Rishi Raj Srivastava, CIPM CDPO CISA DCPLA
Data Protection Officer @ Jindal Steel Ltd.
About
Cyber Security and Privacy Professional with 14+ years of experience in Security and Privacy consulting and management. Experienced in leading cyber security and privacy implementation programs. My qualifications include Masters in Cyber Laws & Information Security and Engineering Degree in Computer Science; along with cIPM, DSCI DCPLA, CISA, ISO 27001 Lead Auditor, ISO 22301 LI, Microsoft AZ 900, OneTrust Privacy Professional and ITIL v3 certifications; and detailed knowledge of various privacy laws and security tools, technologies and best practices. I have also published one research paper titled “Secure Framework for Social Networks”.
India
Gurgaon
Consumer Goods
Data Protection, Regulatory Compliance, Cybersecurity, NIST 800-53, Data Privacy Risk Management, Payment Card Industry Data Security Standard (PCI DSS), ISAE 3402, SOC 2, SOC 1, General Data Protection Regulation (GDPR), Risk Management, Enterprise Risk Management, IT Risk Management, SOX 404 Top–Down Risk Assessments (TDRA), Risk Based Testing, Data Privacy, Privacy Compliance, Privacy Policies, Privacy Law, Privacy Protection
Experience

Data Protection Officer
Gurugram, Haryana, India
Data Protection and GRC Lead - Lead organizational compliance with regional and global privacy laws including India’s DPDPA, Oman PDPL, South Africa POPIA, and GDPR. - Overseeing privacy governance, DPIAs, RoPA, DSARs, vendor due diligence, and breach management. - Develop and maintain the Privacy Management Framework aligned with ISO 27701 and global best practices. - Drive privacy-by-design and data protection awareness across business functions and technology initiatives. - Manage end-to-end compliance and certification under ISO 27001, ensuring effective ISMS controls and continuous improvement. - Oversee risk management, internal audits, and policy governance across information security and privacy domains. - Align GRC initiatives with ISO 27001, 22301 (BCMS), ISO 31000 (Risk Management), NIST CSF frameworks. - Lead cross-functional collaboration on regulatory readiness, incident response, and third-party risk management. - Conduct training, awareness, and management reviews, fostering a culture of compliance and accountability. - Advise leadership on emerging privacy, cybersecurity, and regulatory developments to strengthen organizational resilience.

IT GRC Consultant
Gurgaon, India
• Performing Internal ITGC Audits. • Perform IT audits basis MSA requirement, Organisation policies and applicable standards. • Identify and highlight gaps to respective teams for closure. • Report identified issues to Senior Management. • Follow up and validate closure. • Handle PCI DSS, ISAE 3402 and SOX 404 audits. • Support organization security and compliance activities.

Senior Associate
Noida
•Part of GS India Security and Compliance Team •ISMS Implementation and maintenance. •Ensuring compliance to PCI DSS, SSAE 16, ISO 27001 and Corporate Audits. •Conducting Internal PCI DSS and Quarterly internal audits aiming to identify gaps and timely remediation. •Performing ODC audits as per client requirements. •Conducting Risk Assessment and Business Impact Analysis. •Implementation and testing of BCP plan. •Coordination with various support functions in remediation of identified gaps. •Running Security Awareness campaigns. •Reviewing monthly Vulnerability Scans reports to ensure timely remediation of identified vulnerabilities. •Implementation of new controls based on the organizational changes, framework updates and audit findings. •Coordinating with External Auditors and facilitating external audits. Additional Responsibilities •Part of Enterprise Risk and Resilience Team •Development of Client Assurance framework to provide consistent and timely response to Fiserv’s customers and clients’ vendor security questionnaires. •Creation of repository of questions with enterprise, client, business unit, product and location specific details of security controls as implemented in the organization. •Interacting with various ISOs and function heads across the globe. •Creation of process documents, communication plans.

Systems Engineer
New Delhi Area, India
Client: Indian Government Organization Project: Strong Authentication Solution •Leading the complete design and delivery of Two Factor Authentication Solution. •Designed Security Solution to provide Strong Authentication (Two Factor Authentication) •Designed High Level and Detailed design document in accordance with client requirements. •Presented solution to the client. •Activity involved creation of Use Cases and Test Cases. •Defined various roles, policies and workflow processes. •Integration of solution with other proposed and existing security solutions. •Presently working on Implementation of RSA SecurID solution. •Worked on development of Hardening Guidelines for windows desktop systems.

Assistant Systems Engineer
Bengaluru Area, India
Client : UK Government Project: Vulnerability Assessment and Penetration Testing •Conducted Network and Application VAPT on client’s internet facing infrastructure, applications and internal network and portal. •Conducted network vulnerability scanning using Nessus. •Performed manual testing using Nmap, Netcat, Openssl, and Metasploit auxiliary modules. •Conducted Vulnerability Assessment & Penetration testing for Scheme website application and internal portals using HP WebInspect and WebScarab. •Analyzed the results and involved in report preparation for the vulnerabilities discovered along with the appropriate recommendations and risk factors.

Information Security Analyst
Bengaluru Area, India
Client : US Based Financial Service Provider Project: Security Operations Center (Vulnerability Management and Surveillance). •Surveillance and analysis of incidents using SIEM Tool ArcSight ESM , nCircle IP360 and AirDefense using logs from various perimeter devices. •Monitoring client network from the Information Security perspective using ArcSight ESM 4.0. •Handling security incidents in real time. •Finding out anomalies and taking preventive measures for external attacks. •Monitoring and prevention of any sensitive data leakage from the network using Vontu 11.1. •Performing BAU and on demand vulnerability scan on the network using nCircle IP 360. •Preparing vulnerability and security related reports. •Handling tickets through IBM ticketing tool ManageNow. •Handling WebSense exceptions and analyzing WebSense logs time to time. •Interacting with different vendors on different issues and working along with them to resolve those. • Analyzing phishing and spam emails.

Information Security Analyst
Bengaluru Area, India
Client : US Based Financial Service Provider Project: Vendor Security Assessment •Assessing third party vendor’s security posture and the level of security controls they have in place throughout their enterprise according to client’s security policy and requirements and help in decision making. •Conducted vendor’s security assessment using Standard Information Gathering (SIG) reviews and Application Service Provider (ASP) reviews. •Assessing controls present in vendor’s environment based on response to questionnaire and security documents and audit reports shared by vendors. •Updating assessment findings on Archer and following up with vendor towards closure.

Internship at
Gurgaon, India
Threat Modelling of e-commerce web-application. •Analysing architecture and workflow of the application to identify possible threats and risks using STRIDE and DREAD. •Defining use and misuse case scenarios, entry/exit points and trust boundaries •Developing Threat Model and Attack trees using Microsoft Threat Analysis and Modelling tool, and using MS Visio. •Suggesting mitigation strategies for secure application development.
Rishi Raj Srivastava, CIPM CDPO CISA DCPLA's Contact Information
Phone
Find the Right Leads
Find Verified Contact Data
What LeadContact does well
Find verified emails, phone numbers, and decision-makers with 98% accuracy.
Find Leads
Find the right people by company, role, industry, location, and more.
925M+ professional profiles

Find Emails
Access verified email addresses for your target contacts.
657M+ emails

Find Phone Numbers
Get cross-validated phone data from multiple top sources.
239M+ phone numbers

More Accurate. Lower Cost.
Find contact data in 1 tool with 98% accuracy
LeadContact integrates leading enrichment tools to deliver more accurate contact data—without paying for each one.
Great conversations start with the right contact.
It’s time to find yours.




