PCI DSS & SWIFT CSP Consultant · Senior Manager, GRC

Compliance that holds up under audit.

I'm Madhup Bajpai. I help banks, payment processors and merchants turn PCI DSS, SWIFT CSP, NIST CSF and ISO 27001 requirements into controls that pass assessment and actually reduce risk.

About

From gap analysis to signed attestation.

I'm a cybersecurity and risk consultant with more than eight years of leading several high-stakes engagements at once. My work sits between the auditor and the engineer: I translate dense requirements such as PCI DSS, NIST CSF, SWIFT CSP, CBUAE and the NPCI risk and compliance framework into a plan that technical teams can execute and leadership can sign off on.

Today I lead PCI DSS delivery at Sandbox Security, producing Reports on Compliance, Attestations of Compliance and SAQs, and acting as delivery head across concurrent projects. Before that I built assessment practices at Atos, Deloitte, NetSentries and Crossbow Labs.

Based in
Bengaluru, India
Works across
India · GCC · Americas · APAC · Africa
Education
B.Tech, Computer Science & EngineeringAlliance College of Engineering & Design · 2012–2016
Focus sectors
Banking, payments, fintech, merchants

Experience

Five firms, one discipline.

  1. – Present

    Current

    Senior Manager

    Sandbox Security Pvt. Ltd.

    • Leads PCI DSS implementation and compliance assessments, producing RoCs, AoCs and SAQs.
    • Runs several engagements at once as engagement lead and delivery head.
    • PCI DSS v4.0.1
    • RoC
    • AoC
    • SAQ
    • Delivery lead
  2. Consultant, GCM-4

    Atos

    • Led PCI DSS implementation and compliance assessments, and produced RoCs and SAQs.
    • Performed PCI DSS readiness and security assessments against NIST CSF and NPCI frameworks.
    • Worked with client technical and business teams to find remediation gaps and practical fixes.
    • Presented assessment results and recommendations to technical and business audiences.
    • PCI DSS
    • NIST CSF
    • NPCI
    • Readiness
  3. Solution Advisor

    Deloitte USI

    • Directed NIST CSF maturity evaluations, identifying policy, procedural and control gaps.
    • Authored enterprise security policies aligned with NIST to raise security maturity.
    • Reviewed complex architectures against NIST and reported improvements.
    • Benchmarked clients with proprietary tooling to guide security investment decisions.
    • NIST CSF
    • Policy
    • Architecture review
    • Benchmarking
  4. Consultant

    NetSentries Technologies

    • Owned the full SWIFT CSP compliance lifecycle, from scoping and client interviews to gap analysis and control validation.
    • Advised client information security offices on SWIFT CSP requirements.
    • Defined the assessment approach and standardised review and validation processes.
    • SWIFT CSCF
    • Gap analysis
    • Methodology
  5. Associate Consultant

    Crossbow Labs LLP

    • Ran PCI DSS gap assessments to define scope and baseline compliance across a diverse merchant portfolio.
    • Guided merchants through SAQ A, SAQ C-VT and SAQ D.
    • PCI DSS
    • SAQ A
    • SAQ C-VT
    • SAQ D

Earlier 247.AI · Runnr (Carthero Technologies) · Finalytics Consultancy

Skills

Frameworks I audit and implement.

Frameworks

  • PCI DSS v4.0.1Audit · Implement
  • SWIFT CSP / CSCFAudit · Implement
  • ISO/IEC 27001:2022Audit · Implement
  • NIST CSFAssess · Mature
  • CBUAE CPSAssess
  • NPCI complianceAssess

Capabilities

  • Auditing and assessment
  • Security strategy and roadmaps
  • Policy and framework development
  • Zero Trust architecture
  • Third-party risk (TPRM)
  • Programme management (PMO)

What I deliver

  • Report on Compliance
  • Attestation of Compliance
  • SAQ A · C-VT · D
  • SWIFT CSCF assessment
  • Gap analysis
  • Remediation roadmap
  • Policy suite
  • Board reporting

Every finding I write comes with an owner, a fix and a date. An assessment is only useful if it changes something.

Clients

49 clients across 8 countries.

    By framework

      Certifications

      Credentials you can verify.

      ISO/IEC 27001:2022 Lead Implementer

      Information security management

      Certified

      ISO/IEC 27001:2013 Lead Auditor

      Information security management

      Certified

      Contact

      Planning an assessment?

      Tell me about your scope, your deadline and the framework. I'll tell you honestly what it takes.

      Message me on LinkedIn