Vishnu Rajkumar Nair · Pune, India Actively building

Aspiring GRC &
Information Security
Professional

Focused on IT Governance, Risk, and Compliance (GRC), with a target of entering Big 4 Risk Advisory and BFSI security roles. Building domain expertise through structured certifications, cloud security fundamentals, and formal ISM training at SCIT Pune.

Cloud Security Risk Assessment IT Audit Governance Basics Compliance Fundamentals
Background

About Me

The context behind the credentials.

I'm a BCA graduate from SICSR Pune (CGPA: 7.0) entering the MBA-ITBM programme at SCIT Pune with an Information Security Management specialisation — aligned with the ISACA model curriculum for information security management.

My focus is the intersection of technology risk, control frameworks, and business assurance — specifically IT audit and GRC advisory. The goal is clear: Big 4 Risk Advisory or a senior BFSI security role within 3–5 years of graduating.

Before SCIT, I completed a DevOps internship at HJCloud Systems and earned my AWS Cloud Practitioner certification — giving me hands-on exposure to cloud architecture that most GRC candidates don't have at entry level. I'm using the pre-MBA window deliberately: AWS SAA by March, Security+ by May, then SCIT in June.

"Most MBA students walk into GRC with zero technical context. I'm walking in with cloud architecture experience and two security certifications. That gap is the plan."

I'm tracking toward CISA and CRISC — the two credentials that define serious IS audit and enterprise risk management careers.

Beyond technical credentials, I've demonstrated early leadership through roles as House Captain, Student Committee Member, and Football Team Captain — responsible for team coordination, decision-making under pressure, and representing peer interests in structured environments. These experiences built the communication and stakeholder management skills that GRC roles demand.

2022 – 2025
BCA — SICSR Pune · CGPA 7.0 · Systems, networks, and cloud fundamentals
Jan – Apr 2025
DevOps Internship — HJCloud Systems · CI/CD, cloud operations
Jul 2024
AWS Cloud Practitioner — First certification earned
Now → Jun 2026
Pre-MBA sprint — AWS SAA + Security+ before SCIT begins
Education
BCA — SICSR Pune
CGPA: 7.0 · Graduated 2025
Current Programme
MBA-ITBM
ISM Specialisation · SCIT Pune
Joining June 2026
Target Role
GRC / Risk Advisory
Big 4 · BFSI Security
Location
Pune, Maharashtra
Open to Mumbai, Bangalore
Credentials

Certifications

A structured credential path, not a random collection.

1 / 6earned so far · building
Cloud Foundation
AWS Certified Cloud Practitioner
Amazon Web Services · Earned July 2024
✓ Earned
AWS Solutions Architect – Associate
Amazon Web Services · Target: March 2026
In Progress
Security Fundamentals
CompTIA Security+
CompTIA · Planned: April – May 2026
Planned
GRC Core (During MBA)
CISA — Certified Information Systems Auditor
ISACA · The primary IS audit credential
MBA Phase
ISO 27001 Lead Implementer
PECB · Information security management systems
MBA Phase
Advanced Risk (Post-MBA)
CRISC — Certified in Risk and Information Systems Control
ISACA · Completes the CISA + CRISC risk advisory stack
Post-MBA
Verified digital badges will be embedded here via Credly as each certification is earned.
Planning & Trajectory

Learning Roadmap

Where I've been, where I am, where this compounds.

~10 wks
Pre-MBA window remaining
being used deliberately
5 yrs
Horizon for senior GRC role
with full CISA + CRISC stack
2022 – 2025
Foundation — BCA + Technical Exposure
Completed BCA from SICSR Pune (CGPA: 7.0) with focus on systems, networks, and cloud fundamentals. Supplemented with IBM Cloud Computing course, AWS Cloud Practitioner, and a DevOps internship at HJCloud Systems. Established the technical baseline that most GRC candidates lack.
SICSR PuneCGPA 7.0AWS CCPDevOps Internship
Now — March 2026
AWS Solutions Architect – Associate
Deep-diving into VPC design, IAM policy architecture, multi-region DR planning, and cloud security controls. The goal isn't just the certification — it's being able to audit AWS environments and speak to cloud risk in Big 4 engagements with actual technical credibility.
Stephane Maarek · UdemyTutorials Dojo Practice Exams
April – May 2026
CompTIA Security+
Core security principles, threat categories, cryptography, identity management, and network security. Bridges technical cloud knowledge with the security fundamentals needed for GRC — and provides a globally recognised baseline credential heading into SCIT.
Security FundamentalsPre-SCIT
June 2026
MBA-ITBM · ISM Specialisation — SCIT Pune
Entering with AWS SAA + Security+ already earned. The programme is aligned with the ISACA model curriculum, covering IS audit, risk management, governance frameworks, and information security management — the formal training layer on top of the technical foundation.
ISACA CurriculumIS AuditGRC Frameworks
During MBA · 2026 – 2028
CISA + ISO 27001 Lead Implementer
The two credentials that define IS audit and GRC credibility. CISA is the global standard for IT auditors; ISO 27001 Lead Implementer adds the implementation and compliance layer. Both will be pursued in parallel with the MBA, sequenced to align with coursework.
ISACAPECBIT Audit Core
Post-MBA · 2028+
CRISC + Senior Risk Advisory Role
CRISC (Certified in Risk and Information Systems Control) adds the enterprise risk management dimension to a CISA-anchored profile — the combination that positions for senior Big 4 or BFSI security leadership roles.
CRISCBig 4 / BFSISenior GRC Role
Capabilities

Skills & Competencies

Honest levels — this profile is designed to compound, not to overclaim.

GRC & Risk
Risk Identification & Categorisation
Developing
Control Mapping (Asset→Risk→Control)
Developing
IT Audit Concepts
Foundational
Compliance Framework Awareness
Foundational
↑ Primary growth area · SCIT + CISA
Cloud & Security
AWS Architecture (SAA level)
Proficient
Cloud Security Principles
Developing
IAM & Access Control
Developing
Network & Infrastructure Basics
Developing
↑ Security+ adds depth · May 2026
Communication & Analysis
Structured Written Communication
Strong
Technical Documentation
Proficient
Analytical Problem Framing
Proficient
Frameworks (Awareness Level)
ISO 27001
Studying
NIST CSF
Aware
COBIT
Aware
CISA Body
Planned
SOC 2
Planned
CRISC
Post-MBA
Analytical Work

Work Samples

Pre-formal training exercises. Labeled honestly — the depth compounds with SCIT, CISA, and real internship engagements.

2now · growing
Cloud RiskControl Mapping

Cloud Risk Analysis: AWS Shared Responsibility Model

An analysis of how the AWS Shared Responsibility Model distributes security obligations between the cloud provider and the customer — and where residual risk concentrates on the customer side. Uses the Asset → Risk → Control → Framework mapping template.

This exercise reframes a technical cloud concept through a risk and control lens — the core translation skill in IS audit and GRC advisory.

AssetRiskControlFramework Ref
S3 BucketUnintended public exposure of sensitive dataBlock Public Access setting; bucket policy reviewISO 27001 A.8.2
IAM RolesPrivilege escalation via overly permissive policiesPrinciple of least privilege; periodic access reviewNIST AC-6
EC2 InstancesUnpatched OS vulnerabilities post-launchAWS Systems Manager Patch Manager; patching scheduleISO 27001 A.12.6
CloudTrail LogsTampering or deletion of audit trail evidenceLog file integrity validation; S3 MFA DeleteNIST AU-9

Foundational exercise — pre-formal training. Framework references sourced from public NIST SP 800-53 and ISO/IEC 27001:2022 documentation.

Risk AssessmentFoundational

Risk Identification: Hypothetical College ERP System

A structured risk identification exercise applied to a generic college ERP system covering student records, fee management, and faculty portals. Demonstrates systematic threat identification and basic control suggestion across common risk categories.

The goal here isn't deep technical audit — it's demonstrating that risk thinking can be applied systematically to a familiar operational context.

RiskCategoryImpactSuggested Control
Unauthorised access to student recordsAccess ControlData breach, regulatory exposureRBAC; session timeout; MFA for admin accounts
SQL injection via unvalidated form inputsApplication SecurityData manipulation, extractionInput validation; parameterised queries; WAF
Data loss due to absence of backup proceduresAvailabilityOperational disruptionAutomated scheduled backups; tested recovery plan
Fee payment data intercepted in transitData ConfidentialityFinancial data exposureTLS enforcement; HTTPS-only policy
Shared admin credentials across departmentsAccess ControlAudit trail failure, insider riskIndividual accounts; privileged access management

Foundational exercise — pre-formal training. Intended to demonstrate structured analytical thinking, not professional-grade audit output.

SCIT Internship Case Studies

Real GRC and IS audit artifacts from internship engagements will replace these foundational exercises. The profile compounds as credentials and experience accumulate.

Expected: mid-2027 onwards
ISO 27001 Gap Analysis Exercise

A structured gap analysis against ISO 27001 controls for a hypothetical organisation — to be developed during the ISO 27001 Lead Implementer preparation.

Expected: Q3 2026
Connect

Get in Touch

Open to conversations, not just opportunities.

I'm building in public — deliberately, incrementally, and with a long horizon. If you're a recruiter, hiring manager, fellow GRC student, or a professional in Risk Advisory or BFSI security, I'm genuinely happy to talk.

I don't have everything figured out yet. What I do have is a clear target, a structured path, and the intellectual honesty to know the difference between where I am and where I'm going.

That combination is rare. I'd like to think it's worth a conversation.

Preferred contact: LinkedIn
Open to
GRC / Risk Advisory internship conversations
Mentorship from IS Audit or Big 4 professionals
Study groups: CISA, Security+, ISO 27001
Campus recruitment discussions (SCIT 2028 batch)