SJM
SHASWAT MANOJ JHA / CISA

IT audit & technology risk.

Portrait of Shaswat Manoj Jha

I'm Shaswat, a Senior Consultant at EY and a CISA. I work on IT controls, cybersecurity and AI governance, and write scripts to make repetitive review work easier. This is where I keep my experience, qualifications and a few examples of how I approach the work.

Portrait of Shaswat Manoj Jha

Experience at a glance

I work in IT audit and technology risk. That means understanding a process, checking its controls and following the evidence. I also write scripts when a repetitive check can be made easier.

Current role
Senior ConsultantIS Audit & Risk · EY · since August 2024
Core areas
IT controls · cybersecurityCloud security · data privacy · AI governance
Earlier experience
Protiviti · Nangia & Co LLPTechnology risk and cybersecurity
Qualification & location
CISA · Jamshedpur, IndiaFull experience and qualifications in my résumé
0 +
Years in
technology risk
0
Focus areas across
assurance & security
0 +
Files screened
for personal data

About me

I started with programming. Most of my work today is in IT audit and technology risk, but I still like finding the parts of a review that a small script can make easier.

I’m a Senior Consultant in IS Audit & Risk at EY. Before that, I worked at Protiviti and Nangia & Co LLP. My experience covers IT controls, cloud security and data privacy, including work with financial services and insurance organisations.

I’m a CISA and have completed lead auditor training for ISO/IEC 27001 and ISO/IEC 42001. My work includes process walkthroughs, control-design and operating-effectiveness testing, risk and control matrices, audit reporting and follow-up on findings.

I have built a Python scanner for potential personal data and a PowerShell script to reconcile Active Directory users with HR termination records. I’ve also identified and responsibly disclosed an access-control vulnerability in a SaaS platform.

What I want this portfolio to show is the work behind those résumé lines. The project pages explain my contribution, while the fictional examples show the questions I’d ask and the evidence I’d need before reaching a conclusion.

  • I review access management, change management, IT operations and backup and recovery controls. This includes testing both control design and operating effectiveness.
  • For integrated audits, I map IT controls to business processes and document walkthroughs, risk and control matrices, samples and testing evidence.
  • I assess cloud configurations against CIS Benchmarks, including access, encryption, network segmentation and recovery. I also review RPA bot accounts, credential storage and segregation of duties.
  • My recent work includes GitHub access and repository controls, as well as governance over integrated AI tools.
  • I review ISMS policies and carry out gap assessments against frameworks such as ISO/IEC 27001 and NIST SP 800-53.
  • I test interfaces, input checks, master data and report integrity to assess whether applications process data accurately and completely.
  • I review maker-checker workflows, audit trails, access restrictions and configuration settings for risks of unauthorised changes.
  • I recommend improvements to system configurations and the software development lifecycle where testing shows gaps or unnecessary manual work.
  • I map security controls to ISO/IEC 27001, NIST CSF and NIST SP 800-53, and review coverage against IRDAI and RBI requirements.
  • I have carried out SAMA Cybersecurity Framework gap assessments and tracked the resulting findings and corrective actions.
  • For privacy reviews, I check how personal data appears in applications, APIs, logs and reports, including assessments against the DPDP Act 2023.
  • I review business continuity and disaster recovery plans, recovery objectives, backup tests and drill records.
  • I turn policy requirements into testing checklists and evidence requests so that adherence can be assessed.
  • I assess vendor controls for logical and physical access, data protection, service agreements and incident reporting.
  • During on-site reviews, I check data handling, endpoint DLP and how access is granted and removed. I document gaps and follow up on corrective actions.
  • I use Microsoft Visio to map how sensitive data moves between users, processes and systems, then review where it could be exposed.
  • I assess endpoint security and DLP rules, including device controls and restrictions on copying, printing and data transfers.
  • I review asset inventories, patching and EDR coverage, and use dashboards to track gaps and exceptions.
  • I have used Burp Suite, OWASP ZAP and SQLMap for manual and automated testing of web applications.
  • My testing has covered SQL injection, XSS, IDOR, authentication and access control flaws, and security misconfigurations. I record proofs of concept and risk ratings.
  • I work with IT teams to retest fixes and check controls such as least privilege, input validation and rate limiting.
  • I prepare audit scopes, methodologies, effort estimates and acceptance criteria for proposals.
  • I document risk and control matrices, workpapers and supporting evidence so that another reviewer can follow the testing and conclusions.
  • I use Power BI and presentation reports to explain findings, their risk and the actions needed to address them.

Projects & practical work

A few examples of how I use code and control reviews in my work. Each case explains my contribution and the questions I would want the evidence to answer.

View all work
Python · data privacy

PII file scanner

I wrote a Python scanner to look for possible personal data in more than 1,000 logs, PDFs and spreadsheets. It helped reduce the manual screening work. The case study explains where the script helped and where a reviewer still needed to make the call.

Read the case study →
PowerShell · identity & access

User access review automation

I built a PowerShell script to compare Active Directory users with HR termination records. It made the reconciliation easier to review, so the follow-up could focus on the accounts and dates that needed an explanation.

Read the case study →
IT controls · AI governance

GitHub & AI governance reviews

I reviewed access, privileged activity and repository configuration in GitHub environments, along with governance over integrated AI tools. The case study follows the questions about permissions, changes and evidence behind that work.

Read the case study →

Try a small access review

Five made-up records, including an account removed late and a current employee who falls outside the review. Pick the records you'd follow up and compare your reasoning with mine.

Open the walkthrough

Experience

Tools I use

Microsoft Office
AuditBoard
Microsoft Visio
Power BI
Python
Splunk
RSA Archer
SQL
Metasploit
Kali Linux
Burp Suite
OWASP ZAP
Still learning

Education

MBA – Information Technology and Financial Management
2022 - 2024
Swami Vivekananda Subharti University, Meerut (Distance)
B. Tech – Computer Science and Engineering (81%)
2018 - 2022
Madhyanchal Professional University, Bhopal (Full-Time)

Writing & notes

No post available

Notes on the work

Short explanations of the questions I would ask in a review, with enough detail to show why they matter.

Browse all notes

Get in touch

    Fields marked * are required.