Sandeep Singh
Cybersecurity@IBM - CISSP | CCSP | ISO 27001 LA | CTPRA | Manager | Information Security Risk Leader | Security Architect | BSides Bangalore
- Role
- Security Architect, Governance Risk & Compliance at IBM
- Location
- Bengaluru, KA, IN
- LinkedIn followers
- 500 followers
Experience
Security Architect, Governance Risk & Compliance
Oct 2017 — Present · Bengaluru, IN
Third Party Supplier Assessments: • Evaluated the maturity and trustworthiness of a Third Parties security program to reduce risks relating to use of third parties• Designed and developed the policy and procedures for the third-party risk management program and reviewed them periodically to align with regulatory requirements and the organization’s risk appetite• Designed and developed the supplier inherent risk questionnaire to shortlist critical/high/medium risk suppliers. • Designed and developed supplier security risk questionnaire based on NIST and migrated it to shared assessment’s SIG (Standardized Information Gathering Questionnaire) to align with industry standards• Created reporting and intelligence to drive meaningful decisions and outcomes.• Presented reports to senior management on a predetermined basis, including performance metrics and associated reportingSegment Assessments:Conducted risk assessments on areas with strategic importance to IBM which allowed itto implement mitigations to manage and monitor its strategic risksEnterprise Risk Assessments:• Evaluated cyber security risks identified through policy exceptions across IBM to determine risk exposure to manage & maintain risks at an acceptable level• Developed policies and procedures for the enterprise risk management program and reviewed them periodically to align with organization’s risk appetite• Reviewed and supervised action plans developed by risk owners to ensure plans are completed appropriately• Developed compensating controls in absence of primary controls to manage & maintain risks at an acceptable levelProgram Assessment and Standardization:• Lead development, maintenance, and revision of policies, standards, procedures, and guidelines of security programs• Established security baselines and continuous improvement programs based on standard industry frameworks such as PCI, CIS CSC, NIST CSF, SANS 20 Critical Controls, MITRE ATT & K and the Cyber Kill Chain
Education
Visvesvaraya Technological University
B.E, Telecommunication
2006 — 2010
Find verified contacts for anyone on LinkedIn
Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.
Free plan included · No credit card required
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.