جاتين Sethi, Lead – IT Risk Management

جاتين Sethi

Lead – IT Risk Management

Bank of New York Mellon

البلد
الهند - بونة
التعليم
ماجستير, Cyber Law & Information Security
الخبرات
10 years, 7 أشهر

مشاركة سيرتي الذاتية

حظر المستخدم


الخبرة العملية

مجموع سنوات الخبرة :10 years, 7 أشهر

Lead – IT Risk Management في Bank of New York Mellon
  • الهند - بونة
  • أشغل هذه الوظيفة منذ سبتمبر 2020

#End-to-end management of third-party risk assessment:
▪ Assessing inherent risk for new engagements
▪ Performing Due Diligence on Vendor for new engagements and as part of
reassessment
▪ Risk Assessment using Shared Assessment Framework - SIG 2020
Questionnaire
▪ Assess the level of inherent technology risks in the context of business
objectives & risk appetite and establish residual risk
▪ Provides guidance to the lines of business, stakeholders related to thirdparty risk, Global Procurement and Operational Risk teams.

#Subject Matter Expert for following control domains:
▪ Cyber Security
▪ Data Privacy
▪ Compliance
▪ HR Security
▪ Risk Management & 4th Party Controls

Assistant Manager - Information Security في Larsen & Toubro
  • الهند - مومباي
  • يونيو 2018 إلى أغسطس 2020

# Leading Information Security Team with following processes owned and managed for all locations across the globe:
- Information Security Risk Management (ISO 27005, ISO 31000, FAIR)
- Third Party (Vendor) Risk Management
- Formulating information security policies, Gap Analysis, Planning & Implementing Security Controls, ISO 27001-2013 Implementation/Continual Improvement
- ISO 27001:2013 Internal Audits, Supporting ITGC & Third-Party Audits
- Information Security Advisory to business like risk assessment for their projects, GDPR, Encryption Services etc. This helps in smooth functioning of business activities and fulfill their client requirements.
- McAfee Endpoint Threat Defense & Response Solution (McAfee EPO)
- Patch Management
- Software Compliance Life Cycle Management
- Information Security Awareness Activities
- Periodic IT Systems configuration review (Firewall, Proxy, AD etc.)

# Part of Transition Project Team (Acquisition by new organization)
- Data plays a vital role in any acquisition, it need to be complete and to be shared in controlled manner because of involvement of so many third
parties
- IT Systems (Services/Data Centre/Network/Licenses etc.) Transition planning, budgeting and management

# R&D Projects-Initiated inhouse development of Security Tools

Assistant Professor في UPES
  • الهند - دلهي
  • يوليو 2015 إلى يونيو 2018

#Subjects undertaken like PCI DSS, Data Security, Application Security, Information Security Audit (ISO 27001, COBIT, GRC etc.), Digital Forensics, Introduction to BFSI, Open Source and Open Standards, DBMS, Software Engineering, Security in Cloud etc.

#Designed and developed curriculum for B.Tech program for the subjects Data Security, Application Security, Information Security Audit, IT Systems Security and Digital Forensics.

#Designed & Implemented Labs for 4 years B.Tech CSE + Cyber Security Program like Attack Practice Labs on Vulnerable Virtual Machines, VAPT using Nessus, OpenVAS and OWTF, Digital Forensics, GRC & Audit Case Study Labs etc.

#Placement & Internship Coordinator & Course Coordinator

Associate Consultant في Ernst and Young (EY)
  • الهند - جورجاون
  • يونيو 2014 إلى ديسمبر 2014

#Performed IT Application Audit (SAP Audit + ITGC) for couple of clients.

#Consulting Services (Advisory & Project Management) for one of the largest private Indian airlines for Security Information & Event Management.

#Risk Assessment Advisory as per ISO 27001:2013 for an automobile company.

#Proposals for new clients like Application Audit, ISO 27001, PCI-DSS etc.

Intern في M.H. Alshaya Co. W.L.L
  • الكويت - الكويت
  • مايو 2013 إلى يوليو 2013

# Designed a Log Management Framework Guideline for all In-house applications after a detailed study of all critical applications and their existing log management scenario.

# A proper gap analysis was done and documented.

# Technology: OSSEC and Splunk were used for Proof of Concept.

Software Engineer في HSBC GLT
  • الهند - بونة
  • يوليو 2011 إلى مايو 2012

# Handle trouble shooting of development production issues, customer interaction on daily basis; provide support to Middle East countries on Sunday, involved in knowledge transfer sessions.

# Technology: Mainframe with COBOL as programming language and DB2 as database.

الخلفية التعليمية

ماجستير, Cyber Law & Information Security
  • في IIIT
  • مايو 2014
بكالوريوس, Computer Science Engineering
  • في RGPV University
  • يناير 2011

Specialties & Skills

IT Risk
Data Privacy
Information Security
PCI DSS
ISO 27001
Data Privacy
INFORMATION SECURITY
Risk Management
ISO 27001
IRCA Certified ISO 27001 Lead Auditor
Third Party Risk Management

اللغات

الهندية
متمرّس
الانجليزية
متمرّس
الفرنسية
مبتدئ

التدريب و الشهادات

ISO 27001 Implementer (الشهادة)
تاريخ الدورة:
October 2014
Certified Third Party Risk Assessor (CTPRA) (تدريب)
معهد التدريب:
Shared Assessment Group
تاريخ الدورة:
June 2021
Professional Google Cloud Security Engineer (الشهادة)
تاريخ الدورة:
January 2021
Certified Data Privacy Solutions Engineer (CDPSE) (الشهادة)
تاريخ الدورة:
March 2021
IRCA ISO 27001 Certified Lead Auditor (الشهادة)
تاريخ الدورة:
January 2018
صالحة لغاية:
January 2023

الهوايات

  • Part Time Activities
    Following are my part time activities: • Guest Lectures at various CBSE schools for Mathematics & Physics. • Counselling & Orientation for students and teachers. • Editing, Writing and Reviewing of Mathematics & Physics books for a renowned Indian Publisher • Mathematics & Physics (High School) part time tuitions.