JENNIFER TAM
** ****** ***** *****, *******, NJ *7436
Home: 201-***-**** E-mail: ********@*****.*** Mobile: 917-***-****
SUMMARY
Technology & Risk Management / Internal Control Specialist with extensive
experience in Internal Audit, Information Security, Technology Operations
and Policy Development. Mature problem-solving and interpersonal skills.
Proven record of successful delivery and practical knowledge. Areas of
specialization include numerous Security Platforms, Policy and Standard
Creation & Review.
SELECTED ACCOMPLISHMENTS
. Implemented a global compliance strategy to identify vulnerabilities,
generate analytical results of important internal control areas and
highlight opportunities for improving the corporate computing
environment.
. Executed security risk reviews to ensure compliance with security
policies and standards.
. Managed a database project critical in the evaluation of various security
products for business needs. Established relationships with security
software vendors and provided product specifications.
. Defined security requirements and guidelines for new systems. Provided
guidance for application systems development projects.
. Reviewed and identified risk exposure in business applications running on
a variety of platforms ranging from mainframe to client/server
environments. Evaluated adequacy of controls for these applications for
data integrity, consistency and security.
. Worked closely with systems development and user groups to provide the
appropriate level of control based on risk.
. Worked with internal and external auditors in responding to audit
recommendations and preparing reports for senior management.
. Issued management reports of security review findings including
recommendations for corrective actions.
EXPERIENCE
Becton, Dickinson & Company, Franklin 2004-Present
Lakes, NJ
Senior Control Analyst - Continuous Assurance / Internal Audit, Americas
(2004 - Present)
Responsible for key aspects of the Internal Control Function for BD,
Americas.
. Utilize audit technologies to improve internal audit
productivity, analytical capabilities and monitor internal
controls
effectiveness within key business and IT processes.
. Ensure operational effectiveness of internal controls based on
COSO and COBIT frameworks with knowledge of SOX
methodology.
. Conduct IT Segregation of Duties SOD Risk Analysis to identify
SOD issues by SAP transactional level of auditing.
. Defined monitoring key IT controls within the Windows Active
Directory environment utilizing the Quest InTrust Reporting
and assessment tool.
. Implemented the global vulnerability assessment system to
evaluate security vulnerabilities of BD digital assets.
. Designed vulnerability reporting structure and perform
independent internal control vulnerability assessment.
. Performed financial, operational, and IT internal audit
assignments under the direction of the audit manager.
UBS Investment Bank, Stamford, CT 2000-2004
Senior Security Analyst - Security Risk Control, Americas (2000 - 2004)
Responsible for key aspects of the Information Security Risk Control
Function for UBS Investment Bank, Americas.
. Conducted IT Risk Assessment Reviews verifying that recommended
countermeasures are implemented as agreed by the business.
. Approved Policy Exception requests to ensure that control processes
are in place to mitigate risks. Areas include analog lines, account
access, segregation of duties, and data classification.
. Identified high risk areas to improve processes and ensure level of
compliance with policies and standards.
. Conducted extensive software analysis and identify requirements to
enhance security within the database environment.
. Investigated security violations for Windows NT, Unix, and remote access
for Internet usage.
DKB Data Services (USA) Inc., Jersey 1998-2000
City, New Jersey
Security Officer - Corporate Control / Information Technology
Responsible for system security administration, violations, audit
exceptions, and software testing in the development environment.
. Coordinated, planned, and implemented computer system security policies
for all DKB entities.
. Performed system administration tasks of various operating systems,
including Lotus Notes, Novell NetWare, Windows NT Workstation, Unix,
Sybase SQL server, RACF, MVS (OS/390), and Internet access on proxy
server.
. Investigated user access violations, reviewed security reports,
maintained access controls for various resources, and fostered data
security awareness.
Union Bank of California International, 1996-1998
New York, New York
Security Administrator - International Operations & Product Support /
Information Technology
Performed security administration functions for various platforms.
Reviewed systems to ensure adequate data security is maintained.
Provided technical support to both internal and external users by
coordinating with managers to ensure bank systems are operational.
Assisted the IOPS project manager with PC and VAX-based application testing
and implementation.
CoreStates Bank, NA, New York, New York 1992-1996
Operations Representative
Responsible for overall fund transfer operations, including daily
settlement of federal funds borrowed at a discount rate.
. Maintained and managed drawdowns and federal funds for overnight loan
payments.
. Developed a working knowledge of government securities, mutual funds,
money markets, mortgages (CMO), unit investment trust (UIT), and bonds
with yield curve limits and equities.
Banco Economico, S.A., New York, New York 1991-1992
Senior Operations Clerk
Managed clients' fixed income investment portfolios. Ensured outgoing
payments were covered with sufficient funds.
. Managed incoming credits, overnight money market and private banking
investment funds for preparing daily settlement of CHIPS and Fedwire
payments.
EDUCATION
Baruch College, New York, NY
Bachelor of Business Administration (B.B.A.), International Business -
1991;
Concentration: Statistical Analysis
Curriculum included Accounting, Banking and Finance, Management and
Advanced Statistics
Queens College, Queens, NY
Coursework, June 1999
Windows NT 4.0 for Workstation and Server, TCP/IP
COMPUTER SKILLS
Operating Systems: Windows XP, Windows 2000& 2003, Solaris 9.x, Novell
NetWare (3.x - 4.x), MVS (OS/390), VAX
Database Administration: Sybase, Oracle8i/9i, SQL Server 11.x, Database
Security System (Database Scanner)
Compliance and Audit Softwares: FCM (OpenPages Financial Controls
Management), Cognos Command Center, ACL (Audit Command Language), CCM
(Continuous Control Monitoring), CSI Authorization Auditor, SAP Compliance
Calibrator, TeamMate
Security Packages: RACF, Unix Security System (SeOS Version 2.5a), McAfee
Foundstone Vulnerability
Management System, Quest InTrust for Active Directory
Financial Applications: Montran, GFT, SWIFT, MIDAS, MCI Commdesk, LEESON
HOWE, Telex tester, TRACS, NATS, Fedline, Chase Infocash, Q&A, Devon, FNX,
Summit, Homegrown (In-house Application Development), SAP R/3 (3.0-4.7)
INTERESTS
Traveling, swimming, biking and landscaping.