Sakshi Chhabra

Cyber Security Professional

Cyber Security Professional with 2.5+ years of experience in policy development, ISO 27001:2022 audit and implementation, SOC 2 type 1 and 2 audits, ITGC audits, and information security assessments etc. Certified Information Security Consultant and Professional Forensics Analyst with ISO 27001:2022 LA certification.

Mumbai, India

Areas of Expertise

ISO 27001:2022

Expert in implementing and auditing Information Security Management Systems (ISMS). Proficient in risk assessment, security controls, and compliance documentation. Experience in gap analysis and continuous improvement of security frameworks.

SOC Audits

Specialized in SOC 1 and SOC 2 Type assessments for financial institutions and tech companies. Skilled in evaluating control design, implementation, and operational effectiveness. Experience in documenting control objectives and testing procedures.

GDPR Compliance

Comprehensive understanding of GDPR requirements and implementation. Experience in data protection impact assessments, privacy policies, and compliance frameworks. Skilled in conducting data protection audits and implementing privacy controls.

Security Controls

Expertise in IT General Control Audits covering access management, change management, and operations. Proficient in evaluating control effectiveness, identifying gaps, and recommending improvements for robust security posture.

Risk Management

Skilled in vendor and third-party risk assessments, including security questionnaires, documentation review, and compliance verification. Experience in developing risk mitigation strategies and monitoring programs.

Certifications

Certified Information Security Consultant and Professional Forensics Analyst. ISO 27001 Lead Auditor with expertise in security frameworks and best practices. Continuous learning through platforms like Try Hack Me.

Professional Journey

ControlCase International Pvt Ltd

Consultant - Cyber Security

Mumbai

April 2025 – Current
  • Leading the development and implementation of ISO 27001:2022-aligned policies and procedures, ensuring comprehensive security framework adoption
  • Conducting gap analyses and risk assessments aligned with standards like ISO 27001/22301
  • Developed ISO 22301 & ISO 27001 report templates aligned with CERT-IN and industry best practices
  • Created NESA compliance matrix to map and track regulatory requirements
  • Lead preparation efforts and represent the organization during external ISO certification audits
  • Perform comprehensive risk assessments and give Information Security approvals to facilitate secure vendor onboarding and offboarding processes

Nangia Co & LLP

Consultant - Cyber Security

Mumbai

Nov 2022 – March 2025
  • Led the development and implementation of ISO 27001:2022-aligned policies and procedures, ensuring comprehensive security framework adoption
  • Conducted in-depth SOC 1 and SOC 2 audits for banking and product-based companies, evaluating control effectiveness and compliance
  • Performed thorough vendor risk assessments and audits, implementing robust third-party risk management programs
  • Executed comprehensive IS audits and spearheaded Vishing/Phishing awareness campaigns to enhance security culture
  • Developed and delivered engaging security awareness training programs, improving organizational security posture
  • Conducted detailed IT General Controls reviews, ensuring alignment with industry best practices
  • Prepared comprehensive audit reports and compliance reviews, providing actionable recommendations
  • Implemented and maintained internal audit procedures for ISO 27001:2022 compliance
  • Reviewed and enhanced security policies based on emerging threats and compliance requirements

Cova Consultancy

IELTS Instructor

Lalru Mandi, Punjab

Mar 2021 - Dec 2021
  • Created comprehensive IELTS preparation materials tailored to diverse student needs
  • Conducted engaging preparation classes focusing on all four IELTS modules
  • Provided detailed, constructive feedback to help students improve their performance
  • Organized interactive activities to enhance learning and retention
  • Developed effective exam strategies to maximize student success rates

Education

Bachelor of Science in Information Technology

with Mathematics, Statistics

Panjab University, Chandigarh

Certifications

  • Information Security Consultant & Professional Forensics Analyst

    Institute of Information Security

    Comprehensive training in security consulting and digital forensics investigation techniques

  • Pre-Security, Web fundamentals & Jr Penetration Tester

    Try Hack Me

    Hands-on experience with web security, penetration testing, and vulnerability assessment

  • ISO 27001:2022 Lead Auditor

    Professional Certification

    Qualified to lead ISO 27001:2022 audits and assess ISMS implementation