Technology Risk & Compliance
Subhrojeet Saha.Technology Risk & Compliance
I design and lead institutional-grade governance across global financial services and enterprise software.
Professional Profile
I am a technology risk and compliance practitioner with more than seven years of experience gained at Goldman Sachs, JPMorgan Chase, Moody's, Diligent and KPMG. My work spans regulatory compliance, enterprise and technology risk management, third-party risk, information security governance, internal audit and control assurance — consistently delivered in highly regulated, globally distributed environments.
Risk-based vendor assessments governed each year without a single service-level breach, complemented by more than fifty critical supplier reviews for a global SaaS enterprise.
Improvement in operating efficiency achieved by redesigning the third-party risk management framework and operating model in alignment with SOC 2 and BSI C5 requirements.
Programme accountability for frontier-AI vulnerability management at a global financial institution, together with the establishment of a second-line controls surveillance capability that measurably reduced audit findings.
Professional Experience
Architect III
JPMorgan Chase & Co
- Provide technical programme management for Project Glasswing (Anthropic and JPMorgan Chase), overseeing the identification, triage and resolution of vulnerabilities surfaced by Mythos and other frontier AI models across a major line of business.
- Serve as the security governance, risk and compliance subject matter expert to business, engineering, cybersecurity and technology risk stakeholders.
- Automated metric computation and business intelligence reporting to present live key performance indicators, including vulnerability burndown since inception, to C-suite leadership.
- Streamlined application onboarding by aligning delivery workflows with technology and security control requirements across the software development lifecycle.
- Monitor security reliability metrics and risk indicators, reporting control health and remediation progress to executive stakeholders.
Staff GRC Analyst
Diligent Corporation
- Led the security risk and third-party risk management functions for a global SaaS enterprise, directing a team of five risk professionals.
- Established a second-line controls surveillance capability to identify control deficiencies proactively and strengthen assurance coverage.
- Redesigned third-party risk policies, standards and controls in alignment with SOC 2 and BSI C5, improving operating efficiency by approximately thirty per cent.
- Governed more than 250 risk-based vendor assessments annually and over fifty critical supplier reviews, maintaining audit and IPO readiness throughout.
- Delivered executive risk reporting, compliance communications and enterprise security awareness programmes.
Senior IT Auditor
Moody's Corporation
- Executed risk-based technology and integrated audits encompassing risk assessment, control testing, reporting and remediation validation.
- Conducted continuous risk monitoring to identify emerging operational, compliance and information security exposures.
- Advised senior stakeholders on control deficiencies, remediation priorities and risk treatment strategies.
- Maintained enterprise risk registers and coordinated remediation across multiple business functions.
Senior Analyst
Goldman Sachs
- Assessed technology controls and risk management practices supporting Global Markets Engineering and Operations.
- Evaluated control effectiveness across business-critical applications, infrastructure and processes.
- Performed application and source code reviews across Python, Java, SQL and C++ environments.
- Validated remediation activity and monitored the closure of technology risk findings.
Analyst
KPMG India
- Delivered SOC 1, SOC 2, ISAE 3402 and ISAE 3000 assurance engagements across the technology, telecommunications and media sectors.
- Performed risk assessments, compliance reviews and control testing of technology and information security controls.
- Developed risk control matrices aligned to prevailing regulatory and industry frameworks.
Expertise & Credentials
The frameworks, tooling and disciplines underpinning seven years of risk and assurance work in regulated environments.
Education
B.Tech, Computer Science Engineering — SRM Institute of Science and Technology (2015–2019)
Frameworks
Tooling
Competencies
- Programme Management
- Regulatory Compliance
- Enterprise Risk Management
- Technology Risk
- Third-Party Risk Management
- Information Security Governance
- Internal & External Audit
- Operational Risk
- Control Assurance
- Policy & Standards Governance
- Risk Assessment
- Executive Stakeholder Management
- Security Awareness
Certifications
- ISO 42001: AI Management Systems Lead Implementer
- ISC2 Certified in Cybersecurity (CC)
- Microsoft Azure Fundamentals
- AWS Cloud Fundamentals
- UiPath RPA Foundation
- Alteryx Foundation
- Linux LFS 101x
Get in touch.
I welcome enquiries regarding senior appointments and advisory engagements in technology risk, compliance, third-party risk and security governance. Correspondence submitted below reaches me directly and is treated in confidence.
View LinkedIn profile →