SP

sudip pokhrel

Open to opportunities

Cybersecurity Analyst | GRC & IT Risk Analyst

Ottawa, ON

Sign in to follow
Magna International
Academy of Learning

About

Cybersecurity, GRC and IT Risk Analyst with 4+ years across manufacturing and healthcare environments, supporting ITGC testing, access governance, and audit readiness for 40+ in-scope applications. Closed a 30+ item remediation backlog per quarter and coordinated SOC 2 and ISO 27001 evidence collection across 8+ control owners per cycle. Security+ certified, with working knowledge of NIST CSF, PCI-DSS, PIPEDA, PHIPA, and HIPAA, plus hands-on exposure to cloud IAM, vulnerability management, and incident response support. Strong stakeholder communicator with disciplined documentation habits and dependable follow-through on cross-functional risk initiatives.

Skills

  • Attention to detail
  • C#
  • Jira
  • Microsoft Word
  • Problem solving
  • Teamwork
  • Time management

Experience

  1. Information Security Analyst, GRC

    Magna International

    Jun 2024 to Present

    Canada

    • Restructured ITGC evidence repositories across access, backup, and change control domains for 40+ in-scope systems, cutting evidence retrieval time by an estimated 30% during audit prep. • Owned remediation tracking in ServiceNow for a backlog of 30+ open findings per quarter, partnering with 8 to 10 infrastructure and application owners to close items on schedule and keep the enterprise risk register current. • Ran quarterly access certifications across finance and operations systems covering 200+ user accounts, flagging inactive accounts, excessive privileges, and role conflicts before they became audit findings. • Reviewed 15 to 20 production change records per cycle for approvals, rollback plans, and segregation of duties evidence ahead of internal assessments and external audit cycles, reducing rework during fieldwork. • Validated SOC 2 and ISO 27001 evidence artifacts from 8+ technical control owners each cycle and maintained trackers that kept submission timelines on schedule across two concurrent audit workstreams. • Evaluated vendor security questionnaires for 10+ third-party vendors per quarter, documented control gaps, and escalated material risks, improving visibility into third-party risk for leadership. • Updated 12+ security policies, standards, and procedures over two years to align governance documentation with operational practice across four business functions. • Built monthly executive dashboards summarizing open risk items, remediation status, and upcoming milestones for governance review meetings attended by 10+ stakeholders.

  2. Information Security Analyst, GRC

    CitiusTech

    Mar 2020 to Apr 2022

    India

    • Organized compliance evidence for HIPAA, SOC 2, and internal control requirements across regulated healthcare technology environments supporting 20+ applications. • Led walkthrough sessions with development and infrastructure teams across 15+ critical systems per audit cycle to confirm control ownership and documentation completeness. • Maintained issue logs and remediation trackers for audit observations, cutting the backlog of recurring and unresolved control deficiencies by roughly 25% over one year. • Reviewed IAM configurations across sensitive healthcare applications supporting thousands of patient records, identifying dormant accounts and excessive permissions for remediation. • Revised 10+ policies, procedures, and control narratives to keep documentation audit-ready across recurring quarterly regulatory reviews. • Tracked vendor risk follow-up activity for 8+ third-party suppliers, documenting findings and mitigation evidence and following through on remediation commitments. • Coordinated evidence requests with external auditors across annual assessments, shortening average response turnaround time by an estimated 20%. • Supported privacy initiatives on data retention, secure access, and handling practices across regulated healthcare systems used by multiple clinical teams.

Education

  1. Academy of Learning

    Personal Support Worker (PSW)

    London, Ontario

    2025

  2. Fanshawe College

    Information Security Management (ISM)

    Canada

    2023 to 2024

  3. Islington College

    Bachelor of Information Technology, Information Technology

    2018 to 2021

    Affiliated with London Metropolitan University, UK.

Licences & certifications

  • CompTIA Security+

    CompTIA

  • Google Cybersecurity Professional Certificate

    Google