Ama Opoku Agyeiwaa
Elkton, Maryland 631-***-**** ****************@*****.***
Exceptional and Goal oriented IT Auditor with over 4+ years of experience. Proficient in auditing Application and IT General Controls, audit reporting, documentation review, audit tracking, risk control Matrix and mapping controls against standard and frameworks (NIST, COSO, COBIT, HIPAA, SOX, SOC, FISCAM, PCI DSS). Can easily adapt to new systems and quickly learn processes. Fully knowledgeable in applicable regulations and standard audit procedures.
PROFESSIONAL EXPERIENCE
Senior IT Auditor
Soft Afrique – Woodbridge, NJ 06/2019 - Present
•Perform Information Technology General Control (ITGC) and Application Controls testing using FISCAM, and NIST 800-53r4.
•Test Access control and Change Management as part of a SOX and SOC audit.
•Perform walkthrough and audit status meeting to evaluate the design and operating effectiveness of controls.
•Test internal controls and assisted in developing Corrective Action Plan (CAP) to conform with FISCAM and OMB Circular A-123
•Evaluate compliance with corporate security policies from planning phase to completion using COBIT, COSO, PCI DSS, SOX, OMB Circular A-123, SSAE 18, FISMA Frameworks in performing audit.
•Perform SOX testing in the areas of Access Control, Change Management, IT and Network Operations.
•Coordinate with IT department and external auditors during SOX IT testing.
•Use audit tools such as teammate, FX engagement to complete IT work paper documentation.
•Experience in IT auditing with emphasis on commercial public companies and federal government depart using ITGC and Application Controls.
•Prepare work papers and supporting documentation for weaknesses and vulnerabilities found throughout the audit process.
•Manage the PBC list for the audit team.
•Evaluate the design and effectiveness of technology controls throughout the business cycle.
•Participates in all phases of the audit lifecycle.
Page 2
IT Auditor
Soft Afrique - Woodbridge, NJ
05/2018 – 06/2019
•Performed ITGC and Application Control testing using SOX, COSO, HIPAA, SSAE-18 and NIST Guidelines series
•Performed all stages of audit planning, fieldwork, executive, reporting and follow up.
•Performed and document audit activities in accordance with professional standards such as COSO and SOX internal control frameworks Audit Project.
•Review of IT General Controls (ITGC) and various applications, databases, operating systems and network devices.
•Participated in team kick-off and walkthrough meetings.
•Performed SOX Audits and tested Access Controls, Configuration Management using NIST 800 53, and other NIST Guidelines
•Identified and communicated IT audit findings to senior management and client.
•Conducted testing of Sarbanes-Oxley (SOX), PCI DSS and HIPAA, COBIT and COSO.
•Assisted in preparing IT audit program to include access control, change management controls and application controls; and identify deficiencies in the design and operating effectiveness of control and provide recommendation.
•Testing and documentation of key SOX and IT General controls leveraging a defined process compliance monitoring process.
EDUCATION & CERTIFICATIONS
Bachelor of Arts in Social Science – KNUST
Certifications- Qualys Certified, CompTIA Security +, CISA – In Progress