Summary
Overview
Work History
Education
Skills
Certification
Accomplishments
Timeline
Generic

Ravikumar Bana

Dubai

Summary

Strategic and results-driven Principal GRC Expert with 15+ years of experience in IT Governance, Cybersecurity, Risk & Compliance. Proven leader in delivering frameworks aligned with COBIT, ITIL, ISO 27001, and UAE digital regulations. Skilled in policy architecture, SOPs, ISMS readiness, and cross-functional governance across healthcare and public sectors.

Overview

14
14
years of professional experience
1
1
Certification

Work History

Principal GRC Expert

ZENDATA Cybersecurity
11.2024 - Current
  • Strategically leading the establishment of an enterprise-wide IT Governance Framework across all four missions of Dubai Health: Care, Research, Learning, and Giving.
  • Driving cross-functional governance integration across IT departments including: Budget & Contracts, Procurement, Change Management, Release & Deployment, Incident & Problem Management, Project Management (PMO), Software Development Lifecycle (SDLC), Business Relationship Management (BRM), Service Desk, and Service Delivery.
  • Developed and implemented end-to-end SOPs, process workflows, SLAs, KPIs, and RACI matrices aligned with COBIT, ITIL v4, ISO 27001/20000, and UAE regulatory mandates (DDA, CAA).
  • Integrated Ivanti ITSM platform governance across change, incident, and problem workflows to ensure auditability, risk visibility, and compliance alignment.
  • Collaborated with Enterprise Architecture teams to embed TOGAF-aligned EA practices into each phase of the PMO Lifecycle.

Cybersecurity Consultant

EntLeaf Technologies LLC
08.2023 - 11.2024

• Advised on ISO 27001 readiness, ITSM process alignment, and GRC structuring
• Developed and reviewed cybersecurity policies, risk registers, and internal audit tools
• Supported incident response planning, access control practices, and privacy compliance

Associate Director – GRC & Cybersecurity

Kyndryl (CPRO Office)
09.2019 - 06.2023
  • Achieved OneTrust Fellow of Privacy Technology Certification, enhancing enterprise-wide privacy and compliance strategies.
  • Designed and implemented the SaPRA (Security and Privacy Risk Assessment) framework on the OneTrust platform, enabling automated risk scoring and integrated privacy workflows.
  • Contributed to the Cybersecurity and Data Privacy Framework rollout in collaboration with CISO, BISO, and EPB, as part of the Privacy & Risk Steering Committee.
  • Led regulatory readiness initiatives aligned with GDPR, ISO 27701, and global/regional privacy laws.
  • Established scalable policy controls, compliance KPIs, and audit mechanisms embedding privacy-by-design principles across the organization.

Service Delivery Leader

IBM India
03.2011 - 08.2019
  • Led IT service delivery operations, overseeing delivery governance, quality assurance, and compliance monitoring for major clients in healthcare and the public sector.
  • Ensured adherence to SLAs, process KPIs, and contract terms via structured governance models and internal audits.
  • Implemented Continuous Service Improvement (CSI) frameworks and root cause analysis for service efficiency and reduced downtime.
  • Ensured regulatory alignment with ISO 27001, ITIL, and client-specific audit and compliance requirements.
  • Played a key role in risk assessments, audit readiness, and cross-functional delivery reviews.
  • Led service delivery initiatives, ensuring alignment with organizational goals and client expectations.
  • Streamlined operational processes, enhancing efficiency and reducing service disruptions across multiple teams.

Education

Executive MBA - B.P.O Management

ISBM
Bangalore, India
01.2014

Skills

  • GRC Frameworks: COBIT, ISO, NIST
  • ITSM & ISMS Policy & Governance Architecture
  • ISMS & Audit Readiness
  • Cybersecurity Risk Management
  • Enterprise Architecture (TOGAF-aligned)
  • UAE Regulatory Compliance (DDA, CAA, NESA)
  • Ivanti ITSM Integration
  • Stakeholder Engagement & Strategic Advisory

Certification

  • Certified Information Security Officer
  • ISO/IEC 27001 & ISO9001
  • AI Security & Governance
  • COBIT 5
  • ITIL V3
  • ITIL Service Operation
  • ITIL Service Strategy
  • ITIL CSI
  • ITIL Service Design
  • PRINCE2
  • PMI Agile Advocate
  • Privacy Foundations
  • Security & Privacy by Design Foundations
  • OneTrust APA Expert
  • OneTrust Data Mapping Automation Expert
  • OneTrust Privacy Rights Automation Expert
  • OneTrust Certified Privacy Professional

Accomplishments

  • Moment of pride - Receiving the IBM 'Service Excellence Award'.
  • Max Award for Onsite Project Execution - 2006
  • Performance Excellence Award - 2006 & 2007
  • Excellence in Action Award - Offshore Project Management (2007)
  • Award for Excellence (Service Delivery) - Feb & Mar 2010
  • Individual Champ - BRAVO Award 2012
  • Eminence & Excellence Award - 2012
  • GTS Delighters - 2014
  • Elite Awards - 2015
  • Certificate of Excellence - 2016

Timeline

Principal GRC Expert

ZENDATA Cybersecurity
11.2024 - Current

Cybersecurity Consultant

EntLeaf Technologies LLC
08.2023 - 11.2024

Associate Director – GRC & Cybersecurity

Kyndryl (CPRO Office)
09.2019 - 06.2023

Service Delivery Leader

IBM India
03.2011 - 08.2019

Executive MBA - B.P.O Management

ISBM
Ravikumar Bana