Back to Developers
Pavan Kumar

Pavan Kumar

Senior GRC Analyst

4+ yrs exp 88 ยท Excellent

About

Having total 5 years of IT Carrier with hands-on experience in SOC2, ITGC (SOX-404) Audits, ISO 27001:2022, Policy Management and Third-Party Risk Management (TPRM). Experienced in managing end-to-end audit lifecycles, identifying control gaps and ensuring regulatory compliance across complex IT environments. Proven ability to streamline Evidence collection, enhance audit preparedness and drive timely remediation. Well-versed in tools like Jira, Confluence and ServiceNow.

Skills & Expertise (13)

Documentation & Reporting Advanced
8.0/10
5
Years Exp
Third Party Risk Management Advanced
7.5/10
5
Years Exp
Stakeholder Engagement Advanced
7.5/10
5
Years Exp
Audit coordination Advanced
7.5/10
5
Years Exp
stakeholder communication Advanced
7.5/10
5
Years Exp
ServiceNow Intermediate
7.0/10
3
Years Exp
MS Office Advanced
7.0/10
5
Years Exp
Power BI Intermediate
6.5/10
3
Years Exp
HIPAA Intermediate
6.5/10
3
Years Exp
GDPR Intermediate
6.5/10
3
Years Exp
Jira Intermediate
6.0/10
3
Years Exp
PCIDSS Intermediate
6.0/10
3
Years Exp
Policy Creation

Work Experience

Senior GRC Analyst

Accenture Solutions Pvt Ltd

Feb 2026 - Jun 2026

Owned enterprise Disaster Recovery governance, planning, testing, and execution for business-critical applications and infrastructure. Led Application Recovery Plan (ARP) and Technical Recovery Plan (TRP) programs, ensuring recovery readiness across application and infrastructure domains. Directed cross-functional recovery coordination among application, infrastructure, business, and vendor teams to deliver successful recovery outcomes. Established recovery strategies, dependencies, and recovery sequencing aligned with business priorities, RTOs, and RPOs. Managed DR testing, readiness assessments, compliance reviews, and continuous improvement initiatives to enhance organizational resilience. Governed recovery documentation, audit evidence, and DR lifecycle management through ServiceNow and SharePoint platforms. Drove application validation, service restoration verification, and post-recovery reviews to ensure business continuity and operational stability. Partnered with Business Continuity and senior leadership teams to strengthen enterprise resilience and minimize business impact during disruptions.

GRC Analyst

Ascendion Engineering Pvt Ltd

Apr 2022 - Sep 2025

Led SOC 2 Type II audits across business units, ensuring compliance with AICPA Trust Services Criteria. Partnered with external auditors to enhance evidence collection, conduct efficient audit interviews, and produce comprehensive reporting. Conducted testing of design and operating effectiveness for SOC 2 Type II. Trained internal teams on SOC 2 compliance best practices, improving organizational audit preparedness and reducing findings. Conducted walkthroughs and documented the processes to support internal and external audits. Documented control effectiveness throughout audit cycles, ensuring consistent performance and timely remediation of issues. Built centralized audit evidence repository, reducing collection timelines by 45%. Aligned SOC 2 controls with ISO 27001, SOX ITGC, HIPAA, and TPRM frameworks. Collaborated with InfoSec and Legal teams for vendor risk evaluations. Managed the end-to-end process of sending vendor onboarding documentation and compliance questionnaires. Conducted thorough due diligence on third-party vendors, evaluating their compliance with regulatory and internal standards. Reviewed documentation such as SOC reports, ISO certifications, and data protection policies to assess risk levels.

Analyst

First Source Solutions Pvt Ltd

Feb 2021 - Mar 2022

Acted as main client liaison for SOX 404 IT General Controls, ensuring process and control alignment with audit requirements. Led SOX 404 IT General Controls (ITGC) audits across applications, operating systems, databases, and ERP environments, ensuring compliance with regulatory and organizational requirements. Evaluated the design and operating effectiveness of controls covering User Access Management, Change Management, IT Operations, Incident Management, Patch Management, and Backup & Recovery processes. Conducted process walkthroughs, control testing, and evidence validation activities to assess compliance and identify control deficiencies. Conducted organization-wide awareness and targeted training sessions to drive policy adoption, reduce non-compliance, and strengthen security culture. Managed end-to-end third-party risk assessment activities throughout vendor onboarding, ongoing monitoring, and offboarding processes. Evaluated vendor security posture through SIG, CAIQ, SOC reports, ISO certifications, penetration testing reports, and security questionnaires. Assessed cyber security, operational, regulatory, and privacy risks associated with third-party service providers. Maintained vendor inventories, risk registers, and remediation tracking mechanisms to support ongoing compliance monitoring. Reviewed contractual security requirements, SLAs, and data protection obligations to ensure alignment with organizational risk appetite.

Education

B. Tech - JNTUA

- ยท Afghanistan

Certifications

No certifications added yet

Interested in this developer?

Profile Score Breakdown

๐Ÿ“ท Photo 10/10
๐Ÿ“„ Resume 10/10
๐Ÿ’ผ Job Title 10/10
โœ๏ธ Bio 10/10
๐Ÿ› ๏ธ Skills 18/20
๐ŸŽ“ Education 10/10
โฑ๏ธ Experience 15/15
๐Ÿ’ฐ Rate 0/5
๐Ÿ† Certs 0/5
โœ… Verified 5/5
Total Score 88/100

Profile Overview

Member sinceJul 2026