Girish Singh Bhandari

Girish Singh Bhandari

Director - Security and Compliance @ OutcomesAI

About

I'm an experienced information & cyber security professional with strong background in Governance, Risk Management and Compliance (GRC), worked in multiple roles and across industries like banking, fintech, healthcare and SaaS businesses. I specialise in establishing security governance program, control implementation and auditing of info/cyber security frameworks like - ISO 27001, ISO 81001, SOC 2 Type II, CSA, MDS2, PCI DSS, NIST, OWASP etc., also includes building compliance to major regulatory requirements for HIPAA, GDPR, US FDA, EU MDR, MAS, etc, I've built information security governance program from ground up and helped successfully drive & achieve external security certs & compliances like SOC 2 Type II, ISO 27001, PCI DSS and HITRUST. I'm passionate about driving security excellence and enabling businesses to achieve hyper growth with high client satisfaction & trust to the product & service offerings, that we deliver in an increasingly complex digital landscape. Specialities: Adventures, team work, networking, social and coordinator Side hustle (read and learn) - Crypto, blockchain, stocks, funding, sports, M&A activities How can I help, let's connect here or my email : girish.b07@gmail.com

Country

India

City

Nainital

Industry

Information Technology & Services

Skill

IT Governance, Payment Card Industry Data Security Standard (PCI DSS), IT Compliance, Third Party Vendors, Risk Assessment, Auditing, Internal Audits, Internal Controls, IT Audit, Sarbanes-Oxley Act, Technology Security, Global Security, Technology Risk, Stakeholder Management, Microsoft Excel, Identity and Access Management (IAM), Compliance Implementation, Stakeholder Engagement, Risk Monitoring, Risk Analysis

Experience

OutcomesAI

Director - Security and Compliance

OutcomesAI

LinkedIn
2025-12 - Present · 10 mos

Leading global security and privacy compliance initiatives from ground up. Building & implementing GRC at the intersection of Healthcare and AI, implementing security frameworks, achieving external compliance (SOC 2 Type II and HIPAA) and meeting regulatory requirements

Growth Catalyst Group of Companies - Advatix | XPDEL | Archway

Global Director - GRC and Cybersecurity

Growth Catalyst Group of Companies - Advatix | XPDEL | Archway

LinkedIn
2025-6 - 2025-11 · 6 mos

Responsibility for the overall information security governance, risk management and compliance assurance across global locations for the group. Leading efforts to prepare, drive and successfully achieve SOC 2 Type II, ISO 27001, GDPR and PCI DSS. Ensure robust cybersecurity by building up SOC operations including cloud and product security, implementing new and current security tools to best security standards to achieve high ROI and lowered business impact.

Mobbin

Information Security Consultant

Mobbin

LinkedIn
2025-2 - 2025-5 · 4 mos

Singapore

Responsible to build, execute and drive overall security, risk and compliance strategy at Mobbin.

Biofourmis

Director - Information Security and Compliance

Biofourmis

LinkedIn
2023-1 - 2024-12 · 2 yrs

Singapore

Biofourmis

Manager - Information Security and Compliance

Biofourmis

LinkedIn
2019-12 - 2022-12 · 3 yrs 1 mo

Singapore

As first info security hire at Biofourmis, I was responsible to setup & drive security governance and compliance program from scratch across all global entities. Key responsibilities includes: -Established security policies, procedures, templates, etc., aligned to industry frameworks (e.g. ISO 27001, NIST, HIPAA, etc) -Established and implemented security risk management program, evaluate and review remediations with risk owners regularly -Implemented security audit program to regularly evaluate and monitor compliance to policies -Cloud security governance and IT security control implementation guidance (SSO, MDM, DLP, IDS, EDR, WAF and IGA) -Product (software and medical device) and infra security, to integrate security by design and threat modelling (OWASP, SANS, VA/PT, CSA CCM, ISO 81001) -Client security risk assessments and audits (DDQ, RFP/RFIs, SIGs, security annex/DPA/BAA reviews, etc.) by large hospitals, healthcare and pharmaceuticals across US and key EU & APAC regions -Info security SME for responses to internal & external audits, client & vendor security audits, regulatory responses & requirements, etc. -Developed security & risk mgmt. framework for medical device security and supported regulatory filings - MDS2 (NEMA), ISO 81001, pre/post-market approvals, etc. -Third party and partnership risk assessments -Info security incident management, change and exceptions review and approvals -Info security awareness trainings, coordinate phishing simulations, training materials, etc. -Successfully achieve ISO 27001 and SOC 2 Type II for the company -Support regulatory audits - US FDA, EU MDR, Singapore HSA -Project management - DLP, GRC tool and other security initiatives -Information security strategic plan, roadmap and budgets -Supported investors/VCs/ strategic partners security DDQs, and M&A activities -Continuous process improvement measures, integration of security best practices, team management and management reporting

Standard Chartered

Senior Risk Manager - Information and Cyber Security Audits, Risk and Compliance

Standard Chartered

LinkedIn
2018-7 - 2019-12 · 1 yr 6 mos

Kuala Lumpur, Malaysia

Standard Chartered

Manager - Information Security Audits, Risk and Compliance

Standard Chartered

LinkedIn
2017-7 - 2018-7 · 1 yr 1 mo

Kuala Lumpur, Malaysia

Key roles and responsibilities: -End to end Information Security Audits of third parties spread across globally. Scope of audits includes ISO 27001, PCI DSS, NIST, SSAE18, SOC 2, GDPR, UK DPA, MAS, ABS OSPAR etc. and any other country specific compliance requirements. -Third party risk assessment and profiling. -Lead bank’s initiatives on cloud governance and security by establishing SOPs and implementation of controls aligned to industry standards like CSA, CIS, PCI-DSS, etc. -Exception handling with respect to open information security & compliance risks and work closely with regional business contacts on risk treatment plans. -Handling risk acceptance requests and work with regional stakeholders on risk treatment plans. -Review and guide business and other key stakeholders on the bank contractual requirements and other information security addendum. -Handling regional projects (consolidation of third parties within key markets) and working with Big 4's as partners to perform end to end assessments, includes risk assessment till final reporting to management. -Work closely with observation closure team within current team. -Work closely with country specific business and support team and when required globally to carry out risk and compliance audits activities and agree on risk mitigation plans to minimize risk exposure to the bank and its customers, both internally and externally. -Design and development of internal policies, procedures, templates, reference & working documents, etc. -Mapping of frameworks, standards & other regulatory requirements and embedding it into the process to perform risk based audits/assessments. -Multiple process improvement initiatives. -Security project management (business, partners, vendors, etc.)

Broadridge

Team Lead - Information Security, Risk and Compliance

Broadridge

LinkedIn
2015-3 - 2017-7 · 2 yrs 5 mos

New Delhi Area, India

Information Security Management team is the security interface to clients, vendors, and business development teams in the areas of information security, risk and compliance. • Performing client Information Security and compliance audits & assessments, RFP/RFI, security due diligence, reviews, etc. • Risk based vendor assessment via onsite or web-ex and management reporting • Excellent working knowledge on threat intelligence model, Incident Management, Change Management, Forensics Analysis and Investigation of breaches/incidents, etc. • Handling and managing client onsite reviews (client or client’s consultants/Big 4). • Vulnerability Assessment, Network Assessment and Pen Test related requests, target remediation date (test/production release date), SME coordination, etc. • Initial review and red lining MSA, NDA, privacy documents, etc. as part of new business and renewal of contracts corresponding to Info Security, risk and compliance. • Review and update of Information Security documentation (process, procedures, templates, guidelines, etc.) • Excellent knowledge and working experience of ISO standards and other compliance & regulatory frameworks/acts like ISO 27001:2013, ISO 23001, ISO 31000, NIST, COBIT, CIS, UK DPA, SOX, PCI DSS, Safe Harbor, SSAE 16 (SOC 1, 2 & 3 reports)etc. • Excellent working knowledge of GRC tools and other audit/assessment applications. • Proven Ability to work collaboratively across the cross domain disciplines. • Creation and update of SIG documents. SIGs are accepted by most of the Financial and Investments companies. • New hire induction training on ISMS, creating info security awareness periodically across the organization. • Rewards and recognition by Broadridge as part of ACE Program (ACE is Broadridge associate awarding model). • Star Player reward • Best in Teamwork reward

ValueLabs

Senior Information Security Analyst

ValueLabs

LinkedIn
2012-1 - 2015-3 · 3 yrs 3 mos

Hyderabad Area, India

• Information Security Management • ISO 27001, HIPAA, SOX • SSAE 16 or SAS 70 / SOC 1/2/3 Type I/II Reports • Business Continuity Plans (BCP) and site testing • Disaster Recovery Plans (DR) and site testing • Compliance Activities • Conducting Information Security Audits • Facilitation of External Auditors • Creating Risk Profile of Projects • Risk Assessment at project and organizational level • Risk & Incident Reporting and Gap Checks • Business Process Management (work on Policies, Process, Visio, Procedures, Guidelines, Templates/Tracker, other document write up, etc) • Implementing HIPAA for US Heathcare Accounts • Planning for Patch, Firewall & Antivirus Management • Management Services • Managing Network Security • Managing Data Centre Security • Managing DLP, web security and email • Physical & Logical Security • Branding Information Security Internally and Externally • Information Security Learning and Development • Security articles to publish internally • Client's/prospect's info security requirement review, analysis and tailoring. • Review and work on client/vendor assessment programme • Goal Setting and Strategic Planning at Org level for various functions like HR, Admin, IT, etc. • Review of Master Service Agreements, International Data Protection Policy, Country wide Security/Service agreements, Business Associate Agreements and other International Agreements, Acts, etc. • Understanding of CMMI Level 5 Process Areas (Dev and Services)

ValueLabs

Business Analyst

ValueLabs

LinkedIn
2010-2 - 2011-12 · 1 yr 11 mos

ValueLabs, Hi Tech City, Hyderabad.

Worked for US based Healthcare project complying HIPAA norms for US Healthcare Industry. The client is one of the biggest name in Healthcare segment in the United States. Working on business reports, data mining, use of required software applications/tools, in depth research on reports & working on them to avoid any business issues, if so providing appropriate solutions/analyzing to cope up with the time & market crunch. Apart daily client meetings(onsite) through calls or via emails is a regular task. Client services/relationships & retention across Minneapolis, Cali, Louisville, Atlanta, Scottsdale, Seattle & San Francisco regions share a major pie (After Sales Services).  Domain skills & work involves: • Business research, • Data integration, • Management services, • HIPAA Title, • Professional writing, • Financial services, • Web research, • Technology research, • Data mining, • Database creation, • Web support & • SEO.

PepsiCo

Trainee Executive- Branding & Client Relationships

PepsiCo

LinkedIn
2009-8 - 2010-1 · 6 mos

New Delhi Area, India

In PepsiCo I used to take of the Retail business which includes enhancements, dealings, prospecting, segmenting the market and deal finalization in the Delhi NCR(North Delhi Regions Including parts of NCR). Increasing BRAND awareness to meet the right mix was an added responsibility.

Girish Singh Bhandari's Contact Information

Email

******@***.com

Phone

(**) *** ****

Find the Right Leads
Find Verified Contact Data

Try with: Jensen Huang @ nvidia.com Click to autofill
LeadContact awards, five-star ratings, and GDPR compliance badges

What LeadContact does well

Find verified emails, phone numbers, and decision-makers with 98% accuracy.

Find Leads

Find Leads

Find the right people by company, role, industry, location, and more.

925M+ professional profiles

Find Leads
Find Emails

Find Emails

Access verified email addresses for your target contacts.

657M+ emails

Find Emails
Find Phone Numbers

Find Phone Numbers

Get cross-validated phone data from multiple top sources.

239M+ phone numbers

Find Phone Numbers

More Accurate. Lower Cost.

Find contact data in 1 tool with 98% accuracy

LeadContact integrates leading enrichment tools to deliver more accurate contact data—without paying for each one.

LeadContact Logo
Competitor Tools

All these = $289 per month

Great conversations start with the right contact.

It’s time to find yours.