Everything in a risk-based information security compliance or governance model should be driven by business risk, which is managed by a combination of: 1) entity-level controls; 2) manual and automated business process/application controls; and 3) controls within IT general control processes. All three elements must be carefully structured and continuously monitored to ensure the organization is meeting its objectives in the most effective manner possible.• Seasoned technology risk management professional with experience in a wide range of industry verticals.• SOX 404 Specialist - Sarbanes-Oxley Section 404 information technology controls compliance consulting & auditing.• IT Controls Expert - Information technology general & application controls design and effectiveness evaluations, especially experienced in software change management & systems development life cycle methodology planning, auditing, & management.• Risk Assessment - Information technology risk assessment development, planning, & consulting.• Business Continuity/Disaster Recovery Planning (BCP/DRP), development, assessment, & auditing, including business impact analysis (BIA).• IT Audit Staff Development – Technical & “soft” skills set development; coaching, mentoring, supervising; developing operational/financial auditors for true integrated auditing• Business Process Design/Analysis/Improvement – Focused on doing the right thing right, the first time, for all customers & stakeholders • COBIT Implementation – Re-engineering business & IT processes to improve operational maturity through COBIT design & controls principles• Project & program management, organizational development, & strategic planning consulting.Specialties: FFIEC IT audit and examination readiness; SSAE 16/18; SOX 404; financial statement audit support; HIPAA/HITRUST risk assessments, business process and technology risk assessments; process evaluations; general and application controls design & effectiveness evaluations; change management & systems development life cycle methodology & process planning, development & implementation; process reviews & audits.
Listed skills include It Audit, Governance, Security, Program Management, and 50 others.