Profile photo

GRC Professional | Risk, Compliance & Controls.

I'm a dual-qualified legal and technology professional specializing in data privacy and enterprise GRC. With a background spanning full-stack engineering and cyber law, I bridge the gap between regulatory requirements and technical implementation — building ISMS programs that actually work in practice, not just on paper.

What I Do

GRC

ISO/IEC 27001 ISMS design, gap analysis, risk assessment & treatment, Statement of Applicability, and SOC 2 readiness.

Data Privacy

GDPR and DPDP Act 2023 advisory, privacy-by-design reviews, and data subject rights implementation.

Security Frameworks

NIST CSF 2.0, ITGC, CMMI, control mapping, risk assessment, and compliance activities.

Shubhendu Sen