Skip to main content
Vimal SharmaVS
Looking for a job

Vimal Sharma

@vimalsharma

I’m a CISA-certified IT Compliance and GRC professional driving ITGC, ISMS, and information security governance.

India
Message

What I'm looking for

I’m looking to lead ITGC and GRC programs—owning compliance gap assessments, RCM-based audit methodology, and ISO 27001 ISMS governance—while turning security requirements into measurable controls, evidence, and remediation that stands up to regulators.

I’m a CISA-certified IT Compliance and GRC professional with 21+ years of IT experience spanning regulatory compliance assessment, ITGC and internal controls, ISMS implementation, and information security governance across international banking and government environments. I conduct compliance gap assessments against UIDAI’s 127-control information security framework, and validate control design within Group Information Security GRC by aligning evidence and traceability to COBIT and ITIL.

Today, I deepen formal ITGC audit methodology—Risk Control Matrix, Test of Design, Test of Effectiveness, SoD analysis, and SOX 302/404 compliance frameworks—while drafting and governing ISMS policy aligned to UIDAI regulations, Aadhaar Act, DPDP Act 2023, and ISO/IEC 27001:2022. I also translate ITGC requirements into technical specifications for SOC procurements and supported security-first governance for large infrastructure programs, backed by early hands-on application and database security experience in Java, .NET, and SQL Server.

Experience

Work history, roles, and key accomplishments

DH
Current

Deputy System Executive Officer

Department Of IT Haryana

Nov 2022 - Present (3 years 7 months)

Conducted compliance gap assessments of AUA operations against UIDAI’s 127-control information security framework, performing Test of Design (ToD) to identify deficiencies, prioritize risks, and drive remediation to closure. Drafted the AUA ISMS Policy aligned to UIDAI regulations, Aadhaar Act, DPDP Act 2023, and ISO/IEC 27001:2022, and translated ITGC requirements into a ₹25.71 crore SOC RFP for

CRISIL Limited logoCL

Monitoring & Evaluation Specialist

CRISIL Limited

Apr 2021 - Oct 2022 (1 year 6 months)

Monitored physical and financial progress of government infrastructure projects and built governance dashboards. Prepared compliance status reporting for central ministry stakeholders.

National Institute For Smart Government logoNG

Consultant - NISG

National Institute For Smart Government

Oct 2018 - Apr 2021 (2 years 6 months)

Managed government IT procurement and contract governance under GFR 2017, using materiality assessment to identify aggregated deviations constituting material non-compliance. Oversaw LMS service provider contract compliance by analyzing ticket datasets against SLA obligations and applying contractual penalties for non-compliance.

TC

Process Specialist

Terrabit Consulting

Sep 2016 - Sep 2017 (1 year)

Designed and documented information security processes across Standard Chartered Bank Group Information Security (GIS) service lines, including IAM, DLP, Change Management, Privileged Access, and Incident Response. Maintained bidirectional controls traceability matrices linking GIS policies to process documents and KRIs/KCIs, supporting process onboarding, change, and offboarding within the GIS GR

IPE Global logoIG

Consultant - ICT Expert

IPE Global

Jan 2016 - Aug 2016 (7 months)

Evaluated Smart Cities proposals for Integrated Command and Control Centre infrastructure against Smart Cities Mission guidelines, assessing ICT and security requirements to support fund allocation. Designed an MIS framework covering performance indicators, baselines/targets, progress monitoring, and multi-stakeholder governance reporting.

National Institute For Smart Government logoNG

Consultant - NISG

National Institute For Smart Government

Jun 2011 - Oct 2015 (4 years 4 months)

Performed process mapping and re-engineering for e-governance programs, embedding security controls such as role-based access, digital signature workflows, and audit trails in Functional Requirements Specifications. Designed security requirements for Uttarakhand Smart Cities DPR covering access controls, network security, and application data protection aligned to DeitY e-governance security stand

GP

MIS Expert / Consultant

GoI / World Bank Project

Feb 2006 - Jun 2011 (5 years 4 months)

Developed and supported application and database security controls for hosted NIC Data Centre applications, implementing role-based authentication/authorization frameworks and assisting with periodic CERT-In security audits. Built software components using Java, .NET, and SQL Server with secure application and database practices.

Education

Degrees, certifications, and relevant coursework

HNB Garhwal University logoHU

HNB Garhwal University

Master of Computer Applications, Computer Applications

Master of Computer Applications (MCA) from HNB Garhwal University.

HNB Garhwal University logoHU

HNB Garhwal University

Bachelor of Science, Statistics

BSc in Statistics from HNB Garhwal University.

Tech stack

Software and tools used professionally

Find your dream job

Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan