Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
70 changes: 70 additions & 0 deletions engineers/vibhutidahiya.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,70 @@
---
name: "Vibhuti Dahiya"
github: "vibhutidahiya"
specializations:
- "Audit & Assurance"
- "Compliance Automation"
- "Privacy"
- "Risk Management"
- "Security Governance"
- "Third-Party Risk"
- "AI Governance"
- "Cloud Governance"
location: "Atlanta, USA"
linkedin: "https://www.linkedin.com/in/vibhutidahiya/"
blog: "https://vibhutidahiya.github.io"
frameworks:
- "CCPA"
- "CMMC"
- "COBIT"
- "CSA STAR"
- "EU AI Act"
- "FedRAMP"
- "GDPR"
- "HIPAA"
- "ISO 27001"
- "ISO 27017"
- "ISO 27018"
- "ISO 42001"
- "NIST 800-53"
- "NIST 800-171"
- "NIST AI RMF"
- "NIST CSF"
- "NIST RMF"
- "PCI-DSS"
- "SOC 2"
certifications:
- "CISSP"
- "ISO/IEC 27001:2022 Lead Auditor"
- "ISO/IEC 27001:2022 Lead Implementer"
- "ISO/IEC 42001:2023 Lead Auditor"
- "ISO/IEC 27701:2025 Lead Auditor"
- "CEH"
available_for:
- "consulting"
- "open-source"
- "hiring"
- "collaboration"
---

## About Me

Cybersecurity was the first thing in engineering that truly clicked for me. I earned my CEH before I'd even finished my undergrad, and I've been building on that ever since.

I'm a GRC professional with consulting experience across healthcare, financial services, telecom, insurance, and tech. I started at Grant Thornton in India, moved to Accorian, and recently finished my M.S. in Cybersecurity at Georgia Tech, where my focus broadened into privacy and AI governance.

What I love most about GRC is the variety: new projects, environments, frameworks, and people. I enjoy digging into a new standard and working out how it applies in practice, and I'm always looking for the next thing to learn. The intersection of GRC, privacy, and AI is where I want to keep growing.

I've volunteered with IEEE since 2019, starting in my undergrad years, because I like being around people who share what they know and help others grow.

## Experience Highlights

- SOC 2 gap assessment across all five Trust Services Criteria
- Common Controls Framework unifying ISO 27001, SOC 2, NIST CSF 2.0, and HIPAA
- ISO 27001 internal audits for multiple clients
- Built ISO 42001 AI Management System toolkit
- NIST SP 800-30 risk assessment for a major NY Health Information Exchange
- HIPAA risk assessments for six healthcare entities
- Tabletop exercises across incident response, business continuity, and disaster recovery
- ITGC and SOX audits for financial services clients
- RBI-guideline risk assessments for 25+ partners of India's largest credit bureau