Back to Developers
Shubham Mishra

Shubham Mishra

Third-Party Risk Management & Cybersecurity Analyst

Pune, Maharashtra 2+ yrs exp 85 ยท Excellent

About

Cybersecurity and IT Infrastructure professional with 2.5+ years of experience supporting Third-Party Risk Management (TPRM), vendor risk assessment, and information security governance in enterprise environments. Skilled in evaluating vendor security postures, applying ISO/IEC 27001:2022 and SOC 2 principles, and supporting risk-based decision-making across identity and access management, endpoint security, and incident response. Experienced in translating security control requirements into operational practice through Active Directory administration, MFA enablement, BitLocker management, and VPN security. Seeking to apply risk assessment, compliance, and cybersecurity expertise in a Third-Party Risk Management (TPRM) and Cybersecurity Senior Analyst role.

Skills & Expertise (19)

Information Security Risk Assessment Intermediate
7.5/10
3
Years Exp
Third-Party Risk Management Intermediate
7.5/10
3
Years Exp
Group Policy Objects Intermediate
7.0/10
3
Years Exp
MFA Intermediate
7.0/10
3
Years Exp
Active Directory Intermediate
7.0/10
3
Years Exp
Role-based access control Intermediate
6.5/10
3
Years Exp
SOC 2 Intermediate
6.5/10
3
Years Exp
VPN Security Intermediate
6.5/10
3
Years Exp
Endpoint Hardening Intermediate
6.5/10
3
Years Exp
Audit Documentation Intermediate
6.5/10
3
Years Exp
compliance reporting Intermediate
6.5/10
3
Years Exp
Excel Intermediate
6.5/10
3
Years Exp
SLA Management Intermediate
6.0/10
3
Years Exp
User access reviews Intermediate
6.0/10
3
Years Exp
ItIl Intermediate
6.0/10
3
Years Exp
patch management Intermediate
6.0/10
3
Years Exp
Root Cause Analysis Intermediate
6.0/10
3
Years Exp
Microsoft Office Suite Intermediate
6.0/10
3
Years Exp
Power BI Intermediate
5.5/10
3
Years Exp

Work Experience

Senior Technical Process Executive

Infosys BPM

Nov 2025 - May 2026

Supported evaluation of vendor- and third-party-related security controls (MFA, access governance, endpoint protection) against organizational compliance and SLA requirements. Applied risk-based troubleshooting methodologies to prioritize and resolve security incidents, minimizing operational and third-party exposure. Reviewed access requests and account activity against least-privilege and security policy requirements, flagging deviations for follow-up. Identified control gaps during incident and access-related investigations and escalated findings to relevant teams for timely remediation. Maintained audit-ready records of security control checks and remediation actions to support compliance and governance reporting. Coordinated with internal stakeholders to verify that third-party and vendor-facing access remained aligned with organizational risk and compliance requirements. Contributed to process documentation that improved consistency and traceability of security and risk-related activities across the team. Performed vendor risk assessments and prepared assessment reports summarizing findings, risk ratings, and recommendations for stakeholders. Identified third-party risk exposures during reviews and investigations, coordinating remediation actions with relevant teams to ensure timely closure. Performed identity and access management activities including password resets, MFA enrollment, and account verification procedures in line with security policy. Investigated endpoint security issues and coordinated with cross-functional teams to drive timely remediation. Managed security-related incidents and service requests end-to-end while adhering to SLA and compliance requirements. Ensured accurate, audit-ready documentation of incidents and security-related activities to support compliance reviews. Collaborated with cross-functional teams to support secure IT operations and business continuity.

Windows System Administrator

Tata Technologies

Jul 2023 - Jul 2025

Provisioned and reviewed secure remote access (VPN) requests in line with organizational security policy and least-privilege principles. Supported enforcement of security baselines (MFA, encryption, endpoint controls) applicable to internal and externally-managed accounts through Group Policy administration. Assisted stakeholders in maintaining compliance with corporate security standards during access provisioning and periodic reviews. Performed vendor risk assessments and prepared assessment reports supporting governance and compliance reviews. Identified third-party risk exposures linked to vendor-managed access and endpoints, coordinating remediation with relevant stakeholders. Administered Active Directory accounts, user access management, and security group memberships in line with organizational security policy. Conducted periodic access reviews and ensured proper user provisioning and de-provisioning practices, supporting least-privilege and audit-readiness objectives. Supported implementation of security controls including MFA, BitLocker encryption, password management, and endpoint protection mechanisms. Implemented Group Policies to enforce security baselines and organizational compliance requirements. Worked with internal stakeholders to maintain compliance with corporate security standards and IT governance requirements. Assisted in security incident investigation through log analysis and troubleshooting of endpoint-related security issues.

Education

Computer Science and Engineering - IES College of Technology

2023 - 2026 ยท Afghanistan

Computer Science and Engineering - Government Polytechnic Adityapur

2020 - 2023 ยท Afghanistan

Certifications

No certifications added yet

Interested in this developer?

Profile Score Breakdown

๐Ÿ“ท Photo 10/10
๐Ÿ“„ Resume 10/10
๐Ÿ’ผ Job Title 10/10
โœ๏ธ Bio 10/10
๐Ÿ› ๏ธ Skills 20/20
๐ŸŽ“ Education 10/10
โฑ๏ธ Experience 10/15
๐Ÿ’ฐ Rate 0/5
๐Ÿ† Certs 0/5
โœ… Verified 5/5
Total Score 85/100

Profile Overview

Member sinceAug 2026