I wrote a Python scanner to look for possible personal data in more than 1,000 logs, PDFs and spreadsheets. It helped reduce the manual screening work. The case study explains where the script helped and where a reviewer still needed to make the call.
Read the case study →IT audit & technology risk.

I'm Shaswat, a Senior Consultant at EY and a CISA. I work on IT controls, cybersecurity and AI governance, and write scripts to make repetitive review work easier. This is where I keep my experience, qualifications and a few examples of how I approach the work.

Experience at a glance
I work in IT audit and technology risk. That means understanding a process, checking its controls and following the evidence. I also write scripts when a repetitive check can be made easier.
- Current role
- Senior ConsultantIS Audit & Risk · EY · since August 2024
- Core areas
- IT controls · cybersecurityCloud security · data privacy · AI governance
- Earlier experience
- Protiviti · Nangia & Co LLPTechnology risk and cybersecurity
- Qualification & location
- CISA · Jamshedpur, IndiaFull experience and qualifications in my résumé















technology risk
assurance & security
for personal data
About me
I started with programming. Most of my work today is in IT audit and technology risk, but I still like finding the parts of a review that a small script can make easier.
I’m a Senior Consultant in IS Audit & Risk at EY. Before that, I worked at Protiviti and Nangia & Co LLP. My experience covers IT controls, cloud security and data privacy, including work with financial services and insurance organisations.
I’m a CISA and have completed lead auditor training for ISO/IEC 27001 and ISO/IEC 42001. My work includes process walkthroughs, control-design and operating-effectiveness testing, risk and control matrices, audit reporting and follow-up on findings.
I have built a Python scanner for potential personal data and a PowerShell script to reconcile Active Directory users with HR termination records. I’ve also identified and responsibly disclosed an access-control vulnerability in a SaaS platform.
What I want this portfolio to show is the work behind those résumé lines. The project pages explain my contribution, while the fictional examples show the questions I’d ask and the evidence I’d need before reaching a conclusion.
- I review access management, change management, IT operations and backup and recovery controls. This includes testing both control design and operating effectiveness.
- For integrated audits, I map IT controls to business processes and document walkthroughs, risk and control matrices, samples and testing evidence.
- I assess cloud configurations against CIS Benchmarks, including access, encryption, network segmentation and recovery. I also review RPA bot accounts, credential storage and segregation of duties.
- My recent work includes GitHub access and repository controls, as well as governance over integrated AI tools.
- I review ISMS policies and carry out gap assessments against frameworks such as ISO/IEC 27001 and NIST SP 800-53.
- I test interfaces, input checks, master data and report integrity to assess whether applications process data accurately and completely.
- I review maker-checker workflows, audit trails, access restrictions and configuration settings for risks of unauthorised changes.
- I recommend improvements to system configurations and the software development lifecycle where testing shows gaps or unnecessary manual work.
- I map security controls to ISO/IEC 27001, NIST CSF and NIST SP 800-53, and review coverage against IRDAI and RBI requirements.
- I have carried out SAMA Cybersecurity Framework gap assessments and tracked the resulting findings and corrective actions.
- For privacy reviews, I check how personal data appears in applications, APIs, logs and reports, including assessments against the DPDP Act 2023.
- I review business continuity and disaster recovery plans, recovery objectives, backup tests and drill records.
- I turn policy requirements into testing checklists and evidence requests so that adherence can be assessed.
- I assess vendor controls for logical and physical access, data protection, service agreements and incident reporting.
- During on-site reviews, I check data handling, endpoint DLP and how access is granted and removed. I document gaps and follow up on corrective actions.
- I use Microsoft Visio to map how sensitive data moves between users, processes and systems, then review where it could be exposed.
- I assess endpoint security and DLP rules, including device controls and restrictions on copying, printing and data transfers.
- I review asset inventories, patching and EDR coverage, and use dashboards to track gaps and exceptions.
- I have used Burp Suite, OWASP ZAP and SQLMap for manual and automated testing of web applications.
- My testing has covered SQL injection, XSS, IDOR, authentication and access control flaws, and security misconfigurations. I record proofs of concept and risk ratings.
- I work with IT teams to retest fixes and check controls such as least privilege, input validation and rate limiting.
- I prepare audit scopes, methodologies, effort estimates and acceptance criteria for proposals.
- I document risk and control matrices, workpapers and supporting evidence so that another reviewer can follow the testing and conclusions.
- I use Power BI and presentation reports to explain findings, their risk and the actions needed to address them.
Projects & practical work
A few examples of how I use code and control reviews in my work. Each case explains my contribution and the questions I would want the evidence to answer.
User access review automation
I built a PowerShell script to compare Active Directory users with HR termination records. It made the reconciliation easier to review, so the follow-up could focus on the accounts and dates that needed an explanation.
Read the case study →GitHub & AI governance reviews
I reviewed access, privileged activity and repository configuration in GitHub environments, along with governance over integrated AI tools. The case study follows the questions about permissions, changes and evidence behind that work.
Read the case study →Try a small access review
Five made-up records, including an account removed late and a current employee who falls outside the review. Pick the records you'd follow up and compare your reasoning with mine.
Certifications & training
- Information Security
- Artificial Intelligence
- Data Science
- Programming
- Specializations
Experience

EY
I review IT controls, cloud security and AI governance, and document findings for audit and risk assessments.
Senior Consultant · IS Audit & Risk
August 2024 - Present
Protiviti
My work covered IT audits, control testing and technology risk assessments, including reporting and follow-up on findings.
Consultant 3 · IT Audit & Tech Risk
June 2023 - July 2024
Nangia & Co LLP
I worked on cybersecurity reviews, data privacy and DLP assessments, and security policy documentation.
Senior Analyst · Cybersecurity
June 2022 - June 2023
TCS
I completed a remote internship in dynamic application security testing and documented web application vulnerabilities.
Intern · Advanced DAST
June 2020 - August 2020Tools I use













Education
MBA – Information Technology and Financial Management
2022 - 2024
Swami Vivekananda Subharti University, Meerut (Distance)B. Tech – Computer Science and Engineering (81%)
2018 - 2022
Madhyanchal Professional University, Bhopal (Full-Time)Writing & notes
Notes on the work
Short explanations of the questions I would ask in a review, with enough detail to show why they matter.
An access exception is a starting point
A directory mismatch is worth a closer look. I explain how I'd check the identity, dates, scope and supporting evidence before reporting a finding.
Read the note →An AI tool review starts with its data
Before discussing the model, I'd want to know what the tool can read, where the information goes and which actions it can take.
Read the note →Get in touch
LinkedIn
/in/Shaswat Manoj JhaYouTube
/c/ShaswatManojJhaTelegram
@shaswatmanojjhaAddress
Jamshedpur, India