Senior, It / Is Audit Consultant
Current- Lead audits of IT systems and business applications such as Windows Active Directory, Windows Server review, SAP system, and Oracle Database.- Conducting assurance reviews to evaluate the effectiveness of control implemented to mitigate risks and ensure adherence to management standards. - Benchmarking Information Security policies against ISO 27001, and IT policies against COBIT 5 framework for governance and management of IT. - Performing IT application controls (ITAC) review covering controls on system access, configuration, processing, and calculation. - Reviewed configuration management controls on key networking devices including Routers, Switches, and Firewalls using Nipper Studio, and performed Risk Assessments based on Information Security Policy and standards such as ISO 27001, CIS CSC, NIST 800-53, and NIST CSF. - Performing gap assessments to assess deficiencies and leveraging the evaluation to improve ISMS and obtain ISO certifications. - Supporting vendor security controls maturity assessment by leveraging the CMMI model and reviewing vendor security compliance for all tier-1 vendors as part of the third-party risk management process to cover data security, privacy, integrity, and availability. - Providing guidance on security compliance and GRC programs for corporate clients through review of risk management practices and controls. - Analyzing system security posture, policies, and documents determined NIST SP 800-37 compliance, CIS CSC, and developing an overall security compliance framework.