Portrait of Vishal Bhatt
Ontario, Canada Open to opportunities
Identity & Access Management · GRC

From access control to
audit control — governance
that holds up under scrutiny.

I'm Vishal Bhatt — Senior Manager, Technology & Security Operations at PwC, with 19 years in IT security — from systems administration and desktop engineering to identity management, and now leading GRC and audit-focused security operations across the PwC network.

Six disciplines, one objective.

Access that's provable — not just designed, but demonstrable under audit, and increasingly, automated at scale.

01
Identity & Access Management
Enterprise IAM programme design and delivery — joiner/mover/leaver lifecycle automation, access certification, role modelling, and least-privilege enforcement across hybrid estates.
02
Privileged Access & Security Operations
CyberArk-certified (Defender, Sentry) PAM design — vaulting, session control, and running the operations teams that keep an organization's most powerful accounts contained.
03
IT Audit & Security Assurance
Control design and testing, access-risk remediation, and audit readiness — translating technical findings into decisions leadership can actually act on.
04
AI & Agentic Automation for GRC
Leading GenAI/LLM and RPA initiatives that automate internal audit and GRC workflows — building agentic AI systems, and owning the business case and ROI for AI adoption across the team.
05
Vulnerability Management
Vulnerability scanning, risk-based prioritization, and remediation tracking using Qualys and Tenable — closing the gap between finding a weakness and actually fixing it.
06
Data Privacy & Protection
Data loss prevention (Websense DLP) and privacy-conscious data handling, extended to how AI systems and workflows collect, process, and retain information.

Nineteen years in the identity layer.

From on-prem Active Directory to cloud-native IGA — I've governed access through every architecture shift the last two decades produced.

I lead the IAM–GRC pillar at PwC, directly managing a team of 6–8 and working across 50+ senior stakeholders — service leaders, Senior Managers, and program managers — through audit and compliance. Beyond my direct team, I also drive outcomes across 30+ cross-functional team members, influence without formal authority, exercised daily. My path ran from systems administration and Apple Retail IS&T support, through IAM analyst roles, into PwC UK and then PwC Canada, and now covering across the PwC network globally — 100+ member firms — where I've spent 10+ years rising from Senior Associate to Senior Manager.

My work sits at the intersection most security programs get wrong: identity governance that can survive an audit, not just a diagram. Access certifications, privileged account controls, attestations, and the evidence trail that proves a control actually operated — not just that it existed on paper.

Over the last year, I've extended that focus into AI-driven automation — leading GenAI/LLM and RPA initiatives, building agentic AI systems, and owning the ROI case for AI adoption within the team, to automate internal audit and GRC workflows that once relied entirely on manual review.

19
Years in IT & security
10+
Years at PwC
8
Years at manager level+
50+
Senior stakeholders engaged
TOOL STACK
CyberArk (PAM) SailPoint IGA ForgeRock Microsoft Entra ID Active Directory Qualys Tenable Splunk Websense DLP Microsoft Copilot PowerApps
AI & AUTOMATION
GenAI / LLM Tooling Agentic AI Systems RPA (Robotic Process Automation) AI ROI & Business Case Ownership Audit & GRC Process Automation
GOVERNANCE & RISK FRAMEWORKS
ISO 27001 NIST RMF COBIT SOC 2 / SOC 1 Access Certification & Attestation Segregation of Duties (SoD) IT General Controls (ITGC)
LEADERSHIP & STAKEHOLDER SKILLS
Team Leadership (6–8 direct reports) Senior Stakeholder Management (50+) Matrixed Leadership — Influence Without Authority (30+) Executive & Audit Communication Cross-Cultural Team Management Vendor & Client Relationship Management Change & Process Governance
LANGUAGES
English Hindi
EDUCATION

MSc, Networking & Computer Systems Security
University of Greenwich · 2009–2010

BEng (Hons), Computer Technology
University of East London · 2006–2009

Graduate Diploma, IT & Management
College of Informatics & Applied Technologies · 2005–2006

Diploma, Computer Technology
Bharati Vidyapeeth · 2002–2005

Escalating privilege, on purpose.

Each role expanded scope — from supporting individual endpoints to governing identity programs enterprise-wide.

Jul 2021 — Present
TIER 5 · SENIOR MANAGER
Senior Manager, Technology & Security Operations — IAM
PwC · Global Network (100+ member firms) · based in Ontario
Own the IAM–GRC pillar. Direct a team of 6–8 and engage 50+ senior stakeholders across the PwC network; drive access governance, attestation cycles, and PAM/IGA strategy through matrixed influence across 30+ cross-functional team members. Also lead the team's AI initiatives — GenAI/LLM and RPA-driven automation of audit and GRC processes, with ownership of the ROI case for adoption.
Aug 2018 — Jul 2021
TIER 4 · MANAGER
Manager, Technology & Security Operations — IAM
PwC · Toronto
Stepped into people leadership within IAM operations, building the governance processes that scaled into the Senior Manager remit.
May 2017 — Aug 2018
TIER 3 · SR. ASSOCIATE
Sr. Associate ITSRM — Security Analyst
PwC Canada · Toronto
IT security risk management analysis, bridging technical control assessment with client-facing risk reporting.
Jul 2016 — Apr 2017
TIER 3 · SR. ASSOCIATE
Sr. Associate, Information Risk & Security — Product & Service Engineer
PwC UK
Entered PwC via the UK practice, engineering information risk and security products and services.
Mar 2015 — Jul 2016
TIER 2 · ANALYST
Desktop Services & Identity Access Management Analyst
IG
First dedicated IAM role — the pivot point from general IT support into identity as a specialization.
Jan 2011 — Sep 2014
TIER 1 · SUPPORT
Mac Support & IS&T Support
Apple Retail
Nearly four years supporting Apple's internal systems and retail technology at scale.
Aug 2007 — Aug 2008
TIER 0 · ORIGIN
System Administrator
SpiriTel PLC
Where it started — hands-on infrastructure administration.

Issued & active.

Active, currently-held certifications across security, identity, and governance.

GRANTED
CISSP
ISC2
GRANTED
CGRC
ISC2
GRANTED
SSCP
ISC2
GRANTED
MBCS
British Computer Society
GRANTED
CyberArk Sentry
CyberArk
GRANTED
Defender – PAM
CyberArk
GRANTED
Scrum Foundations (SFPC)
SCRUMstudy
GRANTED
Apple Certified Maintenance Technician
Apple
GRANTED
Apple Sales Professional
Apple

Early infrastructure and networking credentials — lapsed, shown for career-trajectory context only.

EXPIRED
MCSE 2003
Microsoft
EXPIRED
MCSA 2003
Microsoft
EXPIRED
CCNA
Cisco

Writing & commentary.

Notes on identity, security, and GRC — spanning IAM, vulnerability management, data privacy, and AI-driven automation — cross-posted from video and long-form.

[ NO ENTRIES LOGGED YET — FIRST POST PENDING ]

This feed is wired up and ready. Drop in your first article, video, or LinkedIn cross-post and it renders here automatically — no rebuild needed.

Let's talk identity,
governance, or opportunity.

Open to conversations on IAM/GRC leadership roles, business development and partnership opportunities, or speaking engagements — particularly across the UAE and Saudi Arabia, and open to opportunities across the Americas and UK.

credential_summary.txtverified