Summary
Overview
Work History
Education
Skills
CERTIFICATIONS
Timeline
Generic

Tanima Dey

Harrow, Greater London,United Kingdom

Summary

11 Years of working experience in various roles and functions in the Information Technology industry of which more than 8 years in information security & compliance with job functions including IT Infrastructure, IT Audit, IT security framework implementation, threat management, vulnerability management, risk assessment, compliance and 3 years of experience as an IT Support Engineer. Information Security Specialist with passion for aligning security architecture plans and processes with security standards and business goals. Extensive experience developing and testing security framework for cloud-based software. Versed in robust network defense strategies.

Overview

12
12
years of professional experience
1
1
year of post-secondary education

Work History

LEAD-Information Security and Compliance

Omega Healthcare Management Services Private LTD
Bangalore, Karnataka, India
02.2017 - 10.2022
  • Develop and manage the organization’s ISMS in alignment with ISO 27001, driving the implementation of security policies, controls, and processes to mitigate risk and ensure compliance.
  • Lead internal and external ISO 27001 audits, working with various departments to identify gaps, enforce compliance, and support corrective actions.
  • Monitored compliance with regulatory requirements (e.g., GDPR, HIPPA, SOC 2) and collaborated with legal and compliance teams to address regulatory changes.
  • Prepare reports and presentations on ISMS performance, compliance metrics, and security incidents, facilitating informed decision-making for executive management and other stakeholders.
  • Conduct regular risk assessments and vulnerability analyses, prioritizing and mitigating risks to protect sensitive data assets and minimize exposure.
  • Develop and implement security training and awareness programs, improving organization-wide security compliance and reducing incidents
  • Oversee incident management and response, investigating incidents, coordinating remediation efforts, and documenting lessons learned for future prevention.
  • Perform Monthly Privilege Access Review meeting for all platform team to ensure Privilege access are aligned as per the Job Role and match with HR MIS report
  • Coordinated with IT and compliance teams to establish automated monitoring of vendor performance and compliance with established SLAs.
  • Conduct regular Vulnerability assessments for IT Infrastructure & application and collaborate with IT teams to remediate identified vulnerabilities along with track progress on mitigation efforts.

IT Executive

Reliance Communication LTD
Bangalore, Karnataka, India
04.2013 - 01.2017
  • Assisted in implementation of ISO 27001 and ISO 9001 standards across the organization, resulting in improved compliance and operational efficiencies.
  • Conduct internal audits to assess adherence to established quality and security protocols, presenting findings to senior management and recommending corrective actions.
  • Support the enforcement of Corporate Security policies, procedures, and standards.
  • Collaborate with cross-functional teams to develop training programs on quality management and information security best practices.
  • Assisted in preparing documentation for ISO 27001 certification and managed communication with certification bodies.
  • Participated in internal and external audits, addressing audit findings and ensuring corrective actions were completed.
  • Contributed to maintenance and improvement of ISMS through regular reviews and updates.
  • Identify and recommend risk mitigation strategies to address identified risks.
  • Collaborate with stakeholders to develop risk treatment plans, control frameworks, and risk mitigation action plans.
  • Monitor the implementation of risk mitigation measures and ensure compliance with established standards.

IT Engineer

A2Z Maintenance & Engineering
Delhi, India
09.2010 - 03.2013

Education

Master of Science - Master of Computer Application

DR B.C.ROY Engineering College
Durgapur, India
08.2024 - 04.2025

Skills

Proficient in ISO 27001, ISO 9001, GDPR, PCI & HIPPA

Risk Assessment and Mitigation

Audit planning and execution

Compliance Monitoring

Incident response and mitigation

Network and application security

Security Tool Management (SIEM, DLP, EDR)

Vulnerability assessment (Nessus, Qualys)

Training and Awareness

CERTIFICATIONS

Certifications (Certified Ethical Hacking) : CEH(V10)

Certifications (Lead Auditor) : ISO 27001:2013 LA

Trainings        : ITIL V3

Timeline

Master of Science - Master of Computer Application

DR B.C.ROY Engineering College
08.2024 - 04.2025

LEAD-Information Security and Compliance

Omega Healthcare Management Services Private LTD
02.2017 - 10.2022

IT Executive

Reliance Communication LTD
04.2013 - 01.2017

IT Engineer

A2Z Maintenance & Engineering
09.2010 - 03.2013
Tanima Dey