| Mounika A - Cyber Security Specialist |
| syed@srimatech.com |
| Location: Chickamauga, Georgia, USA |
| Relocation: Yes |
| Visa: H4EAD |
| Resume file: Mounika_Resume_GRC_1786020043814.docx Please check the file(s) for viruses. Files are checked manually and then made available for download. |
|
Technology Risk, IT Audit, and Information Security GRC leader with 9+ years of experience delivering risk-based control assurance across cloud (Azure/AWS), SaaS, on-prem infrastructure, and enterprise IT operations, including regulated and financial services environments. Expert in IT General Controls (ITGC) and security control testing, performing design and operating effectiveness reviews across logical access, privileged access, change management, SDLC, logging/monitoring, incident management, resiliency, and vendor/SOC report reviews.
Led and coordinated audit readiness and external audit support activities (ISO 27001 programs, PCI DSS and SOC 2-style engagements), partnering with technology owners, risk teams, and auditors to manage evidence, timelines, and remediation closure. Strong background translating complex technical findings into business-impact narratives for executives and Boards, with recurring status reporting and KPI-driven oversight. Experienced in developing and implementing GRC frameworks, monitoring compliance posture, and enabling risk-informed decision-making across enterprise environments. Hands-on with audit automation inputs and continuous monitoring evidence using SIEM, vulnerability management, and cloud audit logs; comfortable building repeatable testing templates, evidence request packs, and quality assurance steps that scale. Proven ability to run multiple engagements concurrently, mentor team members, and drive pragmatic remediation plans that improve control maturity without blocking delivery. CORE COMPETENCIES & EXPERTISE IT Audit & Technology Risk: ITGC, ITAC awareness, risk assessments, control design, operating effectiveness testing, audit scoping, walkthroughs, issue validation, remediation tracking. External Audit & Attestation Support: SOC 1/SOC 2, PCI DSS audits and report review; ISO/IEC 27001:2022 audits; ISAE 3402, NIST CSF, NIST SP 800-53, CIS, HITRUST CSF, COBIT, MITRE ATT&CK, GDPR, HIPAA, CCPA, CPRA concepts and compliance, auditor liaison, evidence management, audit calendars. Cloud & DevOps Risk: Azure, AWS, SaaS controls, cloud logging, IAM, secure SDLC governance, CI/CD control expectations (pipeline risk, code quality, segregation of duties). Security Domains: Authentication/authorization, credential management, PAM concepts, incident management, vulnerability management, threat monitoring, resiliency/availability controls. Analytics & Reporting: Excel (advanced), dashboards/KPIs, data-driven control insights, leadership reporting (Power BI/Tableau exposure). Third-Party Risk (TPRM): Vendor due diligence, SOC report analysis, contract security requirements, remediation oversight. Tools & Platforms: ServiceNow, Jira, Confluence, ControlMap (GRC), Rapid7 InsightIDR/InsightVM, Wazuh, Splunk, QRadar, Qualys, Tenable, CrowdStrike, Azure AD/Okta, Microsoft 365, Salesforce. Leadership: Engagement planning, stakeholder management, coaching/mentoring, quality reviews, executive communication. CERTIFICATIONS ISACA Certified Information Systems Auditor (CISA) ISACA Certified in Risk and Information Systems Control (CRISC) CompTIA Security+ Cisco Certified Network Associate (CCNA) Fortinet Network Security Expert (NSE) Level 5 F5 BIGIP LTM Administrator Microsoft Azure Fundamentals (AZ-900) Azure Security Engineer Associate (AZ-500) ITIL Foundation TECHNOLOGY & AUDIT TOOLKIT Cloud: Microsoft Azure, AWS (EC2, RDS, S3), Azure AD GRC/Workflow: ControlMap, One Trust, ServiceNow, Jira, Confluence, Remedy, Salesforce Security Monitoring/Vulnerability: Rapid7 InsightIDR, Rapid7 InsightVM, Wazuh, Splunk, IBM QRadar, Qualys, Tenable, CrowdStrike Infrastructure/Security: Fortinet, Palo Alto, Check Point, Cisco, F5 BIG-IP, SolarWinds, Wireshark, Bluecoat, Okta Reporting/Visualization: Excel (advanced); Power BI/Tableau (working knowledge; used dashboards/metrics and visual reporting in practice) Keywords: continuous integration continuous deployment business intelligence sthree active directory information technology ffive Arizona |