I am a Certified ISO/IEC 27001:2022 ISMS Lead Auditor and ISO/IEC 42001:2023 AIMS Lead Auditor, with 8+ years in IT security, quality management, and governance. My work spans independent consulting, training, and volunteer leadership, helping organizations build robust security and AI governance programs.\n\nMy core strengths include IT audits, risk management, and compliance with frameworks such as SOX, PCI DSS, and SOC 2, along with AI governance concepts like NIST AI RMF, ISO 23894, and EU AI Act awareness. I excel at audit delivery, stakeholder engagement, incident response, policy development, and establishing effective governance frameworks.

Benita Sophia Michael

I am a Certified ISO/IEC 27001:2022 ISMS Lead Auditor and ISO/IEC 42001:2023 AIMS Lead Auditor, with 8+ years in IT security, quality management, and governance. My work spans independent consulting, training, and volunteer leadership, helping organizations build robust security and AI governance programs.\n\nMy core strengths include IT audits, risk management, and compliance with frameworks such as SOX, PCI DSS, and SOC 2, along with AI governance concepts like NIST AI RMF, ISO 23894, and EU AI Act awareness. I excel at audit delivery, stakeholder engagement, incident response, policy development, and establishing effective governance frameworks.

Available to hire

I am a Certified ISO/IEC 27001:2022 ISMS Lead Auditor and ISO/IEC 42001:2023 AIMS Lead Auditor, with 8+ years in IT security, quality management, and governance. My work spans independent consulting, training, and volunteer leadership, helping organizations build robust security and AI governance programs.\n\nMy core strengths include IT audits, risk management, and compliance with frameworks such as SOX, PCI DSS, and SOC 2, along with AI governance concepts like NIST AI RMF, ISO 23894, and EU AI Act awareness. I excel at audit delivery, stakeholder engagement, incident response, policy development, and establishing effective governance frameworks.

See more

Language

English
Fluent
Tamil
Advanced

Work Experience

Corporate Trainer at Thinkcloudly
April 1, 2025 - Present
Delivering high-quality training sessions on GRC / IT Audit and IT controls, including risk assessment, threat modelling, vulnerability assessment, cybersecurity controls and assessments, SOX, IT auditing controls, ISO 27001, regulatory compliance overview. Create and update training materials. Perform assessments and offer guidance and mentorship to students.
Educator at PlanetSpark & Unbox-ED
December 1, 2021 - Present
Delivering structured training in communication, debate, TED-style talks, and creative writing to 300+ students (Grades 3–10). Design curricula, conduct performance assessments, and support educator recruitment. Used AI tools for content development (ChatGPT, Copilot).
Translator at Watchtower, India
October 1, 2021 - September 24, 2025
Translated publications from English to Tamil for Watchtower's Legal Department. Served as voice over artist for audio/video projects. Trained voice actors and interpreters. Provided technical support.
Software Quality Engineer at Royal Bank of Scotland, India
July 1, 2012 - September 24, 2025
Conducted SOX compliance reviews for application development projects. Facilitated adherence to QMS standards. Compiled monthly project status reports and prepared executive dashboards. Supported PCI DSS compliance activities. Delivered SOX governance training.
Senior Software Quality Engineer at Aspire Systems, India
July 1, 2010 - September 24, 2025
Led creation and rollout of ISO 9001:2008-compliant quality processes. Conducted internal audits, coordinated external certification audits. Authored ISMS policies and procedures, and developed a roadmap for ISO 27001 implementation. Delivered QMS training programs to strengthen compliance culture.
Quality Assurance Executive at Yalamanchili Consultancy Services, India
February 1, 2007 - September 24, 2025
Designed and implemented ISO 27001-compliant processes. Conducted internal functional audits and process adherence assessments. Collaborated with consultants and external auditors during certification. Developed ISMS documentation, policies, and templates. Performed ISO 27001 gap analysis and risk assessments. Delivered information security awareness training. Supported ISO 27001 external certification audits.
Corporate Trainer at Thinkcloudly
April 1, 2025 - Present
Delivering high-quality training sessions on GRC / IT Audit and IT controls, including risk assessment, threat modelling, vulnerability assessment, cybersecurity controls and assessments, SOX, IT auditing controls, ISO 27001, and regulatory compliance overview. Create and update training materials; perform assessments and provide guidance and mentorship to students.
Educator at PlanetSpark & Unbox-ED
December 1, 2021 - Present
Delivering structured training in communication, debate, TED-style talks, and creative writing to 300+ students (Grades 3–10). Design curriculum, conduct performance assessments, support educator recruitment, and enhance documentation and governance skills. Utilize prompt engineering to develop content for public speaking and creative writing curricula using AI tools like ChatGPT and Copilot.
Translator at Watchtower, India
October 1, 2021 - September 24, 2025
Supported the Legal Department by translating publications from English to Tamil, served as voice over artist for audio/video projects, trained voice actors, and provided technical support for Windows and Mac applications.
Software Quality Engineer at Royal Bank of Scotland, India
July 1, 2012 - September 24, 2025
Conducted SOX compliance reviews for application development projects; ensured adherence to QMS standards; prepared monthly project status reports and executive dashboards; delivered PMO training; supported PCI DSS compliance activities; provided governance training.
Senior Software Quality Engineer at Aspire Systems, India
July 1, 2010 - September 24, 2025
Led the creation and rollout of ISO 9001:2008-compliant quality processes; conducted internal audits and coordinated external certification audits; authored ISMS policies and procedures; developed ISO 27001 implementation roadmap; delivered QMS training.
Quality Assurance Executive at Yalamanchili Consultancy Services, India
February 1, 2007 - September 24, 2025
Designed and implemented ISO 27001-compliant processes; conducted internal audits; collaborated with consultants and external auditors during certification; developed ISMS documentation, policies, and templates; performed ISO 27001 gap analyses and risk assessments; delivered information security awareness training.
Corporate Trainer at Thinkcloudly
April 1, 2025 - Present
Delivering high-quality training sessions on GRC / IT Audit and IT controls, including risk assessment, threat modelling, vulnerability assessment, cybersecurity controls and assessments, SOX, IT auditing controls, ISO 27001, regulatory compliance overview.
Educator at PlanetSpark & Unbox-ED
December 1, 2021 - Present
Delivering structured training in communication, debate, TED-style talks, and creative writing to 300+ students (Grades 3–10). Designing curricula, conducting performance assessments, and supporting educator recruitment. Prompt engineering to develop content for public speaking and creative writing curriculum using ChatGPT and Copilot and other AI tools.
Translator at Watchtower, India
October 1, 2021 - September 24, 2025
Translated publications from English to Tamil; served as voice over artist; trained voice actors and interpreters; provided technical support for Windows and Mac.
Software Quality Engineer at Royal Bank of Scotland, India
July 1, 2012 - September 24, 2025
Conducted SOX compliance reviews for application development projects; ensured adherence to QMS; compiled dashboards; supported PCI DSS compliance; delivered SOX governance training.
Senior Software Quality Engineer at Aspire Systems, India
July 1, 2010 - September 24, 2025
Led creation and rollout of ISO 9001:2008-compliant quality processes; conducted internal audits; authored ISMS policies; delivered QMS training; supported ISO 27001 roadmap.
Quality Assurance Executive at Yalamanchili Consultancy Services, India
February 1, 2007 - September 24, 2025
Designed and implemented ISO 27001-compliant processes; conducted internal audits; supported certification audits; developed ISMS documentation and risk assessments; delivered information security awareness training.

Education

Bachelor of Engineering in Computer Science Engineering at Tamil Nadu, India
January 1, 2000 - December 31, 2004
Bachelor of Engineering – Computer Science Engineering at Tamil Nadu, India
January 1, 2000 - January 1, 2004

Qualifications

ISO/IEC 27001:2022 Lead Auditor
January 11, 2030 - September 24, 2025
ISO/IEC 42001:2023 Lead Auditor (AIMS)
January 11, 2030 - September 24, 2025
PCI DSS Implementer Certification
January 11, 2030 - September 24, 2025
Internal Auditor – ISO 9001 & ISO 27001
January 11, 2030 - September 24, 2025
Prompt Engineering for ChatGPT
January 11, 2030 - September 24, 2025
GDPR Training (Udemy)
January 11, 2030 - September 24, 2025
ISO/IEC 27001:2022 Lead Auditor – Information Security Management System (ISMS)
January 11, 2030 - September 24, 2025
ISO/IEC 42001:2023 Lead Auditor – Artificial Intelligence Management System (AIMS)
January 11, 2030 - September 24, 2025
PCI DSS Implementer Certification
January 11, 2030 - September 24, 2025
Internal Auditor – ISO 9001 & ISO 27001
January 11, 2030 - September 24, 2025
Prompt Engineering Certifications
January 11, 2030 - September 24, 2025
GDPR Training (Udemy)
January 11, 2030 - September 24, 2025
Bachelor of Engineering – Computer Science Engineering
January 1, 2000 - January 1, 2004
ISO/IEC 27001:2022 Information Security Management Systems (ISMS) Lead Auditor
January 11, 2030 - September 24, 2025
ISO/IEC 42001:2023 Artificial Intelligence Management Systems (AIMS) Lead Auditor
January 11, 2030 - September 24, 2025
PCI DSS Implementer Certification
January 11, 2030 - September 24, 2025
Internal Auditor – ISO 9001 & ISO 27001
January 11, 2030 - September 24, 2025
Prompt Engineering for ChatGPT
January 11, 2030 - September 24, 2025
GDPR Training (Udemy)
January 11, 2030 - September 24, 2025

Industry Experience

Software & Internet, Professional Services, Education, Financial Services, Government