If you are interested in this candidate, please contact Andrew Wilson via email awilson@cerfinancial.co.uk or call on 0207 626 6065.
00346967
PROFILE:
IT risk professional with extensive experience leading audits, regulatory compliance, business continuity planning, and digital transformation initiatives. CISA-certified with proven ability to leverage industry best practices and collaborate across teams and adept at managing stakeholder expectations.
IT Audit/Risk Experience
CAREER HISTORY:
June 2023 – Present
IT Risk Management Consultant
Delivered independent business continuity, disaster recovery, and IT risk consulting services across banking, telecommunications, and other sectors:
- Assessed IT readiness for business continuity (ISO 27031) and proposed cost-effective recovery strategies for over 50 critical processes.
- Identified opportunities to streamline IT investments through Failure Mode and Effects Analysis (FMEA), resulting in a 30% cost optimization while enhancing resilience.
- Developed IT DR runbooks detailing step-by-step recovery procedures for 8 mission-critical apps.
- Evaluated telecom infrastructure resilience and business continuity maturity, delivering a roadmap for achieving full ISO 22301 compliance.
Banking
February 2021 – June 2023
Senior Manager
October 2018 – June 2021
Manager
Business Risk Monitoring: Utilized data analytics to streamline risk management for lines of business, enhancing collaboration with compliance and audit.
- Designed a Tableau dashboard that enabled early detection of mortgage application errors, preventing an estimated $3M in potential fraud losses.
- Led root cause analysis and remediation project for incorrect interest charges, resulting in $200k in refunds and prevention of regulatory penalties.
- Supported regulatory compliance teams by providing data insights, process walkthroughs, contributing to the successful closure of 4 high-risk issues.
- Established procedures to triage and coordinate remediation of system mismatch incidents, resulting in a 20% improvement in resolution time.
- Supported risk control self-assessments (RCSAs) with data analytics, enhancing quantification of risk impact and control effectiveness.
- Cloud Data Migration: Facilitated the successful migration of Cost of Borrowing (CoB) data to hybrid cloud, implementing strategies to balance business requirements with technology risk management.
- Developed a framework for data classification based on regulatory requirements and enterprise policies.
- Identified 28 essential CoB data elements and mapped end-to-end data lineage across 4 systems.
- Co-designed a robust role-based access control (RBAC) model, defining 8 user roles with granular permissions to ensure least privilege access for sensitive financial data.
- Actively monitored end user testing, collaborating with developers to resolve 10+ identified discrepancies.
Business Management
December 2016 – August 2018
Assistant Manager
October 2013 – December 2016
Consultant
IT Audit: Led and delivered over 20 IT audit assignments in real estate, banking, retail, and government, leveraging industry-recognized frameworks like COBIT, COSO, and ITIL.
- Performed IT risk assessments to define the audit universe and develop risk-based, multi-year audit plans.
- Identified and communicated IT audit findings to senior management and business leaders.
- Evaluated the design and effectiveness of IT General Controls through process walkthroughs, risk-control matrix development, control testing, and issuance of detailed reports to ensure risk mitigation.
- Tested application controls for Point-of-Sale systems, focusing on Application Governance, Change Management, Logical Access, and Network Security.
- Leveraged the ITIL framework to assess controls governing Helpdesk Management, Service Quality Assurance, and Problem Management.
- Reviewed data center security controls, strengthening physical and environmental security measures to ensure data protection and compliance with relevant regulations.
- Utilized the COBIT framework to assess IT Governance controls across key domains including IT Strategy, Organization, Policies, and Risk Management.
- Supported SOX 404 audits ensuring compliance with regulatory requirements and providing assurance on the effectiveness of internal controls over financial reporting.
- Business Continuity: Successfully implemented Business Continuity Management System (BCMS) based on international standards (ISO 22301, ISO 27031 and BCI Good Practice Guidelines) and facilitated the certification of 8 large financial institutions and government entities in the Middle East.
- Supported the rollout of mass notification tool (Everbridge), reducing incident response time by 30%.
- Conducted Business Impact Analysis (BIA) workshops to identify business-critical processes and Recovery Time Objectives (RTOs).
- Developed recovery strategies for people, site, and technology using a risk-based approach.
- Documented Business Continuity Plans (BCPs) outlining procedures for initial response, relocation, recovery, and restoration.
- Enhanced employee preparedness through customized BCMS training sessions.
- Devised test scenarios, developed test scripts, and executed full business continuity simulation testing.
February 2021 – June 2023
Banking
Senior Manager
Risk Appetite: Spearheaded risk appetite reporting for Canadian Banking (CB), developing quarterly reports for regulators, and driving the yearly recalibration of risk appetite measures.
- Cultivated strong relationships with cross-functional risk partners, driving open communication and knowledge sharing, reducing risk incidents by 10% YoY.
- Designed a tool to automate data entry, reducing time and effort required to generate draft reports by 60%.
- Created an interactive dashboard with historical risk appetite data to support trend analysis and enable proactive risk mitigation.
- Ensured alignment between business goals, and top/emerging risks through proactive engagement with first and second-line stakeholders.
- Developed an integrated risk appetite policy, harmonizing risk frameworks across CB and enterprise levels.
EDUCATION:
January 2012 – September 2013: University
MSc Computer Network Technology (Distinction)
September 2007 – September 2011: Institute of Technology and Science
BE (Hons) Computer Science (First)
CERTIFICATIONS:
- May 2023: Certified Professional in Accessibility Core Competencies (CPACC) – IAAP
- April 2018: Certified Information Systems Auditor (CISA) – ISACA
TRAINING:
- February 2024: Web Accessibility Specialist – IAAP
- September 2021: Cloud Fundamentals – ISACA
- July 2016: ISO 22301 Lead Implementer – PECB
References Available Upon Request
If you are interested in this candidate, please contact Andrew Wilson via email awilson@cerfinancial.co.uk or call on 0207 626 6065.
To view other CV's please click here.