Summary
Overview
Work History
Education
Skills
Work Preference
Certification
Timeline
Generic
Sunita Bhardwaj
Open To Work

Sunita Bhardwaj

Dublin,USA

Summary

Specialist in IT infrastructure and information security with deep expertise in policy management and risk mitigation. Proven ability to lead vulnerability management programs, streamline security policies, and ensure compliance, driving significant improvements in organizational security posture and risk awareness.

Overview

1
1
Certification
15
15
years of professional experience

Work History

InfoSec Governance Analyst

VMware Inc.
03.2021 - 11.2023
  • Assessed and documented security policy management processes for all policies and standards.
  • Established and communicated security policy management norms to policy owners and custodians.
  • Ensured alignment of business and technical requirements with security policies within set timeframes.
  • Collaborated with compliance teams to identify and analyze security gaps.
  • Reviewed security policies, recommending streamlining for enhanced clarity and effectiveness.
  • Served as liaison between business units and technology teams to communicate security requirements.
  • Managed distribution of quarterly exception reports to leadership, escalating identified risks.
  • Supported global security awareness program by presenting on policies and exceptions process.

Account Information Security Officer

DXC Technology (Former HPE)
09.2015 - 06.2019
  • Developed IT account security plans to reduce client business process risks.
  • Conducted IT security reviews and audits to assess organizational technology risks and prevent incidents.
  • Recommended information security improvements to stakeholders for timely risk mitigation.
  • Monitored compliance risks using risk management framework best practices, enabling proactive risk recognition.
  • Assisted in external audits and engaged engineering teams for thorough readiness assessments.
  • Led global vulnerability management programs by analyzing reports and effectively communicating gaps.
  • Managed remediation efforts related to incidents, penetration tests, and audits, collaborating with stakeholders.
  • Reported monthly on regulatory updates and vulnerability closure status, providing critical insights.

Risk and Compliance Lead

IBM
08.2008 - 09.2015
  • Collaborated with cross-functional infrastructure, engineering, business, and security teams to identify potential security risks to information systems and data, enhancing overall risk awareness.
  • Develop and implement risk management strategies and processes.
  • Conducted vendor and third-party risk assessments, performed audits and documentation for cloud environment, ensured compliance with contract requirements, identified security vulnerabilities, and recommended remediation strategies.
  • Highlighted deviations to stakeholders and management for action; reviewed risks with the customer and IBM environment; ensured client IT infrastructure met defined requirements, policies, and regulations.
  • Significantly assisted in maintaining PCI-DSS and SOX compliance. Identified the applicable audit requirements, advised on the evidence needed, and acted as a program manager to resolve the findings.
  • Facilitated corporate audits as liaison between technology teams and auditors, ensuring clear communication and efficient audit processes.
  • Performed internal audits and reviews. Under Compliance Assurance, performed testing on customer agreed processes-inclusive of IT General Controls (ITGC); Customer Audits and Reviews preparedness.

Education

3 Year Associates Degree -

Electronic & Radio Engineering

Skills

  • ServiceNow and HPSM
  • JIRA and CIRTAS
  • Qualys and Nessus
  • Policy management
  • Security audits
  • Risk assessment
  • Risk management
  • Data Governance
  • Risk Assessment

Work Preference

Job Search Status

Open to work

Work Type

Full TimeContract Work

Location Preference

On-SiteRemote

Salary Range

$130000/yr - $200000/yr

Certification

  • 1 year Advanced Diploma in Network Computing & Programming
  • ITIL Foundation V3.
  • ISO/IEC 27001:2005 - Info Security Management Systems Auditor/ Lead Auditor.
  • ISO 3100:2009 - Risk Management Principles & Guidelines Implementation.
  • Certified Ethical Hacking V10 from EC-Council.
  • Functional understanding of HIPAA, PCI-DSS, SOX compliance, SOC Compliance, GDPR, NIST framework.

Timeline

InfoSec Governance Analyst

VMware Inc.
03.2021 - 11.2023

Account Information Security Officer

DXC Technology (Former HPE)
09.2015 - 06.2019

Risk and Compliance Lead

IBM
08.2008 - 09.2015

3 Year Associates Degree -

Electronic & Radio Engineering
Sunita Bhardwaj