Anshul Srivastava

Anshul Srivastava

Director, Cybersecurity and GRC @ Unacademy

About

Cybersecurity professional having 18 years of experience, with demonstrated initiative, creativity and success. A proactive team member who is self-motivated, organised, ethical and goal oriented. Worked in global environments, specifically in BFSI, Automobile, EdTech, Product, Consulting and Services sectors. Relevant experience is in Cyber Security and GRC domain, from managing Enterprise, Product Security and GRC teams, conducting ISO 27001 based implementation and audit, Technology Risk Assessments, Information Security Risk Management, managing Cloud Security Risks via PRISMA Cloud, InfoSec Incident Handling and Management, conducting SOC1, SOC 2, SOX 404, IFC/ICFR IT audits, Data Privacy implementations (GDPR/CCPA/DPDP), Threat and Vulnerability Management, Third Party Risk Assessments, Corporate Audit remediations and InfoSec Process enhancements. Experienced Security Architect with a demonstrated history and skills in InfoSec Risk Management, Security Governance & Risk Consulting, and InfoSec Compliance. Strong consulting professional with a Bachelor of Engineering focused in Electronics & Instrumentation from Institute of Technology and Management, Gwalior and PG Diploma from CDAC Noida.

Country

India

City

Bengaluru

Industry

Higher Education

Skill

Vendor Coordination, Problem Solving, Technical Requirements, Issue Management, Engineering, Security Compliance, Regulatory Approvals, Information Systems, Cyber Risk Management, Infrastructure, IT Security Assessments, Leadership, Certified in Risk and Information Systems Control (CRISC), Team Management, Project Management, Technology Planning, Security Management, Vendor Negotiation, Communication Training, NIST

Experience

Unacademy

Director, Cybersecurity and GRC

Unacademy

LinkedIn
2020-11 - Present · 5 yrs 11 mos

Bangalore Urban, Karnataka, India

• Cybersecurity/Technology Risk Assessment/IT Audit/Third Party Risk Management/Data Privacy - Governing and driving InfoSec processes, Secure SDLC (CI/CD – SAST/Secrets/SCA) and Cloud Security Operations. Providing regular updates to the Leadership (CTO/CFO) via Risk Dashboard - Preparing annual operating plan in partnership with the Business Finance teams & forecasting based on gaps and plans for mitigating risks - Assisted businesses by performing technology risk assessments aiming at due diligence on various group level projects. Assessing Go/No Go decisions for technology projects based on the quality and effectiveness of cybersecurity controls - Defined Information Security policies and procedures and reviewed them on a periodic basis. Identified InfoSec risks and collaborated with with Engineering/Business stakeholders to mitigate those risks - Established the cloud security management program and concentrated efforts on continuous improvement of the cloud security configurations aligned to global standards like NIST CSF, ISO 27001, and CIS - Managing Cloud Security Incidents/Risks via PRISMA cloud solution. Collaborating with Engineering teams to mitigate the cybersecurity incidents and assisting in conducting RCAs whenever required - Instrumental in integrating shift-left strategy in the DevOps pipeline through the CI/CD lifecycle and introducing cultural transformation for the DevOps community as part of DevSecOps - Established and implemented IT General Controls and Application Controls for financially significant applications and infrastructure for meeting the IFC IT Audit requirements conducted annually by a BIG 4 auditing firm. - Implemented IT controls as part Data Privacy framework by working with the Legal/Procurement/ Third Parties ensuring compliance with Data Privacy regulations (GDPR/CCPA) - Establishing third party risk management process to identify and manage risks associated with third parties

Juniper Networks

Information Security Analyst Staff

Juniper Networks

LinkedIn
2019-4 - 2020-11 · 1 yr 8 mos

Bangalore

• Technology Risk Assessment & Third Party Risk Assessment - Worked closely with the IT Security team to identify InfoSec risks associated with engineering applications. Maintained the risk register and collaborated with the stakeholders (Business/IT/Legal) to mitigate those risks - Established a Third-Party Risk Assessment program for effectively managing InfoSec risks associated with vendors providing critical services to the organization. Focused on vendor onboarding process and assisted in a go/no go decision in conjunction with Procurement/Legal/Business teams. Established vendor risk re-assessment process and certified them on an ongoing basis. Presented the risk dashboard to the CISO on a bi-weekly basis

PwC

Manager, Cyber Security

PwC

LinkedIn
2018-4 - 2019-4 · 1 yr 1 mo

Bangalore

• Third Party Risk Assessment (Oil & Energy Sector) - Lead Lightly Managed Applications (LMA) project for analysing InfoSec risks associated with business owned applications. Performed Legal & Regulatory Assessments and Business Impact Assessments, carried out an in-depth analysis of associated risks, and implemented technology controls ensuring design and operational effectiveness. Discussed the risks with the Project Managers, Supplier Assurance & Procurement teams and created an action plan towards implementing security controls and mitigating underlying risks

Mercedes-Benz Research and Development India

Solutions Architect, Cybersecurity

Mercedes-Benz Research and Development India

LinkedIn
2012-8 - 2018-4 · 5 yrs 9 mos

Bangalore

• Local Information Security Officer/Information Security Risk Management (Onsite/Offshore) - Analysed the security posture of R&D organizations based on the requirements defined in the Corporate InfoSec policy. Worked with InfoSec Officers globally and provided cybersecurity consulting support. Presented the risk dashboard to R&D Global ISO on a regular basis • Information Security Assessments (Onsite/Offshore) - Conducted InfoSec assessments based on ISO/IEC 27001:2013 standard at client locations, for e.g. RD Japan, Mercedes-Benz Japan, RD Mexico and Daimler Greater China • Corporate Audit Remediation (Onsite/Offshore) - Provided onsite/offshore support to Daimler entities for mitigating risks reported by Corporate Audit. The role involved working with internal stakeholders (CIO/LISO), proposing and coordinating controls implementation and submitting the report to the corporate audit team for review and approval • Information Security Risk Management of Daimler Renault Nissan JV - Drove the Information Security Steering Committee of DRN (from Daimler’s perspective) to establish appropriate security standards and provide an effective governance structure to ensure cyber compliance and accountability

IBM

Senior Consultant, Data Security and Privacy

IBM

LinkedIn
2012-2 - 2012-8 · 7 mos

Bangalore

• SOX 404 Testing (Consumer-Goods Sector) - Responsible for making IBMs client compliant based on the IT controls required for SOX audit. Any findings or observations registered were discussed with the stakeholders before being presented to senior management of the client for review - Worked on Data Security and Privacy project for IBMs clients which aimed at meeting the security specifications as required by the Data Security and Privacy framework. Risk assessments were carried out for meeting compliance and regulatory requirements. Final output of the process was a security assessment report which underwent a review by the independent Security Risk Assessor and rated. If the rating is not satisfactory, then the whole process was repeated for achieving the desired security level

Ernst & Young

Consultant

Ernst & Young

2009-12 - 2012-2 · 2 yrs 3 mos

Bangalore

• SOC 1/SOC 2/SOX 404 Audit/Third Party Risk Assessments (Financial Sector) - Conducted third party risk assessments to ensure the vendors are catering to the Information Security requirements of financial services clients and adhering to their policies, procedures, legal and regulatory aspects for managing the risks. - Executed multiple SOX 404/SOC 1/SOC 2 engagements for BFSI organisations. Carried out technical testing of the critical infrastructure along with IT General and Application controls testing - Worked on a consulting project for a financial client, aimed to strengthen their identity and access management controls and mitigate the audit findings registered by the Monetary Authority of Singapore (MAS) - Assisted UK regulatory authority who wanted to outsource their Web Application development, Infrastructure and BPO services to third parties based in India in making a go/no go decision from an Information Security perspective

IBM

Compliance and Controls Analyst

IBM

LinkedIn
2006-9 - 2009-11 · 3 yrs 3 mos

Bangalore Urban, Karnataka, India

• Infrastructure Security Scanning (Financial/Pharmaceutical Sector) - Worked as an IT Security Analyst to validate that operating systems/applications are appropriately configured to meet the baseline security requirements, thus ensuring adequate and robust controls are in place. The intent of the project was to ensure all devices were set up into the production according to the IT Security guidelines. Deviations were addressed until mitigation based on its criticality - Conducted internal compliance and controls review for the delivery and support processes which IBM had defined for its clients. Carried out Information Security risk assessments and defined controls which were monitored periodically for compliance - Supported external audits (SOC 1/SOC 2) for process documentations like the Global Risk Review, Statement of Work, Configuration Task Matrix and Operational Accountability Model as they remained to be the main focus areas for the auditors - Performed readiness review and periodic compliance testing for IS027001 standards certification - Automated and maintained critical services required for the functioning of User Revalidation Tool as part of Identity and Access Management project. This was done to ensure that IBMs customers were able to maintain compliance with user revalidation process

Education

Centre for Development of Advanced Computing (C-DAC)

Centre for Development of Advanced Computing (C-DAC)

LinkedIn

VLSI and Embedded Systems

2006-2 - 2006-7 · 6 mos
Rajiv Gandhi Prodyogiki Vishwavidyalaya

Rajiv Gandhi Prodyogiki Vishwavidyalaya

LinkedIn

Electronics and Instrumentation

2001-8 - 2005-6 · 3 yrs 11 mos

Anshul Srivastava's Contact Information

Email

******@***.com

Phone

(**) *** ****

Find the Right Leads
Find Verified Contact Data

Try with: Jensen Huang @ nvidia.com Click to autofill
LeadContact awards, five-star ratings, and GDPR compliance badges

What LeadContact does well

Find verified emails, phone numbers, and decision-makers with 98% accuracy.

Find Leads

Find Leads

Find the right people by company, role, industry, location, and more.

925M+ professional profiles

Find Leads
Find Emails

Find Emails

Access verified email addresses for your target contacts.

657M+ emails

Find Emails
Find Phone Numbers

Find Phone Numbers

Get cross-validated phone data from multiple top sources.

239M+ phone numbers

Find Phone Numbers

More Accurate. Lower Cost.

Find contact data in 1 tool with 98% accuracy

LeadContact integrates leading enrichment tools to deliver more accurate contact data—without paying for each one.

LeadContact Logo
Competitor Tools

All these = $289 per month

Great conversations start with the right contact.

It’s time to find yours.