It Security Auditor Resume
2.00/5 (Submit Your Rating)
VA
SUMMARY:
- Highly proficient and experienced IT Auditor entrusted with managing complex and multi - system application control, SOX, SAP, SAS70, FISCAM, FISMA and GCC projects affecting large number of users nationwide, with reputation for adept leadership of business to IT workflow analyzes and walkthroughs and testing relating to Information Technology General Controls (ITGCs).
TECHNICAL SKILLS:
- Microsoft words
- Excel
- Share Point Based System
- SAP
- Oracle Financial and use of automated scripts
PROFESSIONAL EXPERIENCE:
Confidential, VA
IT Security Auditor
Responsibilities:
- Prepare IT audit program to include access control, change management controls and application controls; and identify deficiencies in the design and operating effectiveness of control and provide recommendation.
- Identified and communication IT audit findings to senior management and clients.
- Maintain good working relationship with the clients to enhance customers’ satisfaction and work with client management and staff at all levels to perform audit service.
- Perform all stages of audit planning, fieldwork, executive, reporting and follow up.
- Conduct testing of Sarbanes-Oxley (SOX), OMB Circular A-123 Audit and Service Organization Control (SOC) SSAE 16 Review, using COBIT and FISCAM frameworks.
- Train junior auditors on auditing standards and provide them technical audit training such as auditing Windows, auditing PeopleSoft, SAP and other audit concepts.
- Participate in team kick-off meetings and drew up audit plans
- Review of IT General Controls (ITGC) and various applications, databases, operating systems and network devices
- Perform and document audit activities in accordance with professional standards such as COBIT, COSO and SOX internal control frameworks Audit Project.
- Handle of special projects such as Segregation of Duties (SOD) and SOX Compliance business challenge projects HIPAA and identify conflicts or inadequate internal controls and provide recommendations
IT Security Auditor
Responsibilities:
- +Performed assessment of IT internal controls as part of financial statement audit, Internal and operational audits, Attestation engagement, and Audit readiness.
- Performed IT general controls testing for Sarbanes-Oxley 404 compliance in public companies, OMB A-123 in government agencies, and Service Organization Control (SOC) reports in compliance/SSAE16 (formerly SAS 70). participated in SAP Transaction testing to perform, including testing of segregation of duties to assist the client in improving their user management, authentication management, authorization management, access management, and provisioning capabilities.
- Performed FISCAM audits on Health and Human Services (HHS), Centers of Medicare and Medicaid Services.
- Performed audit of Windows and UNIX logical access controls, including administrative access review, and provided recommendations for remediation of the identified risks and vulnerabilities.
- Performed audit tests, compliance tests and substantive tests and identified key controls and weak points and mapped it against COBIT framework.
- Implemented section 404 and 302 of SOX Acts and tested controls over Segregation of duties, change management and worked on the evidences gathered to support the SOX Acts Compliance Program
- Tested compliance with company policies and procedures to ensure it conforms to industry standards; such as HIPAA and PCI DSS frameworks.
- Tested and evaluated the effectiveness and adequacy of General Computer controls on the Organization’s policies and procedures.
- Demonstrated an understanding of the client’s environment and assessed the adequacy of the application security, application configuration and business Process controls.
Compliance Officer
Responsibilities:
- First Aid, AED and CPR to be performed on a person involved in an accident at the work place.
- Customer service duties which include signing visitors into the visitor database and also employees who misplace their government badges.
- Escorts within the facility
- Control access and egress into the facility.
- Use of X-ray and magnetometer to prevent people from bringing explosives or weapons into facility.
- Extensive search of vehicles at the entry points to prevent explosives or weapons into facility