Instructor
Tushar Kanchan
GRC & Cybersecurity Compliance Consultant | PCI DSS, SOC 2
About me
Tushar Kanchan is an independent information security and compliance consultant with 25 years of experience helping global organizations build audit-ready, resilient security and privacy programs. He now advises organizations directly on PCI DSS and broader GRC (governance, risk, and compliance) programs, drawing on a career built across senior compliance and information security roles at IBM, Standard Chartered GCC, [24]7, and Altisource, where he was directly accountable for driving certification and regulatory programs across PCI DSS, SOC 2, ISO 27001, HIPAA, GDPR, CCPA, and APEC Cross-Border Privacy Rules (CBPR).
His work has spanned complex, multi-country environments — including India, Philippines, United States, Canada, Guatemala, Colombia, and Nicaragua — where he managed compliance for 20+ locations at once, led client and regulatory audits, designed security architecture for cloud and enterprise environments, and served as the primary liaison between global compliance teams and external auditors and regulators.
At IBM, Tushar worked as a Subject Matter Expert on the PCI DSS compliance program for IBM Cloud, assessing new cloud services across IaaS, PaaS, and VPC environments for PCI scope and control readiness. At Standard Chartered Bank, he coordinated audit response across multiple countries as a central point of contact between country compliance teams and auditors. Earlier in his career, he held end-to-end ownership of PCI certification and SOC 2 attestation programs at [24]7 and drove HIPAA and PCI compliance across India, the US, and the Philippines at Altisource.
Tushar brings a practitioner's perspective to every course — translating dense regulatory text into practical, business-aligned steps that security, compliance, and risk professionals can actually implement. His teaching focuses on what auditors look for, how global compliance programs are really run, and how to build a security posture that satisfies regulators without slowing the business down. Through his consulting practice, he continues to work hands-on with organizations on PCI DSS and related compliance programs — the same real-world problems his courses are built around.