Vaibhav Shirbavikar
Information Security GRC Analyst | ISMS (ISO 27001) | SOC 2 Type II | TPRM | ITGC | Risk & Control Assurance
- Role
- Grc Analyst at Concentrix
- Location
- Pune District, MH, IN
- LinkedIn followers
- 500 followers
About Vaibhav Shirbavikar
Governance, Risk & Compliance (GRC) professional with 7+ years of experience leading ISO 27001 ISMS governance, SOC 2 Type II audit readiness, Third-Party Risk Management (TPRM), and IT General Controls (ITGC) compliance within enterprise environments. Proven track record of driving audit excellence with zero material weaknesses, reducing vendor risk exposure, and aligning security programs to ISO 27001, NIST CSF, and SOC 2 Trust Services Criteria. Experienced in translating technical risk findings into executive-level insights, managing risk registers, and strengthening control maturity across cross-functional business units. Strong background in IAM, with a focus on building resilient and audit-ready security governance frameworks.
Experience
Grc Analyst
Dec 2025 — Present · Pune, IN
Lead the end-to-end governance and continuous improvement of the ISO 27001 Information Security Management System (ISMS), including enterprise risk assessments, control testing, Statement of Applicability (SoA) management, internal audits, and management review reporting, ensuring 100% certification retention across multiple business units.•Govern the full Third-Party Risk Management (TPRM) lifecycle for vendors, performing inherent risk classification, security questionnaire assessments (SIG/CAIQ), contractual security clause validation, control gap analysis, remediation tracking, and residual risk approval, reducing high-risk vendor exposure by 30%.•Lead SOC 2 Type II audit readiness and control compliance initiatives aligned to Trust Services Criteria (Security, Availability, Confidentiality), managing walkthrough sessions, evidence lifecycle management, control testing validation, and remediation tracking, achieving zero material weaknesses across three consecutive audit cycles.•Spearheaded a security policy governance transformation initiative, rationalizing and aligning 15+ enterprise policies with ISO 27001 and NIST CSF frameworks, implementing structured version control, exception management workflows, and stakeholder approval governance, improving compliance adherence metrics by 40%.•Oversee Business Continuity and Disaster Recovery governance activities, including Business Impact Analysis (BIA) validation, RTO/RPO alignment, tabletop exercises, and post-exercise gap remediation, reducing Mean Time to Recover (MTTR) by 25% through optimized recovery workflows.•Translate Azure vulnerability management data (CVSS-based risk scoring) into executive-level risk dashboards, monitoring remediation SLAs and systemic risk trends, and providing actionable risk-based insights to the CISO and senior leadership for quarterly governance reporting.•Serve as primary liaison for internal and external auditors, coordinating walkthroughs, control validation discussions
Education
SunRise University Alwar
Bachelor of Computer Application, Computer Science
Find verified contacts for anyone on LinkedIn
Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.
Free plan included · No credit card required
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.