JOHN PEDERSON, CISSP
Lake Villa, Illinois ***** 847-***-****
*************@*****.*** www.linkedin.com/in/john-w-pederson-cissp/
SUMMARY
A results-driven and risk-conscious security and compliance professional with expertise in software application development and maintenance, security design and control reviews, enterprise risk management, segregation of duties (SoD), and software development life cycle (SDLC). Deploys robust IT roadmaps, processes, and procedures to ensure compliance with quality standards. Expert at building and nurturing relations with professional stakeholders from associate to executive levels. Adept at devising effective solutions for complex problems while meeting and exceeding project requirements as well as enhancing the customer journey.
IT Risk Assessment and Mitigation Business Process Redesign Business Continuity Management Software Project Management Continuous Process Improvement Enterprise Resource Planning (ERP) Sarbanes-Oxley (SOX)
ACCOMPLISHMENTS
Streamlined business processes, utilizing third-party software tools and JD Edwards EnterpriseOne (E1) software, to record, report, and track changes to E1 security, user provisioning, and updates to business support tables.
Performed development activities such as project planning, requirements gathering, specifications writing, testing, documenting, implementing, and supporting enhancements for custom and off-the-shelf applications.
Proactively managed multiple JD Edwards (JDE) security and control teams regarding design, testing, and deployment of security and application configuration controls for large corporations across multiple industries.
Credited for resolving over 3,000 SoD conflicts for a large international manufacturer via directing SoD remediation efforts.
EXPERIENCE
LA-Z-BOY INC. Monroe, Michigan
Manager 2021-2025
Directed Central Administration Team to address user provisioning and general security requests, updates to business shared tables, and resolution of day-to-day data and access issues. Oversaw security design of JDE integrated ERP system, including design, configuration, and maintenance of security roles, using a RBAC model. Managed involvement in Sarbanes-Oxley (SOX) IT General Controls (ITGC) testing of JDE integrated ERP system, including working with external auditors on any issues during ITGC testing.
Collaborated with ServiceNow Ticketing developers to configure a ticketing solution to identify, track, and report general business table changes, user provisioning requests, and enhancements to security model.
Enhanced quarterly SOX user access review process to utilize Workiva auditing tool with E1 to distribute, certify, and track user access reviews for 36 groups.
Led segregation of duties (SoD) conflict analysis and collaborated with business owners and IT developers to design effective process controls for La-Z-Boy’s business and manufacturing facilities.
Managed relationship between ALLOut software vendor and La-Z-Boy. Directed upgrade and testing of ALLOut toolset to newer release.
DELOITTE & TOUCHE, LLP Chicago, Illinois
Manager 2005-2020
Administered JD Edwards (JDE) security upgrade and installation designs, including segregation of duties (SoD) conflict and control reviews. Served as team leader for SoD initiatives and contributed to SOX Section 404 assessments. Engaged with cross-functional teams to manage the design and development of new JDE security model. Remediated security access issues. Conducted risk and needs analysis, identified business process control best practices, and provided recommendations to internal audit and business process teams.
Devised and integrated controls framework to identify potential conflicts and mitigate risks / controls.
Managed JDE security and control teams regarding design, configuration, testing, and deployment of security / application configuration controls for large consumer products retail company and other companies across multiple industries.
Directed SoD operations to analyze cross-application conflicts and business process controls for air cargo company.
Resolved 3,000 SoD conflicts for large international manufacturer by directing SoD remediation.
Performed internal / external audit services across ERP systems, executing risk-based methodology within general computer processing environment.
ADDITIONAL EXPERIENCE
AKORN, INC., Buffalo Grove, Illinois, Manager - Application Development, 2001-2005. Oversaw all corporate applications, including JD Edwards ERP, Workbooks CRM, and custom chargeback system.
OUTBOARD MARINE CORPORATION, Waukegan, Illinois, Senior Business Analyst, 1996-2001
CORNING INCORPORATED, Corning, New York, Senior Business Analyst, 1982-1996
EDUCATION
NORTHERN ILLINOIS UNIVERSITY, DeKalb, Illinois
B.S., Computer Science
Skills
Application Development Management
Requirements Analysis
Business Process Design
Team Leadership
Microsoft Office Proficiency
JD Edwards EnterpriseOne
Controls Management
Software Development Lifecycle
Written Communication
Team Collaboration
Business Continuity Manage
Sarbanes-Oxley (SOX)
Continuous Process Improvement
ALLOut Security
QSoftware
CERTIFICATIONS
Certified Information Systems Security Professional (CISSP)
ALLOut Silver Partner