Peter Nwoko
**** ******* ***** ** ******** Texas 77407
***********@*****.***
PROFESSIONAL SUMMARY
Information risk management, audit and compliance professional with experience in operational and systems audit, risk assessment, general system controls and financial information system implementation assessment.
Audit portfolio includes private and public companies in diverse industries.
Has delivered optimum benefits with technical proficiency to organizations in the manufacturing, telecommunications, finance and energy.
Broad skill-set includes: IT Audit and Sarbanes Oxley Compliance, Assessment of Internal Controls, PCI DSS, ISO27001, IT Security and Risk Management.
Has performed Audit Assessment with ITGC and Application Controls.
Experience with SDLC for System acquisition, development and implementation
Utilized core security functions of cybersecurity to identify and address potential threats, attacks and vulnerabilities using established techniques in risk management, risk mitigation, threat management and intrusion detection.
Knowledge of cyber security tools such as Tripwire, QRadar, Wireshark, Splunk, and Nessus
Knowledge of tools such as SAP, SQL, Tableau, Excel, Visio, and Share Point Based System
WORK EXPERIENCE
Realz Integrated Consulting 07/2015 – PRESENT
Senior IT Audit Specialist
Participate in the planning and execution of IT audits, perform walkthroughs and testing procedures on SOX IT controls (ITGCs and application controls), document testing results and communicated findings to the process owners and management.
Work with IT management and functional managers to enhance IT control environment, and work with Engagement Team to identify and resolve client issues discovered during Audit and Review Process.
Prepare work papers as part of documenting procedures to fully support audit findings, and ensuring audit conclusions are based on a complete understanding of the process, circumstances, and risk to the organization.
Recommend improvements that are relevant, practical, and effectively address and correct areas of control concern to process owners.
Track and follow up on audit findings to validate process owner's Corrective Action Plans.
Establish working relationships with IT and business units at various levels to identify and understand process changes or system implementations that are relevant to SOX compliance.
Participate in new systems development and post implementation audits to ensure the System Development Life Cycle (SDLC) is followed and ensure adequate internal controls are built into the systems.
Collaborate with management to evaluate Business Recovery and Continuity Plans as well as implement controls in new systems deployment.
Assist IT management in identifying gaps in existing policy and process, developing
recommendations to remediate control weaknesses.
Review the systems for compliance with policies, plans, procedures and regulations
Prepared audit scopes, reported findings, and presented recommendations for improving data integrity and operations.
Surgitech Inc. 01/2014 – 06/2015 IT Auditor
Assisted in Performing walkthrough meetings to understand system and control implementation and to ensure they are designed appropriately and working effectively.
Communicated IT audit findings to both team mates and senior management.
Responsible for managing PBC list and artifacts for Audit team.
Participated in all phases of the audit process.
Coordinated with IT department and external auditors during SOX IT testing
Coordinated IT related SOX compliance processes, assessing IT general controls in connection with access controls, change management and computer operations.
Extensive experience performing audit on access control, change management, IT operations, disaster recovery and platform reviews for Windows and UNIX OS.
Evaluated and tested segregation of duties over systems application security.
Performed audits on Disaster Recovery, Operating systems such as UNIX, Windows and other IT Infrastructures.
Evaluated effectiveness of control activities in order to provide reasonable assurance regarding client’s achievement of their business objectives including, accounts payable, accounts receivable and cash disbursements.
Tested compliance with company policies and procedures to ensure it conforms to industry standards, and evaluated the effectiveness and adequacy of General Computer controls on the Organization’s policies and procedures.
Prepared audit scopes, reported findings and presented recommendations for improving data integrity and operations.
Sahara Group(Lagos-Nigeria) 12/2012 - 12/2013
IT Compliance Analyst
Conducted security control assessments to assess the adequacy of management, operational privacy, and technical security controls implemented. Security Assessment Reports (SAR) were developed detailing the results of the assessment along with Plan of Action and Milestones (POA&M).
Performed vulnerability assessment, making sure risks are assessed and proper actions taken to mitigate them.
Conducted IT controls risk assessments including reviewing organizational policies, standards and procedures and providing advice on their adequacy, accuracy and compliance with industry standards.
Developed risk assessment reports. These reports identified threats and vulnerabilities. In addition, it also evaluates the likelihood that vulnerabilities can be exploited, assess the impact associated with these threats and vulnerabilities, and identified the overall risk level.
NB Plc Lagos Nigeria 10/2010 – 11/2012 Project Manager
Analyzed the business needs of clients and stakeholders in order to identify business problems and recommend solutions and clearly and unambiguously communicate these solutions.
Lead development of requirements, data models, and all documentation throughout project lifecycles.
Managed project requirements, deliverables and transition to Steady State support.
Collaborated with senior management and sales teams on project development, pre-sales meetings and kick off meeting with clients, and definition of enterprise architecture.
Developed and managed budgets, hiring and training 5 to 10 design staff, interfacing with staff and clients during project cycle and meeting project milestones and delivery dates.
EDUCATION
BS Chemical Engineering
PROFESSIONAL CERTIFICATIONS
CISA
ITIL
SCRUM
PROFESSIONAL MEMBERSHIPS
ISACA