Open to GRC Roles · Melbourne, AU

Cybersecurity GRC
Professional.

A detail-oriented GRC professional bringing 7 years of banking and insurance experience — applying a risk mindset to assessments, control mapping and practical recommendations across ISO 27001, NIST CSF 2.0 and Essential Eight.

Background

About Me

Pooja Mangwani

I am building a career in cybersecurity Governance, Risk and Compliance, bringing 7 years of banking and insurance experience — and a detail-oriented risk mindset — into the field.

Through hands-on projects I have worked across ISO 27001, NIST CSF 2.0 and Essential Eight — assessing risks, mapping controls and developing practical recommendations. This portfolio showcases my GRC project work as I grow in this space.

Work

Projects

Project 01
OSCORP Cybersecurity GRC Assessment ISO 27001 · NIST CSF 2.0 · Gap Analysis · Risk Register
Solo Project

A full cybersecurity GRC assessment of Oscorp evaluating their security posture against ISO 27001 and NIST CSF 2.0, with a gap analysis, risk register and prioritised remediation roadmap.

Oscorp is a technology and research organization with an established IT function but limited cybersecurity maturity. While the organization has invested in foundational IT controls such as business continuity, network security and physical security, significant gaps exist across critical cybersecurity domains including identity and access management, detection and response, vulnerability management and third party risk.

  • Current State Assessment

    Reviewed Oscorp's existing security controls across all key domains — documenting what is in place, what is working well and areas of concern. This formed the foundation for all subsequent analysis.

  • Gap Analysis

    Compared Oscorp's controls against ISO 27001 and NIST CSF 2.0 requirements, rating each gap as Critical, High, Medium or Low. Key findings included the absence of MFA, no SIEM capability, shared admin passwords and no formal vulnerability management program.

  • Risk Register

    Identified the top 13 cybersecurity risks facing Oscorp, scored by likelihood and impact (1-5). Each risk includes the threat, current control and recommended control. Critical and High risks require immediate leadership attention.

  • Recommendations & Roadmap

    A prioritised roadmap organised into immediate, short-term and medium-term timeframes, mapped to NIST CSF 2.0 and ISO 27001. Recommended for board-level presentation given the number of critical gaps identified.

Project 02
Essential Eight Assessment — NBDA ASD Essential Eight · Maturity Ratings · Gap Analysis · Recommendations
Solo Project

A full Essential Eight assessment of the National Benefits Delivery Agency (NBDA), a fictional Australian Government organisation with 1,500 staff. I played the role of GRC Analyst — conducting a structured interview with the IT Manager across all 8 strategies, collecting and reviewing evidence documents, identifying red flags, rating each strategy against the ASD Essential Eight Maturity Model, and producing a findings report with practical recommendations.

NBDA is a fictional Australian Government agency that delivers welfare payments and support services to 1,500 staff across 4 states. Their IT environment is hybrid — on-premise servers plus Microsoft 365 cloud. The assessment used the ASD Essential Eight Maturity Model as the framework, rating each strategy from ML0 to ML3. The overall result was ML1 — below the ML2 requirement expected of Australian Government agencies.

  • Essential Eight Assessment Report (PDF)

    Full assessment report covering all 8 strategies — interview questions, evidence reviewed, red flags identified, maturity ratings, gaps, and recommendations for the National Benefits Delivery Agency.

Strategy Rating Key Issue
Application ControlML1340 unreviewed exceptions; servers not covered
Patch ApplicationsML178% compliance; no SLA; third-party apps months behind
Configure Office MacrosML1Finance OU fully excluded; no macro execution logging
User Application HardeningML1Browser baseline 4 years old; Office hardening unknown
Restrict Admin PrivilegesML114 staff using admin accounts daily; 23 inactive accounts
Patch Operating SystemsML291% compliance; 12 servers on end-of-life Windows Server 2012
Multi-Factor AuthenticationML1No MFA on internal systems; multiple bypass options
Regular BackupsML1No restoration test in 18 months; backups on same network
Overall RatingML17 of 8 strategies at ML1 — below ML2 government requirement
Project 03
Third Party Risk Assessment — MHG x CareConnect Vendor Security Questionnaire · Risk Rating · Findings Report
Solo Project

A formal Third Party Risk Assessment conducted in the role of GRC Analyst at Meridian Health Group (MHG), a fictional Australian healthcare organisation. With the contract for telehealth vendor CareConnect Telehealth Pty Ltd due for renewal in 60 days, I assessed whether CareConnect was a safe and compliant custodian of MHG patient data — sending a vendor security questionnaire, reviewing responses and supporting evidence, identifying red flags, producing a risk rating, and delivering recommendations to the CISO. The assessment was framed under the Privacy Act and the Notifiable Data Breaches scheme.

CareConnect Telehealth Pty Ltd is a cloud-based telehealth platform (80 staff, Sydney-based, hosted on AWS Sydney) providing GP video consultations, specialist referrals, and patient messaging to MHG. The vendor holds highly sensitive patient data including names, Medicare numbers, health conditions, consultation recordings, and referral letters — classified as Critical risk. Annual SaaS contract renewal was due in 60 days.

  • Third Party Risk Assessment Report (PDF)

    Full assessment report including vendor profile, security questionnaire responses, red flags identified, risk rating, and recommendations for the CISO on whether to renew the CareConnect contract.

Expertise

Skills & Frameworks

GRC Frameworks

ISO 27001 NIST CSF 2.0 Essential Eight

GRC Capabilities

Risk Assessment Risk Analysis Third Party Risk Assessment Gap Analysis Control Mapping Risk Register Remediation Planning Policy Development Compliance Monitoring

Domain Knowledge

Networking Fundamentals DNS Linux Windows Cryptography Hashing SOC Fundamentals Incident Response SIEM Firewall Splunk OWASP Top 10 Cyber Kill Chain MITRE ATT&CK

Certifications

ISO 27001 Lead Auditor GRC Mastery Microsoft SC-900 CompTIA Security+ AWS Cloud Practitioner CRISC Vulnerability Management Foundation Okta Professional

Get In Touch

Contact

Interested in collaborating or have a GRC opportunity? I would love to connect.