Skip to main content
Devendra BhanuseDB
Open to opportunities

Devendra Bhanuse

@devendrabhanuse

Cybersecurity GRC and Third-Party Risk consultant, helping organizations manage cyber risk with ISO/NIST-aligned controls.

India
Message

What I'm looking for

I’m looking for a cybersecurity GRC/TPRM role where I can drive ISO/NIST-aligned governance, run enterprise risk and maturity assessments, manage vendor risk, and deliver clear risk reporting and control improvement for senior leadership.

I’m a Cybersecurity GRC professional with around 10 years of experience across governance, risk management, regulatory compliance, and third-party risk management. I help organizations establish and improve cybersecurity governance frameworks, complete enterprise risk and maturity assessments, and implement security controls aligned with ISO/IEC 27001 and the NIST Cybersecurity Framework.

In my current role as a Senior Consultant (TPRM) at WTW, I’ve conducted 300+ security risk assessments and built enterprise risk registers to track cybersecurity risks, control gaps, and remediation activities. I review supplier compliance against ISO 27001, SOC2, PCI DSS, GDPR, and internal policies, then communicate actionable risks to Legal, Procurement, and Business stakeholders—building clear paths toward continuous improvement and audit-ready control effectiveness.

Experience

Work history, roles, and key accomplishments

WT
Current

Senior Consultant (TPRM)

WTW

Mar 2024 - Present (2 years 3 months)

Conducted 300+ third-party security risk assessments aligned to ISO 27001 and the NIST Cybersecurity Framework, identifying and reporting supplier engagement risks. Built and maintained enterprise risk registers and communicated high-risk supplier findings to Legal, Procurement, and Business stakeholders.

IL

Information Security Analyst

Infosys Limited

Oct 2021 - Mar 2024 (2 years 5 months)

Performed enterprise IT and cyber risk assessments to identify threats, evaluate exposure, and drive mitigation planning. Assessed security for org-wide rollouts (e.g., MicroSegmentation and SASE) and reviewed vendor security postures and 50+ client connectivity models to reduce supply chain and connectivity risk.

WL

Technical Specialist

Wysetek System Technologists Pvt. Ltd

Jun 2017 - Dec 2020 (3 years 6 months)

Governed network and application security controls (WAF, firewalls, load balancers) for regulated clients, aligning delivery with ISO 27001, SOC 2 Security & Availability, and the NIST Cybersecurity Framework. Delivered audit-facing risk and control evidence (configs, change logs, SSL inventories, network diagrams) to achieve complete audit closure with minimal or no findings.

IL

Desktop Support Engineer

IT Source Tech. Ltd

Jun 2016 - Feb 2017 (8 months)

Provided day-to-day support for network and system setups by configuring IP addressing and baseline network settings to improve asset identification and access visibility. Assisted with standard domain/device and Outlook/email configurations and helped reduce user-level security risk using secure proxy, browser, and endpoint settings while maintaining evidence for compliance reviews.

Education

Degrees, certifications, and relevant coursework

University of Mumbai logoUM

University of Mumbai

Bachelor of Engineering, Electronics

Earned a Bachelor of Engineering in Electronics from the University of Mumbai in May 2015.

MB

Maharashtra State Board

Higher Secondary Certificate (HSC)

Completed Higher Secondary (HSC) through the Maharashtra State Board in February 2011.

MB

Maharashtra State Board

Secondary School Certificate (SSC)

Completed Secondary School (SSC) through the Maharashtra State Board in March 2009.

Tech stack

Software and tools used professionally

Find your dream job

Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan