RUSSELL VERNALI
East Granby, CT 06026
********@***.***
EXPERIENCE SUMMARY
Information technology professional with over twenty years of diverse IT background including extensive international
experience working in all phases of information systems and IT management including, IT auditing, process
improvement, vendor and risk management, Sarbanes-Oxley (SOX) compliance, SAP security, System Development
Life Cycle (SDLC), policy management and compliance, and general information technology security controls.
Stanley Works – New Britain, CT (11/2009 – present)
Senior IT Auditor – Internal Audit
• Responsible for performing IT related audits and supervising team members in accordance with department and
professional standards while providing guidance on identifying and prioritizing key risks related to IT exposures
• Assisted with the development of the department audit plan that covers significant IT risks and allocates
resources appropriately while ensuring that the audit approach is effective
• Effectively managed audit customer relationships while keeping informed of changes in the business
• Identified deficiencies and proposed solutions for the company’s key IT environmental, strategic and
operational risks
• Performed timely performance evaluations and reviews of work papers and drafted written reports to executive
management
Accume Partners - Moorestown, NJ (2/2008 – 1/2009)
Senior IT Audit Manager - Technology Risk Services
• Senior Manager in charge of the New England region for all IT systems, technology risk management and
IT audit services
• Client responsibilities include identifying and controlling risks, improving corporate governance, re-
engineering business processes, enhancing operational performance, and aligning information technology with
business goals and objectives
• Duties included managing services in the areas of information technology audit and compliance, vendor
management, Sarbanes Oxley (SOX) auditing, IT network security / vulnerability and penetration testing, social
engineering, business continuity and disaster recovery planning
• Analyzed vendor due diligence policies and procedures and made recommendations to improve vendor
management
• Identified standardization gaps in audit work processes and made recommendations for improvement
• Managed IT general controls reviews, SOX audits, and IT security evaluations for clients in
banking/financial services and manufacturing industries
• Partnered with senior and executive management to recommended effective solutions, strengthen operations,
and improve the overall IT control environment
• Ensured quality results by adhering to methodologies based on industry best practices and guidelines,
government banking regulations and mandates, and hands-on experience
• Collaborated with financial management teams to coordinate scheduling and resources
• Drove client satisfaction and company revenue goals by ensuring audit engagements were completed to the
highest quality standards, on time, and within budget
United Technologies Corporation - Hartford, CT (2/2004 – 2/2008)
Pratt & Whitney Division
Senior Information Technology Security Analyst - SAP Security & IT Compliance
• Responsible for design, development, and implementation of corporate SAP security policy and
methodology for 23,000 users worldwide
• Received multiple performance awards for demonstrating initiative, resourcefulness, and innovative
problem resolution
• Partnered with other United Technologies business units such as Sikorsky, Carrier, and United
Technologies Research Center to provide SAP security design strategies and recommendations
• Achieved customer satisfaction through improved delivery of SAP solutions for new Go Lives by
minimizing Segregation of Duties (SOD) issues
• Collaborated with executive and working levels to ensure services were provided in a quality, timely, and
cost effective manner to maximize customer satisfaction
• Managed a team of off shore contractors responsible for maintaining user access security privileges
• Conducted periodic policy compliance reviews of various foreign and domestic Pratt & Whitney
manufacturing sites to ensure compliance with UTC corporate policies and Sarbanes Oxley (SOX) requirements
Ensured P&W compliance to all internal and government regulations
Assisted in tracking for all audit findings and completion of observations/findings actions
Ensured management controls were in place for SAP process controls & security and management
testing was completed
Drove cost savings initiatives within the IT applications area by:
•
Utilizing low cost vendors of SAP Security services
Introducing new ACE processes and standard work which streamlined ongoing SAP security support
requirements
Improved the SAP support processes to decrease the time required to complete customer change
requests
Security team leader of the SAP change control board, responsible for reviewing all transports to the production
•
SAP system before implementation to ensure quality, system availability, and customer satisfaction
Corporate Headquarters Division
Senior Information Systems Audit Leader - IS Internal Audit
• Responsible for leading global IT audit teams throughout North and South America
• Led multiple long term assignments in Europe and Asia which were awarded to top performers
• Duties included planning, executing, auditing, analyzing and reporting on the internal IT audit processes on
general computer controls, security controls, and Sarbanes Oxley (SOX) controls
• Global coordinator responsible for developing the Information Systems annual audit planning and
budgeting process
• Implemented Sarbanes Oxley audit controls for alignment with audit plans
• Performed risk assessments through corroborative inquiry with UTC business unit CIO’s and CFO’s,
information and data gathering
• Developed audit scope, strategies and approaches for IT audit engagements based on conclusions from risk
analysis
• Recommended and implemented corporate wide policy changes based on audit findings and associated risk
• Performed audits in IT general computing controls including System Development Life Cycle (SDLC),
project management, application and infrastructure, change management, computer operations and application
interfaces, and vendor management
• Performed audits in ERP pre and post implementation for JDEdwards and SAP including system setup and
configuration, security controls, transport management, operational controls, and segregation of duties
• Performed IT security audits including application security, operating system security, database security,
network security, and physical security
• Performed audits in IT backup and recovery, business continuity, and disaster recovery planning to ensure
continuity of IT operations in the event of a disaster
• Identified IT audit process & control issues and developed recommendations to address issues in a timely
manner
• Worked with business unit leaders to evaluate management actions to audit issues and jointly develop
solutions
Evaluated control issues to ensure findings were in alignment with business risk
•
Presented audit findings and made recommendations to management for follow up on audit action plans
•
Provided IT expertise for finance and compliance audit teams to evaluate IT related controls
•
Developed and improved audit policies and procedures including automated tools, and training materials
•
Provided IT audit training, subject matter expertise, and mentoring to audit staff members
•
Chubb Specialty Insurance - Simsbury, CT (6/2002 – 1/2004)
Senior Information Technology Analyst - Information Technology
• Responsible for design, development, testing, implementation, and support of Centura Builder policy
issuance application running on an Informix database
• Performed system wide impact analysis and wrote detail design component specifications for application
enhancements
• Made recommendations to improve application maintainability and reliability
• Provided second level help desk production support for all offices in North America, which included trouble
shooting and resolving application, server and database problems
• Coordinated unit and integration testing for software release cycles
• Responsible for maintaining Centura Team Object Manager source code control libraries for application software
components
• Maintained product library database tables and production policy form repository consisting of over 3000 forms
• Supported and configured policy issuance servers that controlled output to branch offices
ProComp Systems Inc. – Simsbury, CT (1/1994 – 6/2002)
President - Independent IT Contracting and Consulting Services
• Provided software development and database design consulting services for clients such as:
• MassMutual Life Insurance Company - Springfield, MA (1/1998 – 1/2002)
• The Hartford Insurance Company - Hartford, CT (1/1997 – 1/1998)
• CIGNA Healthcare - Bloomfield, CT (1/1994 – 1/1997)
PROFESSIONAL AFFILIATIONS:
• INFRAGARD CT – An information sharing organization between the FBI and Connecticut
Department of Emergency Management and Homeland Security specifically targeting physical and computer
infrastructure security issues
ISACA - Information Systems Audit and Control Association
•
VOLUNTEER WORK ACCOMPLISHMENTS:
• Worked with the Executive Director of the Hartford Neighborhood Centers to assist with the ex-offender program
to provide services to inner city youths
• Helped coordinate and implement the Yale University 4Peace anti-gang/anti-violence youth event at Woolsey Hall
• Assisted in the development and implementation of the U.S. Department of Justice, U.S. Attorney Awards given to
federal and local law enforcement agencies for the district of Connecticut
• Provided administrative support for the U.S. Department of Justice Weed & Seed program for Hartford
Connecticut in conjunction with the Connecticut U.S. Attorney’s Office
EDUCATION: Bachelor of Science - Computer Science 1989
Central Connecticut State University