Summary
Overview
Work History
Education
Skills
Timeline
Generic

Robby Sutherland

Summary

Senior GRC and Information Security leader with 9+ years of experience spanning Big Four advisory (EY) and progressive leadership roles in compliance, risk management, and assurance delivery across complex SaaS and enterprise environments. Currently leads a 25-person compliance organization and operates Centers of Excellence for Risk Assessments, HIPAA, and C5, defining standardized methodologies, control frameworks, and scalable audit execution practices that drive consistency and quality across XXX SOC and risk engagements annually. Serves as the executive owner of a strategic partnership with Vanta, acting as the primary liaison between audit delivery teams and platform stakeholders to align SOC, HIPAA, and risk assessment methodologies with modern compliance automation and GRC platform workflows. Recognized for translating audit friction, customer compliance challenges, and framework interpretation issues into structured feedback loops that improve internal processes and inform platform optimization and product-adjacent improvements. Combines deep technical expertise in SOC 1, SOC 2, HIPAA, C5, CSA STAR, Microsoft SSPA, IT general controls, and NIST-based risk assessments with a systems-oriented approach to scaling compliance programs, improving audit readiness, and advancing compliance toward automated, platform-driven models, serving as a trusted advisor to internal leadership, auditors, and technology partners focused on operational excellence, SME development, and the evolution of modern GRC ecosystems.

Overview

10
10
years of professional experience

Work History

Senior Manager, SOC

A-LIGN
05.2023 - Current
  • Lead a 25-person compliance delivery organization executing SOC 1, SOC 2, HIPAA, C5, CSA STAR, Risk Assessments, and Microsoft SSPA engagements across a diverse portfolio of SaaS, technology, and enterprise clients.
  • Own and operate Centers of Excellence (CoEs) for Risk Assessments, HIPAA, and C5, defining standardized methodologies, control interpretation guidance, quality benchmarks, and audit execution practices adopted across the organization.
  • Serve as executive owner of A-LIGN’s strategic partnership with Vanta, acting as primary liaison between audit delivery teams and platform stakeholders to align SOC, HIPAA, and risk assessment methodologies with product workflows and customer implementations.
  • Translate real-world audit friction, control interpretation challenges, and customer implementation issues into structured feedback loops that inform platform optimization, automation opportunities, and scalable compliance delivery improvements.
  • Partner cross-functionally with internal operations, delivery leadership, and external GRC technology stakeholders to improve audit readiness workflows, reduce evidence collection inefficiencies, and increase consistency of compliance outcomes across engagements.
  • Develop and implement enterprise-level engagement models and operational frameworks that standardize delivery across teams, improving scalability, quality assurance, and time-to-completion for complex compliance programs.
  • Act as senior subject matter expert across SOC reporting standards, HIPAA Security Rule requirements, C5 controls, CSA STAR mappings, and NIST-based risk methodologies, advising both internal teams and external stakeholders.
  • Lead continuous improvement initiatives focused on aligning audit execution processes with emerging GRC automation platforms and trust management systems, including structured collaboration with platform partners such as Vanta.
  • Mentor and develop senior managers and consultants across technical compliance domains, building internal SME capability and strengthening delivery consistency across frameworks and client engagements.

Manager, SOC

A-LIGN
07.2021 - 05.2023
  • Managed end-to-end delivery of SOC 1, SOC 2, HIPAA, risk assessment, and compliance engagements across a portfolio of technology and SaaS clients, ensuring consistent application of control frameworks and audit methodology standards.
  • Acted as primary client-facing compliance advisor, translating complex regulatory and framework requirements (SOC, HIPAA, NIST-based controls) into actionable remediation plans and audit-ready compliance programs.
  • Led execution teams through planning, fieldwork, and reporting phases of assurance engagements, coordinating cross-functional stakeholders to ensure timely delivery of high-quality audit outcomes.
  • Developed repeatable engagement processes and internal methodologies to improve consistency, scalability, and quality of compliance delivery across multiple concurrent client engagements.
  • Identified recurring audit friction points and control interpretation challenges, surfacing structured feedback to senior leadership to improve internal tooling, templates, and delivery workflows.
  • Supported the development and training of junior and mid-level staff on SOC reporting standards, risk assessment methodology, and evidence evaluation practices, contributing to internal SME capability building.
  • Collaborated with senior leadership and adjacent service lines to enhance service delivery models and improve alignment between client expectations, auditor requirements, and operational execution.
  • Contributed to early-stage partnership and ecosystem integration work with GRC platforms (including Vanta), gaining exposure to compliance automation workflows and platform-driven audit readiness processes.

Associate Manager, SOC

A-LIGN
09.2020 - 07.2021
  • Managed execution of SOC 1, SOC 2, HIPAA, and risk assessment engagements for a portfolio of technology and SaaS clients, supporting end-to-end delivery across planning, fieldwork, reporting, and remediation phases.
  • Acted as primary day-to-day client lead on compliance engagements, translating SOC and HIPAA framework requirements into clear audit procedures, evidence expectations, and remediation guidance.
  • Coordinated cross-functional engagement teams to ensure timely execution of compliance assessments, maintaining quality standards across multiple concurrent audits and regulatory frameworks.
  • Applied structured understanding of SOC reporting standards, control testing methodologies, and risk assessment frameworks (including NIST-aligned approaches) to support consistent audit execution and documentation quality.
  • Identified recurring inefficiencies in evidence collection, control mapping, and client readiness activities, contributing feedback to improve internal templates, engagement tooling, and delivery workflows.
  • Supported senior managers in defining engagement strategy, scope planning, and risk scoping decisions across complex multi-framework compliance programs.
  • Delivered client-facing presentations and walkthroughs of control environments, audit findings, and remediation requirements to both technical and executive stakeholders.
  • Developed early subject matter expertise across SOC 2 Trust Services Criteria, HIPAA Security Rule requirements, and enterprise risk assessment methodologies, building foundation for later SME and leadership roles.
  • Contributed to internal knowledge sharing and onboarding of junior staff, reinforcing consistent application of audit methodology and documentation standards across teams.

Senior IT Risk Consultant

Ernst & Young
05.2018 - 09.2020
  • Led execution of IT risk and assurance engagements for Fortune 500 and high-growth clients, supporting SOC 1, SOC 2, and IT general controls (ITGC) assessments across complex enterprise environments.
  • Performed detailed control testing, risk assessments, and audit procedures aligned with SOC reporting standards, identifying control gaps and recommending remediation strategies to strengthen compliance posture.
  • Acted as a client-facing senior resource for walkthroughs of IT environments, control design assessments, and evidence validation across infrastructure, applications, and security domains.
  • Managed day-to-day delivery workstreams on multi-phase audit engagements, coordinating across global teams to ensure accuracy, completeness, and adherence to regulatory and reporting requirements.
  • Acted as a trusted advisor to client stakeholders by translating technical control deficiencies into business-impacting risk narratives and actionable remediation guidance.
  • Contributed to engagement planning, scoping, and risk assessment activities, helping define audit approach and identify key systems and controls in scope for SOC and IT risk reviews.
  • Mentored junior staff on audit methodologies, control testing procedures, and documentation standards, improving consistency and quality of deliverables across engagement teams.
  • Supported business development efforts by strengthening key client relationships and contributing to expanded engagement scope through delivery excellence and stakeholder trust.
  • Developed foundational expertise in IT general controls, access management, change management, and system operations—building early specialization in SOC and enterprise risk frameworks.

Staff IT Risk Consultant

Ernst & Young
06.2016 - 05.2018
  • Executed IT audit procedures for Fortune 500 clients, including SOC 1 and SOC 2 control testing, IT general controls (ITGC), and risk-based audit procedures across financial and operational systems.
  • Performed walkthroughs and testing of key control areas including user access management, change management, IT operations, and system development lifecycle controls.
  • Documented audit findings and control deficiencies, providing actionable remediation recommendations aligned with SOC reporting standards and firm methodology requirements.
  • Supported senior team members in planning and executing audit procedures, enhancing evidence collection, sampling, and control design evaluation across client environments.
  • Gained hands-on experience with enterprise IT environments, developing foundational understanding of infrastructure, applications, and control frameworks supporting compliance programs.
  • Assisted in preparing client deliverables, including SOC report support documentation and internal workpapers ensuring audit quality and regulatory compliance standards.
  • Engaged in client meetings and walkthroughs to gather critical system information, assess control environments, and validate audit evidence.
  • Built core competency in IT risk, compliance, and audit execution methodologies that formed the foundation for progression into senior advisory and leadership roles.

Education

Bachelor of Science - Finance

Miami University, Farmer School of Business
Oxford, OH
05-2016

Skills

  • SOC 1, SOC 2, HIPAA, C5, Microsoft SSPA, NIST 800-30 Risk Assessments, ITGCs
  • GRC Platforms Workflows
  • Control Mapping and Framework Harmonization
  • Product Feedback Loop Development
  • Customer Escalation and Executive Partnership Management
  • Audit methodology standardization
  • Cross-team Collaboration
  • Executive-level Stakeholder Communication
  • Multi-level Team Leadership

Timeline

Senior Manager, SOC

A-LIGN
05.2023 - Current

Manager, SOC

A-LIGN
07.2021 - 05.2023

Associate Manager, SOC

A-LIGN
09.2020 - 07.2021

Senior IT Risk Consultant

Ernst & Young
05.2018 - 09.2020

Staff IT Risk Consultant

Ernst & Young
06.2016 - 05.2018

Bachelor of Science - Finance

Miami University, Farmer School of Business
Robby Sutherland