Senior Manager — Information Security (Head of GRC)
Uniphore Software Systems Pvt. Ltd., Chennai, India
- Architect and lead enterprise-wide Security, Risk and Privacy programs across NIST 2.0, ISO 27001/27701/27017/27018, SOC 2 Type II, PCI DSS 4.0, CPRA/CCPA, HIPAA and GDPR.
- Own the Cybersecurity Governance Program, aligning security, risk and privacy controls across cross-functional teams.
- Lead Privacy Impact Assessments for all SaaS products on AWS and GCP; respond to due-diligence inquiries via CSA CAIQ, Cyber GRC, Drata, Metric Stream, RSA Archer and OneTrust GRC.
- Maintain a customer-facing Trust Center and executed the annual TPRM assessment across the top 50 critical vendors within 30 days.
- Led ISMS gap assessments and certification audits to completion within 4 months with zero major non-conformities; delivered GDPR, HIPAA and PCI DSS certifications on the same timeline.