Senior It Auditor
Current• Led audit projects in assessing risk, evaluating controls, identifying process inefficiencies as well as determining compliance with policies, procedures, regulations, and frameworks• Partnered with IT Management to assess the maturity of the IT control environment against the NIST Cybersecurity Framework and provided guidance for control design and mapping throughout adoption of the Framework (Included considerations of SANS CIS Top 20 controls, COBIT, and NIST 800-53)• Worked with Information Security and Third Party QSA during annual PCI DSS Compliance Audits• Led or contributed to IT Audit projects relating to key Company strategic initiatives and priorities across a broad range of domains including IT SOX Compliance, Mobile Device Security, Shadow IT Processes, Data Loss Prevention, Data Privacy, Business Continuity and Disaster Recovery Plans and Exercises, Incident Response Planning, Vendor Risk Management, Security Operations Center and Network Operations Center Implementation, Multiple Application Implementations, Fraud Investigations and end-to-end system and process reviews in support of Legacy System Re-Writes• Presented audit project findings and recommendations to various levels of management as well as performed follow-up to ensure management action plans were appropriately resolved.• Acted as the audit liaison responsible for IT SOX compliance coordination with Ernst & Young external auditors (planning, scoping, communication of deficiencies and remediation plans)• Coached and performed on-the-job training to staff regarding audit process, risk and controls, work paper documentation standards, sampling methodology, etc