Summary
Overview
Work History
Education
Skills
Certification
Tools
Timeline
Generic

SHUBHAM UPRETI

Noida

Summary

Information security and GRC Manager with 8 years of specialized experience in IT risk assessments, privacy assessment, regulatory compliance, and cybersecurity controls for cloud applications. Proven track record in leading audits and collaborating with cross-functional teams to enforce security measures, ensuring alignment with international standards and frameworks.

Overview

8
8
years of professional experience
1
1
Certification

Work History

Information Security Manager

PwC
Gurgaon
05.2022 - Current
  • Conducted IT risk-based assessments as Line of Defense 1, including Business Impact, Cloud Impact Risk, Legal and Regulatory, and Interface Assessments, while reviewing high-level architecture design and implementing cybersecurity controls for cloud-hosted and in-house applications to ensure compliance and mitigate risks.
  • Led end to end SOX engagements evaluating IT General Controls alongside IT Application Controls for OS, DB and application layer for various ERP applications and financial relevant tools for various multinational clients.
  • Performed Privacy Impact Assessments and implemented Privacy Enhancement Technologies for applications in Oil & Gas and Banking sectors, strengthening data protection and regulatory compliance.
  • Evaluated SaaS vendors with supplier assurance team to assess maturity of IT practices through RFP/RFI questionnaires, Vendor Tier Assessment, and validation of third-party assurance reports, enhancing vendor security posture.

Consultant

Deloitte
Gurgaon
03.2021 - 04.2022
  • Executed end-to-end assurance engagements, including SOC 1, SOC 2, and HIPAA audits, from designing controls to mapping them to control objectives.
  • Crafted information security framework for various organizations in alignment with ISO 27001, with development of comprehensive security policies and procedures.
  • Developed client proposals, EL's and other legal documents required for audits.
  • Produced comprehensive reports and workpapers to meet deadlines while ensuring alignment with stakeholder expectations.

IT Auditor

Nagarro
Gurgaon
03.2018 - 02.2021
  • Executed comprehensive end-to-end testing of IT infrastructure as an internal auditor, evaluating all IT domains, including Network, Change, Endpoint Security, Asset, and Access Management.
  • Managed external SOC and ISO audits, coordinating with external auditor to provide IT artifacts and maintain current governance documentation.
  • Presented audit findings and risk summaries to security council, including CISO and DPO, influencing strategic compliance decisions at executive level.

Education

Master of Science - Total Quality Management

Lucknow University
Lucknow
01-2018

B. Tech - Mechanical

THDC Ihet
Tehri
01-2015

Skills

  • IT risk assessment
  • Cloud Security
  • SOX Audit
  • Data Privacy
  • NIST CSF
  • SOC 1 and SOC 2

Certification

  • ISO 27001: 2022
  • ISO 42001: 2023
  • ISO 31000: 2018
  • ISO 22301: 2019

Tools

  • RSA Archer
  • ServiceNow
  • MetricStream
  • Microsoft Intune
  • OKTA
  • JIRA

Timeline

Information Security Manager

PwC
05.2022 - Current

Consultant

Deloitte
03.2021 - 04.2022

IT Auditor

Nagarro
03.2018 - 02.2021

Master of Science - Total Quality Management

Lucknow University

B. Tech - Mechanical

THDC Ihet
SHUBHAM UPRETI