Michael Asamoah-Boateng
Lancaster, SC *****
Technical Project Manager
Summary: Certified Project Management Professional with a foundation of Information System Audit and Compliance experience in operational and system audit, internal control process improvement, compliance/risk assessment, information security system implementation assessment. Proven track record of assessing issues and resolving project conflicts, leading cross-functional teams concurrently with short term and long-term projects. Proficient in developing and implementing effective project management processes and methodologies to improve operational business processes and maximize resource productivity. Quick learner with the ability to think outside the box and provide alternative solutions to challenges. Capable of effectively prioritizing, multi-tasking and thriving when working under pressure in a fast-paced, deadline driven environment.
Education:
Sage of Albany, B.S. Finance; Minor in Marketing, Jun 2014 – May 2016
Certifications:
Project Management Professional
Lean Six Sigma White Belt
Project management Essential
Six Sigma Data Analysis and Root Caused.
Data Analysis Concept Certified
Great analytical and critical thinking while under pressure, with vast knowledge in the following areas.
Agile
Cyber Security
Scrum
Identity Access Management
Assessment of Internal Control
Good knowledge of IIA standards
IT Security and Risk Management
Microsoft Office Suite
Information Security Essential and Incident Management
Business Analysis Process
Sarbanes Oxley Compliance
Anti-Money Laundering and Regulatory Framework
Archer
ServiceNow
JIRA
SDLC
Professional Experience:
PWC, Tampa, FL (Remote)
PMO Project Manager
Duration: January 2023 - August 2023
Coordinated and managed confidential project that has significant impact to the organization. . (IAM, SOD Project Planning, Auditing skills required for this project)
Led team in gathering requirements and managing the RAIDD log.
Coordinating with internal teams to help eliminate any roadblocks, throughout project.
Set weekly touch points with department to ensure all SLA were met.
Created weekly leadership reports to provide insight on area’s that needed more attention and highlight accomplishments.
Providing guidance tracking and documenting activities for consistency and creating a repeatable process.
NielsenIQ, Tampa, FL (Remote)
CyberSecurity Mergers and Acquisition Project Manager
March 2022 – January 2023
Providing guidance to newly acquired company in properly integrating into the enterprise environment by adapting to our security posture.
Provisioned access to recently acquired M&A teams upon completion of enterprise required task that aligned with our Cyber security posture.
Maintain and document tracker of progress on a periodic basis.
Coordinate through any obstacles or roadblocks preventing M&A team to integrate with any security tools or other requirements.
Presented monthly reports to senior leadership addressing areas of risk and proving recommendations to mitigate gaps.
Maintained workflow tool providing weekly in and out updates on task accomplished and areas of focus for the week.
Established connections with various organizations within enterprise to effectively streamline information to the proper audience as needed.
Delegated task and set priorities with ownership to M&A teams.
Provided team with necessary resources throughout various stages of acquisition.
Wells Fargo, Charlotte, NC
Project Manager/POD Lead (Scrum Master)
April 2021 – January 2022
Enterprise Change Management consultant in high visibility domains of Audit, COO, Legal Department, Public Affairs Total, Finance, and Technology.
Ensured SOD with change process to ensure proper implementation.
Lead daily POD call to review roadblocks, updates, and special requests from business, share directions from leadership,
Lead bi-weekly call with the partnering groups/LOBs to review request, roadblock, escalations, share and receive feedback, share, clarify process, guidelines, prepare and share report on need information, approval, aging,
Support subordinates with their individual request, provide clarification, and suggesting improvements.
Create, analyses, and share reports on high priority CRs, aging, defects, need information, Approval, impediment, exceptions escalation.
Responsible for Bulk request submission/reporter, Cancelling tickets,
Coordinate with internal department on areas requiring clarifications- International team, Modelling team,
Ability to problem solve issues among different lines of businesses by listening, analyzing and speaking to each audience in terminologies that are easily understood.
Communicating new iterations of best business practices as they are released periodically, which is followed up with trainings and office hours to facilitate the needs of subordinates
Stand in Liaison for different lines of businesses as they relate to change management and building rapport with key stakeholders to help improve enterprise functionality and efficient work modules.
Conducted monthly reconciliations with data center to ensure changes were implemented correctly and meet company retention policies.
The Select Group (Truist Bank), Charlotte, NC
GRC Test Engineer
Sep 2020 – Feb 2021
Analyzed and evaluated teams prior to executing testing. Constructing testing plans by identifying policies, procedures, systems, and regulatory requirements.
Used Information Security guidelines of BB&T, SunTrust, and Truist to properly assess areas in which control testing were to be conducted during merger.
Prepared test scripts and execute testing to evaluate the design and operating effectiveness of controls.
Execute and review testing for asset categories, controls, and technical qualities.
Analyze and interpret findings
Tracking progress and resolution of open issues identified during testing.
Utilized RSA Archer for control testing and control attributes.
Performed testing on API, Penetration, and IAM systems within the enterprise.
Supported data center with migration of legacy organizations information and retention, and assisted in Business Continuity Program.
TIAA, Charlotte, NC
SR. Info Security Analyst/Project Management Lead
Aug 2019 – Jul 2020
Supported the new campaign of IT Risk Assessment program within Cyber Security. Assisted in testing risk controls and their effectiveness. Streamlining documentation to second line reviewers and external auditors in preparation for regulatory audits. Improving service and protocol of different lines of businesses and overall campaign, when necessary, throughout project.
Reviews and test User’s access control (IAM) – physical access relating to server room or data center, and logical access control relating to various applications, Operating systems, database, Networks and Active Directory.
Focused on data migration and data integrity due to issues discovered around incorrect information related to users entitlements.
Evaluating technical design and controls against risk factors, applicable standards, and regulatory requirements.
Consulting and building rapport with IT component and business components to ensure that valid information/documentation was supplied.
Setting up meetings/conference to ensure application teams understood the importance and relevance of the campaign and the goal to limit risk by ensuring controls are properly in place.
Providing guidance for business processes in displaying controls meet regulatory requirements
Displayed design, effectiveness, and completeness testing for controls to limit internal and external risk.
Implementation of new audit Program Company wide as company transitions into new governance falling into new regulatory requirements.
Coordinates and executes projects and ensured security risks/vulnerabilities are identified, communicated, and remediated.
Coordinated ongoing efforts to identify and resolve security vulnerabilities for all operational systems within identified SLAs
Integrated Single Sign-On (SSO) capabilities for 9 corporate applications via the identity management application
Consulting and building rapport with IT component and business components to ensure that valid information/documentation was supplied.
Setting up meetings/conference to ensure application teams understood the importance and relevance of the campaign and the goal to limit risk by ensuring controls are properly in place.
Coordinates and executes projects and ensured security risks/vulnerabilities are identified, communicated, and remediated.
Assists in maintaining SharePoint repository for policies and procedures, SLAs and other compliance or technology documentations.
Running and executing queries with SQL to pull data in use to provide application teams with required evidence in showing personnel to perform entitlement reviews and other role-based controls.
Vanguard, IT Compliance Auditor, Charlotte, NC
Jun 2018 – Aug 2019
Plan, manage and execute ITGC audit functions using best practice audit guidelines.
Reviews and test other important IT controls such as: Incident management, change management, segregation of duties, Data integrity, Anti Money Laundering (AML), etc.
Assists management in the identification and assessment of technology related risks. Reports on the adequacy of risk-based controls; evaluating technology and business-related controls for integrated IT and business auditing efforts.
Ensured information security assessments, vulnerability scans and internal penetration testing are performed to ensure that information systems are adequately protected to meet security requirements.
Works closely with management (IT Directors, Managers, and Information System Owners etc.); over IT audit findings, compliance issues, recommendations, management’s response, and implementation.
Performs Test of Internal Control to ensure Control effectiveness.
Develop reports regarding compliance with company standards, policies and procedures, and areas that may require strengthening of internal controls.
Manage, and administer contracts for software and application services and products across the organization. This includes overseeing technology spending, managing a repository of applications, and issuing Requests for Proposal, Requests for Quote, and Invitations to Bid.
Complete quality assurance and due diligence of KYC on all customers, potential or current.
Researched suspected individuals for unethical financial practices via Secretary of State, OFAC Sanctioned Countries list and Specially Designated Nationals list and conducted negative news research using internet searches;(AML)
Clear alerts and monitor customers’ transactions; (AML)
Prepare Suspicious Activity Reports (SAR) on moderate to high-risk transactions.
Carry out Enhanced Due Diligence (EDD) and assess the risk of new customers to the firm, document findings, ensure that management has been informed of key issues and risks.
Wells Fargo Bank, Compliance Auditor, Charlotte, NC
Dec 2017 – Jun 2018
Executing targeted reviews (i.e., non-recurring reviews) across the enterprise, as required by the FCRM Review Activities Program.
Conduct Compliance audits as directed to ensure bank maintains compliance with all law and regulation.
Conduct research and analysis to identify deviations from regulatory requirements.
Compile data in an organized manner and develop reports and summaries.
Assist in the revision, preparation and distribution of compliance procedures.
Ensure timely response and closure of all audit observations and findings.
Complete quality control reviews of customer’s loan files.
Provide objective and practical recommendations for management action based on findings
Additional duties as assigned by supervisor.
Investigate and authenticate account information to provide adjustment recommendation for remediation
Substantiate accounts for all errors in original account analysis
Assist in validating compliance remediation for 110,000 accounts
Participate in development of comprehensive spreadsheets to ensure quality control
Support model risk finding remediation efforts to mitigate model risk within line of business management
Manage the consolidation of model risk performance reports for senior management, including trend analysis and recommended strategies.
Assist with automation of manual process and identify opportunities for improvement of training materials.
Develop testing strategies and methodologies; evaluates the adequacy and effectiveness of policies, procedures, processes, systems and internal controls.
Analyses business and /or systems changes to determine impact; identifies and assesses operational risk issues and assigns ratings consistent with established policy standards.
Identifies and assesses key risks and controls and develops effective test plans for engagements as assigned with limited guidance.
Utilizes knowledge that expands across multiple businesses and in subject matter areas
Demonstrates professional skepticism.
Escalates significant risk exposures to appropriate levels of management.
New York State Department of Motor Vehicle, Albany, NY Junior Project Manager/Project Manager
Jun 2012 – Apr 2017
Assisted in a Multi-year campaign to migrate NYS employees onto technology-based roles to streamline all NYS documentation, exchange of information, data migration, expansion, retention, and integrity.
Using source systems to create new data warehouse in data migration in paperless initiative.
Partnering with Cyber Security team to create standard, procedures and best work practices to ensure controls were in place to maintain integrity set by commissioner.
Owned data expansion project of Drinking and Driving Cases state-wide from the mid 1960’s to present day, as well as Driver’s License and Registration documents within the retention period.
Implementation of LEAN to maximize processes in acquiring and handling data, Cutting down overhead expenses on the operational level.
Assisted in Project Charter creation and maintained sprint log of change processes within applicable domains.
Communicated stakeholder requirements and relative deadline to ensure projects maintained their timeline required to meet SLA’s mapped out by commissioner.
Maintained security and chain of command to minimize unethical actions.
Communicating with various entities of the DMV as well as other New York State agencies to complete tasks
Coordinates and executes projects and ensured security risks/vulnerabilities are identified, communicated, and remediated.
Assists management in the identification and assessment of technology related risks. Reports on the adequacy of risk-based controls; evaluating technology and business-related controls for integrated IT and business auditing efforts.