Hammed K. Ibrahim, CISA, CISM, CISSP, PMP
****C Forest Creek Drive, Hazelwood, Mo 63042; ****.*******@*****.***; 630-
SUMMARY A highly motivated individual with over seven years of IT,
financial, and operational auditing and project
management experience. Relevant industries include
financial institution, real estate, healthcare,
manufacturing, and not-for-profit organizations.
SKILLS AND TRAINING
Expertise: Information Systems Audit and Security Control, Project
Management and Business Process Analysis and Evaluation,
SDLC, Change Management, Quality Assurance, BCP/DRP, SOX,
COBIT/COSO.
Applications: AS/400, CBS (Comprehensive Banking System),
LOC (Letters of Credit), PayPlus, Fedline Advantage, Fed
Direct, Commercial Online Banking, BOB, CIBAR, BancWare,
ERP's (SAP, Oracle, Peoplesoft, JDE);
Programming Languages: UNIX, C, C++, Java
Tools/Utilities: Lotus Notes, ACL, Exchange, SharePoint.
O/S and Hardware: Microsoft Windows 95/98//NT/2000/2003/2007/XP,
Netware NT Server, Intel, Client/server, Cisco, IBM
Compatibles;
Microsoft Applications: Visio, MS Project, Excel, Word, Access,
PowerPoint, and Outlook.
EDUCATION:
Bachelor of Science (Dec. 2000)
MBA - Mckendree University; anticipated completion date (Oct. 2011)
PROFESSIONAL MEMBERSHIP
Information Systems Audit and Control Association (ISACA)
Project Management Institute (PMI)
CAREER DEVELOPMENT TRAINING:
Management: Leadership, Total Quality Management (TQM), and Project
Management
Others: Accounting Principles, Corporate Finance, Time Management e.t.c
PROFESSIONAL EXPERIENCE
First Bank Hazelwood, Mo
Senior IT Auditor 2007-Till present
. Lead auditors in completing integrated audits involving IT and
financial & operational auditors. Reviewed work-papers and audit
reports for IT audit projects and Sarbanes-Oxley (Interim and Roll
forward tests).
. Provide management with accurate, independent and timely assessments
and recommendations in the following areas: Risk, Internal control
weaknesses, Information systems security, Banking Applications,
Database technologies (Oracle), Networking (Firewalls, LAN, and WAN),
Disaster recovery and Business continuity planning.
. Assist Information Technology Audit Manager in the development of the
Strategic Plan and in the completion of the Audit Program.
. Assign work to auditors, set priorities and monitors activity. Provide
training in the use of audit tools such as ACL to IT auditors and
Financial & Operational Auditors.
. Reviews IT Auditors and Staff auditor's audit workpapers, findings,
recommendations and final reports.
. Follow up on open issues with management and track issues that are
ACPV (Action Completed Pending Verification) to resolution.
. Resolve conflicts between auditors and the business units to smooth
the relationship between the auditors and the business units
(auditees).
. Assists the IT Audit Manager in identifying those business areas
subject to audit coverage and evaluates their significance by risk
rankings
ABN AMRO,
Chicago, IL
IT Audit Consultant
2006-2007
Worked with audit team members in a mindset which has executive
management/audit committee as the audit customer and treating the process
owners as necessary & valued audit process participants, a risk based
assessment of application systems and relevant business processes is
undertaken, risk points are identified, control objectives tested and
documented, remediation options to weaknesses proposed, which help
strengthen internal controls and help achieve management's objectives to
sustained business optimization.
. Performed company's IS reviews based on understanding of the IT (and
business) goals, policies, procedures and processes in place, the
effectiveness of the overall control environment, perceived risks and
audit objectives.
. Determined adequacy and compliance with the company's enterprise-wide
risk /security program plan.
. Reviewed the effectiveness of the company level controls and IS
control environment as represented by the IS administration and the
organization and placement of the IS department and also its
relationship with user departments for purposes of determining risks.
. Determined the effectiveness of specific general computer controls to
help determine reliance on the automated(application) systems
underlying the various business processes and the necessary compliance
with corporate policies and external (regulatory) policy including
Sarbanes-Oxley, all based on the COSO internal control framework.
Crosstech Solutions, Gilbert, IL
IT Audit project Specialist 2002-2006
. Managed multiple Sarbanes-Oxley Section 404 projects while assisting
the financial audit team; coverage includes company level, general IT
controls and application controls.
. Conducted reviews of controls over IS related business processes as it
pertains to management's financial reporting and assisted process
owners to remediate identified gaps as required for the client's
Sarbanes - Oxley compliance project.
. Reviewed effectiveness and compliance with controls that helped ensure
that information systems assets were continuously available with
regards to disaster recovery and business continuity.
. Performed compliance review of company software use policy, purchase
and installation practices to help determine/mitigate,
exposure/potential liabilities from software copyright violations or
unauthorized use of pirated software for clients.
. Assessed the adequacy of controls in the critical decision points of
the SDLC process - the requirements definition & program's detailed
design, testing and implementation phases (including back out
procedures).
. Audited complex information systems applications and procedures of
clients to ensure compliance with policies, procedures and best
practices.
. Maintained reasonable positive relationships with various staff
levels, including senior management. Ensured confidentiality and
ethical conduct with regards to all clients' information.
. Examine records and interview workers to ensure recording of
transactions and compliance with laws and regulations.
. Report to management about asset utilization and audit results, and
recommend changes in operations and financial activities.
. Advise management with external auditor approach and expectations and
also provide recommendations to management on best practices and
process improvements.
. Supervised three IT auditors on various projects.
. Assisted the financial and operational audit team (integrated audit)
in evaluating and testing general system controls such as access
controls, management reviews, reconciliation, configuration, account
mapping, segregation of duties, change management, physical security,
and backup & recovery.
. Reported and communicated system vulnerabilities and recommendations.
. Planned and performed value-added reviews of information security,
business and operational systems, and IT operations controls.
. Reported and communicated system vulnerabilities and recommendations
and also briefed the audit team on the client's IT environment and
industry IT trends.