Eniola Tobi Akinbileje
****************@*****.*** 240-***-**** Houston,TX
Professional Profile
IT Compliance & Audit Expert with 6+ years of experience aligning IT systems with modern regulatory frameworks (COSO, PCI-DSS, ISO 27001, SOX, HIPAA) and implementing AI-driven compliance monitoring. Adept at integrating Agile auditing methodologies, cloud governance, and third-party risk management to optimize compliance workflows. Skilled in leveraging automation tools (Power BI, ServiceNow GRC) to streamline audits and reporting. Strong focus on data privacy (GDPR, CCPA) and DevSecOps integration for continuous compliance in hybrid environments.
Core Competencies
Compliance Frameworks: COSO, NIST CSF, ISO 27001:2022, PCI-DSS v4.0, SOC 2, HIPAA, GDPR
IT Governance: ITIL 4, COBIT 2019, SOX 404 Controls, Cloud Security Alliance (CSA) STAR
Emerging Tech: AI/ML for anomaly detection, Zero Trust Architecture (ZTA), CI/CD pipeline compliance
Network Security: WAN/LAN, VPNs, micro-segmentation
Tools: ServiceNow GRC, RSA Archer, Power BI, Splunk ES, IBM QRadar, Microsoft 365 Advanced Compliance
Data Protection: Encryption (AES-256, TLS 1.3), DLP, SQL hardening (OWASP Top 10)
Incident Handling: MITRE ATT&CK Framework, automated playbooks, post-incident RCA
Professional Experience
Senior IT Compliance Analyst
Ernst & Young (EY) Remote 2022–Present
(Serving oil & gas, energy, manufacturing, and hospitality sectors)
Key Achievements:
Spearheaded AI-powered compliance monitoring using Splunk and Microsoft Sentinel, reducing manual audit efforts by 40% while improving risk detection accuracy.
Designed cloud-native compliance controls for AWS and Azure environments, aligning with ISO 27001 and CSA STAR benchmarks for 15+ enterprise clients.
Automated SOX 404 testing workflows with Power BI and ServiceNow GRC, cutting reporting time by 35%.
Led third-party risk assessments for SaaS vendors using Shared Assessments SIG v7, standardizing scoring and reducing vendor risks by 25%.
Collaborated with DevOps teams to embed compliance checks into CI/CD pipelines, reducing post-deployment vulnerabilities by 50%.
Day-to-Day Responsibilities:
Conduct end-to-end audits for hybrid IT environments, including cloud (AWS/Azure), on-prem systems, and IoT devices.
Develop dynamic compliance dashboards using Power BI to provide real-time insights to executives.
Evaluate IT systems and processes for compliance with PCI-DSS v4.0 and HIPAA standards.
Partner with cybersecurity teams to implement Zero Trust Architecture (ZTA) controls for privileged access management.
IT Compliance Specialist
Seventh Sense Consulting Remote 2019–2022
(Serving retail and healthcare sectors)
Key Achievements:
Automated PCI-DSS compliance for 50+ retail POS systems using Qualys and Tenable, achieving full audit readiness.
Reduced third-party vendor risks by 45% through standardized assessments using Shared Assessments SIG.
Upgraded legacy AS400 systems with modern RBAC policies and session monitoring, resolving 50+ vulnerabilities.
Deployed Palo Alto Strata IPS for real-time threat blocking and SSL decryption in encrypted traffic flows.
Day-to-Day Responsibilities:
Performed gap analyses for ISO 27001:2022 readiness, focusing on cloud security and supply chain risks.
Audited Microsoft 365 environments against HIPAA requirements using Microsoft Purview Compliance Manager.
Created incident response playbooks integrating MITRE ATT&CK Framework for ransomware preparedness.
Conducted audits of IT infrastructure against GDPR/ISO/NIST standards to identify compliance gaps.
Education
Master of Science in Advanced Computing
Morgan State University Baltimore, MD
Relevant Coursework: AI Ethics & Compliance, Cloud Security Architecture, GDPR Implementation Strategies
Technical Proficiencies
GRC Platforms: ServiceNow IRM, RSA Archer, OneTrust
Cloud Security: AWS Config, Azure Policy, GCP Security Command Center
Automation: Python (Pandas, NumPy), UiPath RPA, Terraform Compliance
Systems & Tools: Windows Server, AS400 Modernization, SQL Database Security Administration
Security Tools: Splunk ES, Wireshark, Snort, Qualys, Tenable
Data Privacy: OneTrust Data Mapping, BigID, Endpoint Protector
Key Projects
PCI-DSS v4.0 Compliance Overhaul: Migrated payment systems to AWS with Terraform-enforced encryption policies, reducing compliance costs by 35%.
AS400 Security Modernization: Implemented RBAC policies and session monitoring, resolving critical vulnerabilities in legacy systems.