Summary
Overview
Work History
Education
Skills
Certification
Timeline
Accomplishments
LinkedIn
SoftwareDeveloper

Vaibhav Singh Bhadauria

Chief Information & Security Officer/Chief Compliance Officer
Toronto,ON

Summary

A dynamic leader in data management and governance, adept at crafting and executing visionary strategies to unlock the full potential of enterprise data assets. Drives medium to long-term data initiatives, aligning with regulatory demands and business priorities. Collaborates seamlessly with stakeholders across all levels to ensure steadfast commitment to data governance policies and practices. Champions transformative data initiatives to enhance global capabilities and drive strategic revenue growth. Directs the implementation of robust data governance frameworks, fostering a customer-centric culture while ensuring strict adherence to risk management protocols.

Overview

12
12
years of professional experience
8
8
Certificate

Work History

Chief Information & Security Officer/Chief Compliance Officer

Total Credit Recovery Limited
Toronto
06.2022 - Current

Lead enterprise technology and security strategy, aligning IT and cyber roadmaps with business objectives, growth plans, and operational efficiency targets, and positioning technology as a key enabler of digital customer experience.
Oversee IT operations, infrastructure, and core systems, directing teams across networks, cloud platforms, applications, and support to ensure high availability, reliability, and performance for mission-critical services.
Drive cloud migration, digital transformation, and technology modernization by leading workload migration to Microsoft Azure, complex Active Directory integrations, and security hardening with Microsoft 365, Intune, ESET Disk Encryption, and ESET MDR, improving scalability, performance, and user experience.
Direct enterprise risk management and incident response, maintaining a live risk register, executing risk analysis and treatment plans, and managing monitoring and response with Wazuh SIEM, FortiGate firewalls, VPNs, and Nessus PCI scanning for continuous monitoring and faster time-to-detect/restore.
Manage vendor risk and outsourced/fintech technology relationships, responding to client due-diligence requests, overseeing third-party assessments using Drata and Comply, and coordinating penetration tests and table-top exercises to validate resilience, controls, and service provider performance.
Develop and manage technology and security budgets, prioritizing investments, optimizing run-the-bank vs change-the-bank spend, and renegotiating key vendor contracts to improve cost-effectiveness without compromising resilience or security.
Maintain IT and security governance aligned to OSFI-style expectations (B-10, B-13, E-21), PIPEDA, FINTRAC, SOX, NIST, ISO 27001/27002, PCI DSS and Cyber Essentials, supporting audits and regulatory-style examinations and strengthening controls, documentation, and decision-making processes.
Partner with CEO and business leaders as a trusted technology advisor, translating complex technology and security topics into business value and risk trade-offs, and championing a “Security First” and technology excellence culture through targeted training, awareness, and continuous improvement initiatives.

Delivery Manager

Infinity Data Technologies Pvt. Ltd.
Bengaluru, Karnataka
06.2021 - 10.2021
  • Spearheaded the formulation and execution of comprehensive enterprise-wide data management and governance strategies, focusing on optimizing data value through advanced analytics and digitalization.
  • Directed strategic investments in data capabilities to address regulatory requirements and align with enterprise priorities, ensuring coordinated allocation of resources for effective data management.
  • Cultivated strong collaborative relationships with stakeholders at operational and executive levels, fostering alignment and commitment to data governance principles, practices, and priorities.
  • Collaborated with cross-functional Enterprise partners to enhance overall data governance and management capabilities, influencing decisions related to policy, technology, and talent development.
  • Advocated for and supported transformative data initiatives aimed at fortifying global data and advanced analytics capabilities, positioning data as a key driver of organizational growth.
  • Orchestrated the establishment of organizational structures and operational frameworks to support data program objectives, including the implementation of robust data governance forums and processes.

Assistant Manager - Projects

Firstsource Solutions Pvt. Ltd
Bengaluru, Karnataka
11.2019 - 06.2021
  • Developed and enforced data governance policies and procedures to ensure compliance with regulatory requirements and industry standards, fostering a culture of data integrity and accountability.
  • Established and maintained data quality standards and controls, conducting regular audits and assessments to monitor data accuracy, completeness, and consistency.
  • Collaborated with stakeholders across departments to identify data governance needs and requirements, aligning strategies with business objectives and priorities.
  • Implemented data stewardship programs to assign ownership and responsibility for data assets, driving accountability and improving data quality throughout the organization.
  • Led the development and implementation of data governance frameworks and tools, leveraging technology solutions to streamline processes and enhance data management capabilities.
  • Provided guidance and training to staff on data governance principles, best practices, and tools, promoting a shared understanding of data management responsibilities and goals.

Team Lead

Altisource Business Solutions Pvt. Ltd
Bengaluru, Karnataka
08.2016 - 09.2019
  • Supported the development and implementation of data protection strategies and initiatives, ensuring compliance with data privacy regulations such as GDPR, CCPA, HIPAA, and relevant North American regulatory frameworks such as PIPEDA, GLBA, NYDFS Cybersecurity Regulation, and the California Consumer Privacy Act (CCPA). Additionally, ensured adherence to industry-specific standards like NIST Cybersecurity Framework, ISO/IEC 27001, and the Payment Card Industry Data Security Standard (PCI DSS).
  • Collaborated with IT security teams to implement and maintain robust data security measures, including encryption, access controls, and threat detection systems, mitigating data breach risks.
  • Conducted regular risk assessments and audits to identify vulnerabilities and gaps in data protection and security practices, implementing corrective actions to address findings.
  • Established data governance frameworks to define data ownership, classification, and lifecycle management processes, ensuring data is handled appropriately throughout its lifecycle.
  • Implemented data governance controls and monitoring mechanisms to track data usage, access, and movement, enhancing visibility and accountability over sensitive information.
  • Provided oversight and governance for data-related projects and initiatives, ensuring alignment with organizational goals, risk tolerance, and compliance requirements.

Associate Analyst

XL Dynamics
Mumbai, India, India
05.2014 - 02.2016
  • Contributed to the development and maintenance of data privacy policies and procedures, ensuring alignment with regulatory requirements.
  • Supported data risk assessments and audits to identify vulnerabilities and gaps in security practices.
  • Assisted in the implementation of data security controls, such as encryption and access controls, to protect sensitive information.
  • Provided support in responding to data privacy inquiries and incidents, including data breaches and subject access requests

Education

Ontario Post Graduate Certificate in Project Management - Project Management

Humber Institute of Technology And Advanced Learning
Toronto, ON
04.2022

MBA - Finance

Pune University
Pune, India
05.2014

Post Graduate Diploma in Business Administration - Business Administration

Institute of Management & Technology
Ghaziabad, India
06.2012

Bachelor of Technology -

AK Technical University
Lucknow, India
08.2010

Skills

  • Data Governance & protection
  • Data Security
  • Infrastructure Management
  • Information Security
  • IT service management
  • Service Delivery Oversight
  • Budget Administration
  • Disaster Recovery
  • Information risk management
  • Audit Coordination
  • Internal Controls
  • Business continuity planning
  • Risk mitigation strategies
  • Incident Management
  • Regulatory Compliance
  • Strategic Planning
  • Contract Negotiation
  • Change Management

Certification

1. ISO 27001:2022 Lead Auditor (BSI/Exemplar Global)

2. Certified Fraud Examiner (ACFE)

3. Certified Information Security Manager (CISM - ISACA Global Pursuing)

3. Certified SAFe® 5 Scrum Master (SSM)

4. PRINCE2 Project Management Practitioner

5. Certified Scrum Master(CSM)

6. Agile Scrum Foundation

7. Six Sigma - Yellow Belt Certified

8. ON Graduate Certificate in Project Management

Timeline

Chief Information & Security Officer/Chief Compliance Officer

Total Credit Recovery Limited
06.2022 - Current

Delivery Manager

Infinity Data Technologies Pvt. Ltd.
06.2021 - 10.2021

Assistant Manager - Projects

Firstsource Solutions Pvt. Ltd
11.2019 - 06.2021

Team Lead

Altisource Business Solutions Pvt. Ltd
08.2016 - 09.2019

Associate Analyst

XL Dynamics
05.2014 - 02.2016

Ontario Post Graduate Certificate in Project Management - Project Management

Humber Institute of Technology And Advanced Learning

MBA - Finance

Pune University

Post Graduate Diploma in Business Administration - Business Administration

Institute of Management & Technology

Bachelor of Technology -

AK Technical University

Accomplishments

  • Led the successful implementation of ISO 27001:2013 framework certification and oversaw the transition to the latest ISO 27001:2022 standards.
  • Upgraded organizational compliance to GDPR, PCI DSS 4.0, SOC 2, and SOC 1 standards, ensuring adherence to rigorous security and compliance protocols.
  • Currently spearheading the transition of ISO 27001:2013 certification to meet the updated 2022 standards, demonstrating a commitment to maintaining cutting-edge security practices and regulatory compliance.

LinkedIn

www.linkedin.com/in/vaibhav-singh-bhadauria

Vaibhav Singh BhadauriaChief Information & Security Officer/Chief Compliance Officer