Phone: 908-***-**** Email: ********@*********.***
Objective:
Diverse experience in Risk Management, Audit, and IT Compliance. Specialize in identification of IT Security weaknesses
and control deficiencies, gap remediation and implement cost effective solutions. Has a very good communication,
presentation, and interaction skills with all levels of staff and management. A good listener, with very organized work habits.
Well focused to team and management annual business objectives, with attention to timely delivery, detail, and quality of
work. Promotes sharing knowledge and development of team members.
Career Achievements:
Successfully converted (mapped, tested, merged) 50 + Business application systems for 3 major New York banks.
o
Remediation of major issues for Production Runbooks (over 130,000 jobs) and information security for the Employee
o
transfer systems and process. Periodically improved Risk Assessment testing and reporting process for Production.
Recommended and Implemented 5 global improvements to Security and Change Standards for a global bank.
o
Improved and implemented the Corporate Audit Division methodology standards for Auditing and Review of Project
o
Life and Systems Development Life Cycle.
PROFESSIONAL EXPERIENCE
SCTI Technology Institute, Bridgewater NJ Dec. 2009 – May 2010
Computer Support - Technician
Maintains technology work and maintenance for 1500 + computers, printers, and 5 networks spread over 7 buildings.
o
Troubleshoot TCP/IP networks, printers, and software related problems. Setup computer patches, upgrades, and system
backups. Deploys and maintain Windows Operating Systems. Configure server roles, functions, and security.
JPMorganChase, New York, NY Oct. 1997 – Nov. 2008
Information Risk Management - Lead (2007-2008) – Production Services, Global Technology Infrastructure Division
Responsible and performed semi-annual Risk and Control Assessments of Infrastructure (900+ Engineers,
o
Developers, Computer Operations, Application Developers, for - Data, Command Centers, Networks) and Business
Application systems. Identify control deviations, present issues and recommend solutions to management, and address
gaps. Continuously check IT setup and processes for compliance to Security Standards and Financial IT Regulations.
Conducts application development and business process risk reviews, risk mitigation and implementation of
o
solutions.
Identify information security breach, flaws and business impact. Work with the Lines of Businesses and Engineering
o
with recommendations, alternative options, and optimum solutions. Monitor resolved risk issues to prevent repeats.
Performed monthly IT Security Monitoring reports (vulnerability scans), prepare Security, Audit, and Production
o
Quality Assurance metrics reporting dashboard. Performed Security Access recertifications for midrange system
applications. Developed vendor contract requirements for Security, Service Level Agreements, and Change
Management compliance.
Formally critique global changes to Corporate IT Security, Business Continuity, and Change Management Standards.
o
Identify security flaws & business impact. Partner with Lines of Business Management to recommend, test, and
implement and follow-up to ensure effective change. Perform risk, security and BC/DR awareness class sessions.
Chaired and run Security compliance to Engineering development Projects. Ensure Development phases and actual
o
risk methodology practices conform to Enterprise Risk Standards and Federal/Government Regulations.
Technology Program Management – Lead (2005-2007)–Production Services, Global Technology Infrastructure Division
Performed project management for remediation of risk issues. This includes chairing weekly meetings, documentation,
o
scheduling, testing, implementation, and update presentations to IT management.
Performed SOX 404/302 tests (planning, testing, documentation, reporting, and resolution), point of contact and
o
assist SAS70, Internal Audit, External Examiners reviews. Performs control/risk issues remediation. Prepares full
documentation for all testing, management summary writeup, then updates the risk registers.
Monitors QA metrics and SLA performance in Production, including capacity thresholds and Security breach.
o
Performed Business Continuity, Disaster Recovery Testing in Global Production Operations and Application Systems.
o
Conduct Business impact analysis and develop the strategy and plan testing.
Infrastructure Auditing – Audit Senior (2001-2005) – Corporate Auditing Division
Performed risk based audits (plan, test, report) of computer operating systems (Distributed, Midrange, Mainframe),
o
database management, Networks, and Voice Communication and Call Center systems.
Formally audited Data Centers, Command Centers, BC/DR sites, and Voice/communication, and Call centers.
o
Performed continuous auditing and installed Key Risk Indicators and control alerts for Infrastructure systems.
o
Application Auditing – Audit Senior (1997-2001) – Corporate Auditing Division
Responsible for Integrated audits of Application and Business Systems. This includes planning and reviews of Project
o
Development Life Cycle, disaster recovery and change management systems.
Audited methods and controls for Outside Service Providers and vendors (i.e. IBM). Reviewed systems conversions.
o
Prudential Insurance Company of America, Newark, NJ Feb. 1994 – Oct. 1997
Management Audit Consultant
Responsible for audits of applications systems, data centers, and voice communications systems. Performed data
o
analytics (extract, report, analyze) using SAS and ACL.
Worked with various Line of Business management as controls advisor for development and implementation of the
o
Enterprise Application and Distributed computing standards. Implemented and Tested the IT standards of the firm.
National Westminster Bank North America (now Bank of America)
Systems Auditor
Responsible for review of Business Applications, Systems Conversions, and all Data centers.
Responsible for programming, development and reporting functions for the Audit Division. Includes Local Area Network,
o
application development, and Computer Audit Assist Technique (CAATs) support.
Responsible for reviews of system conversions and business application development. Prepared quarterly reports and
o
quarterly presentations to the Audit Committee.
Lockheed Corporation, Burbank CA
Computer Programmer Analyst
Responsible for code development, and testing of various on line financial application systems (i.e. Accounts Payable).
EDUCATION and TRAINING
Monmouth University, West Long Branch, New Jersey - Masters in Business Administration. MBA
o
Business, (diploma received)
De La Salle University, Manila, Philippines - BS Accounting (diploma received)
o
SCTI Technology Institute, Bridgewater, New Jersey - Computer Technology (diploma received)
o
CISCO Networking Academy, Midland, Texas – Computer Networking (certificate received)
o
Rutgers University, Computer Science (OS, Programming, compilers, DBMS)
o
CERTIFICATION
Certified Information Systems Auditor (CISA-#9718220 - active status)
SKILL SET
Proficient:
MS Windows; 2000, XP, Microsoft Word/Excel/Access/Powerpoint/Visio, MS Project, OS400, MVS JCL
Knowledge:
Operating and Networking Systems
o
Window Server 2003 – Active Directory
o
CISCO Routers - IOS commands – TCP/IP, DHCP, CIDR/Subnetting, DNS, Routing protocols, ACL,
o
Security, Wireless AP, Cisco Firewall
Unix, OS400, ZOS/390, Visual Basic, C SQL, HTML Netcool Console Integrator
o
Security, Risk, and Audit Tools:
o
ISA/NSS Scans, TACACs/+, ACF2/RACF
o
Audit Command Language (ACL), Phoenix and Horizon Risk Registers
o
Siteminder, RSA SecureID, Illumin and PostX Security
o
Business Technology
o
Database and Change Management – Oracle, DB2, PVCS
o
Application Development – Mercury Interactive
o
Application
o
PeopleSoft/SAP, Wire Transfers, Mortgage Banking (Origination & Servicing), Trust, Trading and Investment
o
Banking
Commercial, Deposits and Savings, Credit Card Services and Payment Systems
o
Asset Management, Health, Property, and Casualty Insurance
o
Regulations and Standards
o
COBIT, GLBA, ISO27000+, NIST, COSO, FFIEC, Basel II, ITIL, CMMI/6Sigma, PCI/DSS, HIPAA
o