JEFFERY PLUMP, CISA
Austin, TX 78704
Home: 847-***-**** ************@*****.***
SUMMARY
IT Audit Manager with over 12 years experience and special expertise in manufacturing, telecommunications and financial
services. Acquired early technical, auditing and team-leadership skills as non-commissioned officer in US Marine Corps (field
communications systems). Resilient and grounded, meets deadlines and achieves results under challenging circumstances.
Independently develops detailed audit plan to accomplish audit objectives. Strong background in audit planning and reporting,
staff management and standards development.
TECHNICAL EXPERTISE
Project Management • Midrange Systems • AS/400 • Network Security • Firewalls • Intrusion Detection • Network Scanning
Tools (ISS, Foundscan) • SOX 404 Compliance • SAP • UNIX (All Versions) • Data Reporting and Analysis (Access, ACL,
EXCEL) • Assessment of IT Processes • Software Development Life Cycle (Change Management) • Oracle Financials • SQL
PROFESSIONAL EXPERIENCE
ADVANCED MICRO DEVICES, Austin, TX 2005 – 2009
Internal Audit Manager
Responsible for managing and training staff of 13 auditors, which included developing Audit Schedule and managing audit
engagements.
• Developed audit strategy, plans and department framework; and presented to Audit Committee, which resulted in the
approval of the annual audit plan.
• Created audit report and presented to Audit Committee on a quarterly basis to identify risk and remediation.
• Proactively met with business process owners to identify and remediate risk areas, which resulted in receiving a company
spotlight award for creating companywide controls awareness.
• Developed and grew the audit department from 3 to 13 professionals to effectively manage risk within the company’s
overall control environment.
• Developed and implemented new audit approach and methodology that changed the company to a controls-focused
culture.
• Redesigned and refined the SOX testing methodology that reduced the time spent performing SOX testing by 50%.
Received a Vice President Spotlight award for refinements to SOX process.
• Planned and led Software Development Lifecycle (SDLC) reviews, resulting in the successful implementation of several
major applications including SAP.
AMERICAN EXPRESS, Chicago, IL 2004 – 2005
Manager, IT Risk Management
Responsible for conducting operating system security reviews and risk assessments.
• Developed and implemented SOX methodology, conducted SOX audits, performed risk assessments ad operating system
security reviews for clients.
• Formalized and standardized the department reporting processes and audit reports, resulting in greater client satisfaction
and increased repeat business.
JEFFERY PLUMP, CISA PAGE TWO
MOTOROLA, Schaumburg, IL 2000 – 2004
Global Internal Controls Manager 2004
Managed SOX readiness and testing for worldwide business units, including US, Europe and Asia. Acted as liaison with
external auditors on certification process.
• Project Manager for developing, implementing and testing SOX-compliant IT controls, resulting in a favorable opinion
from the external auditors.
In-Charge Auditor 2001 – 2004
Conducted nearly 30 engineering and general-control reviews. Planned and scoped audits; developed audit report and presented
audit findings. Evaluated audit staff performance. Managed 5 engineering general-control reviews for co-sourcing project.
• Project Manager for general control reviews using external staff, resulting in satisfactory completion of Audit Committee’s
request for compliance coverage.
• Co-created an add-in tool to automatically format reports generated as a result of performing network vulnerability scans
resulting in the ability to quickly scan and assess the whole network population versus sample scanning.
Corporate eAuditor 2000 – 2001
Assisted the in-charge auditor in the completion of IT audits. Performed data analysis using ACL, ACCESS and EXCEL;
conducted reviews of Oracle Financial modules and network configurations using Internet Security Scanner. Authored audit
programs used by the audit department to successfully review the security configurations for UNIX and Windows NT/2000
operating systems, and Oracle databases.
PHILIP MORRIS MANAGEMENT CORPORATION, Northfield, IL 1997 – 1999
Senior IT Auditor 1997 – 1999
Performed data analysis using Easytrieve, Query/400, Access and Excel. Supported financial auditors with data extraction and
analysis. Conducted solo audits of UNIX and AS/400 operating systems and application reviews of legacy applications and
supply chain management systems.
Associate IT Auditor 1997 – 1997
Analyzed data using Easytrieve, Query/400, Access and Excel. Supported financial auditors with data extraction and analysis.
Assisted IT Auditors with warehouse reviews.
THE PRINCIPAL FINANCIAL GROUP, Des Moines, IA 1995 – 1997
IT Staff Auditor 1997
Conducted application reviews and audits of UNIX, AS/400 and the VMS/VAX operating systems.
Trained new staff on auditing of UNIX and AS/400 operating systems. Conducted intrusion detection reviews. Investigated
potential fraud in role as initial investigator of calls to fraud hotline. Selected as member of special Tiger Team.
Assistant IT Staff Auditor 1995 – 1997
Assisted senior IT auditor with audits, reports and reviews.
US MARINE CORPS, Numerous Locations 1985 – 1991
Sergeant
Promoted four times during six-year tenure. Set up and maintained communications network for Task Force Ripper during
Operation Desert Storm. Numerous medals, commendations and letters of appreciation.
EDUCATION
BS, MIS (Computer Science Minor), Western Illinois University, Macomb, IL
AFFILIATIONS / CERTIFICATIONS
Information Systems Audit and Control Association
Certified Information Systems Auditor (CISA)