I wrote a Python script to look for personal data in more than 1,000 files, including logs, PDFs and spreadsheets. The case study explains the scope and includes a fictional example of the output.
Read the case study →IT audit & technology risk.

I'm Shaswat, a Senior Consultant at EY and a CISA. My work covers IT controls, cybersecurity and AI governance. Here you'll find my experience, certifications and some of the projects I've worked on.

Experience at a glance
IT audit and technology risk are the centre of my work. I also build small tools that make repetitive checks easier.
- Current role
- Senior ConsultantIS Audit & Risk · EY · since August 2024
- Core areas
- IT controls · cybersecurityCloud security · data privacy · AI governance
- Earlier experience
- Protiviti · Nangia & Co LLPTechnology risk and cybersecurity
- Qualification & location
- CISA · Jamshedpur, IndiaFull experience and qualifications in my résumé















technology risk
assurance & security
for personal data
About me
I started with programming. These days, most of my work is in IT audit and technology risk.
I’m currently a Senior Consultant in IS Audit & Risk at EY. Before that, I worked at Protiviti and Nangia & Co LLP. Over the past four years, I’ve reviewed IT controls, cloud security and data privacy, including work with financial services and insurance organisations.
I’m a CISA and have completed lead auditor training for ISO/IEC 27001 and ISO/IEC 42001. My audit work involves understanding how a process works, testing its controls and explaining what the evidence shows. I also review policies, prepare risk and control matrices and follow up on findings.
Alongside audit work, I write scripts to make repetitive checks easier. I’ve built a Python scanner for personal data and a PowerShell script to compare Active Directory users with HR exit records. I’ve also identified and responsibly disclosed an access control vulnerability in a SaaS platform.
- I review access management, change management, IT operations and backup and recovery controls. This includes testing both control design and operating effectiveness.
- For integrated audits, I map IT controls to business processes and document walkthroughs, risk and control matrices, samples and testing evidence.
- I assess cloud configurations against CIS Benchmarks, including access, encryption, network segmentation and recovery. I also review RPA bot accounts, credential storage and segregation of duties.
- My recent work includes GitHub access and repository controls, as well as governance over integrated AI tools.
- I review ISMS policies and carry out gap assessments against frameworks such as ISO/IEC 27001 and NIST SP 800-53.
- I test interfaces, input checks, master data and report integrity to assess whether applications process data accurately and completely.
- I review maker-checker workflows, audit trails, access restrictions and configuration settings for risks of unauthorised changes.
- I recommend improvements to system configurations and the software development lifecycle where testing shows gaps or unnecessary manual work.
- I map security controls to ISO/IEC 27001, NIST CSF and NIST SP 800-53, and review coverage against IRDAI and RBI requirements.
- I have carried out SAMA Cybersecurity Framework gap assessments and tracked the resulting findings and corrective actions.
- For privacy reviews, I check how personal data appears in applications, APIs, logs and reports, including assessments against the DPDP Act 2023.
- I review business continuity and disaster recovery plans, recovery objectives, backup tests and drill records.
- I turn policy requirements into testing checklists and evidence requests so that adherence can be assessed.
- I assess vendor controls for logical and physical access, data protection, service agreements and incident reporting.
- During on-site reviews, I check data handling, endpoint DLP and how access is granted and removed. I document gaps and follow up on corrective actions.
- I use Microsoft Visio to map how sensitive data moves between users, processes and systems, then review where it could be exposed.
- I assess endpoint security and DLP rules, including device controls and restrictions on copying, printing and data transfers.
- I review asset inventories, patching and EDR coverage, and use dashboards to track gaps and exceptions.
- I have used Burp Suite, OWASP ZAP and SQLMap for manual and automated testing of web applications.
- My testing has covered SQL injection, XSS, IDOR, authentication and access control flaws, and security misconfigurations. I record proofs of concept and risk ratings.
- I work with IT teams to retest fixes and check controls such as least privilege, input validation and rate limiting.
- I prepare audit scopes, methodologies, effort estimates and acceptance criteria for proposals.
- I document risk and control matrices, workpapers and supporting evidence so that another reviewer can follow the testing and conclusions.
- I use Power BI and presentation reports to explain findings, their risk and the actions needed to address them.
Projects & practical work
These projects come from my experience in audit, security and automation. Public examples use fictional data.
User access review automation
I built a script to reconcile Active Directory users with HR termination records. It reduced the manual comparison work involved in reviewing whether access had been removed.
Read the case study →GitHub & AI governance reviews
My reviews covered identity and access, privileged access monitoring, repository configuration and governance over integrated AI tools. Here I explain the control questions behind that work.
Read the case study →Take a look inside an access review
Five fictional records. A few possible exceptions. Follow the evidence and compare your reasoning with mine.
Certifications & training
- Information Security
- Artificial Intelligence
- Data Science
- Programming
- Specializations
Experience

EY
I review IT controls, cloud security and AI governance, and document findings for audit and risk assessments.
Senior Consultant · IS Audit & Risk
August 2024 - Present
Protiviti
My work covered IT audits, control testing and technology risk assessments, including reporting and follow-up on findings.
Consultant 3 · IT Audit & Tech Risk
June 2023 - July 2024
Nangia & Co LLP
I worked on cybersecurity reviews, data privacy and DLP assessments, and security policy documentation.
Senior Analyst · Cybersecurity
June 2022 - June 2023
TCS
I completed a remote internship in dynamic application security testing and documented web application vulnerabilities.
Intern · Advanced DAST
June 2020 - August 2020Tools I use













Education
MBA – Information Technology and Financial Management
2022 - 2024
Swami Vivekananda Subharti University, Meerut (Distance)B. Tech – Computer Science and Engineering (81%)
2018 - 2022
Madhyanchal Professional University, Bhopal (Full-Time)Writing & notes
Notes on the work
A couple of short explanations of the questions behind an audit review.
An access exception is a starting point
Why an enabled account needs investigation, and why a disabled account can still need follow-up.
Read the note →An AI tool review starts with its data
A practical way to understand what a tool can see, where data goes and what it can do.
Read the note →Get in touch
LinkedIn
/in/Shaswat Manoj JhaYouTube
/c/ShaswatManojJhaTelegram
@shaswatmanojjhaAddress
Jamshedpur, India