Jeffrey D. Stargell, CISA; CISM*
Garland, Texas 75044
Qualifications:
Data Processing Professional with over 18 years experience in Information Systems, With more
than 10 years of IT Audit Management experience specializing in Internal Controls and IT Risk
Management.
Business Experience
Summary of qualifications:
IT Audit Experience: Sarbanes-Oxley audits; Network & Systems Security; Disaster
o
Recovery Planning; Business Continuity Planning; SDLC Methodology Auditing; Ethical
Hacking/Vulnerability Assessments-Network Security: Firewalls security policies,
authentication, IDS, War-dialing, War-driving and penetration testing utilizing industry
tools.
IT Risk Assessment experience incorporating COSO, and CoBIT control frameworks;
o
SOX 404 experience relative to IT enabled and GCC control compliance;
o
Continuous monitoring programs and ongoing IT Risk Management experience, and;
o
Client relationship with strong analytical, logic, problem solving and management skills,
o
ability to meet tight deadlines with competing priorities.
Developed top-notch internal audit professionals and deployed resources out to various
o
business function within the enterprise.
Nortel
Sr. Manager IT Audit (Aug 2000 - Present)
Managed IT Security & Risk assessments based on the COBIT and ISO17799 frameworks
focusing on safeguarding of company assets through technical analysis while seeking efficiencies
and comparison to industry best practices and TCO data.
Managed and provided effective feedback to information security risk assessments and project
audit engagements in support of company wide System Development Life Cycle (SDLC) projects
and processes.
Managed Internal Audit testing, monitoring and remediation of Information System controls for
Sarbanes Oxley compliance. Assist management in the development and implementation of risk
mitigation strategies for Sarbanes Oxley compliance. Ensuring that IT related processes and
procedures aligned with CoBIT.
Responsible for on-going and effective communication to key stakeholders regarding risk
assessment, audit issues and audit results.
Bank of America
Vice President,
Internal Audit Systems Manager (Feb. 1997 –Aug. 2000)
• Coordinated and supervised nationwide audit activity involving IT Data Processing application
systems; providing process efficiencies and risk management recommendations to Senior
Management.
• Developed and implemented Information Systems risk analysis techniques to assist in
determining effective use of company resources.
• Managed major conversions and new development to ensure SDLC principals were properly
utilized.
• Instructed staff on project management methodologies and techniques including
development, management, and successful execution of work plans.
• Designed, recommended and implement technology based training solutions to fulfill in-
house training for non technical staff.
• Partnered with LOB management in developing testing and quality measurement techniques
for newly designed processes or application systems.
• Negotiate, structure, and manage vendors and/or consultants relative to SAS70 and SLA .
• Prepared comprehensive audit plans.
Assistance Vice President,
Senior Applications Auditor (Nov. 1994 - Feb. 1997)
First Data Corporation
Senior EDP Auditor (Oct. 1990 - Nov. 1994)
Responsibilities include performing data center reviews to ensure that adequate administrative and
operational controls are practiced at the various Banking, Credit Card, and Healthcare
environments. Assessed control procedures relative Disaster Contingency Planning, Data Security
Network and Telecommunications, and Service Contracts. In this capacity, I directed and
participated in summary meetings with various levels of management in order to communicate
findings and recommendations. Duties also include preparing written reports of findings and
recommendations for corporate management.
Programmer Analyst (Sept. 1986 - Oct. 1990)
Computer Operator (Aug. 1985 - Sept. 1986)
* Awaiting experience for Certification
SPECIFIC TECHNOLOGY EXPERIENCE AVAILABLE UPON REQUEST
REFERENCES AVAILABLE UPON REQUEST