Laura T. Morton
Dallas, TX ****6
214-***-**** (cell) 214-***-****(cell)
***********@*****.***
Education
Keller Graduate School of Management December 2005
Masters of Science in Information Systems Management, (concentration on Information Security),
Masters in Project Management
Southern Methodist University June 2009
Executive Masters of Science in Information Engineering
Six Sigma Specialist January 2008
CoBIT Foundations Certification May 2008
ITIL Foundations Certification August 2010
CISA Certification June 2011
CRISC Certification December 2011
Professional Affiliations
ISACA active member since 2005, Member of IIA since 2005, NSHMBA member, SHPE member,
Member of Toastmasters International, President of Raytheon Hispanic Organization for
Leadership and Advancement, Garland, Texas chapter.
Professional Qualifications and Skills
Project Planning and Management: Strong verbal and written communication skills, highly
organized, proven ability to plan, detail oriented, self-motivated, dependable, ability to interact
well with customers and employees at all levels of management.
Technical Support & Training: Demonstrated skill in training and supporting end users as well
as developing technical skills to performance objectives.
Work Experience
Raytheon Intelligence and Information Systems (November 2006-Present)
Information Technology Auditor /Risk Management, Controls and Governance Team
• Execute annual audit planning and risk assessment regarding IT processes.
• Conduct Monthly Self-assessments, prepare and evaluate remediation items, produce
reports for corporate review, and train process owners and key control owners in proper
usage of the Self-assessment software and its tools.
• Ensure that the IT related controls such as system security and access are tested,
compliant and documented in a logical yet simple manner in order to meet and surpass
compliance requirements.
• Report findings in a concise, accurate and understandable way. Analyze potential
impact, root cause and provide recommendations.
• SOX and GGC testing of the IT-related key controls by the Internal Controls Team, as
appropriate
• Cooperate in promoting a culture of control compliance and ongoing enhancement.
• Monitor the control execution and remediation activities.
• Analyze control’s self-assessments and testing exceptions of IT-related internal controls,
ensuring appropriate follow up and closure of audit findings.
• Assist and lead company-wide project compliance efforts through system development
• lifecycle.
• Coordinate DCAA audits, providing information needed for specific audits.
• Lead other audits as assigned, such as ISO 9100, ISO 27001.
• Implementation of controls for acquired companies.
• Lead performance of Business Impact Analysis and base lining for execution of yearly
Disaster Recovery Exercise.
• Continuous review of policies and procedures in order to update them to most current
required business needs while meeting standards.
Northwood University (June 2006-December 2009)
Adjunct Professor
• Consulting with program and course directors and other faculty members, advisory
committee.
• Defining course objectives and evaluating and validating those objectives.
• Developing individualized instruction and multimedia presentations where applicable
• Selecting or approving textbooks and learning materials.
• Evaluating student progress/achievement, assuming responsibility for the overall
assessment of the student’s work with assigned courses (curriculum consisting of all
Information Systems subjects).
• Ensuring student awareness of course objectives, approach and evaluation techniques.
• Delivering new and actualized information regarding SAP R/3, covering each end every
module and adapting it for student’s comprehension.
Maajere Financial Services, Inc. (Dec 2004-November 2006)
IT Auditor (SOX) / Security
• Knowledge of COSO and COBIT framework mapping of controls.
• Use the project life cycle and industry standard System development life cycle (SDLC)
methodologies, analyzed the risk inherent in each phase of project implementation.
• Assess internal management policies to determine compliance with generally accepted
internal control environment and accounting principles.
• Determine the adequacy of security and controls in remote access connection (frame
relay, modem connection and vendor direct access to System Applications and
networks).
• Perform network and host security and penetration vulnerability tests and worked with
management to determine appropriate level of access.