Priya Vunnam
Email: *****.******@*****.***
Mobile: 937-***-****
___________________________________________________________________________________________
Objective: Seeking a challenging opportunity to utilize my risk management, IT audit, and compliance skills to enhance my
professional growth in the field of Information Security.
Summary of Experience:
5 years of overall IT experience in the field of Information Management
3 years of experience in Risk Management/IT Audit at Deloitte & Touché LLP (BIG 4 Accounting Firm)
Extensive experience in performing Security Audits, Internal IT Audits, and Risk Assessments for Fortune 100 clients
Worked on compliance of applicable regulations, standards, and other requirements such as SOX, PCI DSS, FTC, HIPAA, etc
Worked extensively on designing an Information Security Framework aligned to specific client’s businesses
Developed robust Information Security Policy’s based on standards such as NIST, ISO/IEC 17799
Developed corporate-wide Information Security Training and Awareness Programs for employees at all levels
Worked directly with C Level Executives in making decisions on Information Security Programs in their organizations
Performed Compliance Monitoring and ensured Internal Controls are effective
Excellent written and verbal communication skills, Project Management (PMO) and problem-solving skills
Possess superior communication and team-relationship skills, including delegation and time-management functions
Willing to travel 60% + (domestic and international)
Work Experience:
Deloitte & Touché LLP June 2006 – March 2009
Enterprise Risk Consultant
2 World Financial Center, NY, NY
Worked as a consultant for 3 years providing information security consulting services to diverse clients in Financial Services, Retail,
Consumer Markets, Manufacturing, and HealthCare industries. Following are the projects and their details
Project Name: Sarbanes-Oxley (SOX) Compliance/Operational Risk and Controls
Project Experience:
Designed and developed risk control matrices and process overviews for several processes
Identified key risks and documented key control activities to mitigate theses risks
Tested several processes, identified exceptions, design gaps and process improvements
Developed multiple presentations for scoping analysis based on detailed operational risk analysis
Analyzed self-assessments to identify design gaps and process improvements
Presented the audit findings to the audit committee
Project Name: Payment Card Industry (PCI) Compliance/Security Administration Centralization/User Access Reviews
Project Experience:
Created an inventory of key IT systems in the corporate home office as well as in the other subsidiaries of the organization
Performed extensive security reviews on key IT systems based on specific set of PCI requirements for a tier-1 company
Remediated the non-compliant areas that were identified from the security reviews
Performed user access reviews to streamline employee’s access rights and privileges to critical IT applications
Designed a web portal for PCI Training and Awareness
Project Name: Federal Trade Commission (FTC) Compliance
Project Experience:
Mapped the FTC order to the Information Security program at the client
Assisted in developing a robust Information Security (IS) Policy
Worked with different business group heads to perform extensive security reviews to measure their compliance against the IS
policy
Page 1 of 2
Educated clients at various levels (VP’s through Manager’s) about the FTC order and the need to be compliant with the IS
policy
Analyzed the non-compliant areas identified from the reviews and discussed remediation with the client
Conducted general security store audits by visiting physical stores all over the US
Project Name: System Security Information Management
Project Experience:
Worked directly with C level executives and other senior management to gather requirements for project SIM
Developed a current state assessment for Asset and Configuration Management
Developed process flows for Asset and Configuration Management
Managed the vendor selection process and performed detailed analysis of tools for Asset Management and Configuration
Management
Compiled and maintained an Asset Inventory of all assets in the organization
Worked on customizing HP Asset Manager tool according to the client’s requirements
Project Name: Role Based Access Control (RBAC) Implementation
Project Experience:
Designed detailed Process Flows for RBAC activities
Created Use Cases and an Organizational Model for RBAC
Developed an RBAC User Guide that guides Application teams through the RBAC process end-to-end
Assisted with the implementation of th RBAC tool (Sun’s Role Manager) and its customization in the client’s environment
ZF Industries June 2005 – Aug 2005
Logistics Intern
Lancaster, SC
Streamlined the Shipping and Receiving processes in the Sales and Distribution (SD) module in SAP, by building process flows
Documented numerous business processes like production confirmation, return goods handling, shipping goods, etc
Evaluated and loaded customer master data through mass transactions in SAP
Generated reports from SAP for various transactions in SD
Worked extensively with MS Excel containing part numbers, customer numbers, price and other details
Renaissance Info Tech Limited Apr 2003 – May 2004
Software Engineer
Hyderabad, India
Developed a CRM system to implement business processes and enforce business rules
Developed supporting tools using J2EE, front-end Java Swing, back-end Oracle 9i
Performed a detailed analysis on the various CRM tools available
Implemented the Siebel Tool for CRM – The Assignment Manager
Educational Qualifications:
Syracuse University, Syracuse, NY August 2006
Master of Science in Information Management
GPA: 3.70/4.0
Syracuse University, Syracuse, NY August 2006
Certificate of Advanced Studies in Information Systems and Telecommunication Management
Jawaharlal Nehru Technological University, India May 2004
Bachelor of Engineering in Computer Science
GPA: 3.70/4.0
Page 2 of 2