AI Governance and Cloud Security
Java | Spring Boot | REST APIs | PostgreSQL | AWS | GenAI & Agentic AI
Results-driven Java Backend Developer with 1 year of experience building scalable backend applications using Java, Spring Boot, REST APIs, PostgreSQL, and AWS. Strong in OOP, Spring Data JPA, Hibernate, database design, API development, exception handling, and backend architecture, with hands-on AWS exposure. Specializing in Generative AI, LLMs, Agentic AI, and production-ready secure services.
Pranit K
Information Security Analyst
Pune, India
About My GRC Approach
Bridging the gap between technical security controls and executive business risk management.
I am a Java Backend Developer with professional experience at HCLTech building enterprise backend microservices using Java, Spring Boot, Spring Data JPA, Hibernate, and PostgreSQL.
My expertise centers on designing secure RESTful APIs with Spring Security, JWT, BCrypt, and Role-Based Access Control (RBAC), alongside cloud infrastructure exposure across AWS EC2, S3, RDS, Lambda, API Gateway, and CloudWatch.
I actively integrate emerging Generative AI, Large Language Models (LLMs), and Agentic AI concepts into modern backend application architectures to create intelligent, automated, and maintainable services.
Core Competency Summary
- ISO 27001 ISMS Implementation
- NIST 800-53 / CSF 2.0 Mapping
- SOC 2 Type II Audit Readiness
- Third-Party Risk Management (TPRM)
- Cloud Posture & IAM Access Review
Risk Management & Quantification
I evaluate IT and cloud risks using structured frameworks like NIST 800-30 and FAIR. I translate raw vulnerability data into actionable risk matrices that business stakeholders and executive leadership can prioritize.
Governance & Policy Architecture
I author clear, operational security policies aligned with ISO/IEC 27001 and NIST CSF. My goal is to create governance documents that reflect actual engineering workflows without adding unnecessary friction.
Compliance & Audit Defensibility
I lead internal audit preparation and external CPA auditor engagements for SOC 2 Type II, ISO 27001, and PCI DSS. I focus on automated evidence collection to minimize engineering audit fatigue.
Business Alignment & Continuous Improvement
I view security compliance as an enabler of enterprise revenue. By unblocking vendor security questionnaires and maintaining strong compliance posture, I help accelerate enterprise deal velocity.
Skills & Security Framework Competencies
Searchable inventory of risk evaluation methods, security control frameworks, GRC platform tools, and technical audit capabilities.
Security Policy & Procedure Development
ProficientInformation Security Management System (ISMS)
ProficientSecurity Governance & Risk Alignment
ProficientSecurity Awareness & Training Fundamentals
ProficientIT Risk Assessment & Risk Matrix Analysis
AdvancedThird-Party Risk Management (TPRM)
AdvancedRisk Register & Risk Treatment Tracking
AdvancedBusiness Continuity & Disaster Recovery (BCP/DR)
ProficientSOC 2 Control Mapping & Readiness
AdvancedISO/IEC 27001 Gap Assessment & Control Mapping
AdvancedPCI DSS v4.0 Compliance Assessment
ProficientHIPAA & GDPR Compliance Fundamentals
ProficientAWS Security & Compliance Posture
AdvancedCloud Security & Compliance Fundamentals
ProficientIdentity & Access Management (IAM) Governance
AdvancedSecurity Monitoring & Compliance Concepts
ProficientInternal Control Assessment & Testing
AdvancedAudit Evidence Collection & Documentation
AdvancedFindings, Exceptions & Remediation Tracking
AdvancedPython for GRC Automation & Data Processing
ProficientPowerShell & Windows Security Fundamentals
ProficientSQL & Data Analytics for Compliance Reporting
AdvancedServiceNow GRC / IRM Fundamentals
ProficientJira / Confluence Risk & Compliance Workflows
AdvancedMicrosoft Defender for Cloud & Sentinel Fundamentals
ProficientSplunk SIEM Fundamentals & Security Log Review
ProficientGRC Platform & Compliance Workflow Fundamentals
ProficientTechnical-to-Business Risk Communication
AdvancedCross-Functional Stakeholder Communication
AdvancedTechnical Policy Writing & Security Documentation
AdvancedGRC & Cybersecurity Projects
Detailed case studies documenting real-world ISO 27001 readiness programs, NIST 800-53 cloud risk assessments, SOC 2 Type II audit remediation, and vendor security management.
PayNova GRC360: Enterprise Risk & Compliance Control Assurance
End-to-End Governance, Technology Risk Management & ServiceNow GRC Program
An end-to-end Governance, Risk & Compliance (GRC) program covering enterprise technology risk management, control assurance, compliance cross-mapping, third-party vendor risk, audit management, remediation tracking, evidence management, executive reporting, and ServiceNow GRC module implementation.
Streamlined multi-framework compliance mapping, reducing duplicate control testing efforts by 45%.
CloudDesk GRC360: SaaS Security, Compliance & Technology Risk
Cloud Compliance Automation & Multi-Account Risk Management
Comprehensive SaaS cloud security governance framework evaluating cloud security controls, continuous compliance monitoring, IAM permission boundaries, and multi-tenant cloud risk posture.
Improved cloud compliance benchmark scores from 64% to 95% within 90 days.
CoreStack: Enterprise Java Spring Boot Microservices Platform
Distributed Microservices Architecture, API Gateway, OAuth2/JWT & Docker Containerization
Enterprise-grade Java Spring Boot microservices platform featuring API Gateway routing, OAuth2/JWT security, PostgreSQL database persistence, Redis caching, and Docker container orchestration.
Decoupled backend infrastructure into independently scalable, fault-tolerant microservices.
MediCloud GRC360: Healthcare Risk, Privacy & Compliance Assurance
HIPAA Security Rule & GDPR Health Data Protection Framework
Healthcare risk management, privacy assurance, and regulatory compliance framework designed for cloud-hosted Protected Health Information (PHI) under HIPAA Security & Privacy Rules and GDPR.
Verified 100% compliance alignment across HIPAA Security Rule technical safeguards.
ShopSphere GRC360: Third-Party Risk & Vendor Security Assurance
Supply Chain Risk Management & Vendor Evaluation Program
Enterprise Third-Party Risk Management (TPRM) framework evaluating vendor security postures, supply chain risks, and third-party SaaS integrations using SIG questionnaires and threat analysis.
Assessed 100% of critical SaaS vendors, identifying and mitigating supply chain security risks.
IndusMach GRC360: IT & OT Industrial Cybersecurity Risk & Compliance
Operational Technology (OT) Risk Assurance & Industrial Control Systems Security
Cybersecurity risk and compliance management framework tailored for converging IT and Industrial Control System (ICS/SCADA) Operational Technology (OT) environments.
Hardened critical industrial infrastructure against unauthorized network cross-traversal.
Cloud Security Automated CI/CD Security Pipeline & OPA Policy Enforcement
Infrastructure-as-Code Scanning, Rego Policies & Automated Gatekeeper Checks
Automated CI/CD security scanning pipeline integrating Infrastructure-as-Code (IaC) security checks, static code analysis, and Open Policy Agent (OPA) Rego policy enforcement to prevent security drift.
Shifted security testing left into dev workflows, preventing 100% of IaC misconfigurations before deployment.
EU AI Act High-Risk System Assessment & Algorithmic Risk Governance
Conformity Evaluation, Model Transparency & Regulatory Compliance Framework
Risk assessment framework aligned with the EU AI Act compliance requirements, classifying artificial intelligence systems by risk category, evaluating algorithmic transparency, data governance, and human oversight.
Provided structured regulatory compliance roadmap for enterprise AI deployments in European markets.
AI-Driven Lead Scoring & Customer Acquisition Engine
Predictive Machine Learning Classification & Feature Engineering
Predictive machine learning pipeline estimating customer lead conversion probability based on demographic, behavioral, and engagement feature vectors to optimize sales resource allocation.
Automated lead propensity scoring, allowing sales teams to focus resources on top-tier prospects.
Enterprise AI System Inventory & Responsible AI Policy Suite
Algorithmic Model Cataloging, Ethical AI Governance & Incident Response Playbooks
Comprehensive AI governance program establishing an enterprise AI system registration inventory, Responsible AI policy guidelines, algorithmic risk assessment methodologies, and specialized AI incident response playbooks.
Established 100% visibility over deployed organizational AI models and third-party LLM API integrations.
ISO/IEC 27001:2022 Statement of Applicability (SoA) Audit Tool
Annex A Controls Mapping & Implementation Justification Matrix
Automated Statement of Applicability (SoA) evaluation matrix mapping all 93 ISO/IEC 27001:2022 Annex A control objectives to operational technical evidence, inclusion/exclusion rationales, and control ownership.
Prepared organization for Stage 1 ISO 27001 audit with a 100% verified control mapping matrix.
PCI DSS v4.0 Network Segmentation Review & Scope Reduction
Cardholder Data Environment (CDE) Boundary Validation & Firewall Auditing
PCI DSS v4.0 Cardholder Data Environment (CDE) network segmentation review, scope reduction analysis, and firewall rule validation framework.
Reduced PCI DSS audit scope by 40%, decreasing annual external Qualified Security Assessor (QSA) audit costs.
AWS Cloud Security Infrastructure-as-Code (IaC) & Hardening Suite
Terraform Modules for Cross-Account IAM, Centralized Logging, VPC Isolation & Break-Glass Access
Suite of production-ready Terraform Infrastructure-as-Code modules automating secure AWS multi-account IAM cross-account access, emergency break-glass access workflows, centralized CloudTrail logging, and VPC network isolation.
Standardized security baseline deployment across enterprise AWS cloud accounts in minutes.
Borrow Platform: Spring Boot RESTful API & Asset Borrowing Backend
Enterprise Java Backend, Role-Based Access Control & Relational Data Management
Production Spring Boot RESTful API backend service managing item borrowing workflows, asset reservation catalogs, user authentication, and transaction histories.
Provided a reliable, scalable backend architecture for item tracking and reservation management.
Python GRC Audit Control Automation & Risk Acceptance Workflow
Continuous Compliance Monitoring, API Evidence Scrapers & Risk Exception Management
Python security auditing scripts and risk acceptance documentation framework automating evidence collection from cloud APIs and formalizing risk exception sign-off procedures.
Replaced manual audit evidence gathering with automated script executions.
Industry Certifications
Verified credentials in cybersecurity governance, cloud security architecture, and systems auditing.
Google Project Management Professional Certificate
Google (via Coursera)
Foundations of Cybersecurity
Google (via Coursera)
Oracle Certified Foundations Associate (Agentic AI)
Oracle University
Google AI Essentials
Google (via Coursera)
Professional Experience
Track record of leading security risk assessments, establishing enterprise governance policies, and guiding organizations through external compliance examinations.
JAVA Developer
Core Responsibilities:
- Developed and maintained scalable backend services using Java, Spring Boot, Spring Data JPA, Hibernate, and RESTful APIs, implementing business logic and reusable application components.
- Designed and integrated RESTful APIs with request validation, exception handling, authentication, authorization, and standardized response handling for backend applications.
- Implemented database operations using PostgreSQL, SQL, JPA, and Hibernate, including entity relationships, CRUD operations, transactions, and query optimization.
- Secured backend APIs using Spring Security, JWT, BCrypt, and Role-Based Access Control (RBAC), implementing authentication and authorization mechanisms.
- Developed and tested application components using JUnit, Mockito, and Postman; performed debugging, defect resolution, API testing, and code reviews to improve application reliability and maintainability.
- Worked with AWS cloud services including EC2, S3, RDS, Lambda, API Gateway, and CloudWatch, applying Agile development practices and exploring Generative AI, LLM, and Agentic AI integration into backend applications.
Quantifiable Achievements & Outcomes:
- •Architected secure, production-grade REST APIs enforcing BCrypt encryption and JWT stateless authentication.
- •Optimized PostgreSQL database queries and JPA entity mapping, reducing backend transaction response latency.
- •Pioneered Generative AI & Agentic AI service integration research within backend cloud infrastructure.
Software Developer Intern
Core Responsibilities:
- Developed and enhanced Java-based backend components using Java 17/21, Spring Boot, Spring MVC, Spring Data JPA, Hibernate, and PostgreSQL.
- Designed and integrated RESTful APIs with proper validation, exception handling, logging, and database interaction following clean coding and layered architecture practices.
- Implemented backend security features using Spring Security, JWT-based authentication, role-based access control, and secure API authorization mechanisms.
Quantifiable Achievements & Outcomes:
- •Contributed to scalable backend modules and REST APIs following industry-standard Java and Spring Boot development practices.
Education & Recognition
Formal education, academic honors, specialized cybersecurity coursework, and industry recognition.
Academic Degrees
Bachelor of Engineering (B.E.) in Computer Engineering
JSPM JSCOE, Pune (Savitribai Phule Pune University) • Pune, Maharashtra
Honors & Thought Leadership
College Backend Engineering Hackathon Winner
JSPM JSCOE Tech Fest & Hackathon
Designed and built a high-concurrency Java Spring Boot microservices backend within 24 hours, integrating Spring Security JWT authentication, PostgreSQL ORM persistence, and clean RESTful API endpoint design.
Inter-College Tech Symposium & Hackathon Finalist
SPPU Regional Engineering Hackathon
Developed an automated cloud security and compliance auditing tool utilizing Python and API scrapers, earning top finalist recognition for technical implementation and security control mapping.
Academic Excellence & High Merit Recognition
Department of Computer Engineering
Maintained consistent academic performance with a 8.87 / 10.0 CGPA across computer engineering coursework and practical lab assessments.
Curriculum Vitae / Resume
Download the official recruiter-ready PDF resume or view key qualifications below.
Pranit K - Official Resume Document (PDF Format)
Formatted specifically for ATS (Applicant Tracking Systems) & Executive Recruiters.
Executive Recruiter Summary & Qualifications Checklist
- Results-driven Java Backend Developer with 1 year of professional experience building scalable applications at HCLTech.
- Strong technical expertise in Java 17/21, Spring Boot 3, RESTful APIs, Spring Data JPA, Hibernate, and PostgreSQL.
- Secured backend APIs implementing Spring Security, JWT, BCrypt, and Role-Based Access Control (RBAC).
- Cloud infrastructure experience across AWS services including EC2, S3, RDS, Lambda, API Gateway, and CloudWatch.
- Specialized in Generative AI, Large Language Models (LLMs), Prompt Engineering, and Agentic AI concepts.
- Graduated with Bachelor of Engineering in Computer Engineering from SPPU University (CGPA: 8.87 / 10.0).
Frequently Asked Questions
Direct, factual answers regarding Pranit's technical background, GRC transition, project portfolio, and hiring availability.
Pranit is a Java Backend Developer with professional experience at HCLTech building scalable enterprise services using Java 17/21, Spring Boot 3, RESTful APIs, Spring Data JPA, Hibernate, PostgreSQL, and AWS. He bridges strong backend engineering depth with hands-on Information Security, GRC (Governance, Risk & Compliance), and Generative AI integrations.
Contact & Recruitment Inquiries
Reach out regarding GRC opportunities, security audit consultations, or recruitment inquiries.
Direct Communication Channels
Security Note: Submissions are validated for XSS and processed with standard encryption. No sensitive confidential credentials should be sent via public forms.