Back to Developers
shaik

shaik

Information Security Analyst

Hyderabad, India
85
Profile Score

About

Cyber Security & GRC Analyst with 1.6+ years of experience in ISO/IEC 27001:2022 (ISMS) internal audit support, risk assessments, and compliance documentation aligned with PDPL (KSA), NCA ECC, and SWIFT CSP. Skilled in control testing support, evidence collection/validation, CAPA tracking, remediation follow-ups, and risk register maintenance. Also bring 3+ years of Application Support experience, supporting business users, handling incidents, troubleshooting, and coordinating with cross-functional teams to ensure stable operations. Experienced in running KnowBe4 security awareness/phishing simulations and monitoring endpoint alerts using Trend Micro Vision One.

Skills & Expertise (17)

ISO/IEC 27001:2022 Advanced
8.3/10
4.6
Years Exp
GRC & Compliance Advanced
8.0/10
4.6
Years Exp
Security Awareness Advanced
8.0/10
4.6
Years Exp
Risk Management Advanced
7.8/10
4.6
Years Exp
audit support Advanced
7.5/10
4.6
Years Exp
Monitoring & Operations Advanced
7.3/10
4.6
Years Exp
MySql LINUX MS Office RCA Archer MXToolbox Shodan VirusTotal ServiceNow Nipper Rapid7 Nexpose ManageEngine Log360

Work Experience

Application Support Engineer

Nityo Infotech

Present - Present

Managed incidents and service requests, ensuring timely resolution and clear stakeholder communication. Troubleshot application and backend issues; collaborated with teams for root cause analysis and documented fixes to prevent recurrence. Supported production stability via monitoring and operational checks; contributed to continuous improvement and knowledge base updates.

Cyber Security & GRC Analyst

TechnoVal Information Systems

Nov 2024 - Present

Supported enterprise GRC initiatives by coordinating control owners and maintaining compliance documentation for audit readiness. Assisted internal audits aligned with ISO 27001:2022, SWIFT CSP, NCA ECC, and PDPL (KSA) by collecting, validating, and organizing evidence. Tracked and followed up 25+ audit findings (CAPA) with stakeholders; ensured remediation actions were documented and progressed to closure. Maintained evidence repositories and audit trackers; ensured completeness, version control, and timely availability for auditors. Supported risk assessments across 8 departments by updating the risk register, capturing threats/vulnerabilities, and monitoring mitigation plans. Conducted cybersecurity onboarding sessions for all new joiners, covering phishing awareness, social engineering, password security, MFA, data protection, and incident reporting procedures. Assigned mandatory security training modules to new employees through the awareness platform and ensured timely completion. Created awareness content including presentations, newsletters, bulletins, posters, and quick user guides for all staff levels. Planned and executed phishing simulations for 900+ employees every month using KnowBe4; monitored metrics (open/click/credential) and shared targeted improvement actions. Supported mandatory security awareness Computer based training campaigns; assisted with communications and completion tracking. Created and distributed security bulletins/newsletters to promote secure behavior and reinforce policy requirements. Delivered sessions on phishing indicators, social engineering tactics, password hygiene, MFA, safe browsing, and secure data handling. Owned the security awareness onboarding process: enrolled users, assigned mandatory modules, tracked completion, sent reminders, and maintained records for audit evidence. Monitored endpoint security alerts, trends, and health using Trend Micro Vision One; escalated suspicious activity per incident handling process. Supported compliance mapping activities for NCA ECC and PDPL requirements through documentation, evidence mapping, and control support. Processed approvals for Local Admin, VPN, USB, and WhatsApp access in line with security policies; maintained approvals for audit reference.

Education

Bachelor of Science (B.Sc.) — Computers - Yogi Vemana University

- · Afghanistan

Certifications

ISO/IEC 27001:2022 – ISMS Foundation

· 2026

Interested in this developer?

Profile Score Breakdown

📷 Photo 10/10
📄 Resume 10/10
💼 Job Title 10/10
✍️ Bio 10/10
🛠️ Skills 20/20
🎓 Education 10/10
⏱️ Experience 5/15
💰 Rate 0/5
🏆 Certs 5/5
Verified 5/5
Total Score 85/100

Profile Overview

Member sinceMar 2026

Skills (17)

ISO/IEC 27001:2022 GRC & Compliance Security Awareness Risk Management audit support Monitoring & Operations MySql LINUX MS Office RCA Archer +7 more