With my long association with HCL Technologies, I was handling primarily the following roles:
Corporate Information Security Team for SSAE16/SAS70, ISO27001, Implementation for projects/OMC departments.
Responsible for MSA and Security compliance of few assigned projects.
(MSA, Security policy, SSAE 16, ISO 27001 and PCI-DSS)
Lead Security Incident investigations in high-profile information security incidents, conduct Technical Security Risk Assessments (TSRA) where there is a high-risk item reported from any of the incidents and report the weakness via forma report to Senior Management at large.
Perform Social engineering attacks on periodic basis at organization covering entire population of around 90000+ resources.
Perform and Monitor a team of Security testers for Blackbox and Whitebox testing of Applications based on project requirements.
Additional Duties from Time to time: In addition to the duties mentioned above.
Deputy Manager - Information Security September 13 - May 15
Onsite PIA (Privacy Impact and Security Assessment-PISA) for a Finnish Telco customer - Ongoing Project which includes compliance with EU Data protection for Infrastructure, Applications, and Operational Privacy along with Security baselines, as per Finish/EU laws.
Hands on Security Assessment where required.
DISO, Delivery Aligned security officer for a brief period taking care of Information and Security requirements for the project, role aligned to meet compliance requirements enforced by client to project/OMC/ODC.
Role 1: Lead Information Security, Corporate Information Security team till September 13.
Lead audit team for Process and Technology clauses for SSAE 16(SAS 70) SOC1 and SOC2 (Service Organizational controls for HCL as well as User Organizational Control’s for various projects), PCI DSS for Banking Projects and Merchant clients, ISO27001, and HIIPA Security rule - audit covers the following domains as per Internal ITGC checklist (Physical security and Access Control, Logical security, BCP/DR, MSA Review’s, Human Resources, Project, Maintenance and I.T Audits).
Responsible for driving regular Internal shadow audits for the SSAE16 and ISO27001, publishing Internal audit plans and reports, also driving the respective Information Security Officers for the closure of findings, thus ensuring smooth and regular compliance for all the controls in SSAE 16 and ISMS.
Suggesting Complementary/Compensatory controls wherever applicable in case the primary control is not meeting the objective it has been designed for.
Security Incident Investigation and reporting includes forensics as and when required.
Implementation, GAP Analysis and Audit of SSAE 16 SOC2 compliance across some of the HCL projects, for the customer security policy and the MSA compliance requirements.
Speaker at Induction and Various Security Awareness Trainings within HCL.
Alternatively, /other than my KRA and assisted the project team thus enhancing my knowledge in current job: -
Revised Internal SSAE 16 SOC1 checklist aligning with internal process within 8 months of my joining one of my significant achievements.
Designed the DISO (Delivery Aligned security officer) Framework for Project level compliance from security baselines point of view.
Assisting Projects with Risk Assessment, Risk Register, designing of compensatory controls, GAP Analysis, Server hardening, Application security audit, InfoSec trainings, etc.
- Company industry:
- IT Services
- Job role:
-
Information Technology