Managed Application Services, Associate Director, Soc Audit Program Lead
CurrentPrimary responsibility to lead the SOC (Service Organization Controls, a.k.a SSAE18) program across all IBM/Kyndryl Managed Application Services offerings which includes a mix of public and private cloud hosting solutions developed on IBM Cloud, Kyndryl GTS, Azure, AWS and Oracle.● Managed $1.3M SOC audit testing engagement budget to provide external attestation of security controls in cloud based application management services.● Identified opportunities to consolidate testing methods… Show more Primary responsibility to lead the SOC (Service Organization Controls, a.k.a SSAE18) program across all IBM/Kyndryl Managed Application Services offerings which includes a mix of public and private cloud hosting solutions developed on IBM Cloud, Kyndryl GTS, Azure, AWS and Oracle.● Managed $1.3M SOC audit testing engagement budget to provide external attestation of security controls in cloud based application management services.● Identified opportunities to consolidate testing methods and scope to reduce from $1.3M to $600K while also expanding testing into additional application layers to meet customer needs.● Continuously reviewed and consulted with external auditors to refine testing procedures as the offerings and processes changed.● Evaluated operational security controls and developed testing objectives across each offering for both SOC 1 and SOC 2 controls.● Delivered security attestation and assurance to meet portfolio contractual requirements for $230M in customer engagements and meet their control objectives and financial reporting schedules.● Forged relationship between PricewaterhouseCoopers and IBM/Kyndryl Managed Application Services.● Ensured alignment of SOC 1 and SOC 2 testing scope to SOX for customer financial reporting and AICPA Trust Principles.● Assisted technical process owners in developing tools to manage compliance and perform internal assessments prior to external audit engagements.● Consistently delivered unqualified reports to as many as 400 customers.● Gained a deep technical understanding of the design of the security controls at all levels of the environment and translated those details in a way for auditors to understand.● Collaborated with Agile teams responsible for security control automation and orchestration to ensure compliance and auditability of artifacts and documentation. Show less