Sonu Vinod Mehta

CEO

Bengaluru, Karnataka, India8 yrs 5 mos experience
Highly Stable

Key Highlights

  • Over eight years of experience in Information Security.
  • Led major compliance transitions for ISO standards.
  • Recognized as a top performer in Information Security Consulting.
Stackforce AI infers this person is a Cybersecurity and Risk Management expert with extensive experience in financial services.

Contact

Skills

Core Skills

Governance, Risk Management, And Compliance (grc)Information Security ManagementStrategic PlanningProject ManagementOperations Management

Other Skills

ADHICSAudit ReadinessAzure Active DirectoryClient Relationships StrengtheningComplianceCompliance FrameworksControl TestingCorporate GovernanceCustomer Relationship Management (CRM)Cyber Awareness ProgramEmployee Training ProgramsGovernanceISO 27001IT AuditIT GRC

About

Learning is an ongoing journey for those committed to making a meaningful impact in their lives and the lives of others. As an entrepreneur at heart and an Information Security Consultant by profession, I engage in thought-provoking discussions that translate complex topics into accessible language. With over eight years of experience in the corporate sector, I have accumulated valuable insights and lessons that I am eager to share. I welcome opportunities to connect, collaborate, and contribute to your organization’s success.

Experience

8 yrs 5 mos
Total Experience
2 yrs 2 mos
Average Tenure
1 yr 10 mos
Current Experience

Capgemini

Risk and Compliance (GRC) Manager

Aug 2024Present · 1 yr 10 mos

  • Client Engagement Highlights:
  • Led the management of the enterprise-wide cybersecurity risk register, ensuring comprehensive risk visibility and mitigation tracking.
  • Oversaw ISMS KPIs across critical cybersecurity domains including access reviews, security posture assessments, phishing simulations, training metrics, CISO dashboard reporting, BCP/DR drills, physical access reviews, change management, cloud application assessments, SIEM analysis, and deep/dark web monitoring.
  • Conducted audit readiness assessments for ISMS (ISO 27001) and ADHICS compliance frameworks.
  • Successfully transitioned the organization from ISO 27001:2013 to ISO 27001:2022, aligning with the latest international standards.
  • Led the migration of ADHICS compliance from Version 1 to Version 2 to meet updated regulatory requirements.
  • Performed self-assessments and pre-audit checks to ensure continuous compliance and preparedness.
  • Reviewed and refined cybersecurity policies in line with evolving best practices and regulatory updates.
  • Monitored and drove the closure of cybersecurity audit findings in close collaboration with internal stakeholders.
Control TestingRisk Control Self Assessment (RCSA)IT GRCSecurity ControlsCorporate GovernanceNIST+6

Eci

3 roles

Team Lead - Information Security Consulting

Promoted

Mar 2023Aug 2024 · 1 yr 5 mos

  • Global Top Performer: Recognized as a top performer in both 2021 and 2022 for exemplary contributions to the field.
  • Leadership: Managed the Governance and Risk Compliance Program for over 40 financial services clients globally. Overseeing IT security infrastructure, identifying weaknesses and business risks, and providing strategic recommendations.
  • Cyber Awareness Program: Led phishing simulations, training programs, and incident response exercises for over 400 clients, ensuring robust security awareness and preparedness.
  • Tool Migration and Project Leadership: Directed major tool migration initiatives and managed projects to enhance security infrastructure and compliance, including Phishing and Training, Vulnerability Management, and GRC Tool.
  • Executive Interaction: Engaged with executive leadership at client organizations, hosted business meetings and quarterly reviews, and discussed information security gaps and remediations.
  • Security and Risk Assessments: Conducted security and risk assessments to identify information security weaknesses and gaps, ensuring proactive risk management based on frameworks like NIST, ISO 27001, SEC OCIE, and HiTrust.
  • Policy Development: Developed and revised key policies, including Information Security Policy, Business Continuity Plan, Acceptable Use Policy, BYOD Policy, and Access Control Policy, ensuring regulatory compliance.
  • Third-Party Risk Assessments: Executed comprehensive third-party risk management for client vendors and performed detailed business impact analyses.
  • Vulnerability Management: Conducted vulnerability scans and analyzed remediation strategies to enhance security posture.
  • Collaboration with Support Teams: Worked with SOC and technology support teams on backup restoration, vulnerability remediation, and access management, fulfilling client IT security requirements.
  • Tools: Microsoft Entra, Azure Active Directory, Elastic SIEM, Sentinel One, ServiceNow, Apptega, Cynomi, Cofense, Keepnet, Power BI.
GovernanceRisk ManagementComplianceCyber Awareness ProgramVulnerability ManagementPolicy Development+5

Senior Security Consultant

Mar 2022Feb 2023 · 11 mos

IT Security Consultant

Apr 2021Feb 2022 · 10 mos

House of kanchan

Growth Manager

Jun 2020Mar 2021 · 9 mos

  • Spearheaded strategic growth and acquisition initiatives, driving revenue and market expansion in the textile industry.
  • Developed and implemented comprehensive employee training programs to enhance operational efficiency and skill development.
  • Leveraged advanced social media marketing strategies to boost brand visibility and customer engagement.
  • Managed international business development projects, identifying new markets and mitigating operational risks.
  • Conducted risk assessments and formulated risk management plans to ensure sustainable business operations.
Strategic GrowthEmployee Training ProgramsSocial Media MarketingRisk AssessmentsStrategic PlanningProject Management

Ciphon industries

2 roles

Brand Manager

Promoted

Mar 2019Mar 2020 · 1 yr

  • Ciphon Industries Private Limited earlier known as Crescent India Polymers.
  • Streamlined vendor management processes, ensuring optimal supplier performance and cost-efficiency.
  • Optimized supply chain management, enhancing product flow and reducing operational bottlenecks.
  • Led business development efforts, successfully acquiring high-value government projects.
  • Executed project management strategies, delivering projects on time and within budget.
  • Implemented robust operations risk management frameworks to safeguard business continuity.
Vendor ManagementSupply Chain ManagementProject ManagementOperations Risk ManagementOperations Management

Assistant Brand Manager

Mar 2018Mar 2019 · 1 yr

Ey

Associate Consultant

May 2016Oct 2017 · 1 yr 5 mos · Bengaluru, Karnataka, India

  • Client Projects:
  •  Third party risk assessment – Goldman Sachs
  • Key Responsibilities:
  • o Vendor risk management for Goldman Sachs
  • o Building client relationship
  • o Assessing the Vendors policies with regard to clients Information security policies and making decisions with regard to its compliance
  • o Assessing the level of risk involved in case of noncompliance with the policy set
  • o Maintaining the work flow of internal site blocks for the client
  •  Internal Audit – Landmark Group
  • o ITGC financial audit for Landmark group
  • o Taking decision with regard to requirement of policies
  • o Giving remediation’s in case of noncompliance.
  •  Identity and Access Management – JP Morgan Chase & Co.
  • o Identifying access related risks in the system.
  • o End to End remediation of risk in access management process.
  • o Quality check of breaks in system during tool transfer.
  •  SOX Audit - JP Morgan Chase & Co.
  • o Audit controls testing as per SOX 404 guidelines.
  • o Adhering to SCO guidelines and performing root cause analysis of issues identified.
  • o Performing the role of Project management officer.
  • o Managing the SLAs and escalations for overall project performance.
  • o Keeping track of project progress.
  •  Other responsibilities –
  • o Content writing for upcoming projects.
  • o Working with the Directors and Partners closely and creating key proposals for bringing in new business to the firm.
  • o Referring to RFPs and working on proposals for new projects.

Education

Mats Institute Of Management and Entrepreneurship

Master's degree MBA — Finance and marketing

Jun 2014May 2016

Karnatak University

Bachelor of Commerce - BCom

Jun 2011May 2014

Stackforce found 100+ more professionals with Governance, Risk Management, And Compliance (grc) & Information Security Management

Explore similar profiles based on matching skills and experience