Akshaya Reddy
IT Grc Analyst @Bank of America
Signup · Get unlimited contacts
WORK HISTORY
IT Grc Analyst @Bank of America
Wilmington, DE, US
As an IT Risk & Compliance Specialist at Bank of America, I drove IT risk assessments across digital banking and lending platforms using ITGC, NIST CSF, and ISO 27001, identifying 21 control gaps and reducing residual risk by 36% through ServiceNow GRC remediation tracking. I strengthened control design by evaluating access management and change management processes, improving audit readiness across critical financial systems, and ensured control effectiveness by testing user access reviews, privileged access, and Joiner-Mover-Leaver workflows, achieving a 97% control pass rate. I managed access recertification for over 1,400 users, eliminating inactive and excessive entitlements and reducing unauthorized exposure. Additionally, I streamlined audit evidence management in SharePoint and Confluence, enabling 100% on-time submissions and reducing follow-ups by 30%, while advancing third-party risk oversight for 30+ vendors, closing 89% of identified risk gaps. By reviewing change approvals, exception documentation, and incident root cause analyses in ServiceNow GRC, I reinforced governance compliance, raising adherence from 85% to 96%, and improved incident closure rates from 74% to 93%.
EDUCATION
Jawaharlal Nehru Technological University
Bachelor's degree
Wilmington University
Master's degree
ABOUT AKSHAYA REDDY
I am a Senior IT GRC & Technology Risk professional with 5+ years of experience strengthening governance frameworks across banking, fintech, and enterprise technology environments. My expertise spans SOC 2 Type I & II, ISO 27001 alignment, NIST CSF / 800-53 mapping, ITGC testing, Third-Party Risk Management, and Access Governance. I specialize in identifying control gaps, reducing residual risk, and improving audit readiness through structured remediation and cross-functional collaboration. Across complex financial and enterprise environments, I have driven measurable governance improvements by reducing residual risk by up to 38% through targeted control gap identification and structured remediation programs. I consistently achieved 96–98% control effectiveness in access and change management testing while leading enterprise-wide access recertification initiatives for 1,400+ users to strengthen least-privilege enforcement and reduce unauthorized exposure. By conducting comprehensive third-party risk assessments and SOC report analysis, I successfully closed 87–90% of identified vendor risk gaps. My efforts improved overall governance compliance from the mid-80% range to 96%+, while ensuring 100% on-time audit submissions through streamlined evidence management, stakeholder coordination, and proactive audit readiness planning. I bring hands-on expertise in ServiceNow GRC, risk registers, remediation tracking, audit evidence management, vendor due diligence, and compliance reporting dashboards.I am passionate about transforming compliance from reactive audit support into proactive risk governance programs that drive measurable security maturity.
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.