Rishipal Yadav

Rishipal Yadav

Assistant Manager

Uniqus Consultech Inc

Noida, IN

About Me

I'm a CISSP-certified cybersecurity professional with 5+ years of experience spanning GRC, cloud security, and AI risk advisory across Big 4 consulting, fintech, and cybersecurity startups in India, the US, and the Middle East. My GRC journey started at Cyble, where I owned an end-to-end ISO 27001 ISMS implementation from scratch - risk assessment, gap analysis, certification readiness - in under 8 months. That experience of building a compliance program from the ground up shaped how I think about GRC: not as checkbox exercise, but as a risk ownership culture problem.At PwC and now at Uniqus Consultech, I've led enterprise audits against ISO 27001, NIST CSF 2.0, and the RBI Cyber Resilience Framework, engaging directly with CXOs and Risk teams to translate technical findings into remediation decisions that actually stick. What I find most compelling is the translational layer - turning regulatory complexity into commercially viable, operationally feasible controls.My current passion is where GRC meets AI. I built ThreatCompass, an AI threat modeling tool grounded in OWASP LLM Top 10, because I kept seeing organizations adopt GenAI without structured risk frameworks to govern it. I've also been building internal LLM-powered workflows to automate audit tasks - evidence summarization, control mapping, report drafting - which has meaningfully changed how I think about the future of GRC Engineering as a discipline.

Experience Highlights

  • Led ISO 27001 ISMS implementation end-to-end at Cyble, achieving certification within 8 months across 200+ assets
  • Conducted enterprise cybersecurity audits against ISO 27001, NIST CSF 2.0, and RBI Cyber Resilience Framework at Uniqus Consultech, engaging CXOs and IT Heads on remediation prioritization
  • Designed Microsoft Purview DLP and data governance solutions for PwC's Managed SOC, standardizing classification policies across multiple enterprise clients
  • Led Database Activity Monitoring (DAM) deployment across 900+ databases for a Fortune-scale US logistics client, strengthening SOX compliance and insider threat detection
  • Advised a global enterprise on secure GenAI (Microsoft Copilot for M365) adoption for 1,000+ users, accelerating secure rollout by 2 months
  • Built LLM-powered audit automation workflows, reducing manual effort by 40% across concurrent engagements
  • Built ThreatCompass — an AI threat modeling tool implementing deterministic OWASP LLM Top 10 evaluators with automated PDF/Markdown reporting
  • Co-authored peer-reviewed research on attack surface measurement across US county government networks (UMD/OSF, 2023)
  • Certifications: CISSP, GSEC, CCSK, GCP-ACE, AZ-900 | RSA Conference Security Scholar '24

Get in Touch

Happy to connect via LinkedIn (preferred for a first hello) or directly at yadav.rishipal001@gmail.com. You can also find my work at rishipalyadav.github.io and github.com/rishipalyadav.

Specializations

Audit & AssuranceRisk ManagementSecurity ArchitectureSecurity Governance

Languages & Tools

BashPython

Frameworks

ISO 27001NIST CSF

Certifications

CISSPGSECCCSKAZ-900

Projects

ThreatCompass

Threat modeling built specifically for AI-enabled products — mapped to OWASP LLM Top 10 Describe your AI-powered application in plain English. Answer a few clarifying questions. Get a structured threat model — with confidence-scored findings, system-specific narratives, and exportable checklists for developers and GRC teams.