Experienced Risk and Compliance professional with 8 years of experience in multiple areas of Business Risk and Compliance and IT Governance. Experienced in Information Security assessment of Databases and Applications, internal and external Business, and IT Audits. Working knowledge of frameworks and regulations including SOX, SOC 1, SOC2, ISO 27001, NIST, FedRamp, PCI and GDPR. Effective communicator and experience in collaborating with stakeholders and teams. Experience with remote auditing techniques, team, and project management.
• Spearheaded and executed multiple client engagements (public & non-public) across Insurance, Aerospace, and Healthcare industries.
• Skilled in Sarbanes-Oxley Section 404 (SOX 404) Compliance, Financial Statement Integrated IT Audit, IT
• Provided consultation on engagements by applying ISO 27001 & NIST cyber standards to evaluate risks on audit and department wide initiative to
establish audit framework for emerging technologies.
• Supervised and executed PCI compliance framework for banking clients to ensure cardholder data is protected.
• Experienced in testing business process controls like Revenue Recognition for in-scope applications and systems.
• Risks & Controls Assessment, and 3rd party reporting (SSAE 16/SAS 70/ SOC) type engagements
• Solid understanding of infrastructure, IT general system controls, business process controls; practical audit experience conducting risk assessments and executing audit programs
• Evaluate key business/IT risks and controls to prepare audit programs and communicate defined scope with stakeholders by reviewing the system architecture and designing effective test plans.
• Identify control deficiencies and present findings to key business/IT stakeholders that assisted management in timely mitigation of issues impacting considerable number of customers and potential regulatory concerns.
• Identify improvements in post audit issue closure process for the team including identifying resources/budget that enhanced timely closure of regulatory and non-regulatory issues.
• Collaborate with business audit teams to prepare audit reports, document/review test results and manage budgets and resources.
• Exhibited project management skills, including developing project plans, budgets, and deliverable schedules.
• Supervised, trained, and developed junior staff and interns through on-the-job coaching and timely feedback.
• As a Lead Senior, directed the daily audit progress, and managed team performance.