I'm Joy Singh, a Cybersecurity and Technology Risk Specialist with 6+ years of experience leading IT GRC, SOX, ISO 27001, and NIST-driven cloud security programs across global enterprises. I'm recognized for driving governance transformation, securing $1M+ cyber deals, and building scalable security frameworks across regulated industries. I collaborate with cross-functional teams to embed security by design into product lifecycles and deliver risk-informed outcomes.

Joy Singh

I'm Joy Singh, a Cybersecurity and Technology Risk Specialist with 6+ years of experience leading IT GRC, SOX, ISO 27001, and NIST-driven cloud security programs across global enterprises. I'm recognized for driving governance transformation, securing $1M+ cyber deals, and building scalable security frameworks across regulated industries. I collaborate with cross-functional teams to embed security by design into product lifecycles and deliver risk-informed outcomes.

Available to hire

I’m Joy Singh, a Cybersecurity and Technology Risk Specialist with 6+ years of experience leading IT GRC, SOX, ISO 27001, and NIST-driven cloud security programs across global enterprises.

I’m recognized for driving governance transformation, securing $1M+ cyber deals, and building scalable security frameworks across regulated industries. I collaborate with cross-functional teams to embed security by design into product lifecycles and deliver risk-informed outcomes.

See more

Work Experience

Senior Security Specialist at Smith & Nephew
December 1, 2024 - Present
Lead IT GRC and cloud security initiatives, including risk assessments, control design, and alignment with ISO 27001, NIST CSF, PCI DSS across SAP, Oracle NetSuite, Dynamics 365, and cloud environments. Managed remediation programs, delivered executive risk summaries, and guided security-by-design decisions. Drove cybersecurity awareness and vendor risk assessments across ISO 27001, PCI DSS, IT Audit and Vendor Risk domains.
Senior Cyber Security Consultant at Ernst & Young
September 1, 2021 - November 30, 2024
Led end-to-end IT risk assessments aligned with ISO 27001, ISO 22301, NIST CSF across SAP, Oracle, ServiceNow, AD, and Azure environments. Built governance artifacts, managed enterprise IT risk assessments, cloud security governance, third-party risk, and embedding security by design into product lifecycles. Delivered executive risk summaries and mentored cross-functional teams. Awarded multiple Spot and Innovation awards.

Education

MBA at Welingkar Institute of Management, Mumbai, India
January 11, 2030 - July 1, 2019
Bachelor's Degree in Mechanical Engineering at Pune University
January 11, 2030 - June 1, 2013

Qualifications

CISM Certification
January 1, 2024 - March 31, 2026
ISO 27001 Lead Auditor Certification
January 1, 2024 - March 31, 2026
BSI EY Cyber Security and Cloud Security Bronze Badge
January 1, 2023 - March 31, 2026

Industry Experience

Software & Internet, Professional Services, Government, Financial Services, Manufacturing