Ajesh John, Information Security Manager

Ajesh John

Information Security Manager

Infosys Ltd

Location
India
Education
Master's degree, Computer Applications
Experience
14 years, 5 Months

Share My Profile

Block User


Work Experience

Total years of experience :14 years, 5 Months

Information Security Manager at Infosys Ltd
  • India
  • My current job since November 2013

Implement and maintain Information Security standards such as ISO 27001, PCI DSS, HIPAA, SSAE 16 etc. in organization level and engagement level.
•Information Security Risk Management- Conduct assessment of risks to information assets and risk mitigation activities to safeguard organizational assets
•Participate in external audits and client audits providing information security related assurance
•Client SPOC for information security activities in one of the designated account
•Conduct engagement level information security reviews, audits and risk assessments against information security standards, customer specific information security requirements and Infosys information security policies
•Participate in security architecture reviews and provide inputs related to security requirements.
•Perform Vendor Risk management and third party security assessments.
•Conduct routine enterprise information security audits of accounts and projects against defined standards / policies in order to ensure compliance with the company’s information security policies / customer requirements and suggest areas of improvement.
•Participate ISC (Information Security Council) and discuss about trend analysis including latency and statistical derivations to derive deliverable value from security metrics.
•Handling Information Security related queries, requirements and activities in delivery centers in other countries.
•Creation of new Information Security related policies and procedures, periodic review and update of existing policy and procedural documents.
•Undertake review of all MSA’s, Contracts, Request for Proposal (RFP)/Request for Information (RFI).
•Participate in Pre-Engagement negotiations and discussions with prospects/clients from Information Security perspective.
• Worked as an Information Security Professional

PCI at Infinite Computer Solutions
  • India
  • October 2012 to November 2013

Responsibilities: -
•Accountable for IT Security, Compliance & Risk of the whole organization’s IT infrastructure (Includes servers, network devices and other systems) and ensure end to end IT compliance with respect to ISO 27001.
•Implementation of

at IBM India Pvt. Ltd
  • India
  • April 2011 to September 2012

Responsible for client Servers and Network devices are compliant with Security Policy (GSD 331 & ISeC : Information Security policies, Standard Operating Procedures in accordance with ISO 27001:2005)
•Review of security checklist with respective departments like UNIX, WINTEL, ORACLE, CITRIX, Network & Service Management.
•Ensuring PCI compliance based on internal compliance calendar.
•Review all non-compliances (controls) are documented with deviation report.
•Review all risks were raised for non-compliances and perform periodic internal reviews and audits.

Network & System Administrator at IT WIZ
  • India
  • December 2009 to March 2011

Installation & Configuration of various Linux, Windows Servers & desktops
•Creating and Maintaining User Accounts
•Installing and configuring new hardware and software
•Monitoring and Tuning Performance & troubleshooting any reported problems
•Configuring a Secure System
•Backing Up and Restoring Files

Information Security Manager at Infosys Ltd
  • India
  • April 2016 to

Education

Master's degree, Computer Applications
  • at Mahatma Gandhi University
  • November 2009
Master's degree, Computer Applications
  • at Mahatma Gandhi University
  • January 2009

in

Specialties & Skills

PCI DSS
ISO 27001
BANKING
COMPUTER HARDWARE
CONTRACT MANAGEMENT
COUNCIL
CUSTOMER RELATIONS
INFORMATION SECURITY
POLICY ANALYSIS

Languages

English
Expert
Hindi
Expert

Training and Certifications

ITIL (Certificate)
ISO 27001 Lead Implementer (Certificate)
CPISI (Certificate)
CEH (Certificate)
ISO 27001 Lead Auditor (Certificate)
CISSP (Certificate)
Date Attended:
February 2017