Prasanna Kumar
@prasannakumar9
Information Security GRC Analyst specializing in ISO 27001, NIST CSF, and cloud third-party risk governance.
What I'm looking for
I’m an Information Security GRC Analyst with 4.2 years of experience across Governance, Risk & Compliance, Information Security, Third-Party Risk Management, security audits, and regulatory compliance. I’m hands-on with ISO 27001:2022, NIST CSF 2.0, SOC 2, HIPAA, and GDPR, and I focus on turning assessments into clear remediation and measurable progress.
In my recent role, I coordinated enterprise GRC governance activities—risk management, compliance monitoring, remediation tracking, and audit readiness updates. I oversaw TPRM by validating vendor risk assessments, reviewing remediation plans, and ensuring timely closure of high-risk findings, while aligning ISMS documentation and policies to ISO/IEC 27001:2022.
Previously at Infosys, I performed information security risk assessments, conducted control testing and gap analysis aligned to ISO/IEC 27001:2022 and NIST CSF 2.0, and supported internal and external audits through structured evidence collection and observation tracking. I also contribute to cloud security governance across AWS and validate controls against organizational policies and ISO/IEC 27001 requirements.
Experience
Work history, roles, and key accomplishments
Senior Information Security GRC Analyst
Veramed Data Services Private Limited
Aug 2025 - Feb 2026 (6 months)
Coordinated enterprise GRC activities including risk management, compliance monitoring, remediation tracking, and third-party risk management. Supported audit readiness by managing audit evidence, corrective action plans, and ISMS documentation aligned to ISO/IEC 27001:2022.
Performed information security risk assessments and control testing aligned to ISO/IEC 27001:2022 and NIST CSF 2.0, documenting risks and mitigation plans. Conducted TPRM assessments in ServiceNow GRC and supported audits with evidence collection and remediation tracking, including access governance and cloud control reviews.
Assisted with maintaining the ISMS in line with ISO/IEC 27001:2022 by supporting risk assessments, policy and SOP maintenance, and audit evidence collection. Supported access reviews and third-party/vendor security assessments while tracking remediation activities for management and audit readiness.
Education
Degrees, certifications, and relevant coursework
CMR Engineering College
Bachelor of Technology (B.Tech), Engineering
2015 - 2019
Completed a B.Tech (Bachelor of Technology) at CMR Engineering College in Hyderabad from 2015 to 2019.
Tech stack
Software and tools used professionally
Availability
Location
Authorized to work in
Job categories
Skills
Interested in hiring Prasanna?
You can contact Prasanna and 90k+ other talented remote workers on Himalayas.
Message PrasannaGet matched with your dream remote job
Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!
