SJM
SHASWAT MANOJ JHA / CISA

IT audit & technology risk.

Portrait of Shaswat Manoj Jha

I'm Shaswat, a Senior Consultant at EY and a CISA. My work covers IT controls, cybersecurity and AI governance. Here you'll find my experience, certifications and some of the projects I've worked on.

Portrait of Shaswat Manoj Jha

Experience at a glance

IT audit and technology risk are the centre of my work. I also build small tools that make repetitive checks easier.

Current role
Senior ConsultantIS Audit & Risk · EY · since August 2024
Core areas
IT controls · cybersecurityCloud security · data privacy · AI governance
Earlier experience
Protiviti · Nangia & Co LLPTechnology risk and cybersecurity
Qualification & location
CISA · Jamshedpur, IndiaFull experience and qualifications in my résumé
0 +
Years in
technology risk
0
Focus areas across
assurance & security
0 +
Files screened
for personal data

About me

I started with programming. These days, most of my work is in IT audit and technology risk.

I’m currently a Senior Consultant in IS Audit & Risk at EY. Before that, I worked at Protiviti and Nangia & Co LLP. Over the past four years, I’ve reviewed IT controls, cloud security and data privacy, including work with financial services and insurance organisations.

I’m a CISA and have completed lead auditor training for ISO/IEC 27001 and ISO/IEC 42001. My audit work involves understanding how a process works, testing its controls and explaining what the evidence shows. I also review policies, prepare risk and control matrices and follow up on findings.

Alongside audit work, I write scripts to make repetitive checks easier. I’ve built a Python scanner for personal data and a PowerShell script to compare Active Directory users with HR exit records. I’ve also identified and responsibly disclosed an access control vulnerability in a SaaS platform.

  • I review access management, change management, IT operations and backup and recovery controls. This includes testing both control design and operating effectiveness.
  • For integrated audits, I map IT controls to business processes and document walkthroughs, risk and control matrices, samples and testing evidence.
  • I assess cloud configurations against CIS Benchmarks, including access, encryption, network segmentation and recovery. I also review RPA bot accounts, credential storage and segregation of duties.
  • My recent work includes GitHub access and repository controls, as well as governance over integrated AI tools.
  • I review ISMS policies and carry out gap assessments against frameworks such as ISO/IEC 27001 and NIST SP 800-53.
  • I test interfaces, input checks, master data and report integrity to assess whether applications process data accurately and completely.
  • I review maker-checker workflows, audit trails, access restrictions and configuration settings for risks of unauthorised changes.
  • I recommend improvements to system configurations and the software development lifecycle where testing shows gaps or unnecessary manual work.
  • I map security controls to ISO/IEC 27001, NIST CSF and NIST SP 800-53, and review coverage against IRDAI and RBI requirements.
  • I have carried out SAMA Cybersecurity Framework gap assessments and tracked the resulting findings and corrective actions.
  • For privacy reviews, I check how personal data appears in applications, APIs, logs and reports, including assessments against the DPDP Act 2023.
  • I review business continuity and disaster recovery plans, recovery objectives, backup tests and drill records.
  • I turn policy requirements into testing checklists and evidence requests so that adherence can be assessed.
  • I assess vendor controls for logical and physical access, data protection, service agreements and incident reporting.
  • During on-site reviews, I check data handling, endpoint DLP and how access is granted and removed. I document gaps and follow up on corrective actions.
  • I use Microsoft Visio to map how sensitive data moves between users, processes and systems, then review where it could be exposed.
  • I assess endpoint security and DLP rules, including device controls and restrictions on copying, printing and data transfers.
  • I review asset inventories, patching and EDR coverage, and use dashboards to track gaps and exceptions.
  • I have used Burp Suite, OWASP ZAP and SQLMap for manual and automated testing of web applications.
  • My testing has covered SQL injection, XSS, IDOR, authentication and access control flaws, and security misconfigurations. I record proofs of concept and risk ratings.
  • I work with IT teams to retest fixes and check controls such as least privilege, input validation and rate limiting.
  • I prepare audit scopes, methodologies, effort estimates and acceptance criteria for proposals.
  • I document risk and control matrices, workpapers and supporting evidence so that another reviewer can follow the testing and conclusions.
  • I use Power BI and presentation reports to explain findings, their risk and the actions needed to address them.

Projects & practical work

These projects come from my experience in audit, security and automation. Public examples use fictional data.

View all work
Python · data privacy

PII file scanner

I wrote a Python script to look for personal data in more than 1,000 files, including logs, PDFs and spreadsheets. The case study explains the scope and includes a fictional example of the output.

Read the case study →
IT controls · AI governance

GitHub & AI governance reviews

My reviews covered identity and access, privileged access monitoring, repository configuration and governance over integrated AI tools. Here I explain the control questions behind that work.

Read the case study →

Take a look inside an access review

Five fictional records. A few possible exceptions. Follow the evidence and compare your reasoning with mine.

Open the walkthrough

Experience

Tools I use

Microsoft Office
AuditBoard
Microsoft Visio
Power BI
Python
Splunk
RSA Archer
SQL
Metasploit
Kali Linux
Burp Suite
OWASP ZAP
Still learning

Education

MBA – Information Technology and Financial Management
2022 - 2024
Swami Vivekananda Subharti University, Meerut (Distance)
B. Tech – Computer Science and Engineering (81%)
2018 - 2022
Madhyanchal Professional University, Bhopal (Full-Time)

Writing & notes

No post available

Notes on the work

A couple of short explanations of the questions behind an audit review.

Get in touch

    Fields marked * are required.