Nirupam Jha

Operations Associate

Delhi, India6 yrs experience

Key Highlights

  • Led security initiatives for high-profile products.
  • Implemented CCF across cloud-based platforms.
  • Authored publications in IT risk and cybersecurity.
Stackforce AI infers this person is a SaaS security compliance expert with extensive experience in risk management and governance.

Contact

Skills

Core Skills

Risk ManagementCompliance

Other Skills

Security GovernanceStakeholder EngagementGovernanceSecurity AuditsRisk AssessmentIT AuditsISO StandardsCisspCrowdstrike FalconAws Solution ArchitectureSailPointDatabricks ProductsLucidchartConfluenceJira

About

As a seasoned professional, I have led initiatives that ensure security is embedded into high-profile products and services. I have successfully implemented the Common Controls Framework (CCF) across cloud-based platforms and operations, integrating security into the feature development roadmaps for products developed on AWS, Azure, on-premises environments, and generative AI platforms. Additionally, I have implemented Artificial Intelligence Management System Implementation (example - ISO 42001 ) to ensure that AI is secured throughout the Software Development Life Cycle (SDLC) process. In addition to this, I support the compliance automation platform, strategizing data sets and data governance initiatives to alleviate compliance fatigue. I have been involved in conducting various audits, performing risk assessments, and developing frameworks to ensure reasonable security assurance and build customer trust, further channeling these efforts in coordination with Sales, Marketing, Product Security, and other teams. I hold multiple certifications and have authored numerous publications in IT risk and cybersecurity. My passion lies in ensuring robust security and compliance, and I thrive in collaborative environments, working with diverse and talented teams to achieve these goals. Please feel free to reach out. Thanks :)

Experience

6 yrs
Total Experience
2 yrs
Average Tenure
2 yrs
Current Experience

Atlassian

2 roles

Manager - Risk and Compliance

Promoted

Nov 2024Present · 1 yr 7 mos

  • 1.Mentored dynamic team of security compliance professionals, guiding them in achieving compliance across Atlassian products and services with a focus on innovation and collaboration.
  • 2.Spearhead the implementation and management of the IRAP and C5 compliance programs, ensuring alignment with business objectives to drive growth and facilitate expansion into new markets.
  • 3.Design and implement comprehensive security risk management processes, conducting thorough risk assessments and developing strategies that align with the organisation’s broader goals.
  • 4.Develop and oversee Compliance Obligation Monitoring Program, ensuring adherence to regulatory standards while strategically targeting various market segments to boost revenue growth.
  • 5.Collaborate closely with stakeholders across the organisation to refine processes in response to evolving security threats, and engage with external auditors and regulatory bodies to maintain transparency and uphold trust.
Risk ManagementComplianceSecurity GovernanceStakeholder Engagement

Security GRC Engineer

Jun 2024Nov 2024 · 5 mos

Adobe

2 roles

Senior Compliance Product Owner

Jan 2023Jun 2024 · 1 yr 5 mos

Compliance Product Owner

Sep 2021Jan 2023 · 1 yr 4 mos

  • 1.Orchestrated global governance and compliance certifications external audit for Adobe's suite of products/services (SAAS), including SOC 1, SOC 2, PCI DSS, ISO, IRAP, ISMAP etc.
  • 2.Conducted Internal Audits spanning various domains such as Entity Level (Policy and Procedure) Management, Identity and Access Management, Backup Management, Change Management, Network Security, Vulnerability Management, Incident Management, and BIA/DR to align with industry best practices.
  • 3.Collaborated with stakeholders including engineering, product, and operations teams to ensure integration of security controls into product and feature development roadmaps. Validated security controls across Adobe cloud platforms(AWS, Gen AI Platform, etc.) within the Software Development Lifecycle (SDLC).
  • 4.Identified security gaps and executed root cause analyses (RCA) to address risks through Remediation, Mitigation, Acceptance, or Transfer strategies. Produced comprehensive reports on security findings and recommendations, fostering transparent communication with management and stakeholders.
  • 5.Led initiatives to automate security controls, leveraging data optimization techniques to streamline workflows and reduce compliance overhead, demonstrating proficiency in technology-driven solutions.
  • 6.Spearheaded the Vulnerability Management Program, ensuring timely treatment of vulnerabilities for cloud/On-Prem Services thereby maintaining robust security postures and compliance with Service Level Agreements (SLAs).
GovernanceComplianceSecurity AuditsRisk Management

Grant thornton llp

Senior Consultant - Risk Advisory

Jun 2020Sep 2021 · 1 yr 3 mos · Bengaluru, Karnataka, India

  • 1.Orchestrated comprehensive Risk Assessment Audits and formulated Risk Control Matrix (RCM) to effectively address a spectrum of client risks, showcasing adeptness in risk management and mitigation strategies.
  • 2.Spearheaded Information Technology General Control (ITGC) and Information Technology Automated/Application Control (ITAC) audits to ensure adherence to SOX regulations.
  • 3.Implemented Information Security Management System (ISMS) grounded on the ISO 27001 framework to optimize business processes. Conducted thorough Service Organization Control (SOC 2 Type 2) Attestation audits, underscoring experience in enhancing security frameworks and verifying compliance with rigorous standards.
Risk AssessmentComplianceIT AuditsISO StandardsRisk Management

Vodafone idea limited

Management Trainee

Apr 2019Jun 2019 · 2 mos · Mumbai, Maharashtra, India

  • 1.Vodafone Idea Business Services-Large Accounts, Vodafone Global Enterprises, Government, Small Medium Enterprises, Small Office Home Office GST Clean up (Project Synergy) and Machine to Machine Analysis.
  • 2.Analyzed problems in each vertical of VIBS back office to save revenue of Vodafone Idea in GST activation and Machine to Machine services.
  • 3.The analysis was done from AMDOCS, Oracle CRM and IBM FileNet tool to present a report (master sheet) with all the validations and submitted to Head of VIBS.
  • 4.To check plans with respect to activation in CPOS, to analyze COFU added to the plan, to analyze plan SOC ID with Allcos Master sheet.
  • 5.Raise EDM to Authorised Signatory for validation and confirmation for correct GST and Enterprise code
  • 6.Raise and check VDM (ER Sheet) for plan correction after validation.
  • 7.Access Point Number(APN), VAS, Voice Barrier validation and UAT done for all processes.
  • 8.Multiple customer ID validation with confirmation of Account Manager, Service Lead, Service managers, Corporate and Marketing team.

Education

Indian School of Business

CyberSecurity for Leaders — Computer and Information Systems Security/Information Assurance

Jun 2025Dec 2025

Symbiosis Institute of Digital & Telecom Management (SIDTM), Pune

Master of Business Administration - MBA

Jan 2018Jan 2020

DIT UNIVERSITY

Bachelor of Technology - BTech — Computer Science

Jan 2014Jan 2018

Stackforce found 100+ more professionals with Risk Management & Compliance

Explore similar profiles based on matching skills and experience