w
wittypiscean

Jineshwar

@wittypiscean

ISMS Lead Auditor

Inde
Anglais, Hindi
Certaines informations sont présentées en anglais.
À propos de moi
ISO 27001 Certified Lead Auditor I help organizations understand their information security posture against ISO/IEC 27001:2022 and build a practical roadmap to close gaps. I'm an ISO/IEC 27001:2022 certified Lead Auditor (TÜV SÜD) and GIAC Information Security Professional. I've designed and audited ISMS programmes for organizations across industries, so I know what auditors look for and what actually works in practice.... Plus d’infos
w
wittypiscean
Jineshwar
hors ligne • 

Voir mes services

Évaluation des risques
I will iso 27001 gap assessment and security roadmap

Expérience professionnelle

Deloitte

Assistant Manager

Deloitte • Temps plein

Aug 2017 - Mar 2024 • 6 yrs 7 mos

• Reduced projected annual security-testing expenditure by ~90%, from nearly $1 million to ~$100,000, by conducting vendor due diligence, comparing technology platforms, rationalising security capabilities, and presenting a cost-and-risk-based recommendation to senior leadership. • Reduced security-assessment turnaround from approximately 2–3 weeks to 1 business day by standardizing risk-assessment intake, scanning, triage, quality review, reporting, and stakeholder communication across the global Cyber Risk Assessment service. • Maintained ~95% SLA adherence across 30–40 cyber-risk assessments per month by governing team capacity, technical execution, quality reviews, risk triage, escalation, and regional stakeholder coordination. • Prevented approximately 30–40 high-risk technology changes annually from entering production by embedding cybersecurity assessment and release-gating controls into the production change-management process. • Reduced enterprise security risk YoY by introducing layered controls, vulnerability scanning, remediation tracking, and release gating across the global enterprise landscape. • Improved executive and stakeholder decision-making across global technology programmes by translating technical vulnerabilities into business impact, remediation requirements, risk exposure, and approval or release recommendations. • Improved delivery governance and team capability across the global cyber-risk service by managing five direct reports, mentoring approximately 47 cybersecurity professionals, and standardizing engagement planning, work allocation, quality reviews, and professional-development support.