Technology Risk & Compliance

Subhrojeet Saha.Technology Risk & Compliance

I design and lead institutional-grade governance across global financial services and enterprise software.

JPMorgan Chase · Diligent · Moody's · Goldman Sachs · KPMG
Seven years in risk, audit and security governance
Bengaluru, Karnataka, India
Download curriculum vitae (PDF)

Professional Profile

I am a technology risk and compliance practitioner with more than seven years of experience gained at Goldman Sachs, JPMorgan Chase, Moody's, Diligent and KPMG. My work spans regulatory compliance, enterprise and technology risk management, third-party risk, information security governance, internal audit and control assurance — consistently delivered in highly regulated, globally distributed environments.

250+

Risk-based vendor assessments governed each year without a single service-level breach, complemented by more than fifty critical supplier reviews for a global SaaS enterprise.

~30%

Improvement in operating efficiency achieved by redesigning the third-party risk management framework and operating model in alignment with SOC 2 and BSI C5 requirements.

Priority 0

Programme accountability for frontier-AI vulnerability management at a global financial institution, together with the establishment of a second-line controls surveillance capability that measurably reduced audit findings.

Professional Experience

Mar 2026 — Present

Architect III

JPMorgan Chase & Co

  • Provide technical programme management for Project Glasswing (Anthropic and JPMorgan Chase), overseeing the identification, triage and resolution of vulnerabilities surfaced by Mythos and other frontier AI models across a major line of business.
  • Serve as the security governance, risk and compliance subject matter expert to business, engineering, cybersecurity and technology risk stakeholders.
  • Automated metric computation and business intelligence reporting to present live key performance indicators, including vulnerability burndown since inception, to C-suite leadership.
  • Streamlined application onboarding by aligning delivery workflows with technology and security control requirements across the software development lifecycle.
  • Monitor security reliability metrics and risk indicators, reporting control health and remediation progress to executive stakeholders.
May 2024 — Mar 2026

Staff GRC Analyst

Diligent Corporation

  • Led the security risk and third-party risk management functions for a global SaaS enterprise, directing a team of five risk professionals.
  • Established a second-line controls surveillance capability to identify control deficiencies proactively and strengthen assurance coverage.
  • Redesigned third-party risk policies, standards and controls in alignment with SOC 2 and BSI C5, improving operating efficiency by approximately thirty per cent.
  • Governed more than 250 risk-based vendor assessments annually and over fifty critical supplier reviews, maintaining audit and IPO readiness throughout.
  • Delivered executive risk reporting, compliance communications and enterprise security awareness programmes.
Jun 2022 — May 2024

Senior IT Auditor

Moody's Corporation

  • Executed risk-based technology and integrated audits encompassing risk assessment, control testing, reporting and remediation validation.
  • Conducted continuous risk monitoring to identify emerging operational, compliance and information security exposures.
  • Advised senior stakeholders on control deficiencies, remediation priorities and risk treatment strategies.
  • Maintained enterprise risk registers and coordinated remediation across multiple business functions.
Jul 2021 — Apr 2022

Senior Analyst

Goldman Sachs

  • Assessed technology controls and risk management practices supporting Global Markets Engineering and Operations.
  • Evaluated control effectiveness across business-critical applications, infrastructure and processes.
  • Performed application and source code reviews across Python, Java, SQL and C++ environments.
  • Validated remediation activity and monitored the closure of technology risk findings.
Jan 2019 — Jun 2021

Analyst

KPMG India

  • Delivered SOC 1, SOC 2, ISAE 3402 and ISAE 3000 assurance engagements across the technology, telecommunications and media sectors.
  • Performed risk assessments, compliance reviews and control testing of technology and information security controls.
  • Developed risk control matrices aligned to prevailing regulatory and industry frameworks.

Expertise & Credentials

The frameworks, tooling and disciplines underpinning seven years of risk and assurance work in regulated environments.

Education

B.Tech, Computer Science Engineering — SRM Institute of Science and Technology (2015–2019)

Frameworks

NIST CSFSOC 1SOC 2FedRAMPHIPAABSI C5COBITGDPRISO 27001ISO 42001DORA

Tooling

Power BIAlteryxSQLPythonJiraConfluenceAWSAzure

Competencies

  • Programme Management
  • Regulatory Compliance
  • Enterprise Risk Management
  • Technology Risk
  • Third-Party Risk Management
  • Information Security Governance
  • Internal & External Audit
  • Operational Risk
  • Control Assurance
  • Policy & Standards Governance
  • Risk Assessment
  • Executive Stakeholder Management
  • Security Awareness

Certifications

  • ISO 42001: AI Management Systems Lead Implementer
  • ISC2 Certified in Cybersecurity (CC)
  • Microsoft Azure Fundamentals
  • AWS Cloud Fundamentals
  • UiPath RPA Foundation
  • Alteryx Foundation
  • Linux LFS 101x

Get in touch.

I welcome enquiries regarding senior appointments and advisory engagements in technology risk, compliance, third-party risk and security governance. Correspondence submitted below reaches me directly and is treated in confidence.

View LinkedIn profile →