CISA-certified cybersecurity & compliance expert · Founder & CEO, ITSECOPS · Speaker on AI and cybersecurity
Gaurav Sengar is a CISA-certified cybersecurity and compliance expert with more than 12 years across security operations, IT audit and regulatory compliance. He is the founder and CEO of ITSECOPS, a security-first IT operations company running defense-grade security and compliance operations across four continents, and he speaks internationally on AI and cybersecurity.
About Gaurav Sengar
Gaurav founded ITSECOPS on a simple conviction: IT operations should be built security-first, not patched after the fact. Today the firm runs 24/7 security operations, managed IT and compliance programs for clients across Europe, North America, the Middle East and Asia, from offices in Stavanger (Norway) and Greater Noida (India).
His specialist niche is a category of one: he is the CMMC specialist that US defense-supply-chain contractors outside the United States call — navigating US-persons restrictions on ITAR data, remote C3PAO assessment logistics and enclave scoping from Europe, the Gulf and Asia.
Credentials and expertise
- CISA — Certified Information Systems Auditor (ISACA), the global benchmark credential for information systems audit, control and assurance.
- 12+ years in cybersecurity, IT operations and compliance, from hands-on security engineering to running a multi-country SOC.
- Frameworks: CMMC and NIST SP 800-171, NIS2, ISO 27001, SOC 2, GDPR, DFARS 252.204-7012.
- Operations: 24/7 SOC leadership with sub-15-minute mean time to triage, Microsoft 365 and Azure security, zero-trust rollouts.
AI and cybersecurity
Gaurav works at the intersection the industry is still figuring out: what AI does to security, and what it can do for it. He advises organisations on adopting AI without opening new attack surface — data exposure, model and prompt risk, vendor governance — and on putting AI to work inside the security function itself: alert triage, detection engineering and compliance evidence automation. ITSECOPS runs AI-assisted tooling in its own SOC and on its own website, so his positions come from production experience, not slideware.
What he leads at ITSECOPS
- 24/7 Security Operations — managed SOC with sub-15-minute mean time to triage.
- Compliance engineering — CMMC, NIS2, ISO 27001, SOC 2 and GDPR programs that deliver controls, not just documents.
- Cloud & infrastructure security — Microsoft 365, Azure and zero-trust architecture.
- MSP enablement — white-label NOC/SOC and L1–L3 support for MSPs in the US, UK and Europe.
Public work and free tools
- SPRS Score Calculator — all 110 NIST SP 800-171 controls with official DoD weights, no signup.
- CMMC Cost & Roadmap Planner — interactive cost and timeline estimator.
- CMMC Cost Index — annual, citable cost benchmarks for eight contractor profiles.
- Open-source SPRS scoring engine on GitHub (MIT).
Speaking and media
Gaurav speaks at CISO events, industry panel discussions, cybersecurity meetups and on podcasts, on AI security and defense-supply-chain compliance. He is available worldwide, on-site or remote, for keynotes, panels, podcasts and workshops.
Frequently asked questions
Who is Gaurav Sengar?
Gaurav Sengar is a CISA-certified cybersecurity and compliance expert and the founder and CEO of ITSECOPS, a security-first IT operations company operating across four continents from bases in Stavanger, Norway and Greater Noida, India.
What is Gaurav Sengar known for?
He is best known as the CMMC specialist for defense suppliers outside the United States, for free public compliance tooling (the SPRS Score Calculator, CMMC Cost & Roadmap Planner and the annual CMMC Cost Index), and for practitioner-grade commentary on AI in cybersecurity.
What certifications does Gaurav Sengar hold?
He holds the CISA (Certified Information Systems Auditor) credential from ISACA and has more than 12 years of experience across cybersecurity, IT audit and compliance.
Is Gaurav Sengar available for speaking engagements?
Yes. He speaks at conferences, CISO roundtables, panels and podcasts worldwide on AI and cybersecurity, CMMC and EU regulation such as NIS2. See the speaking page or email info@itsecops.cloud.
Contact
E-post info@itsecops.cloud · Stavanger, Norway · Greater Noida, India · Book a consultation