CISA · Cybersecurity GRC · Regulatory Audit · Risk & Compliance

Ravinder Yadav

Cybersecurity GRC
& Technology Risk

Cybersecurity governance, regulatory compliance, IT audit and risk advisory — with hands-on security operations experience behind the controls.

  • Based in Gurugram, India
  • Focus Regulated & enterprise environments
Ravinder Yadav, cybersecurity GRC and technology risk professional
CISA Certified Information
Systems Auditor
Working knowledge across
  • SEBI CSCRF
  • RBI Cybersecurity Framework
  • NIST CSF
  • ISO 27001
  • PCI DSS
  • DPDP Act 2023

Turning cybersecurity requirements into practical controls.

Cybersecurity is not only a technology problem. Organisations also need governance that holds, controls that actually operate, regulatory alignment that survives scrutiny, and evidence that stands up in an audit.

My work sits where those requirements meet reality — assessing how controls are designed and operated, where the gaps sit, what the risk actually is, and what has to be fixed first.

  • Regulatory cybersecurity audits
  • Cybersecurity governance
  • Risk assessment
  • Control assessment
  • Third-party risk
  • Incident governance
  • Business continuity & disaster recovery
  • Security operations
  • Vulnerability management
  • Audit reporting & documentation

Where I can help

Advisory areas drawn directly from regulatory audit, IT control assessment and security operations experience.

01

Cybersecurity GRC

Make sense of what a cybersecurity requirement actually demands — then establish the governance structure, policies and controls that satisfy it. Identify gaps between stated policy and operating practice, define control ownership, and give leadership reporting that reflects the real control position.

  • Governance Structure
  • Policy & Framework Development
  • Control Design
  • Gap Analysis
  • Committee Reporting

02

Regulatory Compliance & Readiness

Compliance assessments and control reviews against the frameworks that matter in regulated environments, with practical support on evidence readiness, documentation quality and remediation planning ahead of an inspection or audit.

  • SEBI CSCRF
  • RBI Cybersecurity Framework
  • NIST CSF
  • ISO 27001
  • PCI DSS
  • DPDP Act 2023

03

IT Audit & Control Assessment

Review technology and IT general controls for design and operating effectiveness, surface control weaknesses, and prepare documentation that is audit-ready — sample coverage, testing periods and control ownership included.

  • ITGC Review
  • Control Testing
  • Audit Documentation

04

Cyber Risk Assessment

Assess technology and cybersecurity risk across the environment, identify the genuinely high-risk areas, and support risk-based remediation rather than an undifferentiated list of findings.

  • Risk Identification
  • Risk Reporting
  • Remediation Tracking

05

Third-Party & Vendor Risk

Evaluate the cybersecurity posture of third parties and vendors — reviewing audit reports for scope, methodology and finding quality, assessing control coverage, and identifying the security risk carried into your environment.

  • TPRM
  • Audit Report Review
  • Vendor Assessment

06

Incident & Resilience Governance

Review incident governance end to end — response process, root cause analysis discipline and reporting quality — alongside BCP/DR plans and whether recovery objectives hold against resilience requirements.

  • Incident Lifecycle
  • RCA
  • BCP / DR Review

07

Security Operations Advisory

Practical SOC experience applied to oversight questions: whether detection coverage is real, whether alerts are triaged properly, whether vulnerability management closes anything, and whether operational evidence supports the control claim.

  • SIEM
  • EDR / XDR
  • DLP
  • Vulnerability Management
  • Incident Response

Where governance meets technical security

Most cybersecurity advice comes from one side of the line — either the framework or the console. The useful work happens where both are understood.

Regulatory Perspective

Working experience inside cybersecurity regulatory compliance and with regulated entities — including how a regulator reads an audit report and what a compliance gap looks like from the other side of the table.

Audit Discipline

Hands-on with inspections, control assessments and third-party audit reports: scope, methodology, sample sizes, testing periods, control ownership and whether a finding is actually evidenced.

Technical Foundation

A SOC background in SIEM, EDR/XDR, DLP, vulnerability assessment and incident response — the technical depth that lets a control conversation go past the policy document.

Risk-Based Thinking

Identifying control gaps, documenting risk clearly, performing root cause analysis and supporting remediation in the order that reduces the most exposure first.

Experience that shapes the advisory approach

Two very different vantage points on the same problem — regulatory oversight of cybersecurity, and the security operations floor where controls either work or don’t.

Nov 2024 — Present

Securities & Exchange Board of India

Cyber Security Analyst (YP) Mumbai

Regulatory cybersecurity oversight of SEBI-regulated entities, including Market Infrastructure Institutions.

Regulatory Cybersecurity

Driving compliance audits across SEBI-regulated entities and assessing adherence to the Cyber Security and Cyber Resilience Framework (CSCRF), reporting compliance gaps to leadership.

Cybersecurity Inspections

Leading cybersecurity inspections and control assessments to identify governance and technical gaps, and coordinating remediation timelines with regulated entities.

Third-Party Assurance

Reviewing and validating third-party cybersecurity audit reports, and evaluating audit firms and security vendors on scope, methodology and finding quality.

Incident Governance

Managing end-to-end incident lifecycle governance, including RCA documentation and risk-based reporting for regulatory and executive audiences.

Control Testing Methodology

Applying ITGC testing methodology — control design and operating effectiveness — when reviewing third-party audit evidence against CSCRF audit quality standards.

Resilience

Reviewing Business Continuity and Disaster Recovery plans, verifying resilience controls against regulatory recovery time and recovery point objectives.

Jun 2023 — Nov 2024

Code Caters IT Solutions

Associate Gurugram

Security operations, endpoint governance and vulnerability assessment in an enterprise SOC environment.

SOC Monitoring & Detection

Monitoring enterprise systems and network logs with Splunk and ELK Stack, detecting and analysing security incidents across the environment.

Endpoint Threat Response

Investigating alerts and suspicious activity through EDR and XDR platforms, supporting triage, containment and remediation.

Data Loss Prevention

DLP monitoring and policy enforcement to prevent data exfiltration and maintain compliance with organisational security standards.

Endpoint Governance

Implementing and administering Mobile Device Management with Microsoft Intune and ManageEngine — compliance policy, remote wipe and encryption standards across the endpoint estate.

Vulnerability Assessment

Performing vulnerability assessments with OpenVAS and web application testing with OWASP ZAP, reporting identified security risk.

Incident Response & RCA

Supporting incident response and root cause analysis, preparing incident summaries and helping develop response playbooks to standardise procedure.

The expertise map

Four connected domains — governance, risk, regulation and security operations — applied together rather than in isolation.

Governance

  • GRC
  • Governance Frameworks
  • Policy & Framework Development
  • Control Design
  • Control Assessment
  • Compliance Oversight
  • Audit Readiness
  • Audit Reporting & Documentation
  • Executive & Committee Reporting
  • Security Architecture Review

Risk

  • Cyber Risk
  • Risk Assessment
  • Root Cause Analysis
  • Third-Party Risk

Regulatory

  • SEBI CSCRF
  • RBI Cybersecurity Framework
  • NIST CSF
  • ISO 27001
  • PCI DSS
  • DPDP Act 2023

Security

  • SIEM
  • EDR / XDR
  • DLP
  • Vulnerability Management
  • Incident Response

Frameworks & standards

Areas of professional working knowledge and applied experience, developed through regulatory audit and control assessment work.

SEBI CSCRF

Cyber Security and Cyber Resilience Framework — compliance audits, control assessment and audit-report review across SEBI-regulated entities.

RBI Cybersecurity Framework

Working knowledge of the RBI cybersecurity expectations for regulated financial entities, applied for cross-framework alignment.

NIST CSF

Functional structuring of cybersecurity capability — used as a reference model when mapping controls across frameworks.

ISO 27001

Information security management system structure, control domains and documentation expectations.

PCI DSS

Payment data security control requirements and their overlap with wider regulatory control obligations.

DPDP Act 2023

India’s Digital Personal Data Protection Act — data protection obligations and their intersection with security controls.

These represent professional working knowledge and applied experience. Framework-specific certification is listed separately under Credentials.

Technical depth behind the GRC

Control assessment is more credible when the assessor has operated the tooling that produces the evidence.

Security Operations

  • Splunk
  • ELK Stack
  • SIEM
  • EDR / XDR
  • DLP

Assessment

  • OpenVAS
  • OWASP ZAP
  • Vulnerability Assessment

Cloud & Infrastructure

  • Azure
  • Firewall & Network Security
  • Linux

Automation & Scripting

  • PowerShell
  • Python

Credentials

Certified Information Systems Auditor

ISACA

The audit credential that underpins the control assessment, evidence review and IT audit work.

CompTIA CySA+

Cybersecurity Analyst

Certified Ethical Hacker

EC-Council

CompTIA Security+

Security Fundamentals

Microsoft Azure AZ-500

Azure Security Engineer

A risk-first approach to cybersecurity

I am a CISA-certified cybersecurity GRC professional working at the intersection of regulatory cybersecurity, IT audit, risk and compliance.

My current work is regulatory: driving compliance audits and cybersecurity inspections across regulated entities, assessing controls against framework requirements, reviewing third-party audit reports and governing the incident lifecycle from RCA through to risk-based reporting. Before that, my time was spent in security operations — SIEM monitoring, endpoint detection and response, DLP, vulnerability assessment and incident handling.

That combination is deliberate. Governance without technical grounding produces documents nobody can operate; technical work without governance produces fixes nobody can evidence. I work on the connection between the two — regulatory requirement, control design, operating reality, and the risk that remains.

View professional profile (PDF)

A practical approach to cyber risk

The working method applied to a cybersecurity, audit or compliance requirement — a professional framework rather than a fixed engagement model.

  1. 01

    Understand

    Understand the organisation’s regulatory obligations, technology environment and risk posture before assuming what the problem is.

  2. 02

    Assess

    Identify control gaps, risks and the areas that genuinely require attention — assessed on design and on how the control actually operates.

  3. 03

    Prioritise

    Translate findings into risk-based remediation priorities, so effort goes where exposure and regulatory consequence are highest.

  4. 04

    Strengthen

    Support practical control improvement, documentation and audit readiness — the state where the control works and can be evidenced.

Have a cybersecurity or GRC requirement?

For discussions around cybersecurity governance, regulatory readiness, IT audit, technology risk and compliance, get in touch.

Email Ravinder