Resourceful Auditor with over 7 plus years hands-on experience in ITGC detailed/Walkthrough control testing, SOC, SOX, SAP applications, IT infrastructure, PCI DSS, SQL server, Window server, GDPR control assessment using NIST, ISO 27001, COSO, COBIT, FISMA & FISCAM. Am Well-versed in in independent testing, Risk assessment, Audit review, Cybersecurity reporting, People management, policy management, creating procedure, compliance testing, Business analysis, process improvement, sustainability, Business continuity, strategic planning, time management, client relationship, system integration, agile methodology, data management, business collaboration, vendor management, fieldwork mapping, operational design, and implementation.
Organized and dependable candidate successful at managing multiple priorities with a positive attitude. Willingness to take on added responsibilities to meet team goals.
· Developed and created IT Audit program including access control, change management, IT operations and application controls Identified deficiencies in the design and operating effectiveness of controls and provided recommendations for all clients
· Implemented appropriate security controls for information system based on NIST 800-53 rev 4
· Participated in SAP transaction testing to perform included testing of segregation of duties to assist the client in improving their user management, authentication management, authorization management, access management and provisioning capabilities
· Conducted ITGC walk through and detailed testing by reviewing document and observing procedures to gather useful evidence
· Involved in conducting SOX ITGCs testing and IT application Control testing, audit readiness, attestation engagements, Infrastructure audit, compliance, and risk assessment
· SOX walkthrough meetings with control owners, and internal/external auditors, and perform follow-up discussions as needed
· Performs walk through and executes testing procedures to determine control design/operating effectiveness against industry standards (SOX, COBIT, COSO, FISMA, FISCAM, A-123, ITIL, NIST, FFIEC)
· Conducted and supervised end to end SOX IT audit process including engagement planning, coordination, scope determination, risk and control identification, design of audit program, procedures, test control and evaluate results.
· Drafted well-written audit reports and other communication to foster accurate interpretation.
SAP, SQL Database, FFIEC, ISO 27000, 27001, 27002 OCC, NIST SP 800-53 Rev 4, metric stream, Rally, UNIX, Microsoft Dynamics, NetSuite, Windows Server, IDEA, SOX, Oracle Database, GRC Archer and Aurora, Prime, PeopleSoft, CARS, Linux, Network Systems, Security , Microsoft Windows, ERP, Active Directory, Azure, AWS,
Microsoft Office Suite (Word, PowerPoint, Excel, Access), SQL database, SSIEM, Intrusion Detection Systems, Firewall, SOC 2, SOC 123, HIPAA, PCI DSS, PeopleSoft, ACL, ATS, Agile Methodology, COBIT, Share Point-Based System, Audit Command Language (ACL)
Certified Information Security Auditor