Saumyajit Chakraborty

Product Manager

Bengaluru, Karnataka, India15 yrs 9 mos experience
Most Likely To SwitchAI Enabled

Key Highlights

  • Expert in Cyber Security and Risk Management.
  • Proven track record in compliance across multiple industries.
  • Leadership in digital transformation and security governance.
Stackforce AI infers this person is a Cyber Security and Compliance expert with extensive experience in enterprise risk management across various industries.

Contact

Skills

Core Skills

It Risk ManagementCompliance AssuranceSecurity ComplianceData PrivacyDigital Technology SecurityCompliance GovernanceCloud SecurityTechnology Risk AssessmentVulnerability ManagementGovernance And Compliance

Other Skills

Architecture FrameworksArtificial Intelligence (AI)BenchmarkingBudget OversightBusiness Impact AnalysisCertified Information Security Manager (CISM)Continuous MonitoringCorrective and Preventive Action (CAPA)Cyber Security RiskCybersecurity strategyEnterprise RiskGap AnalysisGeneral Data Protection Regulation (GDPR)HTMLISO 27001 Lead Auditor

About

Information Security, Technology Audit & Risk, Security Compliance and Privacy management professional having experience to align with technology strategy to deliver business goals by enabling secure by design, privacy by design principles. Saumyajit brings in broad expertise in providing technology risk advisory to reduce surface attack of an organisation, manage compliance posture and implement controls to protect Network, Application, Computing resources & Cloud assets. Areas of Expertise : Cyber Security - Digital technology Security, Security Architecture, Technology & Enterprise Risk, Security Management and Assurance, Security Governance, Vulnerability and Threat Management, Identity and Access Management, Third party Risk Assessment, IT Audit, ITGC, Data Privacy, Cloud Security, Information protection and management, Cyber Strategy and Operations, Security policy and Governance. Compliance Expertise : PCI,SOC 2,ISO 27001, ISO 27017, ISO 27018,GDPR,CCPA,HIPAA,PDPA, Export Control for IT, SOX etc Business Expertise : Program Management, Budget and Planning, Resource Management, Vendor Management, General management and business administration. Diverse information security, technolgy risk, audit and compliance work experience across various industrial sectors which includes - banking, energy management, power and water, Electronics and entertainment, Consumer products & goods, Fin-tech and financial services and now health technology.

Experience

15 yrs 9 mos
Total Experience
2 yrs 7 mos
Average Tenure
3 yrs 3 mos
Current Experience

Philips

Senior Manager - Security Risk and Compliance

Mar 2023Present · 3 yrs 3 mos · Bengaluru, Karnataka, India

  • Leading IT Risk and audit requirements for group - IT. Establish Risk universe, defined IT Risk framework and actions to monitor, address risk effectively across IT landscape.
  • Review and advise on Compliance, Security, Privacy, Audit, Export control and CAPA / SCAR requirements for large technology regulated projects and establish governance.
  • Compliance assurance review for IT landscape and provide governance oversight for Enterprise architecture data integration platform, hyper automation platforms.
  • Drive simplification and digitization for risk and compliance work stream.
  • People leader responsibility to mentor and guide direct reportees of highly experienced managers, measure performance, drive engagement, simplification and help the team to maximize business outcome.
  • Report Risk and IT Audit finding progress matrix, key performance indicators to ARC, CIO and leadership team.
Strategic ThinkingSecurity RiskRoot Cause AnalysisNegotiationRisk FrameworksArtificial Intelligence (AI)+16

Fiserv

Advisor - Information Security (Cloud and Platform Services)

Aug 2021Mar 2023 · 1 yr 7 mos

  • Lead Security Compliance, data privacy and technology audit function with in cloud business unit in an agile dev-sec-ops environment. (From design to execution)
  • Ensured cloud business unit is meeting the requirements of PCI (ROC) , SOC2, ISO 27001, ISO 27017, ISO 27018 along with privacy readiness requirements of GDPR, CCPA etc. Also collaborated with external auditors and various internal functions to support the renewals.
  • Worked closely with various functions includes - cloud ops, engineering, Dev, QA etc and planning out the dependencies for delivery in regards with security and compliance.
Strategic ThinkingNegotiationIT Security PoliciesRisk FrameworksProduct SecurityRegulatory Standards+17

Diageo

Manager - Global Digital Security & Compliance

Jul 2017Jul 2021 · 4 yrs · Greater Bengaluru Area

  • Reported to Global CISO
  • Lead Diageo's global digital technology security, compliance portfolio and established governance. Provided technology risk advisory guidance to leadership team and ensured establishment of controls to protect global digital websites, consumer data, customer data and maintain overall digital compliance posture (GDPR Regulation, PCI standard.)
  • Worked closely with P&L leaders to support omni channel digital transformation strategy of e-commerce, POS, online ticketing, QR code, onplatform and off platform websites and ensure enablement of technology solutions with secure by design principles and maintain holistic security compliance posture.
  • Oversight technology risk assessment, technical vulnerability remediation across digital portfolio and provide advisory.Established governance and measure effectiveness of the controls implemented.
  • Maintained oversight governance to PCI compliance matrix.
  • Collaborated with various internal teams such as platform owners, application owners, Enterprise Architecture, security operations, Cyber threat management, digital technologist, Consumer data governance, Legal, social media and brand teams to support various strategic initiatives with in Digital footprint.
  • Ensured Diageo have the right mechanism of tools and technologies to identify, protect, detect, monitor & respond to various Digital risk channels. Evaluated vendor product capabilities which can cater to meet organizational needs.
  • Involved in budgeting, planning and working closely with overall cyber strategy.
  • Lead the Global security assurance for cloud application and services, Digital services, RPA services etc.
  • GDPR security assessment, review controls and provide recommendation, asses implementation and review risk mitigation.
  • Involved in setting up cloud security strategy - Identify the cloud security posture,map it to the enterprise risks and propose risk mitigation plan. Set up clear business objective and outcome.
Strategic ThinkingNegotiationBudget OversightIT Security PoliciesRisk FrameworksRegulatory Standards+17

Sony

Senior Consultant - Technology Risk

Sep 2016Jun 2017 · 9 mos · bangalore

  • worked as a Cloud Security - Technology Risk Consultant :
  • Business impact analysis, Design reviews, Third Party Technology Risk assessments - for Cloud Security Services, Traditional IT, Network Security, Application Security,Data Privacy,PCI DSS etc.
  • Performed Security exhibit contract reviews. Identified technology Risk areas, Proposed Risk remediation recommendation, validated mitigation, participated in security project implementation.
NegotiationRisk FrameworksThird Party Risk Management (TPRM)Information Security StandardsContinuous MonitoringTechnical Compliance+9

Capgemini

Lead Engineer - Information Security

Sep 2011Aug 2016 · 4 yrs 11 mos · Bengaluru Area, India

  • Consulting Sector - Power and Water, Energy Management, Oil and Gas, Banking.
  • Vulnerability Management & integration program for Application, Infrastructure and cloud assets, Enterprise Risk management, Technology Risk Assessment,Cloud security assessments, Design reviews,Governance and compliance, ISO 27002 implementation, IT Audit, SOD reviews, Change management review, asset Management, System classification, Application toll gate review, handling Security exception, Security approval for change execution, driving COP session for cyber Security awareness across delivery.
NegotiationRisk FrameworksInformation Security StandardsContinuous MonitoringTechnical ComplianceRisk Compliance+7

3i infotech ltd.

Consultant

Jun 2010Sep 2011 · 1 yr 3 mos

  • Firewall configuration, configuration of router/switch, Network monitoring, end- point health monitoring, Maintain IT compliance and facilitate in IT audit, Confonet database update, Computerization of consumer forum.
Risk ComplianceEnterprise RiskCyber Security Risk

Education

Indian Institute of Management Ahmedabad

Senior Management / Leadership

Apr 2022Apr 2023

Dr MGR Educational and Research Institute

Bachelor of Technology (B.Tech.) — Computer Science Engineering

Jan 2005Jan 2009

Stackforce found 100+ more professionals with It Risk Management & Compliance Assurance

Explore similar profiles based on matching skills and experience