Skip to main content
Prasanna KumarPK
Open to opportunities

Prasanna Kumar

@prasannakumar9

Information Security GRC Analyst specializing in ISO 27001, NIST CSF, and cloud third-party risk governance.

India
Message

What I'm looking for

I’m looking to lead GRC and audit readiness efforts—owning risk assessments, control testing, and third-party risk management—while strengthening ISO 27001/NIST-aligned governance across cloud environments and using automation to drive faster remediation closure.

I’m an Information Security GRC Analyst with 4.2 years of experience across Governance, Risk & Compliance, Information Security, Third-Party Risk Management, security audits, and regulatory compliance. I’m hands-on with ISO 27001:2022, NIST CSF 2.0, SOC 2, HIPAA, and GDPR, and I focus on turning assessments into clear remediation and measurable progress.

In my recent role, I coordinated enterprise GRC governance activities—risk management, compliance monitoring, remediation tracking, and audit readiness updates. I oversaw TPRM by validating vendor risk assessments, reviewing remediation plans, and ensuring timely closure of high-risk findings, while aligning ISMS documentation and policies to ISO/IEC 27001:2022.

Previously at Infosys, I performed information security risk assessments, conducted control testing and gap analysis aligned to ISO/IEC 27001:2022 and NIST CSF 2.0, and supported internal and external audits through structured evidence collection and observation tracking. I also contribute to cloud security governance across AWS and validate controls against organizational policies and ISO/IEC 27001 requirements.

Experience

Work history, roles, and key accomplishments

VL

Senior Information Security GRC Analyst

Veramed Data Services Private Limited

Aug 2025 - Feb 2026 (6 months)

Coordinated enterprise GRC activities including risk management, compliance monitoring, remediation tracking, and third-party risk management. Supported audit readiness by managing audit evidence, corrective action plans, and ISMS documentation aligned to ISO/IEC 27001:2022.

IL

Information Security GRC Analyst

Oct 2023 - Jul 2025 (1 year 9 months)

Performed information security risk assessments and control testing aligned to ISO/IEC 27001:2022 and NIST CSF 2.0, documenting risks and mitigation plans. Conducted TPRM assessments in ServiceNow GRC and supported audits with evidence collection and remediation tracking, including access governance and cloud control reviews.

Education

Degrees, certifications, and relevant coursework

CC

CMR Engineering College

Bachelor of Technology (B.Tech), Engineering

2015 - 2019

Completed a B.Tech (Bachelor of Technology) at CMR Engineering College in Hyderabad from 2015 to 2019.

Get matched with your dream remote job

Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan