Cybersecurity GRC & Information Security Risk β I turn complex security findings into business-risk decisions leadership can act on.
Currently at EY, working on portfolio security compliance: risk-backlog remediation, real-time risk dashboards, and compliance-workflow automation. Background spans GRC, DFIR, and digital forensics across EY, a DFIR engineering team, and KPMG.
I'm especially interested in where regulation meets operations β ISO 27001, NIST CSF, NIS2, DORA, GDPR β and in building AI-powered tools that make compliance programmes actually run, not just pass an audit.
GRC Β· ISO/IEC 27001 Β· NIST CSF 2.0 Β· NIS2 Β· DORA Β· GDPR Β· COBIT Β· PCI-DSS
Risk Management Β· Incident Response Β· MITRE ATT&CK Β· Digital Forensics
Python Β· Bash Β· Power Automate Β· Microsoft 365 Β· OpenAI API Β· Streamlit
- grc-gap-ai β AI-powered compliance gap analyzer: upload a policy document, get a structured gap report mapped to ISO 27001, NIST CSF 2.0, NIS2, or DORA. Built with GPT-4o + Streamlit.
- ir-playbook-gen β AI-powered IR playbook generator: specify incident type, sector, and framework β get a complete incident response playbook in markdown with containment steps, forensic checklists, and NIS2/DORA notification timelines.
- control-crosswalk β dependency-free Python CLI that maps controls across ISO 27001:2022, NIST CSF 2.0, and NIS2, with coverage gap analysis and audit-ready CSV export.
- risk-register-ai β AI risk register: paste audit findings, get a scored, framework-mapped register with inherent/residual scoring and audit-ready export. Streamlit + GPT-4o. Live demo
- nis2-readiness-checker β dependency-free NIS2 readiness assessment CLI: answer questions mapped to Articles 20, 21(2) and 23, get a scored report and a prioritised remediation backlog.
GRCP (OCEG) Β· In progress: ISO/IEC 27001 Lead Auditor
M.Sc. Digital Forensics & Information Security β National Forensic Sciences University
B.Sc. Computer Science β University of Delhi
LinkedIn Β· work.mukul.chauhan@gmail.com
Open to GRC / IT risk / information security roles, including opportunities across Europe.