Cyber Security professional providing cyber-risk advisory and control assessment for technology and business applications, APIs, Servicing IT, currently with one of the leading Canadian Bank, RBC (Royal Bank of Canada) as Infrastructure Risks and Controls Previously worked with TD Bank and CIBC with Enterprise Protects supporting Payment platform; time to time supported Channels Technology Solutions such as ATM, North American Contact-Centre infrastructure, Collection, Merchant Services and Retail Technology Well-rounded Global exposure with various industry Public Sector, Universities, BIG 4 Accounting Firms, Financial Institutions, Manufacturing (Auto, Engineering, Food and Paper), Insurance and Service Sectors (IT, Telecommunication) InfoSec Audits, Compliance and Review: Responsible for Information / Cyber Security Audit, Risk Assessment, OPC (Operational Processing Controls) and CET (Control Effectiveness) testing, leading Canadian Payments Association (CPA), PCI-PIN, PCI-DSS and INTERAC annual attestation (Compliance) reviews that includes tracking, updating and reporting control deficiencies, including recommending Process improvements. Cyber-Risk Consultation: Championed in providing guidance to business and technology partners on various IT Security Framework such as NIST800-53, COBIT, ISO27002, SOC2 framework, 3rd and 4th Party Cyber Risk Assessment, took leadership role during vendor contract negotiation including providing cyber security requirements Relationship Management: Developing and managing professional relationships with various internal-external vendors/clients, stakeholders such as VISA Canada, external/internal auditors, and various regulators within INTERAC & PCI Council. Project Management: Key deliverables include PCI PIN/DSS Control Mapping, identified delta between Master Card and VISA regulations, aligning testing methodologies with other compliance requirements such as ISO27002, NIST800-53, INTERAC, SOX and OSFI Multi-layered and multi-dimensional defense acumen: Worked with 1st, 2nd and 3rd lines of defense (LOD) such as Risk Management Consulting, InfoSec challenge function, Audit and Regulatory Compliance reviews include site assessments, data center visits, Business Process Reviews, identifying and reporting Design Deficiencies, Operating Effectiveness Strong Educational Background CISSP, CISA, CIA, CRMA, CRISC, CA (Inst. Of CA of India)