Senior IT Audit Manager - £115,000

If you are interested in this candidate, please contact Andrew Wilson via email awilson@cerfinancial.co.uk or call on 0207 626 6065.

00211088

PROFILE

Highly skilled IT Audit Manager priding myself on being a high-achiever in each role I take on. I bring a wealth of technical and audit experience, leadership qualities, specialist knowledge of applications/ infrastructure, IT processes and excellent written and interpersonal skills, leading teams, mentoring junior members, ability to build strong relationships with clients / team and involvement in the annual planning of resources and budget.

Application Audit Reviews

I have covered a range of experience within the financial services sector, specializing in Disaster Recovery/Business Continuity and IT Audit of business processes / financial applications supporting Retail Banking (Personal Loans, / Deposit Management (Current Account / Savings), Alternate Delivery Channels (Mobile Banking), Payments (Foreign exchange transactions, SWIFT, VISA, POS DEBIT Card, Interbank Clearing systems, Western Union Payments & others), Corporate (Payroll, Tax Management, Human Resources,) Treasury (Trading, Middle Office, Back Office) covering IT process (change management, incident & problem management, logical security & user access management, application development, release management, etc.)

Network Infrastructure Reviews

Review of Information Security Management, IT Resilience reviews, Information Risk Management, Operating system & database reviews and comprehensive IT Audit of Data Centres, Business Continuity and Disaster Recovery reviews.

I look forward to a career that consolidates these skills and allows me to drive forward best practice within an organization's audit division. I also desire a challenging position that would further enhance my technical and management skills; a position that would provide opportunities for professional growth and career advancement.

CAREER HISTORY

July 2014 - January 2016

Banking

IT Audit Manager - Global Infrastructure Audit Team-AVP, Internal Audit (BIA)

  • Audit of Banks Network Infrastructure
  • System Database an Operating systems reviews
  • Information Risk Management
  • Information Security, Disaster Recovery & Business Continuity
  • IT Policy/ Standards reviews, Quality Assurance Reviews covering Cyber Technology, Banks GIS standards, etc.
  • Security Incident Management, Business Continuity & Disaster Recover, Recertification, Change Management
  • Complete 5 Days Internal Audit academy training covering BIA Audit Methodology.
  • Audit completed: VISA PIN Attestation Audit, Security Incident Response Audit & SharePoint Security & Resilience Infrastructure Audit,
  • Core Data Centre Audit and Intra Bank Data Exchange.
  • Issue Validation- End User Computing Applications EUDA, Business Continuity Management (BCM) and Unsupported Infrastructure & Applications and IT Digital Governance.
  • Assisting Directors in Preparation of Management Information reports.
  • Data Project- Updating Auditable Entity in line with inherent risks for the development of Audit Plan.
  • Preparing agenda and organizing weekly team meetings.
  • Providing support to other Technology Audit Teams as and when required.

March 2013 - May 2014

Career Break

February 2013 - March 2013

Banking

IT Audit Manager - Global Infrastructure Audit Team-AVP, Barclays Internal Audit (BIA)

  • Audit of Bank’s Network Infrastructure
  • System Database
  • Information Risk Management
  • Information Security, Disaster Recovery & Business Continuity
  • IT Policy /Standards review
  • Issue Validation/ Continuous Audit Monitoring

September 2006 – November 2012

Banking

Senior IT Auditor Manager, AVP, Application Audit, IT Audit & Automation Wing, Audit & Inspection Group

  • Perform Audit Support activities which included IT control and security reviews.
  • The primary areas of attention included risk management, OS (AS-400, Windows) security, business application security, Entity level controls and financial reporting controls in application supporting the Credit, Investment, Treasury, Retail Banking functions of the Bank.
  • Evaluate existing IT policies and recommend new or improved policies in order to achieve best practices in IT security & control.
  • Participated in closing meetings at the end of fieldwork, noting comments and providing clear explanations for findings and ratings, as required.
  • Communicating IT audit reports and synopsis of audit findings on monthly and yearly basis to Senior Audit Manager.
  • Preparation and updating IT audit checklist / audit programs.
  • Meet with Divisional Heads/ Managers and other staff, as appropriate, to ensure the relevance and validity of audit findings and recommendations
  • Prepare formal written reports summarizing and expressing opinions on the adequacy and effectiveness of system of control
  • Communicating IT audit reports and synopsis of audit findings on monthly and yearly basis to Senior Audit Manager.
  • Facilitating in analysis and implementation of Risk-based Audit requirements, i.e., preparation of entity based risk rating system for IT audit of Branches, Computer Centres and IT applications.)
  • Preparation of quarterly audit performance reports, synopsis of monthly/ yearly major IT audit findings for the audit committee.

Major Assignment as an IT Application Auditor:

  • IT General Controls (ITGC) and IT Application Controls (ITAC) Audit of Treasury Management Systems supporting Front Office: Foreign Exchange, Money Market and back office: Settlement and Reconciliation of Transactions.
  • IT GC and ITAC control review of Investment Banking Operations supporting Equity Trading / Stock Investment operations of the Bank covering Trade execution, Payments, Reconciliation, Settlement, Access Authorization & Administration, Change Management, Release Management, Data Security & backups, Software Application Interfaces, Business Continuity, etc.
  • IT Audit of Islamic Banking System support based branches running in the Bank. Audit focused on General Banking transactions, Islamic Banking loan products, etc.
  • IT Audit of HR System covering payroll and employees related payments. (medical, incentives, etc)
  • IT Audit of Banks payments system covering banks ATM Settlements, Reconciliation and international payments via SWIFT.
  • IT Audit of Personal Loan Application Software covering entire process from loan initiation to disbursement and monitoring of markup payment and record of delinquency of loan accounts. Evaluated the Reports generated from the system for its accuracy and authenticity.
  • Comprehensive IT Audit of Banks Software Applications running on IBM i-series supporting ATM Network involving ATM Reconciliation system, ATM Server Hosting IBM EURONET transaction software, ATM Monitoring Software, ATM Machines Security Testing, ATM Cash Balancing with Banks G/L and EURONET transactions. Tested User access security environment of AS 400 server hosting ATM applications, review of database security and operating system security controls on critical data files and production files, ATM Card Issuance and ATM PIN Mailer System reviews covering entire operations and software applications used for issuance of ATM cards and ATM PIN Mailer. Review of Service contracts / agreements with third party vendors providing support to bank ATM operations for maintenance of IBM EURONET Transaction software. The audit also involved the test of Design and operative effectiveness of Debit Card operations.

Major Assignment as an IT Infrastructure Auditor:

  • Review of User Level Access and Logical controls in EBS Online Banking system running IBM AS400, i-series Servers.
  • Comprehensive IT Audit of Regional Data Center involving Audit of IBM AS-400 Server, Window Based Servers, Network Infrastructure Controls and General IT Controls.
  • IT Audit of Network Infrastructure covering Business Continuity Management, Threat & risk Identification & Network Security Management.

January 2003 - August 2006

Banking

IT Auditor / Officer Grade I, IT Audit & Automation Wing, Audit & Inspection Group

Risk based Audit of Information Systems of the bank which includes the Information System audits of Regional Data Centers/IT Centers & Software Applications.

Areas covered:

  • Operating System security (Windows, AS-400/ i-series servers, Unix)
  • Software Application reviews.
  • Database Security reviews (SQL)
  • Business Process Reviews.
  • Adequacy and completeness of Business Continuity Planning.
  • Appropriateness of Change Control Procedures.
  • Security and availability of Corporate Network.
  • Access controls over the business applications.

January 2002 - December 2002

Banking

Product Manager (IT), Officer Grade I, Commercial & Retail Banking Group (CRBG), Head Office

  • Implementation of Loans Module in Core Banking Software (CAMSS). The system supports all features of product and operations of Consumer loans. i.e., Auto loans, Personal Loans and Mortgages.
  • Worked as an interface between end users and IT department to ensure that user requirements are translated into actual delivery of systems.
  • Managed the budget timelines to ensure the timely implantation of the systems prior to the launch of the products. Also, developed various MIS reports to support the monitoring of loans portfolio such as repayment schedules, delinquency reports etc.
  • The projects also involved complete integration of Consumer banking Products with banks legacy servers running in AS 400 environment.

January 1996 - December 2001

Banking

Business Analyst, Officer Grade II (Trainee Officer), Marketing Development Division

  • Developed MIS system to effectively monitor Business Performance & Targets of 29 Regional Business Offices of the Bank.
  • Developed MIS to effectively monitor Credit Card Portfolio in collaboration with concerned department at a bank.
  • Identifications of options for potential solutions and assessing them for both technical and business suitability.
  • Working closely with Software developers and a variety of end users to ensure technical compatibility and user satisfaction.
  • Overseeing the implementation of a new system.

EDUCATION

1990 – 1994: University

Bachelors in Electrical Engineering

1994 – 1995: University

Masters in Electrical Engineering

(Specialization in Computer Communication & Networks)

CERTIFICATION:

2001: Institute of Bankers

Banking Diploma (Stage I)

2007: IT Governance, Institute

Certificate of Information Security Management (ISMS)

ISO Certified 27001 Lead Auditors

2014: AAT Accounting Course through Home Learning College

Currently enrolled in Level 2 & 3 Course

TECHNICAL

  • Knowledge of various operating system: AS400 windows, UNIX, databases: SQL, Excel, MS Access and Good understanding of best practice IT Management disciplines, standards and governance arrangements

ACHIEVEMENTS & TRAINING

  • Financial Crime and AML Training Feb 2015
  • Methodology refresher Training 2015.
  • Internal Audit Academy Training Nov 2014.
  • Training on Visa Debit Encryption - Internal Audit-2014
  • 5 Days offsite Academy Training - Internal Audit - July 2014
  • Auditing - Cloud Infrastructure - Internal Audit-2014
  • Training on Ethical Hacking.
  • Member of Technical & Management Committee for implementation of Business Continuity Planning (BCP).
  • Attended 4 Days training on CISA conducted by Institute of Management (PIM)
  • Received Letter of Appreciation from SEVP Commercial & Retail Banking (C&RBG) for Launching of Consumer Durable Product and Personal Loan Product.
  • Two Days Training Seminar held on Information Security Management & Implementation held on ISO 27001 standards conducted by IT Governance Institute.
  • Two days Internal Auditing training on CISA conducted by Business Solutions.

References Available Upon Request

If you are interested in this candidate, please contact Andrew Wilson via email awilson@cerfinancial.co.uk or call on 0207 626 6065.

To view other CV's please click here.