Girish Singh Bhandari
Director - Security and Compliance @ OutcomesAI
About
I'm an experienced information & cyber security professional with strong background in Governance, Risk Management and Compliance (GRC), worked in multiple roles and across industries like banking, fintech, healthcare and SaaS businesses. I specialise in establishing security governance program, control implementation and auditing of info/cyber security frameworks like - ISO 27001, ISO 81001, SOC 2 Type II, CSA, MDS2, PCI DSS, NIST, OWASP etc., also includes building compliance to major regulatory requirements for HIPAA, GDPR, US FDA, EU MDR, MAS, etc, I've built information security governance program from ground up and helped successfully drive & achieve external security certs & compliances like SOC 2 Type II, ISO 27001, PCI DSS and HITRUST. I'm passionate about driving security excellence and enabling businesses to achieve hyper growth with high client satisfaction & trust to the product & service offerings, that we deliver in an increasingly complex digital landscape. Specialities: Adventures, team work, networking, social and coordinator Side hustle (read and learn) - Crypto, blockchain, stocks, funding, sports, M&A activities How can I help, let's connect here or my email : girish.b07@gmail.com
India
Nainital
Information Technology & Services
IT Governance, Payment Card Industry Data Security Standard (PCI DSS), IT Compliance, Third Party Vendors, Risk Assessment, Auditing, Internal Audits, Internal Controls, IT Audit, Sarbanes-Oxley Act, Technology Security, Global Security, Technology Risk, Stakeholder Management, Microsoft Excel, Identity and Access Management (IAM), Compliance Implementation, Stakeholder Engagement, Risk Monitoring, Risk Analysis
Experience

Director - Security and Compliance
Leading global security and privacy compliance initiatives from ground up. Building & implementing GRC at the intersection of Healthcare and AI, implementing security frameworks, achieving external compliance (SOC 2 Type II and HIPAA) and meeting regulatory requirements

Global Director - GRC and Cybersecurity
Responsibility for the overall information security governance, risk management and compliance assurance across global locations for the group. Leading efforts to prepare, drive and successfully achieve SOC 2 Type II, ISO 27001, GDPR and PCI DSS. Ensure robust cybersecurity by building up SOC operations including cloud and product security, implementing new and current security tools to best security standards to achieve high ROI and lowered business impact.

Manager - Information Security and Compliance
Singapore
As first info security hire at Biofourmis, I was responsible to setup & drive security governance and compliance program from scratch across all global entities. Key responsibilities includes: -Established security policies, procedures, templates, etc., aligned to industry frameworks (e.g. ISO 27001, NIST, HIPAA, etc) -Established and implemented security risk management program, evaluate and review remediations with risk owners regularly -Implemented security audit program to regularly evaluate and monitor compliance to policies -Cloud security governance and IT security control implementation guidance (SSO, MDM, DLP, IDS, EDR, WAF and IGA) -Product (software and medical device) and infra security, to integrate security by design and threat modelling (OWASP, SANS, VA/PT, CSA CCM, ISO 81001) -Client security risk assessments and audits (DDQ, RFP/RFIs, SIGs, security annex/DPA/BAA reviews, etc.) by large hospitals, healthcare and pharmaceuticals across US and key EU & APAC regions -Info security SME for responses to internal & external audits, client & vendor security audits, regulatory responses & requirements, etc. -Developed security & risk mgmt. framework for medical device security and supported regulatory filings - MDS2 (NEMA), ISO 81001, pre/post-market approvals, etc. -Third party and partnership risk assessments -Info security incident management, change and exceptions review and approvals -Info security awareness trainings, coordinate phishing simulations, training materials, etc. -Successfully achieve ISO 27001 and SOC 2 Type II for the company -Support regulatory audits - US FDA, EU MDR, Singapore HSA -Project management - DLP, GRC tool and other security initiatives -Information security strategic plan, roadmap and budgets -Supported investors/VCs/ strategic partners security DDQs, and M&A activities -Continuous process improvement measures, integration of security best practices, team management and management reporting

Manager - Information Security Audits, Risk and Compliance
Kuala Lumpur, Malaysia
Key roles and responsibilities: -End to end Information Security Audits of third parties spread across globally. Scope of audits includes ISO 27001, PCI DSS, NIST, SSAE18, SOC 2, GDPR, UK DPA, MAS, ABS OSPAR etc. and any other country specific compliance requirements. -Third party risk assessment and profiling. -Lead bank’s initiatives on cloud governance and security by establishing SOPs and implementation of controls aligned to industry standards like CSA, CIS, PCI-DSS, etc. -Exception handling with respect to open information security & compliance risks and work closely with regional business contacts on risk treatment plans. -Handling risk acceptance requests and work with regional stakeholders on risk treatment plans. -Review and guide business and other key stakeholders on the bank contractual requirements and other information security addendum. -Handling regional projects (consolidation of third parties within key markets) and working with Big 4's as partners to perform end to end assessments, includes risk assessment till final reporting to management. -Work closely with observation closure team within current team. -Work closely with country specific business and support team and when required globally to carry out risk and compliance audits activities and agree on risk mitigation plans to minimize risk exposure to the bank and its customers, both internally and externally. -Design and development of internal policies, procedures, templates, reference & working documents, etc. -Mapping of frameworks, standards & other regulatory requirements and embedding it into the process to perform risk based audits/assessments. -Multiple process improvement initiatives. -Security project management (business, partners, vendors, etc.)

Team Lead - Information Security, Risk and Compliance
New Delhi Area, India
Information Security Management team is the security interface to clients, vendors, and business development teams in the areas of information security, risk and compliance. • Performing client Information Security and compliance audits & assessments, RFP/RFI, security due diligence, reviews, etc. • Risk based vendor assessment via onsite or web-ex and management reporting • Excellent working knowledge on threat intelligence model, Incident Management, Change Management, Forensics Analysis and Investigation of breaches/incidents, etc. • Handling and managing client onsite reviews (client or client’s consultants/Big 4). • Vulnerability Assessment, Network Assessment and Pen Test related requests, target remediation date (test/production release date), SME coordination, etc. • Initial review and red lining MSA, NDA, privacy documents, etc. as part of new business and renewal of contracts corresponding to Info Security, risk and compliance. • Review and update of Information Security documentation (process, procedures, templates, guidelines, etc.) • Excellent knowledge and working experience of ISO standards and other compliance & regulatory frameworks/acts like ISO 27001:2013, ISO 23001, ISO 31000, NIST, COBIT, CIS, UK DPA, SOX, PCI DSS, Safe Harbor, SSAE 16 (SOC 1, 2 & 3 reports)etc. • Excellent working knowledge of GRC tools and other audit/assessment applications. • Proven Ability to work collaboratively across the cross domain disciplines. • Creation and update of SIG documents. SIGs are accepted by most of the Financial and Investments companies. • New hire induction training on ISMS, creating info security awareness periodically across the organization. • Rewards and recognition by Broadridge as part of ACE Program (ACE is Broadridge associate awarding model). • Star Player reward • Best in Teamwork reward

Senior Information Security Analyst
Hyderabad Area, India
• Information Security Management • ISO 27001, HIPAA, SOX • SSAE 16 or SAS 70 / SOC 1/2/3 Type I/II Reports • Business Continuity Plans (BCP) and site testing • Disaster Recovery Plans (DR) and site testing • Compliance Activities • Conducting Information Security Audits • Facilitation of External Auditors • Creating Risk Profile of Projects • Risk Assessment at project and organizational level • Risk & Incident Reporting and Gap Checks • Business Process Management (work on Policies, Process, Visio, Procedures, Guidelines, Templates/Tracker, other document write up, etc) • Implementing HIPAA for US Heathcare Accounts • Planning for Patch, Firewall & Antivirus Management • Management Services • Managing Network Security • Managing Data Centre Security • Managing DLP, web security and email • Physical & Logical Security • Branding Information Security Internally and Externally • Information Security Learning and Development • Security articles to publish internally • Client's/prospect's info security requirement review, analysis and tailoring. • Review and work on client/vendor assessment programme • Goal Setting and Strategic Planning at Org level for various functions like HR, Admin, IT, etc. • Review of Master Service Agreements, International Data Protection Policy, Country wide Security/Service agreements, Business Associate Agreements and other International Agreements, Acts, etc. • Understanding of CMMI Level 5 Process Areas (Dev and Services)

Business Analyst
ValueLabs, Hi Tech City, Hyderabad.
Worked for US based Healthcare project complying HIPAA norms for US Healthcare Industry. The client is one of the biggest name in Healthcare segment in the United States. Working on business reports, data mining, use of required software applications/tools, in depth research on reports & working on them to avoid any business issues, if so providing appropriate solutions/analyzing to cope up with the time & market crunch. Apart daily client meetings(onsite) through calls or via emails is a regular task. Client services/relationships & retention across Minneapolis, Cali, Louisville, Atlanta, Scottsdale, Seattle & San Francisco regions share a major pie (After Sales Services). Domain skills & work involves: • Business research, • Data integration, • Management services, • HIPAA Title, • Professional writing, • Financial services, • Web research, • Technology research, • Data mining, • Database creation, • Web support & • SEO.

Trainee Executive- Branding & Client Relationships
New Delhi Area, India
In PepsiCo I used to take of the Retail business which includes enhancements, dealings, prospecting, segmenting the market and deal finalization in the Delhi NCR(North Delhi Regions Including parts of NCR). Increasing BRAND awareness to meet the right mix was an added responsibility.
Girish Singh Bhandari's Contact Information
Phone
Find the Right Leads
Find Verified Contact Data
What LeadContact does well
Find verified emails, phone numbers, and decision-makers with 98% accuracy.
Find Leads
Find the right people by company, role, industry, location, and more.
925M+ professional profiles

Find Emails
Access verified email addresses for your target contacts.
657M+ emails

Find Phone Numbers
Get cross-validated phone data from multiple top sources.
239M+ phone numbers

More Accurate. Lower Cost.
Find contact data in 1 tool with 98% accuracy
LeadContact integrates leading enrichment tools to deliver more accurate contact data—without paying for each one.
Great conversations start with the right contact.
It’s time to find yours.


