS

Consultant

India10 yrs 11 mos experience
Most Likely To SwitchAI Enabled

Key Highlights

  • Expert in Governance, Risk, and Compliance.
  • Proven track record in cybersecurity frameworks.
  • Strong analytical and problem-solving skills.
Stackforce AI infers this person is a Cybersecurity expert with a focus on Governance, Risk, and Compliance.

Contact

Skills

Core Skills

Risk ManagementComplianceCybersecurityAudit

Other Skills

Security StrategyThird Party Risk ManagementPower AutomateUpguard (VRM)Risk RegisterPolicy GovernanceCybersecurity FrameworkProject Control ImplementationStrategic Security GovernanceCybersecurity FunctionsDLP ImplementationSecurity ScorecardInternal AuditSecurity Awareness TrainingIOT Audit

About

Experience in Governance,Risk,Audit,Advisory,Data Security,Data Governance,Data Privacy and Compliance domain. Expert at providing solutions (from concept to implementation) that span multiple enterprise wide system from General Data Protection regulation (GDPR) Knowledge on Risk Management Framework and various other regulatory framework such as NIST etc. Performing auditing on the High,medium,Low vulnerability of all technical function like Wintel, Network, Linux etc along with mitigation measures and artifacts sharing for closure. Knowledge on DPIA,PCI DSS, GDPR,ISO 27001, SOX 404, BCP, Fedramp strategy. Analytical, detail oriented, problem solver with excellent communication skills. Create and maintain system and process documentation. Performing audit on Third Party software in inventory, EICAR Test on Prod environment. for efficient Antivirus detection capabilities. Knowledge on IT Security, Policies and Procedures. German Language Certification A1 level.

Experience

10 yrs 11 mos
Total Experience
1 yr 4 mos
Average Tenure
3 yrs 3 mos
Current Experience

Ibm

Senior Security Consultant(Security Strategy Risk & Compliance)

Feb 2023Present · 3 yrs 4 mos · Onsite · On-site

  • #Security Strategy, Risk and Compliance
  • #Third Party Risk Management
  • #Security Program creation and development as per the Strategy outlined
  • #Implementation of Australian Energy Sector Cybersecurity Framework on the project control implementation.
  • #Security Governance on the SP1,SP2 & SP3 control requirements.
  • #Using Power automate for automation of response documentation by creating workflow between forms and SharePoint list.
  • # Using Upguard (VRM) tool to evaluate vendor security posture as per the requirements outlined in AES-CSF standard.
  • # Developing and maintaining Risk Register of the vendor documenting residual risk
  • # Preparing dashboard for reporting purpose for leadership view.
  • # Policy governance, procedure, and guidelines.
  • # Process workflow automation and optimization.
  • # Working with Senior Architect on certain SIA process & optimization.
Security StrategyRisk ManagementComplianceThird Party Risk ManagementPower AutomateUpguard (VRM)+2

Brillio

Senior Lead Cybersecurity

May 2022Feb 2023 · 9 mos · Bengaluru, Karnataka, India

  • #Strategic security governance for reducing the internal and external risk landscape of the organization.
  • #Drive the Cybersecurity functions on various risk remediation and control optimization plan for the enterprises.
  • # Conducted DLP implementation across the enterprises.
  • # Leverage various tools & technologies for ensuring a strong organization external security posture management.. Security Scorecard
  • # Conducted internal audit across multiple functions.
  • # Assist in preparing various security & awareness monthly deck, Security & Awareness Quiz & mandatory security awareness training for the enterprise.
  • # Leverage various techniques & technologies to track and monitor the training compliance progress.
Strategic Security GovernanceCybersecurity FunctionsDLP ImplementationSecurity ScorecardInternal AuditSecurity Awareness Training+1

Jll

Global lT Audit Manager

Nov 2021May 2022 · 6 mos · Remote

  • #Conducted enterprises Internal Audit as part of IA Charter.
  • #Executed IOT Audit with multiple functions to identify the risk surface due to IOT devices.
  • #Performed Critical application audit as part of critical application inventory w.r.t to potential financial & business impact.
  • #Facilitated Payroll audit on various payrole application being used across geographies.
  • # Prepare Privacy map data footprint in alignment with the corresponding data privacy laws and it's possible privacy impact.
  • # Prepared cloud security vision map along with risks and mitigation control.
Internal AuditIOT AuditCritical Application AuditPrivacy Map Data FootprintCloud Security Vision MapAudit

Wipro limited

Technical Lead - Data Security, Protection,Privacy (ERM) GRC & Cybersecurity

Jun 2021Nov 2021 · 5 mos · India

  • Data Security & Data Protection
  • Enterprise governance
Data SecurityData ProtectionEnterprise Governance

Hcl technologies

GRC Cybersecurity Specialist

Sep 2019Jun 2021 · 1 yr 9 mos · Noida Area, India

  • Performing audit on Third Party software in Wintel,Linux, Network inventory within the PCI Scope standpoint.
  • Monitoring EICAR Test on Prod environment. for efficient Antivirus detection capabilities on the production environment.
  • Responsible for conducting various audits such as internal Enterprise Compliance audit, Infrastructure audit etc based on Cobit5 framework.
  • Performing auditing on the High,medium,Low vulnerability (CVE Scores) of all technical function like Wintel, Network, Linux etc along with mitigation measures and artifacts sharing for closure.
  • Auditing the missing Active Host on the PCI Scope Inventory of Wintel,Linux etc
  • Preparing the BCP documents along with senior management of the project along with Crisis Management Team.
Third Party Software AuditPCI ComplianceInfrastructure AuditVulnerability AssessmentBCP DocumentationCompliance

Fujitsu global

Senior Technical Consultant

Jul 2017Sep 2019 · 2 yrs 2 mos · Noida Area, India

  • Encouraging the staff the essence of Personal Identifiable Information (PII) from GDPR Prospective.
  • Knowledge on International data Transfer clause, Privacy shied framework, Adequacy Decision etc.
  • Responsible for mapping out Compliance with ISO 270001 standard.
  • Assist in the building of training using content from the vendor.
  • Gather data related to training completion and follows up on it to ensure full participation.
  • Train IT staff and Business users on IT Policies and Processes.
  • Follow process to fulfill GDPR and other data privacy request.
  • Training and Cascading emails throughout organization on ISMS guidelines.
  • Preparing and Drafting Monthly L& D Calendar and share across the business.
  • Compliance Process Definition and Designing.
  • Process Map creation Personal Data Processing as per GDPR norms.
  • Understanding of mandatory documents required for GDPR implementation.
  • Understanding on Personal Data protection policy, Personal Data retention policy.
  • Understanding of Privacy Notice, Employee Privacy notice Policy.
  • Knowledge on fundamentals of PCI SSC, PCI DSS, QSA and SAQ.
  • Training and Cascading emails throughout organization on Phishing Attack.
  • Assist in the completion of PCI Self-Assessment Questionnaires(SAQ)
  • Resolving and Tracking incidents/ service change request assigned to the team.
  • Providing support to the project by handling all levels of tickets.
  • Provides PCI- DSS Compliance guidance to Business.
  • Assist in the completion of DPIA, data privacy inventories and flows
Personal Identifiable Information (PII)GDPR ComplianceISO 27001TrainingIncident TrackingCompliance

Hcl technologies

Information Technology Specialist

Dec 2015Jun 2017 · 1 yr 6 mos · Noida Area, India

  • Understanding of DPIA and Data Breach Register.
  • Performing Risk Assessment, Risk Analysis and Risk Event.
  • Perform Hardware Certification before roll out of new hardware in the Production Environment.
  • Encouraging Transparent Internal Data Protection policies, approved and endorsed by the Highest Level of management.
  • Following the Best Practices of PCI DSS.
  • Informing and Training all people in the Organization on how to implement policies.
  • Understanding Importance for redressing poor compliance and data breaches.
  • Knowledge on PCI DSS along with it its 12 core security rules.
DPIARisk AssessmentPCI DSS

Capgemini

Associate Consultant

Nov 2013May 2014 · 6 mos · Kolkata

  • Knowledge on GDPR Accountability Life Cycle (Prepair,Activity and Maintain)
  • Monitoring Compliance of Data from a GDPR Guidelines and regulation.
  • Process mapping and Data Privacy Law to be followed and monitored in entire life cycle of data from Source to Destination.
  • Processing of Data related to privacy request.
  • Understanding of core 6 GDPR accountability Principle as defined in Article 5(2) and Article 33.
  • Enhancing the existing Privacy Process (Data Subject Access) in Smart Service Desk (SSD) to include right similar to data access like right of forgotten, Data Portability etc.
GDPR Accountability Life CycleData Privacy LawData Processing

Education

Punjab Technical University

Master of Science (M.Sc.) — Information Technology

Jan 2010Jan 2012

Gauhati University

Bachelor of Science (B.Sc.)

Jan 2006Jan 2009

Stackforce found 100+ more professionals with Risk Management & Compliance

Explore similar profiles based on matching skills and experience