Submitting more applications increases your chances of landing a job.

Here’s how busy the average job seeker was last month:

Opportunities viewed

Applications submitted

Keep exploring and applying to maximize your chances!

Looking for employers with a proven track record of hiring women?

Click here to explore opportunities now!
We Value Your Feedback

You are invited to participate in a survey designed to help researchers understand how best to match workers to the types of jobs they are searching for

Would You Be Likely to Participate?

If selected, we will contact you via email with further instructions and details about your participation.

You will receive a $7 payout for answering the survey.


User unblocked successfully
Irshad Khan, Associate consultant GRC & Risk Resiliency Advisory

Irshad Khan

Associate consultant GRC & Risk Resiliency Advisory·HCLtech

India

Master's degree, Information security

Work experience

Total years of experience: 11 years, 5 months

Associate consultant GRC & Risk Resiliency Advisory

June 2025 - Present

HCLtech

Delhi, India

June 2025 - Present

Expertise in information security management, risk assessments, and
compliance audits to ensure adherence to information security and
regulatory standards.
Experienced in reviewing SOC 1 & 2, conducting TPRM, ITGC testing, and
ensuring compliance with ISO and NIST CSF frameworks.
Skilled in auditing third-party vendors, assessing their security posture, and
implementing best practices to mitigate associated risks effectively.
Led risk audits for global clients across APAC, US, UK, and Europe,
focusing on business optimization and risk mitigation strategies.
Coordinated cybersecurity initiatives with CISOs and security teams to align
cybersecurity practices with the organizationʼs overall business goals.
Possesses strong knowledge of HIPAA compliance, ensuring regulatory
adherence and data privacy for U.S. clients in healthcare sectors.
Proficient with risk assessment tools such as OneTrust, ServiceNow, DMS,
SAP Ariba, and UpGuard for auditing and evaluating security risks.
Strong interpersonal skills that foster collaboration, teamwork, and high
levels of client satisfaction promote strong, productive business
relationships.
Consistently delivered high-quality work within deadlines, earning
recognition for exceptional project completion and maintaining long-term
client satisfaction.
Skilled in using risk assessment tools like Onetrust, ServiceNow, GMS,
DMS, Archer, SAP Ariba, and UpGuard to audit and evaluate security risks.
Conduct walkthroughs, including documentation and process flow, for
validating the design effectiveness testing and operating effectiveness of
ITGCs, proposing remediation of controls based on deficiencies identified,
and drafting observations and risks.
Performing control testing on the external party's environment to check
compliance against the NIST cyber security framework.
Ensuring compliance with internal policies (audit methodology and risk
management) and regulatory requirements.
Security review for technical projects before implementation & assessing
the information security risks.
Monthly and quarterly dashboards are released to all the business
stakeholders for all the assigned accounts at the organisation and
engagement level.
Performing a risk assessment audit as per the control of information
security management system control framework library (CFL),
and NIST Framework.
Responsible for internal process governance, risk & compliance,
information security management system, cyber security, ITGC, TPRM.
Risk Review with Engagements as different aspects with baseline and
contractual requirements from MSA and SOW as per client requirement.

Company industry:
IT Services

Senior Associate | Cyber Resilience and Risk Management.

March 2023 - June 2025

PWC

Delhi, India

March 2023 - June 2025

Expertise in information security management, risk assessments, and
compliance audits to ensure adherence to information security and
regulatory standards.
Experienced in reviewing SOC 1 & 2, conducting TPRM, ITGC testing, and
ensuring compliance with ISO and NIST CSF frameworks.
Skilled in auditing third-party vendors, assessing their security posture, and
implementing best practices to mitigate associated risks effectively.
Led risk audits for global clients across APAC, US, UK, and Europe,
focusing on business optimization and risk mitigation strategies.
Coordinated cybersecurity initiatives with CISOs and security teams to align
cybersecurity practices with the organizationʼs overall business goals.
Possesses strong knowledge of HIPAA compliance, ensuring regulatory
adherence and data privacy for U.S. clients in healthcare sectors.
Proficient with risk assessment tools such as OneTrust, ServiceNow, DMS,
SAP Ariba, and UpGuard for auditing and evaluating security risks.
Strong interpersonal skills that foster collaboration, teamwork, and high
levels of client satisfaction promote strong, productive business
relationships.
Consistently delivered high-quality work within deadlines, earning
recognition for exceptional project completion and maintaining long-term
client satisfaction.
Skilled in using risk assessment tools like Onetrust, ServiceNow, GMS,
DMS, Archer, SAP Ariba, and UpGuard to audit and evaluate security risks.
Conduct walkthroughs, including documentation and process flow, for
validating the design effectiveness testing and operating effectiveness of
ITGCs, proposing remediation of controls based on deficiencies identified,
and drafting observations and risks.
Performing control testing on the external party's environment to check
compliance against the NIST cyber security framework.
Ensuring compliance with internal policies (audit methodology and risk
management) and regulatory requirements.
Security review for technical projects before implementation & assessing
the information security risks.
Monthly and quarterly dashboards are released to all the business
stakeholders for all the assigned accounts at the organisation and
engagement level.
Performing a risk assessment audit as per the control of information
security management system control framework library (CFL),
and NIST Framework.
Responsible for internal process governance, risk & compliance,
information security management system, cyber security, ITGC, TPRM.
Risk Review with Engagements as different aspects with baseline and
contractual requirements from MSA and SOW as per client requirement.

Company industry:
Accounting

Cyber Security and GRC Consultant

January 2022 - February 2023

Capgemini

Delhi, India

January 2022 - February 2023

Reported security assessments and risk management to CIS, CISO, and client function.
Conducted ITGC control testing and third-party risk assessments.
Led GCP integration testing and managed security incident tracking.
Performed risk assessments with SAP Ariba and UpGuard for security evaluations.
Developed disaster recovery plans, ensuring business continuity and policy alignment.
Ensured compliance with internal policies, regulatory frameworks, and contracts.
Conducted risk reviews and baseline assessments and produced reports.
Performed desktop assessments via VDI/Citrix and developed SOPs for incident response.
Aligned security practices with global frameworks (ISO 27001, NIST CSF, etc.).
Audited ISMS compliance, managed remediation efforts, and updated risk registers.

Company industry:
IT Services

Associate Manager| Cyber Risk and Compliance

November 2020 - January 2022

HCL Technologies

Delhi, India

November 2020 - January 2022

HCL
Led GRC initiatives across client projects, including ISMS and risk management.
Managed TPRM audits, ensuring compliance and risk mitigation.
Oversaw ISMS implementation and audits for banking, healthcare, and retail clients.
Conducted risk assessments across three verticals: applications, infrastructure, and BPO.
Ensured infrastructure and application security compliance for Health care sector, Banking, IT, Retail and insurance
sectors.
Coordinated cross-functional teams to align business objectives with compliance.
Reviewing business continuity and disaster recovery plans.
Release the Monthly and quarterly dashboards to all the business stakeholders.
Facilitated client reviews and escalated issues for timely resolution.
Aligned security practices with global frameworks (ISO 27001, NIST CSF, etc.).
Led enterprise and engagement-level risk assessments for global clients.

Company industry:
IT Services

Senior Consultant Risk and Compliance

January 2020 - November 2020

Innovaccer

Delhi, India

January 2020 - November 2020

Conducted ISMS audits, documenting and addressing findings.
Provided HITRUST compliance evidence and coordinated with US auditors.
Maintained risk register and documentation, ensuring compliance.
Developed risk management policies and streamlined assessments.
Reviewed and ensured HIPAA policy compliance.
Led monthly reviews and created escalation reports for compliance tasks.

Company industry:
Other Healthcare Services

Senior Analyst Risk and Compliance

January 2019 - January 2020

Glaze Trading India Pvt. Ltd.

Delhi, India

January 2019 - January 2020

Conducted internal audits per ISMS and ISO 9001:2015 standards for Information Security and Quality Management.
Performed process audits to ensure compliance with procedures and standards.
Submitted detailed audit reports to senior management within deadlines.
Led monthly reviews, providing escalation reports to ensure timely audit completion.
Communicated audit findings to facilitate decision-making at the management level.

Company industry:
Marketing

Sr. Engineer Internal Audit GRIE

January 2015 - January 2019

Mat India Technologies Pvt. Ltd.

Delhi, India

January 2015 - January 2019

Conducted ISMS and ISO 9001:2015 QMS audits for compliance.
Collaborated with US clients for effective audit execution.
Coordinated RCA and CAPA reports with departments.
Implemented a global management system organization-wide.

Company industry:
Automotive Dealership & Distributor

Education

Sikkim Manipal university

September 2018

September 2018

Master's degree, Information security

India

Sikkim Manipal university

January 2018

January 2018

Master's degree, MBA

India

Sikkim Manipal university

January 2018

January 2018

Master's degree, MBA

India

Maharishi University Of Management

September 2014

September 2014

Bachelor's degree, Automotive Engineering

India

MDU UNIVERSITY

January 2014

January 2014

Bachelor's degree, Automotive Engineering

India

GPA (percentage): 75%

GPA (percentage): 75%

HBSE

January 2010

January 2010

High school or equivalent, PCM

India

Skills

Information Security
Expert
Information Security
Expert
Cyber Security
Expert
Cyber Security
Expert
IT Risk
Expert
IT Risk
Expert
IT Governance
Expert
IT Governance
Expert
ITGC
Expert
ITGC
Expert
INFORMATION SECURITY MANAGEMENT
Intermediate
INFORMATION SECURITY MANAGEMENT
Intermediate
ITGC
Expert
ITGC
Expert
TPRM
Expert
TPRM
Expert
Information security
Expert
Information security
Expert
Risk Assessment
Expert
Risk Assessment
Expert
Risk management
Expert
Risk management
Expert
IT GENERAL CONTROLS ITGC
Intermediate
IT GENERAL CONTROLS ITGC
Intermediate
GRC
Expert
GRC
Expert
CYbersecurity
Expert
CYbersecurity
Expert
CERTIFIED INFORMATION SYSTEM AUDITOR CISA
Intermediate
CERTIFIED INFORMATION SYSTEM AUDITOR CISA
Intermediate
COMPLIANCE REPORTING
Intermediate
COMPLIANCE REPORTING
Intermediate
CORPORATE GOVERNANCE
Intermediate
CORPORATE GOVERNANCE
Intermediate
CYBER RISK
Intermediate
CYBER RISK
Intermediate
CYBER SECURITY
Intermediate
CYBER SECURITY
Intermediate
ENTHUSIASM
Intermediate
ENTHUSIASM
Intermediate
GOVERNANCE
Intermediate
GOVERNANCE
Intermediate
GOVERNANCE RISK MANAGEMENT AND COMPLIANCE
Intermediate
GOVERNANCE RISK MANAGEMENT AND COMPLIANCE
Intermediate
IT GENERAL CONTROLS ITGC
Intermediate
IT GENERAL CONTROLS ITGC
Intermediate
IT RISK MANAGEMENT
Intermediate
IT RISK MANAGEMENT
Intermediate
CERTIFIED INFORMATION SYSTEM AUDITOR CISA
Intermediate
CERTIFIED INFORMATION SYSTEM AUDITOR CISA
Intermediate
CORPORATE GOVERNANCE
Intermediate
CORPORATE GOVERNANCE
Intermediate
CYBER RISK
Intermediate
CYBER RISK
Intermediate
CYBER SECURITY
Intermediate
CYBER SECURITY
Intermediate
ENTHUSIASM
Intermediate
ENTHUSIASM
Intermediate
GOVERNANCE
Intermediate
GOVERNANCE
Intermediate
GOVERNANCE RISK MANAGEMENT AND COMPLIANCE
Intermediate
GOVERNANCE RISK MANAGEMENT AND COMPLIANCE
Intermediate
INFORMATION SECURITY MANAGEMENT
Intermediate
INFORMATION SECURITY MANAGEMENT
Intermediate
IT RISK MANAGEMENT
Intermediate
IT RISK MANAGEMENT
Intermediate
RISK MANAGEMENT
Intermediate
RISK MANAGEMENT
Intermediate
Information Security
Expert
Information Security
Expert
Cyber Security
Expert
Cyber Security
Expert
IT Risk
Expert
IT Risk
Expert
IT Governance
Expert
IT Governance
Expert

Social profiles

Personal Website
Personal Website

URL removed due to policy violation. Please contact support for further information.

Languages

English
Expert
Hindi
Native Speaker

Training and Certifications

Certifications
LA
27001:2013
CompTIA Information security
Certified Information Systems Auditor (ISACA
CISA
IT General Control Testing
Third-Party Risk Management System
QMS: Quality Management System Audit
ISMS | 27001:2013
CompTIA Information security
CISA | Certified Information Systems Auditor (ISACA
IATF 16949:2015 (IATF
ISMS | 27001 | LA (Auditor Information Security Management System (ISMS)
CompTIA Information security
ISO 9001:2015
Sep 2019
ISO ISMS 27001:2013

Hobbies

  • Reading Books
    Science Fictions
  • Reading the New technologies
    Connect with the new technologies