Head Of It & Security Audit And Risk
Blackfriars, London, Gb
Created and implemented Information Technology and Information Security internal audit methodology and audit team for €53 billion global company. Reduced business risk by identifying key information security and operational risks, prioritizing assessments, designing and implementing control improvements. IT risk business partner to senior management, including board and audit committee. Member of IT and Audit leadership teams. Led delivery of 50+ information technology audits globally. Implemented IT Risk, Compliance, and Control framework, based on COBIT 5, NIST Cybersecurity framework, and ISO 27001, 27002, and 27005. Introduced assessment programs for third parties (SSAE 16 SOC2, ISO/IEC 27001).Created global audit universe communicating the scope and scale of business risk, auditable entities, coverage, and weaknesses. Developed metrics to monitor and report on effectiveness of IT controls. Audited IT controls for information security, cybersecurity, privacy, business continuity, network security, identity and access management, vendors, incident response, change management, user devices, cloud software and platform as a service, patches and upgrades, data centers, and legal requirements.Developed and reviewed information security policies and standards, working collaboratively with IT, legal, human resources, compliance, and business units driving agreement and compliance. Designed 100s of improved information security, cyber security, and continuity controls and processes across all domains. Investigated breaches, security incidents, and sensitive issues as requested by management. Led digital internal audit project, implementing TeamMate cloud hosted software.Increased coverage of SAP to 90% of security controls for 100% of the population while reducing audit time by 40% by implementing automated testing.