About
Cybersecurity and IT Infrastructure professional with 2.5+ years of experience supporting Third-Party Risk Management (TPRM), vendor risk assessment, and information security governance in enterprise environments. Skilled in evaluating vendor security postures, applying ISO/IEC 27001:2022 and SOC 2 principles, and supporting risk-based decision-making across identity and access management, endpoint security, and incident response. Experienced in translating security control requirements into operational practice through Active Directory administration, MFA enablement, BitLocker management, and VPN security. Seeking to apply risk assessment, compliance, and cybersecurity expertise in a Third-Party Risk Management (TPRM) and Cybersecurity Senior Analyst role.
Skills & Expertise (19)
Work Experience
Senior Technical Process Executive
Infosys BPM
Nov 2025 - May 2026
Supported evaluation of vendor- and third-party-related security controls (MFA, access governance, endpoint protection) against organizational compliance and SLA requirements. Applied risk-based troubleshooting methodologies to prioritize and resolve security incidents, minimizing operational and third-party exposure. Reviewed access requests and account activity against least-privilege and security policy requirements, flagging deviations for follow-up. Identified control gaps during incident and access-related investigations and escalated findings to relevant teams for timely remediation. Maintained audit-ready records of security control checks and remediation actions to support compliance and governance reporting. Coordinated with internal stakeholders to verify that third-party and vendor-facing access remained aligned with organizational risk and compliance requirements. Contributed to process documentation that improved consistency and traceability of security and risk-related activities across the team. Performed vendor risk assessments and prepared assessment reports summarizing findings, risk ratings, and recommendations for stakeholders. Identified third-party risk exposures during reviews and investigations, coordinating remediation actions with relevant teams to ensure timely closure. Performed identity and access management activities including password resets, MFA enrollment, and account verification procedures in line with security policy. Investigated endpoint security issues and coordinated with cross-functional teams to drive timely remediation. Managed security-related incidents and service requests end-to-end while adhering to SLA and compliance requirements. Ensured accurate, audit-ready documentation of incidents and security-related activities to support compliance reviews. Collaborated with cross-functional teams to support secure IT operations and business continuity.
Windows System Administrator
Tata Technologies
Jul 2023 - Jul 2025
Provisioned and reviewed secure remote access (VPN) requests in line with organizational security policy and least-privilege principles. Supported enforcement of security baselines (MFA, encryption, endpoint controls) applicable to internal and externally-managed accounts through Group Policy administration. Assisted stakeholders in maintaining compliance with corporate security standards during access provisioning and periodic reviews. Performed vendor risk assessments and prepared assessment reports supporting governance and compliance reviews. Identified third-party risk exposures linked to vendor-managed access and endpoints, coordinating remediation with relevant stakeholders. Administered Active Directory accounts, user access management, and security group memberships in line with organizational security policy. Conducted periodic access reviews and ensured proper user provisioning and de-provisioning practices, supporting least-privilege and audit-readiness objectives. Supported implementation of security controls including MFA, BitLocker encryption, password management, and endpoint protection mechanisms. Implemented Group Policies to enforce security baselines and organizational compliance requirements. Worked with internal stakeholders to maintain compliance with corporate security standards and IT governance requirements. Assisted in security incident investigation through log analysis and troubleshooting of endpoint-related security issues.
Education
Computer Science and Engineering - IES College of Technology
2023 - 2026 ยท Afghanistan
Computer Science and Engineering - Government Polytechnic Adityapur
2020 - 2023 ยท Afghanistan
Certifications
No certifications added yet
Interested in this developer?
Profile Score Breakdown
Profile Overview
Skills (19)
Click a skill to find developers with the same skill