dallas@grc:~$
about experience skills projects education contact

whoami

GRC & IT Risk Associate — Cybersecurity, Governance, Risk & Compliance

Dubai, UAE Available immediately (visiting visa) 2+ yrs consulting experience

cat about.md

Cybersecurity Governance, Risk, and Compliance (GRC) professional with 2+ years of consulting experience delivering IT risk assessments, ISO 27001 audits, SOC engagements, third-party risk reviews, and business resilience initiatives across financial services, healthcare, technology, BPO, insurance, and marketing sectors.

Conducted 25+ audit assessments and contributed to 50+ client engagements, supporting organizations in achieving audit readiness, maintaining certification compliance, and strengthening control environments.

Experienced in risk assessments, control testing, risk register management, governance reporting, policy development, and stakeholder engagement — with a proven ability to translate technical findings into actionable business recommendations for senior leadership.

ls -la experience/

Security Risk Consultant Jun 2025 — Jun 2026
MitKat Advisory · Remote, Mumbai, India
  • Conducted risk assessments across physical security, operational risks, and business resilience — identifying vulnerabilities and delivering actionable mitigation recommendations across multiple sectors.
  • Supported design and optimization of risk management frameworks, including SOPs, risk dashboards, and monitoring processes aligned with organizational objectives.
  • Assisted in developing and reviewing Business Continuity Plans (BCP) and Crisis Management Plans (CMP), contributing to crisis simulations, tabletop exercises, and post-incident improvement initiatives.
  • Managed multiple client engagements remotely, delivering risk assessment reports and advisory documentation while maintaining strong stakeholder communication.
  • Collaborated with senior consultants and clients on security advisory and pre-sales activities, contributing to proposals and tailored risk management solutions.
  • Analyzed emerging threats and geopolitical factors to support decision-making and strengthen client resilience strategies.
Associate IT Risk Advisory Oct 2023 — Sep 2024
RiskPro India Pvt. Ltd. · Mumbai, India
  • Supported 30+ client engagements delivering IT risk, compliance, and third-party risk assessments across financial services, healthcare, and IT sectors.
  • Led ISO 27001 and NIST audits across 25 assessments, including control design review, operating effectiveness, and remediation tracking.
  • Tested and tracked 114 Annex A controls across access management, change management, operational security, and governance domains.
  • Collected, validated, and mapped audit evidence to control requirements, including technical security controls and supporting documentation.
  • Drafted and updated ISMS policies, standards, and procedures to strengthen audit readiness and control alignment.
  • Maintained shared and department-level risk registers, identified emerging risks, and tracked open items through closure.
  • Supported third-party risk management and vendor audits for a major Indian bank's insurance division, covering 35 vendors across India.
  • Prepared governance, audit, and compliance reports each month for stakeholder review and decision-making.
  • Collaborated with internal teams and client stakeholders to close non-conformities and reduce open risks before external audits.
Information Security Executive Jun 2023 — Oct 2023
ShieldByte Infosec Pvt. Ltd. · Mumbai, India
  • Supported 15+ SOC engagements — SOC 1, SOC 2 Type 1 & Type 2 — including control testing, evidence review, and audit reporting.
  • Performed controls testing, evidence collection and review, and audit report preparation across security, privacy, confidentiality, and data processing/integrity control areas.
  • Used Vanta to manage audit evidence, track control readiness, and support audit execution.
  • Communicated findings, open risks, and remediation requirements to stakeholders using both technical and non-technical language.
  • Supported remediation tracking and drafted detailed and final audit reports after gap closure.

cat skills.json

frameworks_standards
ISO/IEC 27001 NIST CSF MITRE ATT&CK CIS Controls SOC 1 SOC 2 GDPR PCI DSS
security_and_compliance
Threat Hunting Incident Response Vulnerability Management Digital Forensics Malware Analysis Network Security Cyber Kill Chain IT Risk Control Design Review Operating Effectiveness Testing Evidence Collection Audit Support Policy Drafting Risk Registers Remediation Tracking Gap Analysis Third-Party Risk Management
tools
Vanta Microsoft Sentinel Splunk Microsoft Defender Kali Linux Nmap Wireshark Microsoft Azure Palo Alto Firewall Jira ServiceNow
technical
Python Blockchain Machine Learning Data Analytics

ls projects/

Securing Vulnerabilities in Autonomous Vehicles using Blockchain Aug 2025

Designed a blockchain-based framework to enhance authentication, integrity, and trust in V2X communication — implementing secure controls such as replay attack detection and cryptographic key management using Python.

Cryptocurrency Price Prediction Apr 2023

Built a machine learning based prediction model for forecasting cryptocurrency prices by gathering and analyzing live datasets from Yahoo Finance, using Prophet, LSTM, ARIMA, and XGBoost.

ijirt.org/Article?manuscript=159274 →

cat education.log

MSc Cybersecurity Sep 2024 — Nov 2025
National College of Ireland · Dublin, Ireland
B.E. Information Technology · CGPA 8.77/10 Aug 2019 — May 2023
Xavier's Institute of Engineering · Mumbai, India

cat certifications.log

contact --send

email
dallasvaz0@gmail.com
phone
+971 55 168 5995
location
Dubai, UAE
linkedin
linkedin.com/in/dallas-vaz