Mohiuddin
ISO27001 Lead Auditor | TPRM | Risk and Compliance | AZ 900 | ISC2 CC | Sr GRC Analyst | Cloud & Information Security Enthusiast | ITGC | ServiceNow GRC | IT Audit | SOC 2 | SOX ITGC
- Role
- Grc Analyst at UltraViolet Cyber
- Location
- Hyderabad, TG, IN
- LinkedIn followers
- 500 followers
About Mohiuddin
Cybersecurity and GRC professional with 5+ years of experience specializing in Third-Party Risk Management (TPRM), Internal Audits, and Enterprise Risk Governance. Proven expertise in designing and scaling risk and compliance programs aligned with ISO 27001, NIST, SOC 2, SOX, and PCI DSS frameworks. Currently working as a Senior GRC Analyst, leading TPRM transformation initiatives by shifting traditional processes into automation-driven, scalable operating models. Experienced in managing the full vendor lifecycle, including onboarding, risk assessments, continuous monitoring, audits, and offboarding, ensuring compliance with regulatory, contractual, and security requirements. Conducted 100+ vendor risk assessments annually, evaluating cybersecurity posture, identifying control gaps, and driving remediation. Strong experience in third-party due diligence, vendor audits, and continuous monitoring using tools such as OneTrust, BitSight, and ServiceNow GRC. Skilled in implementing governance frameworks and automation solutions to enhance efficiency and consistency. Designed ISO 27001:2022-aligned Risk Assessment and Treatment frameworks, configured advanced workflows in OneTrust, and built AI-driven solutions to streamline security questionnaire responses and vendor evaluations. Strong background in Internal Audits and IT General Controls (ITGC), supporting ISO 27001 audits and SOX compliance. Hands-on experience in control testing across Identity & Access Management, Change Management, Backup & Recovery, and Incident Management domains. Experienced in developing Power BI dashboards and risk metrics reporting, enabling real-time visibility into risk posture, audit findings, and remediation progress, supporting data-driven decision-making at the leadership level. Well-versed in cybersecurity frameworks, including ISO 27001 (Annex A), NIST, SOC 1/2, PCI DSS, and privacy regulations such as GDPR and CCPA. Strong understanding of risk assessment methodologies (qualitative and quantitative), risk registers, and the three lines of defense model. Known for strong stakeholder collaboration, working closely with Threat Intelligence, Incident Response, Supplier Management, and M&A teams to strengthen enterprise-wide risk coverage and support business-critical initiatives. Focused on driving continuous improvement, enhancing organizational resilience, and enabling secure business growth through effective risk management, governance, and automation.
Experience
Grc Analyst
Sep 2022 — Present · Hyderabad, IN
TPRM Strategy & Automation Leadership:Led transformation of Third-Party Risk Management (TPRM) from a manual to an automation-driven model. Managed end-to-end vendor lifecycle including onboarding, risk assessments, due diligence, monitoring, reassessments, and offboarding. Strengthened vendor oversight and improved compliance alignment with ISO 27001, SOC 2, and NIST frameworks. Conducted vendor security reviews to assess posture, identify gaps, and ensure regulatory compliance.Cyber Risk Management:Identified, assessed, and documented cyber risks aligned with organizational risk appetite. Maintained risk registers and performed qualitative and quantitative risk assessments. Led risk review discussions and provided actionable recommendations to improve controls and reduce risk exposure.OneTrust Governance and Configuration:Designed TPRM workflows and templates for onboarding, reassessments, and M&A within OneTrust. Configured risk scoring, inherent risk logic, and automated workflows. Developed an ISO 27001:2022-aligned RATP framework to standardize risk evaluation and treatment.Automation and AI-Driven Innovation:Implemented Loopio automation for security questionnaires, improving speed and accuracy. Built a ChatGPT-based solution to streamline vendor document reviews and assessments, reducing manual effort.Vendor Incident and Process Improvement Initiatives:Established vendor incident management processes and reporting questionnaires. Designed ServiceNow escalation workflows to improve issue tracking and accountability.Data Analytics and Reporting:Developed Power BI dashboards for real-time visibility into TPRM performance, risk posture, and remediation. Delivered periodic reports to support data-driven decisions.Cross-Functional Collaboration:Collaborated with CTI, IR, Supplier Management, and M&A teams on reassessments, due diligence, and integrations, translating risks into actionable insights.
Education
VNRVJIET
Diploma, ECE
2014 — 2017
Muffakham Jah College Of Engineering And Technology
Bachelor's degree, Electronics and communication Engineering
2017 — 2020
Find verified contacts for anyone on LinkedIn
Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.
Free plan included · No credit card required
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.