Olasunkanmi Omotosho
Chicago, Illinois. ***** 773-***-****
*******************@*****.***
Professional Summary
A detailed oriented and results-driven Information System/technology auditor with 5+ years of experience. Skilled in performing Information Systems audit using NIST CSF, NIST 80053 r5A and RMF. Reviewing Business Processes, and appraising policies and procedures to ensure their compliance with regulatory requirements, laws, standards and alignments with business objectives. Risk Analyst experienced in controls implementation, IT Audit processes and formulating recommendations for improving organization operating performance.
Professional knowledge of dedicated IT Audits, Integrated IT Audits, and Special IT Audit Projects. Extensive experience in providing observations and to improve business processes, increase operating efficiencies, and reduce operational, technology and management risks.
Skills
Experienced with auditing/consulting and business process improvements.
Excellent understanding of business and IT processes.
Able to conduct audit research, technical interviews, write audit reports and provide regular updates to internal management and clients.
Experienced in executing IT audits in large IT and business environment.
Experienced in surroundings with technical compliance practices, common IT/Tech regulatory frameworks and laws such as NIST, ISO, SOC 1 & 2, SOX, PCI-DSS, COBIT, ICFR, RMF using Nist 80037, etc.
Experienced with GRC platform (Service Now, TeamMate, Audit Board, and Microsoft Excel.)
Knowledge of Audit assurance, governance, and control frameworks such as COBIT, NIST, and ISO, SOX/MAR, Service Organization Controls (SOC).
Actively staying abreast of emerging issues involving IT audit, changes in technology, and evolving cybersecurity laws and regulations that could impact the organization.
Able to evaluate and communicate security assessment reports, management, technical report, and risks to stakeholders.
Ability to effortlessly interpret business needs into technical solutions and other way round.
Understand and apply audit methodology and professional practices.
Ability to identify and communicate opportunities to reduce risk and improve the overall effectiveness and operational efficiency of the organization.
Implement and manage security tools, continuous monitoring and interpretation of threats using IDS and SIEM.
Related Experience
IT Auditor (Indigo Flex Consulting)
Skip the dishes. On. Canada Feb 2020 – Sept. 2022
Participated in SOX, PCI-DSS & SOC 2 compliance program.
Testing controls and assisted in the development and advancement of IT audit and compliance efforts pursuant Sarbanes-Oxley (SOX)
Examine IT controls, evaluate the design and operational effectiveness, determine exposure to risk and review remediation strategies
Interacting effectively with clients, stakeholders, and team members in a wide variety of settings.
Maintained business relationships with appropriate levels of management to ensure that audit is aware of changes in business activities and objectives, and a necessary Audit response is developed.
Identify information, people, process and technology risks and weaknesses and participate in stakeholder and team meetings
Assist with the identification and communication of significant IT risks and the closure of IT Audit reports
Participated in providing feedback to management through the Audit Report on discovered IT risk, for risk monitoring of the internal control structure, and operating processes
IT Auditor. (Indigo Flex Consulting)
Salesforce. On Canada Nov 2016- Dec 2019
Developed and proposed recommendations for control and efficiency improvements.
Conducted SOX & SOC 2 readiness assessment & gap analysis in support of annual recertification process.
Executing audit procedures including leading walkthrough interviews, requesting, reviewing, and analyzing evidence, and documenting test steps in detailed, well-supported work papers.
Participated in the planning of internal audits by collaborating with IT and business management to develop control walkthrough narratives, the matrix of key controls, testing approach, and schedule.
Support audit reporting and issue remediation efforts, including tracking the status of open issues and other IT-related findings.
Assist with the preparation and review of formal written reports expressing opinions on the adequacy and effectiveness of the systems.
Promoted effective communication and information exchange by attending status meetings to highlight new and unresolved assessment issues.
Junior IT Auditor, Globacom. Lagos, Nig. Feb 2015- Aug 2016
Supporting stakeholders in determining the appropriate treatment of identified
Risks and gaps; identifying appropriate action plans for risk remediation.
●Defining and documenting business process responsibilities and ownership of the controls in the GRC tool.
●Coordinating and maintaining management’s compliance process controls documentation and review controls regularly to ensure adequate design and identification of key controls for processes that affect the company
● Planning and executing collaborative risk-based IT audits and concluding whether risks are appropriately managed through the existence of effective control or other techniques
Assisting with the planning and execution of projects in internal controls over financial reporting (ICFR) and internal audits.
Conducted and reviewed of team products audit work performed in line with approved audit plan (work papers, testing finding and artifacts, status reports, etc.)
Credit Analyst, (Internship)
Intercontinental Bank. Lagos, Nig. May 2011 – Aug. 2012
Maintains and updates existing credit files.
Evaluate credit profile, risk exposure and other risk factors.
Analyzes balance sheet, cash flow, and credit history.
Ensures compliance with credit policies.
Stays updated about industry news, key trends and macroeconomic news.
Education and Certifications.
Certified in Risk and Information System control (CRISC) In view
CompTIA Security+ 2022
Certified Information System Auditor (CISA) 2021
Cybersecurity – University of Toronto 2021- 2022
YCT. Bachelor’s in Engineering 2008- 2014