TAMMIE KIM
Los Gatos, CA ***** *******@**********.*** Cell: 858-***-****
Experienced information security professional well versed in risk
management, internal audit, regulatory compliance, and information
protection. Recently led project reviews include Product Development,
Intellectual Property Management, Software as a Service (SaaS), and Global
Customer Support. Provides technical leadership with experience managing
global projects of varying size and is skilled at developing relationships
across cross functional organizations. Mentors and trains others in
information security, in addition to creating process standards and
guidelines. Strengths include excellent interpersonal skills, superior
written communications and strong analytical skills. Effectively delivers
quality projects on time, with the ability to multi-task, re-prioritize and
make sound decisions.
Areas of Expertise
Information Security Business Continuity Project Management
Risk Management Management Operational
Regulatory Compliance Privacy & Data Protection Audits/Reviews
Identity & Access Management IS Strategy &
Governance
Professional Experience
ORACLE - Redwood Shores, CA 1/08 to Present
IT Assessment & Assurance Lead Auditor
. Lead responsibility for risk-based, integrated global process reviews,
managing projects of up to 8 team members. Identified critical risks in
business processes that required control improvements, defined criteria
to evaluate focus areas, assessed and prioritized focus areas, and
designed audit plans based on approved project effort estimates.
. Created written reports provided to executive management, for projects
including Product Development (Design, Build & Evaluate)/Software
Development Life Cycle (SDLC), Intellectual Property Management, Software
as a Service (SaaS) and On Demand Hosted Services, IT Capacity,
Virtualization, Applications Systems Implementation & Maintenance, Global
Customer Support, Information Security Management, forensic
investigations and CFO requests.
. Evaluated financial, operational and technology risks in accordance with
global business practices, regulatory requirements and industry standards
to develop key recommendations. Experienced with industry standards and
regulatory controls including ISO 27002, ITIL, NIST, PCI DSS, FISMA,
DIACAP, HIPAA, EU Directive, privacy (anti-spam and data breach), and
Section 508 of the US Rehabilitation Act of 1973(Accessibility).
DELOITTE & TOUCHE,LLP - Los Angeles, CA & Hamilton, Bermuda 3/05 to 4/07
Enterprise Risk Services Field Manager, 2/07 to 4/07
Enterprise Risk Services Senior Consultant, 3/05 to 2/07
. Managed SOX project and team of 6 staff, produced internal control
documentation for over 100 processes spanning 25 entities and 3 physical
locations (5 domiciles), for an international reinsurance company.
Advised on technical issues in support of SOX compliance, managed program
processes and built online repository supporting company standards and
version control. Identified control weaknesses and presented findings to
client management.
. Project manager for the patching, hardening and remediation of over 600
SOX and PCI servers for the IT Risk Management and Compliance Program at
the world's premier entertainment company. Developed PCI Compliance
Assessment program processes and metrics including executive
presentations, communication flows, dashboards and other PCI PMO reports
for the Level 1 merchant.
. Produced with a cross functional team a comprehensive business continuity
management program for the world's largest food and beverage manufacturer
to address the recovery of all aspects of the organization, combining
manual process recovery with IT, in support of their SAP implementation.
Executed business impact analyses to determine the financial, operational
and reputation-based impacts of a system outage. Identified a range of
recovery strategies to address interruptions of business processes,
including external interruptions related to third-party vendors.
. Representative clients included The Walt Disney Company, Nestl USA,
Inc., Arbonne, Inc., Scottish Re, Employers Insurance Group, Allied World
Assurance Company Limited and Enstar Group Limited.
Tammie Kim
Page 2
MATTEL, INC. (PrO UNLIMITED) - El Segundo, CA 9/04 to 2/05
Internal Audit Associate
. Communicated with all levels of the business unit; developed flowcharts
and internal control matrices to document processes underlying
significant accounts based on these communications. Assisted in
identifying significant business unit accounts and key processes, and
assisted with the financial statement assessment of SOX 404 coverage.
. Tested the operating effectiveness of key internal controls and
documented the results of work performed for processes related to
financial statement accounts, e.g., sales, inventory management,
receivables/payables, capital expenditures, charitable contributions,
payroll, investment, logical security, and application controls.
. Updated the audit deficiency database and assisted in preparing executive
reports for business unit heads. Performed remediation testing and
updated all final documentation for 10 business units.
. Recognized by the CFO for outstanding team performance.
SAMSUNG ELECTRONICS AMERICA - San Diego, CA 8/03 to 9/04
OEM Account Coordinator (IBM)
. Managed all daily activities as the Samsung liaison for key IBM accounts
(IBM Corporate, IBM Canada, IBM Mexico, the IBM Service Center), and
other OEM monitor accounts as needed. Coordinated communications and
collaborated with cross-functional partners in Sales & Marketing,
Accounting, Logistics, IT/MIS, warehouses and other companies.
. Conducted direct data analysis using SAP to maximize profit and
efficiency in all aspects of the supply chain through proper management
of product inventory, purchase order creation, sales forecasting, and
tracking of goods.
. Provided key analytic insights, new prospect information, and recommended
actions to develop new application functionality within SAP in order to
innovate internal processes.
Education and Professional Activities
UNIVERSITY OF CALIFORNIA, SAN DIEGO - La Jolla, CA 2003
Bachelor of Science, Management Science
Provost's Honors 2000-2003, Major GPA 3.4
Technical Training & Professional Activities
. Certified Information Systems Security Professional (CISSP) certification
in progress
. DRII BCP501 - CBCP Certification Training, DRII Certified Business
Continuity Planner (ABCP)
. Institute of Internal Auditors (IIA) member, Certified Internal Auditor
(CIA) in progress
. Facilitated a course seminar at Oregon State University on Regulatory
Compliance (HIPAA, SOX & GLBA)
Skills
. Trilingual: fluent in English; basic writing skills and conversational
proficiency in Spanish and Korean.
. Proficient in Microsoft Excel, Access, Word, PowerPoint, Outlook, Visio,
ACL.
. Excellent leadership skills, with the ability to coach, train, evaluate
and counsel staff.
. Experienced with various industry standards and security regulations,
including the following:
o Privacy: Anti-Spam, Data Breach, EU Directive, UK Data Protection
o Healthcare: FDA 21 CFR Part 11, HIPAA
o Federal: Export Administration Regulations (EAR), Section 508
(Accessibility), FISMA, and DIACAP
o Financial: Payment Card Industry (PCI DSS), FFIEC & GLBA
o Industry Standards: ISO 27002, ITIL, COSO, COBIT, NIST