Aryan Maharjan
@aryanmaharjan
GRC Analyst specializing in third-party risk management and compliance-ready security assessments.
What I'm looking for
I’m a results-driven GRC and Third-Party Risk Management professional, conducting vendor risk assessments for Fortune 500 enterprises. I validate HITRUST CSF and Common Risk Framework (CRF) assessments against HIPAA, SOC 2, ISO 27001, and GDPR, using evidence review and policy analysis to pinpoint gaps in PHI/PII handling, access management, and incident response.
I review security policies, map controls to compliance frameworks, and present risk findings to senior leadership for approval and escalation decisions. In my recent role, I reduced remediation closure timelines by 25% and improved downstream workflow accuracy by 30% through an internal AI-powered compliance knowledge library and standardized control mapping templates.
Experience
Work history, roles, and key accomplishments
GRC & Third-Party Risk Analyst
SecurityPal
Apr 2025 - Present (11 months)
Conducted end-to-end third-party risk management for Humana, validating vendor HITRUST CSF and Common Risk Framework assessments against HIPAA/HITECH, SOC 2 Type II, ISO 27001, GDPR, and NIST CSF. Reduced average remediation closure timelines by 25% and downstream compliance workflow errors by 30% through evidence-based control validation, gap analysis, and audit-ready risk reporting.
Security Research Analyst Trainee
Code Rush / SecurityPal
Feb 2025 - Apr 2025 (2 months)
Investigated cyber threats and helped produce GRC-focused security policy and risk control reports aligned to NIST, ISO 27001, and HIPAA frameworks. Supported application of risk management and regulatory compliance requirements across healthcare and technology contexts.
Cybersecurity SOC & Vulnerability Intern
TeamOne Technologies
Dec 2023 - Apr 2024 (4 months)
Assisted SOC operations with log analysis, vulnerability assessments, and threat detection using Linux CLI, Python automation scripts, and Splunk SIEM. Supported vulnerability scan triage and contributed to risk prioritization and remediation tracking using CVSS scoring standards.
Network & Security Intern
Classic Tech
May 2023 - Aug 2023 (3 months)
Supported network configuration, security monitoring, and troubleshooting in a live ISP environment. Assisted with routing protocol work, firewall rule management, and network access control activities.
Education
Degrees, certifications, and relevant coursework
Lord Buddha Education Foundation
Bachelor of Science in Information Technology, Information Technology
2021 - 2024
Earned a B.Sc. in Information Technology from Lord Buddha Education Foundation (affiliated with Asia Pacific University, Malaysia) from 2021 to 2024.
Availability
Location
Authorized to work in
Job categories
Skills
Interested in hiring Aryan?
You can contact Aryan and 90k+ other talented remote workers on Himalayas.
Message AryanFind your dream job
Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!
