• Information Security and GRC Professional with 12+ years of experience leading enterprise Governance, Risk, and Compliance (GRC) programs across healthcare, financial services, and retail organizations.
• Extensive experience designing and managing SOC 2, ISO 27001, ISO 27701, ISO 42001, NIST SP 800-53, NIST CSF, HIPAA, PCI-DSS, GDPR, and FedRAMP compliance programs.
• Proven expertise in developing Unified Control Frameworks, Control Mapping, and Cross-Mapping across SOC 2, ISO 27001, ISO 27701, ISO 42001, and NIST frameworks.
• Strong background in conducting enterprise-wide Risk Assessments, Security Risk Assessments, Third-Party Risk Assessments, and Cloud Risk Assessments using industry best practices.
• Experienced in leading Internal Audits, coordinating External Audits, managing evidence collection, performing control testing, and successfully driving audit readiness initiatives.
• Demonstrated success in establishing and optimizing Vendor Risk Management (TPRM) programs by evaluating third-party security posture, reviewing SOC 2 Type I & II reports, and managing vendor compliance.
• Hands-on expertise implementing AI Governance frameworks aligned with ISO 42001 and NIST AI RMF, ensuring responsible AI adoption and regulatory compliance.
• Skilled in drafting, reviewing, and maintaining Security Policies, Standards, Control Documentation, and governance procedures aligned with ISO 27001, SOC 2, and NIST requirements.
• Experienced in designing executive Compliance Metrics, KPIs, KRIs, and governance dashboards to provide leadership with actionable compliance insights.
• Proven ability to reduce enterprise risk through effective Risk Assessment, Control Gap Analysis, remediation planning, and continuous compliance monitoring.
• Extensive experience utilizing ServiceNow GRC, RSA Archer, OnSpring, ProcessUnity, AuditBoard, Prevalent, and Vanta to streamline governance, risk, and compliance operations.
• Strong knowledge of AWS Cloud Security, cloud governance, Threat & Vulnerability Management, and cloud compliance aligned with enterprise security standards.
• Adept at collaborating with Engineering, Product, Legal, IT, and executive leadership to integrate Compliance, Security Controls, and Risk Management into business operations.
• Proven expertise in developing enterprise-wide Compliance Roadmaps, improving governance maturity, and strengthening security posture through continuous process improvements.
• Highly experienced in performing Third-Party Risk Management, vendor security reviews, policy exception management, and ongoing compliance monitoring.
• Strong understanding of NIST CSF, NIST SP 800-53, NIST AI RMF, ISO 27001, SOC 2, and regulatory frameworks for enterprise security governance.
• Demonstrated success leading Cross-Functional Teams, mentoring cybersecurity professionals, and driving organization-wide Compliance and Risk Management initiatives.
• Experienced in identifying compliance gaps, performing Control Assessments, implementing corrective actions, and improving audit performance across multiple business units.
• Expertise in integrating Compliance Controls, Security Policies, and Risk Management processes into Secure SDLC, cloud environments, and enterprise operational workflows.
• Strong analytical and problem-solving skills with extensive experience evaluating complex Security Risks, vendor controls, regulatory requirements, and compliance obligations.
• Proficient in delivering enterprise Compliance Reporting, executive presentations, governance dashboards, and KPI/KRI reporting to senior leadership and audit committees.
• Experienced in implementing scalable Vendor Risk Management, Security Governance, Internal Audit, and Compliance Management programs supporting organizational growth.
• Certified CISM, CEH, AWS Certified Solutions Architect, AWS Cloud Practitioner, and CCNA professional with a strong foundation in cybersecurity governance and cloud security.
• Recognized for driving enterprise Compliance, Risk Assessment, Internal Audit, Vendor Risk Management, Security Policy Development, and AI Governance initiatives that enhance operational resilience.
• Results-driven Information Security Manager with proven expertise in SOC 2, ISO 27001, ISO 27701, ISO 42001, NIST, Risk Assessment, Vendor Risk Management, Internal Audit, Security Policies, ServiceNow GRC, RSA Archer, AWS, Compliance Reporting, and Cross-Functional Leadership, delivering measurable improvements in governance, risk reduction, and regulatory compliance.