sudip pokhrel
Ouvert aux possibilitésCybersecurity Analyst | GRC & IT Risk Analyst
Ottawa, ON
À propos
Cybersecurity, GRC and IT Risk Analyst with 4+ years across manufacturing and healthcare environments, supporting ITGC testing, access governance, and audit readiness for 40+ in-scope applications. Closed a 30+ item remediation backlog per quarter and coordinated SOC 2 and ISO 27001 evidence collection across 8+ control owners per cycle. Security+ certified, with working knowledge of NIST CSF, PCI-DSS, PIPEDA, PHIPA, and HIPAA, plus hands-on exposure to cloud IAM, vulnerability management, and incident response support. Strong stakeholder communicator with disciplined documentation habits and dependable follow-through on cross-functional risk initiatives.
Compétences
- Souci du détail
- C#
- Jira
- Microsoft Word
- Résolution de problèmes
- Travail d’équipe
- Gestion du temps
Expérience
Information Security Analyst, GRC
Magna International
juin 2024 to Aujourd’hui
Canada
• Restructured ITGC evidence repositories across access, backup, and change control domains for 40+ in-scope systems, cutting evidence retrieval time by an estimated 30% during audit prep. • Owned remediation tracking in ServiceNow for a backlog of 30+ open findings per quarter, partnering with 8 to 10 infrastructure and application owners to close items on schedule and keep the enterprise risk register current. • Ran quarterly access certifications across finance and operations systems covering 200+ user accounts, flagging inactive accounts, excessive privileges, and role conflicts before they became audit findings. • Reviewed 15 to 20 production change records per cycle for approvals, rollback plans, and segregation of duties evidence ahead of internal assessments and external audit cycles, reducing rework during fieldwork. • Validated SOC 2 and ISO 27001 evidence artifacts from 8+ technical control owners each cycle and maintained trackers that kept submission timelines on schedule across two concurrent audit workstreams. • Evaluated vendor security questionnaires for 10+ third-party vendors per quarter, documented control gaps, and escalated material risks, improving visibility into third-party risk for leadership. • Updated 12+ security policies, standards, and procedures over two years to align governance documentation with operational practice across four business functions. • Built monthly executive dashboards summarizing open risk items, remediation status, and upcoming milestones for governance review meetings attended by 10+ stakeholders.
Information Security Analyst, GRC
CitiusTech
mars 2020 to avr. 2022
India
• Organized compliance evidence for HIPAA, SOC 2, and internal control requirements across regulated healthcare technology environments supporting 20+ applications. • Led walkthrough sessions with development and infrastructure teams across 15+ critical systems per audit cycle to confirm control ownership and documentation completeness. • Maintained issue logs and remediation trackers for audit observations, cutting the backlog of recurring and unresolved control deficiencies by roughly 25% over one year. • Reviewed IAM configurations across sensitive healthcare applications supporting thousands of patient records, identifying dormant accounts and excessive permissions for remediation. • Revised 10+ policies, procedures, and control narratives to keep documentation audit-ready across recurring quarterly regulatory reviews. • Tracked vendor risk follow-up activity for 8+ third-party suppliers, documenting findings and mitigation evidence and following through on remediation commitments. • Coordinated evidence requests with external auditors across annual assessments, shortening average response turnaround time by an estimated 20%. • Supported privacy initiatives on data retention, secure access, and handling practices across regulated healthcare systems used by multiple clinical teams.
Formation
Academy of Learning
Personal Support Worker (PSW)
London, Ontario
2025
Fanshawe College
Information Security Management (ISM)
Canada
2023 to 2024
Islington College
Bachelor of Information Technology, Information Technology
2018 to 2021
Affiliated with London Metropolitan University, UK.
Permis et certifications
CompTIA Security+
CompTIA
Google Cybersecurity Professional Certificate
Google