Open to new opportunities

Governing risk across AI, cloud & quantum.

I help enterprises manage risks end to end, operate securely, meet regulatory obligations, and grow with confidence.

3+
Years in GRC
MSTWO-YEARS
CYBERSECURITY RISK MANAGEMENT
Cross-Functional
STAKEHOLDER MANAGEMENT

01 — About

Professional Summary

A cybersecurity risk professional with experience helping regulated entities translate complex regulatory requirements into business-aligned and scalable security controls that deliver measurable risk reduction with audit ready compliance.   

02 — EXPERIENCE SCOPE

Areas of Expertise

Category 01

Domain Expertise

  • Governance, Risk & Compliance
  • Third-Party Risk Management
  • Cloud Security
  • Data Privacy
  • Business Continuity
Category 02

Industry Experience

Financial ServicesFintechMedia & Entertainment
Category 03

Cross-Functional Partnership

EngineeringProductRiskLegalComplianceHRITAdminOperationsC-Suite
Category 04

Emerging Focus

  • Responsible AI Governance
  • Agentic Systems Security
  • LLM Security
  • Post-Quantum Cryptography (PQC)
  • Zero-Trust Architecture (ZTA)
Category 05

Core Skills

  • Information Security Risk Assessment
  • Privacy Impact Assessment
  • Cloud Security Assessment
  • Vendor Risk Assessment
  • Cybersecurity Maturity Assessment
  • Business Impact Analysis
  • ISO 27001 Implementation
  • Security Policy Development 
Category 06

Professional Certifications

IAPP Certified Information Privacy Manager (CIPM)CompTIA Security+ISO 27001:2022 Lead ImplementerISO 27001:2022 Lead Auditor ISO 27701:2019 Lead ImplementerOneTrust Data Mapping Automation FoundationsOneTrust Incident Management FoundationsAWS Academy Graduate - AWS Cloud ArchitectingAgentic AI Architecture Foundations: Designing Autonomous AI Systems
Category 07

Control Frameworks

NIST CSFNIST AI RMFISO 27001ISO 42001PCI DSSNIST 800-53ISO 27701ISO 22301ISO 27002NIST 800-61
Category 08

Compliance Frameworks

  • EU General Data Protection Regulation (GDPR)
  • California Consumer Privacy Act (CCPA)
  • California Privacy Rights Act (CPRA)
  • EU AI Act
  • Health Insurance Portability & Accountability Act (HIPAA)
  • HITRUST Cybersecurity Framework
Category 09

Tools

OneTrustServiceNowJiraConfluence

03 — IMPACT BY THE NUMBERS

Key Performance Metrics

  • Increased high-risk vendor assessment quality and throughput by ~30% within two quarters for a $7.5B financial services client  
  • Developed a unified compliance dashboard to track compliance across 300+ controls spanning multiple frameworks all in one single pane
  • Identified 87% medium-to-high risk issues across core AWS services for a $108M M&E client and prevented ~$12M in losses by improving the cloud security posture
  • Identified 65% medium-to-high risk issues across 12 security domains for a $1.9B financial services client
  • Reduced third-party assessment time by ~40% by independently leading an organization-wide ISO 27001:2022 implementation for a $2.5B fintech client within one quarter

04 — RECOMMENDATIONS

Professional & Academic Recommendations

What colleagues, mentors, and clients have said about working with me.

Indiana University

Kimberly Herman

Information Security Architect

DIRECT MANAGER 
I had the opportunity to mentor Yash while he worked with a team to create a report and presentation about impactful threats to AWS infrastructure and the best ways to monitor and prevent them. This team of interns went above and beyond in outlining the most impactful threats, why those threats matter, how to prevent them, and which log sources to use to monitor for them. Throughout the process, Yash asked meaningful questions in order to make the work and he and the others put into this be tailored to our environment. The audience of this report is both technical stakeholders and leadership, and the report is both very readable and provides actionable information with technical backing. The research and knowledge that was put into this report is noticeable, and I believe that Yash will be an asset to any team he joins due to his ability to problem solve and communicate with impact.

CAPGEMINI

Varsha Khatri

Senior Manager

PROJECT MANAGER
I teamed with Yash on multiple privacy workstreams during our time together at Capgemini, where his ability to solve problems and deliver tangible results consistently stood out. He took ownership of crafting Records of Processing Activities (ROPA) that captured every minute detail about data processing, and of leading Privacy Impact Assessments that clearly surfaced critical risks for engagement leadership. His work made a significant contribution to Capgemini’s overall compliance efforts with the GDPR. Yash’s knack for translating complex privacy regulations into clear, actionable insights made a positive impact in leadership discussions. His attention to detail and contextual awareness consistently elevated the quality of deliverables. Beyond his own responsibilities, he actively mentored teammates across regions, resolved challenges, and upskilled coworkers, which demonstrated his leadership capabilities. In every interaction, Yash brought analytical rigor, accountability, and a client-first mindset, making him a high-impact professional I would be eager to work with again.

PWC

Pulkit Adlakha

Associate Director

PROJECT MANAGER
I had the pleasure of working with Yash at PwC on a Managed Security Services project where I served as Project Manager. Yash led the Cyber Governance workstream and his contributions have truly made a lasting impact on our firm’s cyber strategy service offerings. One notable achievement was the development of topic-specific systems security policies that, within a quarter of enforcement, drove significant risk reduction, improved regulatory compliance, reduced new findings in third-party audits, shortened vulnerability closure times, and embedded security into the organization’s culture. His profound understanding of client’s business objectives, technical infrastructure, cybersecurity standards, and regulatory landscape were truly instrumental in drafting effective policies. He combined technical expertise with strong collaboration, working effectively with internal teams and external stakeholders. His clear and confident communication with client leadership ensured alignment and built trust. His ability to plan strategically, commitment to excellence, and dedication toward pushing the boundaries of what’s possible set the tone of the project that promises to drive impactful change. I would recommend Yash for any role requiring deep cybersecurity knowledge, client engagement, and the ability to deliver sustained outcomes in challenging environments. He has been an incredibly valuable asset to PwC!

INDIANA UNIVERSITY

Alex Barsi Lopez

Associate Chair of Operations and Decision Technologies Graduate Programs   

PROFESSOR
Yash was my student in the newly created "Information Technology Principles" course at the Kelley School. That course was open for both Cybersecurity Risk Management MS students and MS in IT Management students. Yash exceled in the course. His assignments were outstanding and he was very involved in our optional live sessions (the course was mostly asynchronous but with live sessions every two weeks). He displayed a great amount of knowledge about all the topics that we covered and he was very proficient in our discussions during the live sessions, showing a great passion for learning. Despite his young age, Yash comes across as an experienced professional, someone who could be a great asset in areas related to the cybersecurity and IT management.

05 — REWARDS & RECOGNITIONS

Awards & Honors

Recognitions received for impact, leadership, and contributions across academic and professional milestones.

PWC

SPOT AWARD

For demonstrating sound technical capabilities, extraordinary collaboration, and impactful communication skills

PWC

SPOT AWARD

For demonstrating immense dedication and exceeding client’s expectations

CAPGEMINI

The Rising Star

For outstanding performance and lasting contribution to the Global Risk & Compliance function

I would love to hear from you!

Start a conversation