Vice President Technology Risk
CurrentCreated and managed metric driven control surveillance based upon NIST framework integrated with control incident detection, response, and recovery framework. Established multiple Lines of Defense (3LOD) approach to ensure key controls are operating effectively and efficiently following SSAE16/ SOx guidelines. Implemented continuous control monitoring of IT General Controls and strengthened the relationship between Information Security, technology and business leadership to ensure the health of mainline controls, governance and oversight model from a reactive state to a predictive and ultimately a prescriptive approach. Findings are presented to business leadership, external auditors, federated network of Embedded Risk Officers, and Internal Audit and demonstrated through a quarterly risk control self assessment (RCSA).