Venkata Surya Rashmi Tallapragada

Additional Info

Nominee’s NameVenkata Surya Rashmi Tallapragada
Nominee’s Job Title or RolePCN/OT risk analyst
Company / OrganizationChevron
Company size4,000-6,999 employees
CountryUnited States
World RegionNorth America
Websitehttp://linkedin.com/in/rashmi-tallapragada-409274162

NOMINATION HIGHLIGHTS

I am a cybersecurity and risk analyst with over seven years of experience, specializing in enterprise risk governance and Process Control Network (PCN) security. With a Master’s degree in Cybersecurity and a CISA certification, I’ve worked extensively on aligning internal controls with industry frameworks such as NIST 800-53, SOX, and PCI-DSS across both IT and OT environments.

My career has focused on building policy-driven security programs that address the complex challenges of real-world operations. I have authored more than ten enterprise cybersecurity policies and standards, including those covering access control, identity management, and incident response. My work not only supports compliance but also ensures that security controls are operationally feasible in legacy and industrial control systems.

One of my most meaningful contributions has been addressing the limitations of traditional IT security controls in OT environments. I’ve led initiatives that introduced compensating control models where enforcement of standard practices, like user session timeouts or centralized logging, could negatively impact uptime or safety. These contributions reflect my ability to translate risk requirements into solutions that are both compliant and practical.

In addition to my technical leadership, I conduct peer reviews of internal assessments and vendor risk reports, helping ensure consistency and quality across security operations. I’ve also published a professional article on the gaps in applying NIST standards to PCN systems, currently under review by ISACA.

Mentorship is an important part of my professional mission. I actively volunteer with the ISACA Houston Chapter and support emerging professionals pursuing careers in cybersecurity and risk management.

I believe effective cybersecurity is about more than controls , it’s about leadership, adaptability, and building systems that reflect the realities of the environments we protect. That perspective, and my commitment to serving both industry and community, drive me forward every day.