Yash Malaviya — Consultant
Audited and implemented end-to-end IT General Controls (ITGC), Application, Cloud, IT Infrastructure, Cybersecurity, and Information Security frameworks across industries such as retail, banking, insurance, and stock broking—regulated by IRDAI, SEBI, RBI, and AMFI. Strengthened clients’ IT governance, control environment, and compliance posture in alignment with ISO 27001, NIST CSF, COBIT, ISO 27701, and regulatory standards. Played a key role in the implementation of the Digital Personal Data Protection Act (DPDPA) 2023, driving governance restructuring, policy enhancement, data flow mapping, and maintenance of detailed data inventories and records of processing. Conducted Data Protection Audits and Data Protection Impact Assessments (DPIAs) to evaluate the effectiveness of technical and organizational controls ensuring data confidentiality, integrity, and availability. Enhanced cybersecurity frameworks by reviewing and optimizing IT asset management, endpoint protection, SIEM monitoring, firewall configurations, and vulnerability management programs. Evaluated Business Continuity Plans (BCP) and Disaster Recovery (DR) strategies in accordance with ISO 22301, including review of DR drills, backup processes, and incident response mechanisms. Executed audits of change and release management processes, ensuring secure deployment controls, rollback mechanisms, and adherence to ITIL best practices. Developed and maintained Risk Control Matrices (RCMs) and Risk Registers, streamlining risk identification, control testing, and mitigation planning across technology domains. Certified ISO 27001 Lead Implementer & Lead Auditor, and ISO 27701 Lead Implementer, with a strong foundation in cybersecurity governance, regulatory compliance, and IT risk management. Adept at integrating data analytics and automation techniques to drive efficiency and enhance decision-making in technology risk and assurance functions.
Stackforce AI infers this person is a Cybersecurity and IT Governance expert with a focus on regulatory compliance.
Location: New Delhi, Delhi, India
Experience: 2 yrs 10 mos
Skills
- Cybersecurity
- Data Protection
- Risk Management
- Risk Assessment
Career Highlights
- Expert in ITGC and Cybersecurity frameworks.
- Led DPDPA 2023 implementation for multiple clients.
- Proficient in Python for data analysis and visualization.
Work Experience
PwC India
Consultant (2 yrs 2 mos)
Senior Analyst (8 mos)
Risk Consultant (6 mos)
Education
Bachelor of Technology - BTech at Lakshmi Narain College of Technology, Kalchuri Nagar, Raisen Road, Post Klua, Bhopal-462021