Thumma Sowjanya
Skills
AI & Security Automation: Microsoft Copilot for Security | AI-Driven Risk Scoring | UEBA & Behavioural Analytics | GenAI
Compliance Automation | AI/ML Application Security Review | Responsible AI Governance
Cloud Security: Microsoft Security Defender for Cloud | Azure Active Directory | Zero Trust Architecture (Exposure) | Cloud
Risk Governance | Cloud Compliance Controls | CASB Concepts
GRC & Compliance: NIST CSF | NIST RMF | NIST 800-53 | ISO 27001 | PCI DSS v4.0 | SOC 2 Type II | COBIT | ISO 31000 | FFIEC |
SOX Controls | OCC Requirements
Risk Management: Qualitative & Quantitative Risk Assessments | AI-Augmented Risk Registers | Threat Modelling | Control
Gap Analysis | Risk Matrices | Executive Risk Reporting
Third-Party Risk Management: Vendor Risk Assessments | Third-Party Security Due Diligence | Vendor Onboarding & Tiering
Reviews | Ongoing Vendor Monitoring | OCC/FFIEC Third-Party Guidance
SIEM & Threat Detection: IBM QRadar | QRadar Advisor with Watson | Splunk | Kibana/ELK | Microsoft Sentinel (Exposure) |
Correlation Rule Design | AI-Enhanced Alert Triage
Incident Response: Incident Lifecycle Management | AI-Assisted Root-Cause Analysis | SOP & Playbook Development | DFIR
Support | Containment Workflows
GRC Platforms: RSA Archer Design & Roadmap | RSA Archer ML Risk Features | ServiceNow GRC (Exposure) | RiskManagement Automation | Policy Lifecycle Management
Identity & Endpoint: CrowdStrike Falcon AI-Native EDR | Symantec EDR | Privileged Access Management | IDS/IPS | WAF |
Active Directory Security
About
Cybersecurity and GRC professional with 8+ years of progressive experience across governance, risk and compliance, SOC operations,
and enterprise risk governance. Currently supports Wells Fargo, a Tier-1 global institution, integrating AI tooling and automation into
risk assessment, compliance documentation, and threat-detection workflows since 2024. Combines regulatory and control knowledge
across NIST, ISO 27001, PCI DSS v4.0, SOC 2, FFIEC, and SOX with hands-on use of Microsoft Copilot for Security, AI-driven UEBA
platforms, and GenAI-assisted compliance automation. Brings practical experience in AI-augmented compliance, behavioural analytics
and security reviews for AI/ML applications, supported by Microsoft AI Fundamentals and CEH credentials.
Global Exposure
Support enterprise risk governance, compliance, AI-enabled security operations, and privileged-access management for Wells
Fargo under OCC, FFIEC, PCI DSS, and SOX mandates.
Apply global frameworks including NIST, ISO 27001, PCI DSS v4.0, SOC 2, COBIT, ISO 31000, FFIEC, and SOX.
Deliver SOC-based security advisory, vendor due diligence, & executive reporting across 5 managed-security client
environments.