Swayam Nandi
@swayamnandi
ISO/IEC 27001 Lead Auditor and GRC consultant translating complex compliance into defensible risk decisions.
What I'm looking for
I’m a B.Tech CS graduate and ISO/IEC 27001:2022 Certified Lead Auditor with six months of GRC consulting at Deloitte for enterprise banking clients. I specialize in turning compliance requirements into clear, structured audit findings and risk treatment recommendations.
In my Deloitte role, I conducted ISO/IEC 27001:2022 Annex A control assessments, evaluated control effectiveness, and supported audit lifecycle activities from planning through corrective action tracking. I also performed compliance gap analyses against ISO 27001, NIST, and PCI-DSS, ensuring stakeholders received practical, defensible outcomes.
I co-developed security policy frameworks and governance documentation, communicating results through written reports and client deliverables. My compliance training spans nine international frameworks, including NIST, ISO 27001/27002, COBIT, PCI-DSS, HIPAA, GDPR, DPDP Act, and CCPA, and I’ve completed CompTIA Network+, Security+, and Cloud+ coursework.
My GRC portfolio reflects hands-on judgment across real scenarios—covering PCI DSS network segmentation review, ISO 27001 Statement of Applicability (all 93 controls), EU AI Act high-risk assessment (Articles 9–15), GRC control automation design, and enterprise risk acceptance documentation. I prioritize assumptions, trade-offs, and residual risk acknowledgment—never “template” thinking.
Experience
Work history, roles, and key accomplishments
Conducted ISO/IEC 27001:2022 Annex A control assessments and compliance gap analyses against ISO 27001, NIST, and PCI-DSS for enterprise banking clients. Produced structured risk treatment recommendations and supported the audit lifecycle through corrective action tracking and stakeholder reporting.
Operations Associate
MediaMint
Mar 2025 - Sep 2025 (6 months)
Maintained SLA compliance across high-volume operational workflows using structured QA procedures and systematic issue identification. Supported timely issue resolution through consistent tracking and documentation.
Education
Degrees, certifications, and relevant coursework
Siksha 'O' Anusandhan University (ITER)
Bachelor of Technology, Computer Science & Engineering
2021 - 2025
Grade: CGPA: 7.16
B.Tech in Computer Science & Engineering at Siksha 'O' Anusandhan University (ITER) from 2021 to 2025, achieving a CGPA of 7.16.
Availability
Location
Authorized to work in
Portfolio
github.com/cryon-69/GRC-PortfolioSocial media
Job categories
Skills
Interested in hiring Swayam?
You can contact Swayam and 90k+ other talented remote workers on Himalayas.
Message SwayamFind your dream job
Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!
