Sangeeta Patel

Sangeeta Patel

CISO | NSDL Payments Bank CRISC, CISA, ISO 27001 Lead Implementer, ITIL Foundation Certificate in IT Service Management

NSDL Payments Bank Mumbai, Maharashtra, India

View LinkedIn Profile
Experience20+ Years
LevelCXO

Executive Overview

18+ Year of Experience in IT & Information Security Domain Current Responsibilities: - Cyber /Regulatory Governance: - Performing Information security & Cyber security reporting to RBI and other regulatory bodies such as SEBI, PFRDA, CERT-In, NPCI, NCIIPC as per requirement. Also coordinating /communicating to RBI Personnel during onsite RBI Inspection for collection and submission of required details and during another regulatory requirement as needed. - Policy Framework: - Working on Information Security and Cyber Security Policy Creation and review as per defined frequency. - ISMS: - Successfully design implementation, operation and maintenance of the Information Security Management System based on the ISO/IEC 27001:2013 standards, including certification against ISO/IEC 27001 for IT Department & Call centre Environment. This includes coordination and implementation of security controls in the functions such as Physical Security/Facilities, HR & Call centre. - GRC Tool: - Working on Automation of compliance and other modules via GRC Tool Archer to collect data and provide centralised console for MIS purpose. Modules worked includes Exception, compliance, third party management tool, Issue management for raising finding. Implementation of Service Now GRC module and migration of data from Archer tool. - Audit & Compliance: - Responsible for interacting with external audit teams (Statutory /surveillance) wherever applicable. Co-coordinating and closing audit observation w.r.t required control. Performing ISMS audit/review for internal team. Working to meet internal compliance requirements. - Risk Management (Technical /Process): - Identify and understanding of technical risks and experience in performing/ overseeing assessments such as VA/PT/AppSec /Security architecture review etc. Updating Risk register with identified IT Risk. Performing information security risk assessments and controls selection activities. Professional Certification: - CRISC - ISO 27001 Lead Implementer - CISA - ITIL Foundation Certificate in IT Service Management - Cisco Certified Network Associate (CCNA 640-801) - Cisco Securing Networks with PIX and ASA (SNPA 642-522)

Career Timeline

Professional employment history
  • May 2023–Present· 3 yrs 4 mos
    • Chief Information Security OfficerCurrent
      May 2024–Present
    • Head IT Security and Risk
      May 2023–May 2024
  • Apr 2019–Apr 2023· 4 yrs
    • Vice President, Information Security
      Nov 2021–Apr 2023
    • AVP - IT Risk Governance & Compliance
      Apr 2019–Feb 2022
  • Nov 2016–Apr 2019· 2 yrs 5 mos
    • Associate Director, Information Security
      Nov 2016–Apr 2019
  • Nov 2011–Nov 2016· 5 yrs
    • Senior Manager, Information Technology Security
      Nov 2011–Nov 2016
  • Dec 2007–Nov 2011· 3 yrs 11 mos
    • Technical Specialist - Security Management
      Dec 2007–Nov 2011
  • Mar 2006–Dec 2007· 1 yr 9 mos
    • NSP Executive
      Mar 2006–Dec 2007
  • Oct 2005–Feb 2006· 4 mos
    • System Admininistrator
      Oct 2005–Feb 2006

Education

MBA

Project Management

Sikkim Manipal Institute of Technology - SMU

M.Sc

Physics

University of Mumbai

Bachelor's Degree

Physics and Computer Application

University of Mumbai

Executive Relationship Map

Reports To
Sangeeta Patel
Vice Chair & President
Chief Financial Officer
Chief Technology Officer
Chief Operating Officer

Executive Network Preview

BizKonnect has mapped this leadership network including reporting hierarchies, peer connections, and cross-functional relationships.

Verified Contact Information
Email & Direct Dial
Org Chart & Reporting Lines
Buying Committee Insights
AI-Powered Account Mapping

Skills & Expertise

20 of 20 skills
Change ManagementCISANetwork SecurityPre-salesRisk ManagementVendor ManagementManagementSecurity ManagementConfiguration ManagementIncident ManagementSecurityInformation Security ManagementISO 27001CybersecurityCCNATeam ManagementSlaSecurity AuditsVPNITIL