Himanshi Vashista
@himanshivashista
GRC leader specializing in AI-enabled governance, risk, compliance, and privacy across global enterprises.
What I'm looking for
I’m a GRC leader with 9+ years of experience designing and scaling governance, risk, and compliance programs across global organizations including JioHotstar (Disney+Hotstar), Salesforce, Ernst & Young, and MetLife. I’m proven in AI-enabled GRC and AI governance aligned to ISO/IEC 42001, and I drive enterprise privacy and regulatory compliance across DPDPA, GDPR, PIPEDA, CERT-In, and SOC 2 Privacy.
In my current role as Associate Director, GRC, I lead a team of 6 and spearhead AI implementation across risk assessment, compliance monitoring, and policy management. I automate the full enterprise risk lifecycle, extend DSPM to SOC 2 Privacy criteria, and strengthen access certification through hands-on UAR automation—while translating the GRC roadmap into executive-ready reporting and measurable business outcomes.
Experience
Work history, roles, and key accomplishments
Associate Director, GRC
JioHotstar
Nov 2025 - Present (7 months)
Led a team of 6 GRC professionals to drive AI-enabled governance and GRC automation aligned to ISO/IEC 42001. Owned enterprise privacy and regulatory compliance (DPDPA, GDPR, CERT-In), automated the risk lifecycle, and expanded SOC 2 Privacy coverage including data discovery, classification, and protection.
Tech Lead, GRC
Disney+Hotstar
Oct 2022 - Nov 2025 (3 years 1 month)
Designed and delivered enterprise GRC technology solutions integrating SOX, PCI-DSS, ISO 27001, SOC 2 (Privacy Trust Services), and SSAE 18 requirements. Automated the Enterprise Risk Register, Audit & Compliance board, and TPRM inventory using Drata and JIRA workflows, and supported privacy compliance across DPDPA, GDPR, PDPA, and PIPEDA.
Managed cybersecurity and security/compliance RFI/RFPs across global markets and served as an SME for Salesforce CRM and Hyperforce. Ensured regulatory alignment for PCI-DSS, GDPR, and HIPAA, supported HITRUST-aligned customer audits, and achieved 100% completion for security and compliance training.
Led third-party risk management (TPRM) engagements by conducting inherent and residual risk assessments with business and security stakeholders. Designed TPRM frameworks, reviewed audit reports and policies (SOC 2, PCI-DSS, ISO 27001), and delivered stakeholder training on TPRM best practices.
Conducted vendor risk assessments and due diligence across IaaS, SaaS, PaaS, business services, consultants, legal services, TPAs, and brokers. Implemented a common control framework and administered risk assessments via RSA Archer, aligning controls with IRDAI guidelines and producing formal audit findings and risk recommendations.
Education
Degrees, certifications, and relevant coursework
Galgotias University
Bachelor of Technology, Computer Science & Engineering
Earned a B.Tech in Computer Science & Engineering from Galgotias University.
Tech stack
Software and tools used professionally
Availability
Location
Authorized to work in
Job categories
Skills
Interested in hiring Himanshi?
You can contact Himanshi and 90k+ other talented remote workers on Himalayas.
Message HimanshiFind your dream job
Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!
