VARUN KUMAR BHAKTA

Results-oriented professional with strong experience in IT Security, Risk, Finance & Compliance, focused on Federal and State government engagements.

Email
vkuma5@outlook.com
Telemetry & GRC Dashboard concept

Profile

Results-oriented cybersecurity professional with a strong background in IT Security, Risk, Finance and Compliance management specializing in Federal and State government projects. I leverage frameworks and standards to improve security posture, ensure compliance, and drive remediation.

Technical Skills & Frameworks

Frameworks
NIST, FISMA, MARS-E, ISO/IEC 27001, MITRE ATT&CK, SOC 2, CMMC
Tools
Tenable.io, Nessus, Azure Gov, Kibana, PowerBI, ServiceNow, Burp Suite
Certifications
CC (ISC)², CISA (In Progress), SAS, Graduate Certificates (UIS)
Other
Linux, Windows, Security Policy, ATO, SIEM reviews
Risk Assessment92%
Control Mapping88%
Audit Readiness85%

Risk Management Project — Health Network (Fictional)

June 2023 — Risk Assessment & BCP

Project Overview

Risk assessment for Health Network's product suite — VoltronMessenger, VoltronPay and VoltronConnect. Scope included servers, web applications, availability & integrity.

Infrastructure

3 production data centers, ~3,000 production servers, ~600 employees, ~650 corporate laptops and devices. HTTPS integration across products.

Scope & Purpose

  • Secure web servers & web applications
  • Protect availability & integrity
  • Update assessments with control effectiveness & system changes

Company Products

VoltronMessenger

Primary revenue source: secure electronic messaging for hospitals and clinics. Handles PHI messages routed between customers and providers.

VoltronPay

Web portal for payments & billing; interacts with credit card processors and handles payment flows in production.

VoltronConnect

Directory of doctors/clinics: personal info, addresses, certifications, and services. Providers update profiles.

Assets

  • Hardware — Production servers, laptops, mobile devices
  • Software — Messaging service, payment portal, directory app
  • Information — PHI, billing data, provider records

Risk Ratings — Visual

Risk score (likelihood × impact). Internet threats score highest.

Professional Experience

Lead Security Analyst — Serigor, Inc

Sep 2023 - Present | Annapolis, MD

  • Conducted risk assessments and vulnerability scans — reduced incidents by 30%.
  • Developed ATO documentation & baseline controls per NIST 800-53 & IRS Pub 1075.
  • Implemented MFA/SSO (Cisco Duo) and used Tenable/Nessus & Azure Gov Security Advisor.
  • Reviewed SIEM logs with Kibana/Elastic, created findings & POA&M ahead of IRS audit.

Governance, Risk & Compliance Intern — Illinois DoIT

Nov 2021 - May 2023 | Springfield, IL

  • Reviewed SOC2 reports and tracked IRS Safeguard findings & corrective action plans.
  • Developed Power BI dashboards to reflect compliance KPIs and remediation progress.
  • Monitored IAM and implemented baselines for password strength (FIPS/FISMA).

Financial Analyst — Deloitte

Jan 2020 - Aug 2021 | Hyderabad, India

  • Federal client invoicing, reconciliation and reporting for portfolios > $1.5B.
  • Generated reports with IBM Cognos and analyzed billing/collections metrics.

Associate Financial Analyst — Wells Fargo

Nov 2017 - Dec 2019 | Hyderabad, India

  • Analyzed financial statements, credit merit, and EBITDA calculations.

Let's secure the next system together

Reach out for consultancy, ATO preparation, risk assessments, and GRC engineering.