Sagar S.
Manager @ Cvent
About
With 12 years of experience in Governance, Risk and Compliance (GRC). I hold several credentials, such as CISA, CTPRP, ISO 27001, ITIL, and Six Sigma, that demonstrate my proficiency and expertise in various security frameworks, standards, and methodologies. I lead and deliver GRC projects for clients across different industries and geographies, covering areas such as cyber strategy, third party risk assurance, privacy, internal audit, and regulatory compliance. I leverage my skills in IT audit, policy design, gap assessment, content writing, and GRC tools to provide high-quality solutions that meet the client's needs and expectations. I also contribute to the development and improvement of the GRC, by sharing best practices, mentoring junior staff, and participating in thought leadership initiatives. My goal is to help organizations achieve their objectives while managing their risks and ensuring their compliance.
India
New Delhi
Information Technology & Services
Enterprise Risk Management, Info Sec, Identity and Access Management (IAM), Documentation, ITIL, Emergency Preparedness, Evaluation Methodologies, Recruiting, Recruitment Management, IT Controls, Compliance Operations, Agile Methodologies, Information Audit, Exceptions, IT Compliance, Request for Proposal (RFP), Continuous Improvement, Incident Management, ServiceNow, Regulatory Requirements
Experience

Manager
Gurugram
• Led the regional Security Risk & Compliance team, developing scalable programs and fostering a high-performing culture of ownership, collaboration, and continuous improvement while aligning with global Information Security leadership. • Developed policies, controls, and ISMS framework, ensuring continuous SOC 2 audit readiness and control effectiveness. Owned annual review and updates for all Info Sec policies across Cvent. • Directed certification audit activities across key frameworks including ISO 27001, SOX ITGC ensuring compliance for Cvent's global SaaS operations, enterprise risk assessment and risk assessment of AI technologies. • Monitored regulatory changes and delivered training, reporting, and dashboards to strengthen compliance culture and inform leadership decisions. • Drove AI security assessments for enterprise product enhancements, identifying risks around model misuse, data exposure, and unsafe outputs, and supporting the implementation of appropriate guardrails. • Owned SOC 2 Type II readiness across evidence collection, control testing, and auditor coordination, ensuring year-round audit preparedness. • Managed third-party risk reviews for critical vendors and drove remediation tracking for open issues, improving governance consistency across the program. • Worked closely with the customer assurance team in responding to DDQs, VSQs, SIG, and CAIQ questionnaires for enterprise and institutional clients, and supported security due diligence calls with prospective customers and business stakeholders. • Led compliance efforts for India specific regulatory requirements, including the IT Act, OFSC guidelines, E-Waste Rules, and other applicable statutory obligations.

Manager
Gurugram
• Led assessment and implementation of various Information Security Management System Frameworks including ISO 27001, NIST CSF, NIST 800 Series, COBIT, GDPR, HIPAA and SOC 2 • Assisted clients in reviewing and implementing Information Security controls testing, providing technical expertise, direction, and training to consultants/senior consultants within the Risk Strategy & Technology division • Documented security policies, procedures, risk and controls matrix, and defined KPIs, risk treatment plans, and security roadmap • Supported Third-Party Risk Management (TPRM) strategy and design work, including developing questionnaires, risk assessment methodologies, and evaluation frameworks • Operationalized Third Party Risk Management frameworks; Collaborated with stakeholders to gather and document requirements for services to be procured through RFP process • Documented the RFP process, decisions, and outcomes, prepared reports and presentations for management; Held responsibilities for key activities involving recruitment, rewards and recognitions, and learning and development.

Assistant Manager
Gurugram
• Collaborated with clients to enhance their third-party risk management capabilities, focusing on people, processes, and technology • Assisted in third-party risk assessments and maturity assessments based on ISO 27001, FFIEC, NIST 800, SP 53, COBIT, SOX, ITGC, SOC 1 and 2, and generated dashboards and reports • Collaborated cross-functionally with IT, security, and business teams to drive compliance adherence and operational excellence • Provided technical expertise, direction, and training to consultants within the Risk Strategy & Technology division • Participated in cyber security attestations and remediation of cyber security risks; Developed privacy governance frameworks and upgraded policies and standards • Designed and tested control effectiveness, risk frameworks, and built Management Information and reporting systems; Customer experience includes working with world-leading search engines, and banks based out of the US and UK • Assisted in recruitment by conducting interviews and mentoring.

Technical Specialist
Noida
• Executed advisory and consulting engagements focusing on regulatory risk and compliances for Third-Party Risk Management and SOC 2 readiness. • Reviewed contractual terms and conditions for compliance from security, privacy, and audit perspectives. • Defined comprehensive third-party risk management policies and procedures; Designed controls aligned with vendor classification and underlying policies • Conducted Third-Party Risk Assessments, performed gap assessments, and managed issue resolution, analytics, and reporting, including the creation of customized documentation of gaps with recommendations for the audit function.

Information Security Auditor
Noida
• Assisted in performing Supplier Risk Assessment (SRA) and Pre-Contract Supplier Risk Assessment (PSRA) for Third Parties •Reviewed the security environment of suppliers based on attestations, technical artifacts, and documentation supplied by Third-Party Vendors •Identified and documented operational technical risks within the supplier environment based on the review of technical artifacts and documentation •Assisted in obtaining relevant documentation from suppliers to perform an effective risk assessment; Supported in the remediation of high risks identified during supplier risk assessment; Assisted in reviewing the security program •Advised management regarding appropriate measures to be taken to reduce, eliminate, or manage organizational risks as it pertains to the exception being reviewed

System Engineer
• Led ISO 27001 based internal audits covering Access Controls, Information Classification, User Access Management, System and Application access controls, and Backup procedures • Assessed security posture, identified gaps, and risks in the existing environment, and developed solutions to mitigate the identified gaps and risks • Implemented Agile SDLC methodology for project management to ensure efficient and timely delivery of projects • Conducted audits, prepared comprehensive gap reports, audit reports, and learning documents; Analyzed incidents reported by users and ensured their closure using ServiceNow tool; Managed Integration with inhouse tools • Provided functional support to end users on application issues and offered consulting on tool usage and problem analysis for optimal resolution; Ensured compliance with Access and Identity management Audit Policies • Managed Incident Management and adherence to SLAs for cases logged by users, including server health checks, enforcement of security policies, and certificates on Cloud servers.
Sagar S.'s Contact Information
Phone
Find the Right Leads
Find Verified Contact Data
What LeadContact does well
Find verified emails, phone numbers, and decision-makers with 98% accuracy.
Find Leads
Find the right people by company, role, industry, location, and more.
925M+ professional profiles

Find Emails
Access verified email addresses for your target contacts.
657M+ emails

Find Phone Numbers
Get cross-validated phone data from multiple top sources.
239M+ phone numbers

More Accurate. Lower Cost.
Find contact data in 1 tool with 98% accuracy
LeadContact integrates leading enrichment tools to deliver more accurate contact data—without paying for each one.
Great conversations start with the right contact.
It’s time to find yours.





