Nisha Quadros
Risk Manager II at HERE Technologies
- Role
- Risk Manager Ii at HERE Technologies
- Location
- Thane, MH, IN
- LinkedIn followers
- 500 followers
About Nisha Quadros
Risk and Assurance professional with a strong track record of driving end-to-end supplier risk management, security and privacy control assessments, and enterprise compliance readiness. I specialize in managing strategic third-party relationships, ensuring that supplier engagements align with internal policies, regulatory frameworks (e.g, ISO 27001, SOC 2, TISAX, GDPR), and evolving technology landscapes, including AI governance.My experience spans the full supplier lifecycle—from risk-based due diligence and onboarding to performance monitoring and exit planning—with a sharp focus on mitigating third-party risks. I have led the design and implementation of scalable assessment processes for both traditional and AI-powered suppliers, integrating ethical AI, data privacy, and model explainability into enterprise review workflows.I bring deep expertise in information security and privacy risk management, maintaining enterprise-wide risk registers, conducting control gap analysis, and aligning practices with leading frameworks such as NIST CSF, NIST Privacy Framework, ISO, COBIT, and OWASP. I partner closely with Legal, Procurement, IT, and Internal Audit teams to ensure control assurance and audit readiness across all critical environments.Whether enabling business through risk-informed decision-making or strengthening compliance posture, I am committed to building resilient, secure, and privacy-centric ecosystems that enable innovation without compromising trust.
Experience
Risk Manager Ii
Apr 2024 — Present · Airoli, IN
Conducted supplier due diligence with a focus on security, privacy, and regulatory compliance, ensuring third-party risks were appropriately assessed and managed.• Participated in the RFP and vendor selection process, evaluating supplier risk posture and recommending controls as part of procurement and onboarding workflows.• Collaborated with cross-functional teams (e.g, legal, IT, procurement, finance etc) to embed risk controls into third-party contracts and service level agreements (SLAs).•Capture risks from control owners across the enterprise to compliment compliance efforts, security and privacy requirements, and best practices•Designed and implemented internal risk assessment frameworks, risk heatmaps, and mitigation plans aligned with ISO ISO 27001, NIST, and GDPR standards.•Developed, implemented, and now continually maintain the information security and privacy risk register based on NIST, OWASP, COBIT, ISO, and COSO principles / frameworks•Promoted a culture of risk awareness through policy development, communication, and employee training.•Developed and deployed a new risk assessment process for AI-powered suppliers and models, ensuring alignment with internal governance, ethical AI principles, and global data protection standards.Key Achievements:Successfully integrated risk input into the RFP process for over 20 strategic suppliers, avoiding exposure to high-risk vendors.Enabled a significant improvement in risk reporting through automation and deployment of GRC tooling.Developed and institutionalized a formal AI supplier and model assessment process, covering model explainability, data lineage, privacy impacts, and usage boundaries.
Education
University of Mumbai
BSc
ITM Group of Institutions
Master's degree
Find verified contacts for anyone on LinkedIn
Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.
Free plan included · No credit card required
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.