Yash Malaviya

Consultant

New Delhi, Delhi, India2 yrs 10 mos experience
Most Likely To SwitchHighly Stable

Key Highlights

  • Expert in ITGC and Cybersecurity frameworks.
  • Led DPDPA 2023 implementation for multiple clients.
  • Proficient in Python for data analysis and visualization.
Stackforce AI infers this person is a Cybersecurity and IT Governance expert with a focus on regulatory compliance.

Contact

Skills

Core Skills

CybersecurityData ProtectionRisk ManagementRisk Assessment

Other Skills

Android DevelopmentC (Programming Language)C++Cascading Style Sheets (CSS)ChessCloud FirestoreComputer NetworkingCyberData AnalysisData MigrationData PrivacyDatabasesFirebaseFlaskGeneral Data Protection Regulation (GDPR)

About

Audited and implemented end-to-end IT General Controls (ITGC), Application, Cloud, IT Infrastructure, Cybersecurity, and Information Security frameworks across industries such as retail, banking, insurance, and stock broking—regulated by IRDAI, SEBI, RBI, and AMFI. Strengthened clients’ IT governance, control environment, and compliance posture in alignment with ISO 27001, NIST CSF, COBIT, ISO 27701, and regulatory standards. Played a key role in the implementation of the Digital Personal Data Protection Act (DPDPA) 2023, driving governance restructuring, policy enhancement, data flow mapping, and maintenance of detailed data inventories and records of processing. Conducted Data Protection Audits and Data Protection Impact Assessments (DPIAs) to evaluate the effectiveness of technical and organizational controls ensuring data confidentiality, integrity, and availability. Enhanced cybersecurity frameworks by reviewing and optimizing IT asset management, endpoint protection, SIEM monitoring, firewall configurations, and vulnerability management programs. Evaluated Business Continuity Plans (BCP) and Disaster Recovery (DR) strategies in accordance with ISO 22301, including review of DR drills, backup processes, and incident response mechanisms. Executed audits of change and release management processes, ensuring secure deployment controls, rollback mechanisms, and adherence to ITIL best practices. Developed and maintained Risk Control Matrices (RCMs) and Risk Registers, streamlining risk identification, control testing, and mitigation planning across technology domains. Certified ISO 27001 Lead Implementer & Lead Auditor, and ISO 27701 Lead Implementer, with a strong foundation in cybersecurity governance, regulatory compliance, and IT risk management. Adept at integrating data analytics and automation techniques to drive efficiency and enhance decision-making in technology risk and assurance functions.

Experience

2 yrs 10 mos
Total Experience
2 yrs 10 mos
Average Tenure
2 yrs 10 mos
Current Experience

Pwc india

3 roles

Consultant

Promoted

Apr 2024Present · 2 yrs 2 mos · On-site

  • IT and Cybersecurity Audit: Conducted IT, IS, Cybersecurity, ITGC, and Data Protection Audits for multiple clients. Assessed Network architecture, baseline configurations, and Group policies for various cloud servers. Also, audited Firewall, VPN, DLP configurations, and Data encryption for client systems.
  • Assessed and implemented the Digital Personal Data Protection Act (DPDPA) 2023 for multiple clients. This involved restructuring organizational governance, updating privacy policies and procedures, mapping data flows, and maintaining detailed data inventories and records of processing.
  • Python Proficiency: Developed strong proficiency in Python and various libraries (e.g., Pandas, NumPy, Matplotlib, Seaborn). Applied these skills to perform comprehensive data analysis and visualization, enhancing the decision-making process for clients.
  • IT and Cybersecurity Expertise: Leveraged extensive knowledge in IT, computer networks, and cybersecurity to enhance clients' IT infrastructure and security posture. Continued to construct, manage, and implement robust IT and cybersecurity policies, processes, and procedures.
  • Client Engagement: Actively engaged with clients to understand their unique challenges and requirements. Provided tailored solutions to enhance their IT infrastructure and cybersecurity defenses, delivering high-value advisory services.
  • Risk Management: Played a pivotal role in developing and maintaining comprehensive Risk Registers. Employed a strategic approach to identify, assess, and mitigate risks, bolstering the resilience of clients' business operations.
  • Key Performance Indicators (KPIs): Developed and implemented KPIs tailored to clients' specific needs. Ensured IT and cybersecurity frameworks were aligned with industry best practices through continuous monitoring and analysis.
ITGCCybersecurityData ProtectionPythonRisk Management

Senior Analyst

Jul 2023Mar 2024 · 8 mos · On-site

  • As a Computer Science Engineer and a knowledgeable person in the field of IT and Cybersecurity, I bring extensive expertise to my role as a Senior Analyst at PwC India, holding the distinguished designation of Specialist 3 within the Advisory Line of Service. My primary focus revolves around leveraging my comprehensive knowledge in IT, Computer Networks, and Cybersecurity to assist clients in scaling and effectively managing their IT infrastructure.
  • Adept at constructing, managing, and implementing robust IT and Cybersecurity policies, processes, and procedures, I play a pivotal role in fortifying the security posture of clients. My responsibilities extend to developing and implementing key performance indicators (KPIs) tailored to the unique needs of each client, ensuring that their IT and Cybersecurity frameworks align seamlessly with industry best practices.
  • Moreover, my expertise extends to Risk Management, where I have actively contributed to the creation and maintenance of comprehensive Risk Registers for clients. This involves a strategic approach to identifying, assessing, and mitigating risks, further reinforcing the resilience of their business operations.
  • In essence, my role encompasses a multifaceted approach, combining technical acumen with strategic vision to deliver unparalleled value in enhancing clients' IT infrastructure and cybersecurity defenses.
ITGCCybersecurityRisk ManagementData Protection

Risk Consultant

Jan 2023Jul 2023 · 6 mos · On-site

  • Worked as an Business Risk Consultant Intern in Advisory Line of Service.
  • Gained Knowledge of Firewalls, Active Directory and other Computer Network essentials.
  • Worked on Pre and Post Data Migration Audit, Risk Assessment and Risk Control. Worked on SQL Server Management Studio (SSMS), TSQL, MySQL, and Visual Studio.
Risk AssessmentSQL Server Management StudioData Migration

Education

Lakshmi Narain College of Technology, Kalchuri Nagar, Raisen Road, Post Klua, Bhopal-462021

Bachelor of Technology - BTech — Computer Science

Jan 2019Jan 2023

Stackforce found 100+ more professionals with Cybersecurity & Data Protection

Explore similar profiles based on matching skills and experience