IT Auditor - £700 per day

If you are interested in this candidate, please contact Andrew Wilson via email awilson@cerfinancial.co.uk or call on 0207 626 6065.

00328568

PROFILE

Currently employed as an IT Auditor on a contract basis, with professional certifications including Certified Public Accountant (CPA) and Certified Information Systems Auditor (CISA).

  • Has more than 12 years of professional work experience in Information Systems Auditing focusing on the assessment of risk and evaluation of internal business cycle and application controls and general IT controls including access security, change management, and computer operations.
  • Has almost 2 years of performing IT audit on FCA’s Client Assets Sourcebook (CASS)
  • engagements.
  • Has strong experience in engagement management, staff supervision, risk assessment, review, and evaluation of the following:

SKILLS:

Testing Areas:

  • General IT Controls Testing (Access Security, Change Management, and Network Operations, Product Management, Data Encryption)
  • Application Business Controls Testing (Manual or Application/Automated Controls)
  • Information Produced by the Entity (IPE) or Information Used by the Client (IUC) Testing

Technical Competency on Different Systems:

  • Operating Systems: OS/400, Windows, Red Hat Linux
  • Financial Accounting Systems: SAP R/3, Oracle Financials, JD Edwards, PeopleSoft, CODA, Sage, Microsoft Great Plains, Microsoft Dynamics, Figaro, Frontier
  • Database Systems: Oracle, SQL Databases
  • IT Is supporting Tools: Remedy, JIRA, Splunk, Dynatrace

Nature of Engagement:

  • Statutory financial statement audits subject to Public Company Accounting Oversight Board (PCAOB)
  • Sarbanes-Oxley Section 404 (SOX 404)
  • ISAE 3402 Assurance Reports on Controls at a Service Organization (Examination of an Entity's Internal Control Over Financial Reporting)
  • Third Party Service and Vendor Assessment
  • Client Assets Sourcebook (CASS) IT Audit

Industries within Multinational Companies:

  • Financial Services Industry (Asset Management, Investment Management, Retail Banking, and Insurance)
  • Consumer Business
  • Technology, Media, and Telecommunications

PROFESSIONAL CERTIFICATIONS AND MEMBERSHIPS

  • Certified Information Systems Auditor (CISA) License No. 14114342, March 2014
  • Certified Public Accountant (CPA) License No. 117629, June 2006
  • Member, Information Systems Audit and Control Association (ISACA)
  • Member, Philippine Institute of Certified Public Accountants (PICPA)

EDUCATION

March 1997: Secondary School

March 2001: University – High School

March 2005: Polytechnic University: Bachelor of Science in Accountancy

CAREER HISTORY

October 2021 – Present

Recruitment Firm

IT Auditor (Contractor)

  • Conduct detailed walkthroughs and documentation of the design and implementation (D&I), and operating effectiveness (OE) testing of SOx IT and business controls.
  • Summarise exceptions noted during the controls testing and discuss with the management.
  • Provide recommendations to the management.
  • Coordinate evidence request from external auditors with the process owners.
  • Participate in the control rationalization, test attributes, and templates project.

September 2020 – October 2021

Credit Card Company

Internal IT Audit Manager

  • Attend risk assessment and planning meeting with the business audit team and stakeholders to understand how the business operates and the underlying systems supporting the business processes.
  • Draft risk and control matrix which includes risk level and description, control description, owner, and frequency, documents to evidence the control.
  • Conduct detailed walkthroughs, testing, and documentation of the workpapers.
  • Identify control gaps and communicate it to the stakeholder in a timely manner.
  • Draft audit report and management action plans for internal audit management review.
  • Record the issues on the internal audit database and track until its completion.

IT audit engagements worked on include payment gateway processing, incident and problem management, access security covering data encryption and API controls, platform security and stability, and product management.

September 2017 – August 2020

Professional Services

IT Audit Assistant Manager – Financial Services Audit

  • Perform joint walkthrough with the financial audit team to obtain an understanding of the business process and controls in order to determine the relevant applications and systems.
  • Participate in the risk assessment discussion with the financial audit team on the scoping (i.e., general IT controls as well as reports and automated controls for testing), timing, deliverables, and approach.
  • Oversee the work of less experienced staff during fieldwork, perform the detailed review of workpapers, and ensure that submitted workpapers are in accordance with the methodology and of high quality of work.
  • Prepare regular update to senior management, financial audit team, and client to discuss status of the work, any finding, and outstanding evidence.

December 2014 – September 2017

Professional Services

Senior Consultant - Audit and Risk Advisory

  • Perform risk assessment planning discussion with the audit team and client on the scoping, timing, and approach.
  • Assist the manager in identifying the general IT controls, business process controls, IPE or IUC, and reports testing.
  • Liaise document and meeting request for the team and performs kick-off meeting with the client.
  • Conduct fieldwork and performs test of controls and documentation while supervising and reviewing the work of staff.
  • Manage relationship with the audit and client and timely informs them regarding the status of work performed.
  • Ensure the planning, management letter points, completion memo, and workpapers are consistent with the test documents before submitting the work papers to the managers for review.
  • Lead the issue discussion with the client and ensures responses are received from the
  • client’s management.

March 2010 – September 2014

Professional Services

Assistant Manager – Technology Risk Management

  • Manage the risk service engagements in the Philippines office and extensively reviews the work of staff.
  • Manage client, inter-department, and inter-office relationships.
  • Review general computer controls and business cycle controls (manual and automated) as part of statutory financial statements audits and Sarbanes-Oxley Section 404 Attestation engagements.
  • Perform Computer Aided Auditing Techniques (CAATs), e.g., ACL (Audit Command Language), for controls testing and data analysis
  • Identify and documents internal control insights in the Management Letter, provides recommendations based on industry best practices, and discusses and communicates deficiencies to the client’s management.

February 2013 – March 2013

Professional Services

Senior Consultant (Secondment)

  • Execute the work for Singapore clients covering general IT controls and application controls.
  • Perform data analytics testing using DA JET and ACL.
  • Prepare issue log and management letter documents.

October 2008 – December 2009

Employment Services

Tax Analyst

  • Analyse the sales transactions of key client accounts and identifies the tax amounts as to creditable withholding tax or final value-added tax.
  • Post the identified withholding tax to the ERP application system, SAP R/3.
  • Monitor and performs clean-up of withholding tax based on the tax certificates received from the key client accounts as part of the pre-implementation activities for SAP R/3 go-live.
  • Prepare the weekly and monthly monitoring report of withholding tax amounts per Performance Analysis for each Account Manager.
  • Communicate the quarterly report to the Tax and Credits Department for the statutory reporting.
  • Proactively follow up the tax certificates due from the clients.

September 2006 – September 2008

Accountants

Audit Staff

  • Review the accounting policies, procedure manuals, and relevant contract or agreements and applies the same to the audit testing.
  • Review the accounting records and assess their adequacy for maintaining accurate and complete records.
  • Perform sampling and substantive testing based on audit risks.
  • Check if the client is in compliance with the reportorial requirement with the government agencies.
  • Communicate the internal control loopholes and summarizes the potential impacts through the management letter and make the necessary recommendations.
  • Prepare the audited financial statements, income tax return, and notes to financial statements.

References Available Upon Request

If you are interested in this candidate, please contact Andrew Wilson via email awilson@cerfinancial.co.uk or call on 0207 626 6065.

To view other CV's please click here.