Shashank Rana
Manager, Information Technology - IT & Cyber Security Risk @Sentara Health
Signup · Get unlimited contacts
WORK HISTORY
Manager, Information Technology - IT & Cyber Security Risk @Sentara Health
Lead enterprise-wide IT and cybersecurity risk management program serving the entire IT division, managing a team of 4-5 risk professionals and driving strategic initiatives that identified 95+ critical control gaps and compliance issues in 2025—a 375% increase from 20 issues in the inaugural year—strengthening organizational security posture and regulatory adherence across healthcare operations.
EDUCATION
Winona State University
Bachelor of Science, Accounting and Business/Management
SKILLS
ABOUT SHASHANK RANA
Seasoned IT Risk and Cybersecurity Leader with over 13 years of progressive experience spanning IT and financial audits, regulatory compliance, and data security risk management. Builds and scales enterprise-wide programs in healthcare and financial services, translating complex technical threats into tactical insights. Champions governance models and GRC tool integrations to foster risk-aware cultures, ensure ISO, NIST, and HIPAA adherence, and strengthen resilience. Adept at aligning security initiatives with business objectives to drive sustainable outcomes and poised to lead governance and intelligence functions.Spearheads risk management framework deployment that identifies critical threats, prioritizes key vulnerabilities, integrates ISO 27001 and NIST controls, and delivers executive insights to guide strategic risk mitigation across the enterprise.Orchestrates compliance assessments across healthcare and regulatory requirements, uncovering control gaps, shaping remediation roadmaps through gap analyses, and collaborating with stakeholders to strengthen alignment and audit readiness.Advances cybersecurity program maturity by formalizing risk registers, defining ownership roles, instituting issue-management protocols, integrating continuous monitoring practices, and fostering a culture of preparedness and governance efficiency.Areas of expertise include:Cyber Risk ManagementCompliance AssessmentControl Framework DesignThird-Party RiskProgram MaturityAwareness TrainingData GovernanceIssue ManagementGovernance ImplementationStakeholder EngagementBusiness ContinuityCloud SecurityAudit AssuranceRisk ReportingRegulatory Compliance
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.