Pavan Kumar
Senior GRC Analyst
About
Having total 5 years of IT Carrier with hands-on experience in SOC2, ITGC (SOX-404) Audits, ISO 27001:2022, Policy Management and Third-Party Risk Management (TPRM). Experienced in managing end-to-end audit lifecycles, identifying control gaps and ensuring regulatory compliance across complex IT environments. Proven ability to streamline Evidence collection, enhance audit preparedness and drive timely remediation. Well-versed in tools like Jira, Confluence and ServiceNow.
Skills & Expertise (13)
Work Experience
Senior GRC Analyst
Accenture Solutions Pvt Ltd
Feb 2026 - Jun 2026
Owned enterprise Disaster Recovery governance, planning, testing, and execution for business-critical applications and infrastructure. Led Application Recovery Plan (ARP) and Technical Recovery Plan (TRP) programs, ensuring recovery readiness across application and infrastructure domains. Directed cross-functional recovery coordination among application, infrastructure, business, and vendor teams to deliver successful recovery outcomes. Established recovery strategies, dependencies, and recovery sequencing aligned with business priorities, RTOs, and RPOs. Managed DR testing, readiness assessments, compliance reviews, and continuous improvement initiatives to enhance organizational resilience. Governed recovery documentation, audit evidence, and DR lifecycle management through ServiceNow and SharePoint platforms. Drove application validation, service restoration verification, and post-recovery reviews to ensure business continuity and operational stability. Partnered with Business Continuity and senior leadership teams to strengthen enterprise resilience and minimize business impact during disruptions.
GRC Analyst
Ascendion Engineering Pvt Ltd
Apr 2022 - Sep 2025
Led SOC 2 Type II audits across business units, ensuring compliance with AICPA Trust Services Criteria. Partnered with external auditors to enhance evidence collection, conduct efficient audit interviews, and produce comprehensive reporting. Conducted testing of design and operating effectiveness for SOC 2 Type II. Trained internal teams on SOC 2 compliance best practices, improving organizational audit preparedness and reducing findings. Conducted walkthroughs and documented the processes to support internal and external audits. Documented control effectiveness throughout audit cycles, ensuring consistent performance and timely remediation of issues. Built centralized audit evidence repository, reducing collection timelines by 45%. Aligned SOC 2 controls with ISO 27001, SOX ITGC, HIPAA, and TPRM frameworks. Collaborated with InfoSec and Legal teams for vendor risk evaluations. Managed the end-to-end process of sending vendor onboarding documentation and compliance questionnaires. Conducted thorough due diligence on third-party vendors, evaluating their compliance with regulatory and internal standards. Reviewed documentation such as SOC reports, ISO certifications, and data protection policies to assess risk levels.
Analyst
First Source Solutions Pvt Ltd
Feb 2021 - Mar 2022
Acted as main client liaison for SOX 404 IT General Controls, ensuring process and control alignment with audit requirements. Led SOX 404 IT General Controls (ITGC) audits across applications, operating systems, databases, and ERP environments, ensuring compliance with regulatory and organizational requirements. Evaluated the design and operating effectiveness of controls covering User Access Management, Change Management, IT Operations, Incident Management, Patch Management, and Backup & Recovery processes. Conducted process walkthroughs, control testing, and evidence validation activities to assess compliance and identify control deficiencies. Conducted organization-wide awareness and targeted training sessions to drive policy adoption, reduce non-compliance, and strengthen security culture. Managed end-to-end third-party risk assessment activities throughout vendor onboarding, ongoing monitoring, and offboarding processes. Evaluated vendor security posture through SIG, CAIQ, SOC reports, ISO certifications, penetration testing reports, and security questionnaires. Assessed cyber security, operational, regulatory, and privacy risks associated with third-party service providers. Maintained vendor inventories, risk registers, and remediation tracking mechanisms to support ongoing compliance monitoring. Reviewed contractual security requirements, SLAs, and data protection obligations to ensure alignment with organizational risk appetite.
Education
B. Tech - JNTUA
- ยท Afghanistan
Certifications
No certifications added yet
Interested in this developer?
Profile Score Breakdown
Profile Overview
Skills (13)
Click a skill to find developers with the same skill