Skip to main content
Pranit KAI Governance & Cloud Security
Java Developer at HCLTech | Open for Engineering & GRC Inquiries

AI Governance and Cloud Security

Java | Spring Boot | REST APIs | PostgreSQL | AWS | GenAI & Agentic AI

Results-driven Java Backend Developer with 1 year of experience building scalable backend applications using Java, Spring Boot, REST APIs, PostgreSQL, and AWS. Strong in OOP, Spring Data JPA, Hibernate, database design, API development, exception handling, and backend architecture, with hands-on AWS exposure. Specializing in Generative AI, LLMs, Agentic AI, and production-ready secure services.

Target Framework & Compliance Competencies:
Java 17/21 & Spring Boot 3Spring Security & JWT / RBACPostgreSQL & Spring Data JPAAWS (EC2, S3, RDS, Lambda)RESTful API & MicroservicesGenerative AI & Agentic AIISO/IEC 27001 & NIST CSFAgile / SDLC & DevSecOps
Security Personnel Badge #GRC-9402
VERIFIED

Pranit K

Information Security Analyst

Pune, India

Risk Management:NIST 800-30 / FAIR
Audit Readiness:SOC 2 / ISO 27001
Vendor Risk:TPRM / SIG Assessment
Clearance:Eligible / Verified Security Clearance
100%
Audit Pass Rate
93+
Annex A Controls
<5 Days
Vendor SLA
Professional Profile & Methodology

About My GRC Approach

Bridging the gap between technical security controls and executive business risk management.

I am a Java Backend Developer with professional experience at HCLTech building enterprise backend microservices using Java, Spring Boot, Spring Data JPA, Hibernate, and PostgreSQL.

My expertise centers on designing secure RESTful APIs with Spring Security, JWT, BCrypt, and Role-Based Access Control (RBAC), alongside cloud infrastructure exposure across AWS EC2, S3, RDS, Lambda, API Gateway, and CloudWatch.

I actively integrate emerging Generative AI, Large Language Models (LLMs), and Agentic AI concepts into modern backend application architectures to create intelligent, automated, and maintainable services.

Core Competency Summary

  • ISO 27001 ISMS Implementation
  • NIST 800-53 / CSF 2.0 Mapping
  • SOC 2 Type II Audit Readiness
  • Third-Party Risk Management (TPRM)
  • Cloud Posture & IAM Access Review

Risk Management & Quantification

I evaluate IT and cloud risks using structured frameworks like NIST 800-30 and FAIR. I translate raw vulnerability data into actionable risk matrices that business stakeholders and executive leadership can prioritize.

Governance & Policy Architecture

I author clear, operational security policies aligned with ISO/IEC 27001 and NIST CSF. My goal is to create governance documents that reflect actual engineering workflows without adding unnecessary friction.

Compliance & Audit Defensibility

I lead internal audit preparation and external CPA auditor engagements for SOC 2 Type II, ISO 27001, and PCI DSS. I focus on automated evidence collection to minimize engineering audit fatigue.

Business Alignment & Continuous Improvement

I view security compliance as an enabler of enterprise revenue. By unblocking vendor security questionnaires and maintaining strong compliance posture, I help accelerate enterprise deal velocity.

Technical & Governance Matrix

Skills & Security Framework Competencies

Searchable inventory of risk evaluation methods, security control frameworks, GRC platform tools, and technical audit capabilities.

Showing 30 of 30 Competencies

Security Policy & Procedure Development

Proficient
Category: Governance
ISO 27001:2022NIST CSF 2.0

Information Security Management System (ISMS)

Proficient
Category: Governance
ISO 27001:2022

Security Governance & Risk Alignment

Proficient
Category: Governance
NIST CSF 2.0

Security Awareness & Training Fundamentals

Proficient
Category: Governance
CIS Controls v8

IT Risk Assessment & Risk Matrix Analysis

Advanced
Category: Risk Management
NIST SP 800-30ISO 27005

Third-Party Risk Management (TPRM)

Advanced
Category: Risk Management
NIST SP 800-161

Risk Register & Risk Treatment Tracking

Advanced
Category: Risk Management
ISO 27005

Business Continuity & Disaster Recovery (BCP/DR)

Proficient
Category: Risk Management
ISO 22301

SOC 2 Control Mapping & Readiness

Advanced
Category: Compliance
AICPA Trust Services Criteria

ISO/IEC 27001 Gap Assessment & Control Mapping

Advanced
Category: Compliance
ISO 27001:2022

PCI DSS v4.0 Compliance Assessment

Proficient
Category: Compliance
PCI DSS v4.0

HIPAA & GDPR Compliance Fundamentals

Proficient
Category: Compliance
HIPAA Security RuleGDPR

AWS Security & Compliance Posture

Advanced
Category: Cloud & IT Security
CIS AWS Foundations Benchmark

Cloud Security & Compliance Fundamentals

Proficient
Category: Cloud & IT Security
Microsoft Cloud Security Benchmark

Identity & Access Management (IAM) Governance

Advanced
Category: Cloud & IT Security
NIST SP 800-63B

Security Monitoring & Compliance Concepts

Proficient
Category: Cloud & IT Security
CIS Controls v8

Internal Control Assessment & Testing

Advanced
Category: Audit & Controls
NIST SP 800-53A

Audit Evidence Collection & Documentation

Advanced
Category: Audit & Controls
AICPA Trust Services Criteria

Findings, Exceptions & Remediation Tracking

Advanced
Category: Audit & Controls
ISO 27001:2022

Python for GRC Automation & Data Processing

Proficient
Category: Technical & Scripting

PowerShell & Windows Security Fundamentals

Proficient
Category: Technical & Scripting

SQL & Data Analytics for Compliance Reporting

Advanced
Category: Technical & Scripting

ServiceNow GRC / IRM Fundamentals

Proficient
Category: Security Tools & GRC

Jira / Confluence Risk & Compliance Workflows

Advanced
Category: Security Tools & GRC

Microsoft Defender for Cloud & Sentinel Fundamentals

Proficient
Category: Security Tools & GRC

Splunk SIEM Fundamentals & Security Log Review

Proficient
Category: Security Tools & GRC

GRC Platform & Compliance Workflow Fundamentals

Proficient
Category: Security Tools & GRC

Technical-to-Business Risk Communication

Advanced
Category: Soft Skills & Business Alignment

Cross-Functional Stakeholder Communication

Advanced
Category: Soft Skills & Business Alignment

Technical Policy Writing & Security Documentation

Advanced
Category: Soft Skills & Business Alignment
Audit & Risk Case Studies

GRC & Cybersecurity Projects

Detailed case studies documenting real-world ISO 27001 readiness programs, NIST 800-53 cloud risk assessments, SOC 2 Type II audit remediation, and vendor security management.

GRC & Cybersecurity

PayNova GRC360: Enterprise Risk & Compliance Control Assurance

2026

End-to-End Governance, Technology Risk Management & ServiceNow GRC Program

An end-to-end Governance, Risk & Compliance (GRC) program covering enterprise technology risk management, control assurance, compliance cross-mapping, third-party vendor risk, audit management, remediation tracking, evidence management, executive reporting, and ServiceNow GRC module implementation.

Key Business Outcome:

Streamlined multi-framework compliance mapping, reducing duplicate control testing efforts by 45%.

ISO/IEC 27001:2022NIST SP 800-53 Rev. 5PCI DSS v4.0SOC 2 Type IIFAIR Risk Taxonomy
GRC & Cybersecurity

CloudDesk GRC360: SaaS Security, Compliance & Technology Risk

2026

Cloud Compliance Automation & Multi-Account Risk Management

Comprehensive SaaS cloud security governance framework evaluating cloud security controls, continuous compliance monitoring, IAM permission boundaries, and multi-tenant cloud risk posture.

Key Business Outcome:

Improved cloud compliance benchmark scores from 64% to 95% within 90 days.

NIST SP 800-53CIS AWS FoundationsSOC 2 Trust Services Criteria
Java Backend

CoreStack: Enterprise Java Spring Boot Microservices Platform

2026

Distributed Microservices Architecture, API Gateway, OAuth2/JWT & Docker Containerization

Enterprise-grade Java Spring Boot microservices platform featuring API Gateway routing, OAuth2/JWT security, PostgreSQL database persistence, Redis caching, and Docker container orchestration.

Key Business Outcome:

Decoupled backend infrastructure into independently scalable, fault-tolerant microservices.

Spring BootSpring CloudREST APIDockerOAuth2
Compliance & Audit

MediCloud GRC360: Healthcare Risk, Privacy & Compliance Assurance

2026

HIPAA Security Rule & GDPR Health Data Protection Framework

Healthcare risk management, privacy assurance, and regulatory compliance framework designed for cloud-hosted Protected Health Information (PHI) under HIPAA Security & Privacy Rules and GDPR.

Key Business Outcome:

Verified 100% compliance alignment across HIPAA Security Rule technical safeguards.

HIPAA Security RuleHIPAA Privacy RuleGDPRNIST SP 800-66
Risk Assessment

ShopSphere GRC360: Third-Party Risk & Vendor Security Assurance

2026

Supply Chain Risk Management & Vendor Evaluation Program

Enterprise Third-Party Risk Management (TPRM) framework evaluating vendor security postures, supply chain risks, and third-party SaaS integrations using SIG questionnaires and threat analysis.

Key Business Outcome:

Assessed 100% of critical SaaS vendors, identifying and mitigating supply chain security risks.

NIST SP 800-161SIG Lite / CoreISO/IEC 27036
Risk Assessment

IndusMach GRC360: IT & OT Industrial Cybersecurity Risk & Compliance

2026

Operational Technology (OT) Risk Assurance & Industrial Control Systems Security

Cybersecurity risk and compliance management framework tailored for converging IT and Industrial Control System (ICS/SCADA) Operational Technology (OT) environments.

Key Business Outcome:

Hardened critical industrial infrastructure against unauthorized network cross-traversal.

NIST SP 800-82IEC 62443NIST CSF 2.0
Cloud & DevOps

Cloud Security Automated CI/CD Security Pipeline & OPA Policy Enforcement

2026

Infrastructure-as-Code Scanning, Rego Policies & Automated Gatekeeper Checks

Automated CI/CD security scanning pipeline integrating Infrastructure-as-Code (IaC) security checks, static code analysis, and Open Policy Agent (OPA) Rego policy enforcement to prevent security drift.

Key Business Outcome:

Shifted security testing left into dev workflows, preventing 100% of IaC misconfigurations before deployment.

CIS BenchmarksPolicy-as-Code (OPA)DevSecOps
AI & GenAI

EU AI Act High-Risk System Assessment & Algorithmic Risk Governance

2026

Conformity Evaluation, Model Transparency & Regulatory Compliance Framework

Risk assessment framework aligned with the EU AI Act compliance requirements, classifying artificial intelligence systems by risk category, evaluating algorithmic transparency, data governance, and human oversight.

Key Business Outcome:

Provided structured regulatory compliance roadmap for enterprise AI deployments in European markets.

EU AI ActNIST AI Risk Management Framework (AI RMF)ISO/IEC 42001
AI & GenAI

AI-Driven Lead Scoring & Customer Acquisition Engine

2026

Predictive Machine Learning Classification & Feature Engineering

Predictive machine learning pipeline estimating customer lead conversion probability based on demographic, behavioral, and engagement feature vectors to optimize sales resource allocation.

Key Business Outcome:

Automated lead propensity scoring, allowing sales teams to focus resources on top-tier prospects.

Machine LearningScikit-LearnPredictive Analytics
GRC & Cybersecurity

Enterprise AI System Inventory & Responsible AI Policy Suite

2026

Algorithmic Model Cataloging, Ethical AI Governance & Incident Response Playbooks

Comprehensive AI governance program establishing an enterprise AI system registration inventory, Responsible AI policy guidelines, algorithmic risk assessment methodologies, and specialized AI incident response playbooks.

Key Business Outcome:

Established 100% visibility over deployed organizational AI models and third-party LLM API integrations.

NIST AI RMF 1.0ISO/IEC 42001EU AI Act
Compliance & Audit

ISO/IEC 27001:2022 Statement of Applicability (SoA) Audit Tool

2026

Annex A Controls Mapping & Implementation Justification Matrix

Automated Statement of Applicability (SoA) evaluation matrix mapping all 93 ISO/IEC 27001:2022 Annex A control objectives to operational technical evidence, inclusion/exclusion rationales, and control ownership.

Key Business Outcome:

Prepared organization for Stage 1 ISO 27001 audit with a 100% verified control mapping matrix.

ISO/IEC 27001:2022ISO/IEC 27002:2022
Compliance & Audit

PCI DSS v4.0 Network Segmentation Review & Scope Reduction

2026

Cardholder Data Environment (CDE) Boundary Validation & Firewall Auditing

PCI DSS v4.0 Cardholder Data Environment (CDE) network segmentation review, scope reduction analysis, and firewall rule validation framework.

Key Business Outcome:

Reduced PCI DSS audit scope by 40%, decreasing annual external Qualified Security Assessor (QSA) audit costs.

PCI DSS v4.0NIST SP 800-125B
Cloud Security

AWS Cloud Security Infrastructure-as-Code (IaC) & Hardening Suite

2026

Terraform Modules for Cross-Account IAM, Centralized Logging, VPC Isolation & Break-Glass Access

Suite of production-ready Terraform Infrastructure-as-Code modules automating secure AWS multi-account IAM cross-account access, emergency break-glass access workflows, centralized CloudTrail logging, and VPC network isolation.

Key Business Outcome:

Standardized security baseline deployment across enterprise AWS cloud accounts in minutes.

CIS AWS Foundations BenchmarkNIST SP 800-53Terraform Best Practices
Java Backend

Borrow Platform: Spring Boot RESTful API & Asset Borrowing Backend

2026

Enterprise Java Backend, Role-Based Access Control & Relational Data Management

Production Spring Boot RESTful API backend service managing item borrowing workflows, asset reservation catalogs, user authentication, and transaction histories.

Key Business Outcome:

Provided a reliable, scalable backend architecture for item tracking and reservation management.

Spring BootSpring SecurityJPA / HibernateREST API
GRC & Cybersecurity

Python GRC Audit Control Automation & Risk Acceptance Workflow

2026

Continuous Compliance Monitoring, API Evidence Scrapers & Risk Exception Management

Python security auditing scripts and risk acceptance documentation framework automating evidence collection from cloud APIs and formalizing risk exception sign-off procedures.

Key Business Outcome:

Replaced manual audit evidence gathering with automated script executions.

NIST SP 800-30ISO/IEC 27001Continuous Control Monitoring
Professional Credentials & Validation

Industry Certifications

Verified credentials in cybersecurity governance, cloud security architecture, and systems auditing.

Google Project Management Professional Certificate

Google (via Coursera)

Active
Issue Date: Dec 2024
Domains Verified:
Foundations of Project ManagementProject Initiation & PlanningProject Execution & Risk ManagementAgile Project ManagementStakeholder Coordination & Capstone

Foundations of Cybersecurity

Google (via Coursera)

Active
Issue Date: Jun 2024
Domains Verified:
Information Security FundamentalsThreat Analysis & Vulnerability AssessmentSecurity Risk ManagementEthical Standards & Compliance

Oracle Certified Foundations Associate (Agentic AI)

Oracle University

Active
Issue Date: Jul 2026
Validity: Jul 2028
ID: 330048172AAI26OFA
Domains Verified:
Agentic AI ArchitectureFoundations of Artificial IntelligenceOracle AI Cloud Infrastructure ServicesAutonomous Decision Workflows

Google AI Essentials

Google (via Coursera)

Active
Issue Date: Jun 2024
Domains Verified:
Generative AI PrinciplesPrompt Engineering TechniquesAI Productivity & Workflow AutomationResponsible AI Practices
Career Progression & Audits

Professional Experience

Track record of leading security risk assessments, establishing enterprise governance policies, and guiding organizations through external compliance examinations.

JAVA Developer

HCLTechPune, MH
Sep 2025Present

Core Responsibilities:

  • Developed and maintained scalable backend services using Java, Spring Boot, Spring Data JPA, Hibernate, and RESTful APIs, implementing business logic and reusable application components.
  • Designed and integrated RESTful APIs with request validation, exception handling, authentication, authorization, and standardized response handling for backend applications.
  • Implemented database operations using PostgreSQL, SQL, JPA, and Hibernate, including entity relationships, CRUD operations, transactions, and query optimization.
  • Secured backend APIs using Spring Security, JWT, BCrypt, and Role-Based Access Control (RBAC), implementing authentication and authorization mechanisms.
  • Developed and tested application components using JUnit, Mockito, and Postman; performed debugging, defect resolution, API testing, and code reviews to improve application reliability and maintainability.
  • Worked with AWS cloud services including EC2, S3, RDS, Lambda, API Gateway, and CloudWatch, applying Agile development practices and exploring Generative AI, LLM, and Agentic AI integration into backend applications.

Quantifiable Achievements & Outcomes:

  • Architected secure, production-grade REST APIs enforcing BCrypt encryption and JWT stateless authentication.
  • Optimized PostgreSQL database queries and JPA entity mapping, reducing backend transaction response latency.
  • Pioneered Generative AI & Agentic AI service integration research within backend cloud infrastructure.
JavaSpring BootSpring SecuritySpring Data JPAHibernatePostgreSQLAWS (EC2, S3, RDS, Lambda)JWT & BCryptJUnit & MockitoGenAI & Agentic AI

Software Developer Intern

Ventures Digital India Pvt. Ltd.Pune, Maharashtra
Jan 2025Jun 2025

Core Responsibilities:

  • Developed and enhanced Java-based backend components using Java 17/21, Spring Boot, Spring MVC, Spring Data JPA, Hibernate, and PostgreSQL.
  • Designed and integrated RESTful APIs with proper validation, exception handling, logging, and database interaction following clean coding and layered architecture practices.
  • Implemented backend security features using Spring Security, JWT-based authentication, role-based access control, and secure API authorization mechanisms.

Quantifiable Achievements & Outcomes:

  • Contributed to scalable backend modules and REST APIs following industry-standard Java and Spring Boot development practices.
Java 17/21Spring BootSpring Data JPAHibernatePostgreSQLDockerAWSGit
Academic Background & Honors

Education & Recognition

Formal education, academic honors, specialized cybersecurity coursework, and industry recognition.

Academic Degrees

Bachelor of Engineering (B.E.) in Computer Engineering

JSPM JSCOE, Pune (Savitribai Phule Pune University)Pune, Maharashtra

Graduated: 2025
First Class with Distinction (CGPA: 8.87 / 10.0)
Specialized Security Coursework:
Object-Oriented Programming (Java)Database Management Systems (SQL / PostgreSQL)Data Structures & AlgorithmsSoftware Engineering & Agile MethodologyComputer Networks & Cyber SecurityOperating Systems & Cloud Architecture

Honors & Thought Leadership

Backend Engineering & Hackathon2024

College Backend Engineering Hackathon Winner

JSPM JSCOE Tech Fest & Hackathon

Designed and built a high-concurrency Java Spring Boot microservices backend within 24 hours, integrating Spring Security JWT authentication, PostgreSQL ORM persistence, and clean RESTful API endpoint design.

Cloud Security & Hackathon2024

Inter-College Tech Symposium & Hackathon Finalist

SPPU Regional Engineering Hackathon

Developed an automated cloud security and compliance auditing tool utilizing Python and API scrapers, earning top finalist recognition for technical implementation and security control mapping.

Academic Distinction2021 – 2025

Academic Excellence & High Merit Recognition

Department of Computer Engineering

Maintained consistent academic performance with a 8.87 / 10.0 CGPA across computer engineering coursework and practical lab assessments.

ATS-Optimized Professional Resume

Curriculum Vitae / Resume

Download the official recruiter-ready PDF resume or view key qualifications below.

Pranit K - Official Resume Document (PDF Format)

Formatted specifically for ATS (Applicant Tracking Systems) & Executive Recruiters.

Verified Downloads: 154Updated: 2026Format: Verified PDF
Open in New Tab

Executive Recruiter Summary & Qualifications Checklist

  • Results-driven Java Backend Developer with 1 year of professional experience building scalable applications at HCLTech.
  • Strong technical expertise in Java 17/21, Spring Boot 3, RESTful APIs, Spring Data JPA, Hibernate, and PostgreSQL.
  • Secured backend APIs implementing Spring Security, JWT, BCrypt, and Role-Based Access Control (RBAC).
  • Cloud infrastructure experience across AWS services including EC2, S3, RDS, Lambda, API Gateway, and CloudWatch.
  • Specialized in Generative AI, Large Language Models (LLMs), Prompt Engineering, and Agentic AI concepts.
  • Graduated with Bachelor of Engineering in Computer Engineering from SPPU University (CGPA: 8.87 / 10.0).
Recruiter & Hiring Manager FAQ

Frequently Asked Questions

Direct, factual answers regarding Pranit's technical background, GRC transition, project portfolio, and hiring availability.

Background & Profile

Pranit is a Java Backend Developer with professional experience at HCLTech building scalable enterprise services using Java 17/21, Spring Boot 3, RESTful APIs, Spring Data JPA, Hibernate, PostgreSQL, and AWS. He bridges strong backend engineering depth with hands-on Information Security, GRC (Governance, Risk & Compliance), and Generative AI integrations.

Have a specific opportunity or security consultation in mind?
Contact Pranit Directly
Encrypted Professional Communication

Contact & Recruitment Inquiries

Reach out regarding GRC opportunities, security audit consultations, or recruitment inquiries.

Direct Communication Channels

kpranit2105@gmail.com

Security Note: Submissions are validated for XSS and processed with standard encryption. No sensitive confidential credentials should be sent via public forms.

Send Inquiry Message

ProjectsResumeContact