Senior IT Auditor - £70,000

If you are interested in this candidate, please contact Andrew Wilson via email awilson@cerfinancial.co.uk or call on 0207 626 6065.

00346967

PROFILE:

IT risk professional with extensive experience leading audits, regulatory compliance, business continuity planning, and digital transformation initiatives. CISA-certified with proven ability to leverage industry best practices and collaborate across teams and adept at managing stakeholder expectations.

IT Audit/Risk Experience

CAREER HISTORY:

June 2023 – Present

IT Risk Management Consultant

Delivered independent business continuity, disaster recovery, and IT risk consulting services across banking, telecommunications, and other sectors:

  • Assessed IT readiness for business continuity (ISO 27031) and proposed cost-effective recovery strategies for over 50 critical processes.
  • Identified opportunities to streamline IT investments through Failure Mode and Effects Analysis (FMEA), resulting in a 30% cost optimization while enhancing resilience.
  • Developed IT DR runbooks detailing step-by-step recovery procedures for 8 mission-critical apps.
  • Evaluated telecom infrastructure resilience and business continuity maturity, delivering a roadmap for achieving full ISO 22301 compliance.

Banking

February 2021 – June 2023

Senior Manager

October 2018 – June 2021

Manager

Business Risk Monitoring: Utilized data analytics to streamline risk management for lines of business, enhancing collaboration with compliance and audit.

  • Designed a Tableau dashboard that enabled early detection of mortgage application errors, preventing an estimated $3M in potential fraud losses.
  • Led root cause analysis and remediation project for incorrect interest charges, resulting in $200k in refunds and prevention of regulatory penalties.
  • Supported regulatory compliance teams by providing data insights, process walkthroughs, contributing to the successful closure of 4 high-risk issues.
  • Established procedures to triage and coordinate remediation of system mismatch incidents, resulting in a 20% improvement in resolution time.
  • Supported risk control self-assessments (RCSAs) with data analytics, enhancing quantification of risk impact and control effectiveness.
  • Cloud Data Migration: Facilitated the successful migration of Cost of Borrowing (CoB) data to hybrid cloud, implementing strategies to balance business requirements with technology risk management.
  • Developed a framework for data classification based on regulatory requirements and enterprise policies.
  • Identified 28 essential CoB data elements and mapped end-to-end data lineage across 4 systems.
  • Co-designed a robust role-based access control (RBAC) model, defining 8 user roles with granular permissions to ensure least privilege access for sensitive financial data.
  • Actively monitored end user testing, collaborating with developers to resolve 10+ identified discrepancies.

Business Management

December 2016 – August 2018

Assistant Manager

October 2013 – December 2016

Consultant

IT Audit: Led and delivered over 20 IT audit assignments in real estate, banking, retail, and government, leveraging industry-recognized frameworks like COBIT, COSO, and ITIL.

  • Performed IT risk assessments to define the audit universe and develop risk-based, multi-year audit plans.
  • Identified and communicated IT audit findings to senior management and business leaders.
  • Evaluated the design and effectiveness of IT General Controls through process walkthroughs, risk-control matrix development, control testing, and issuance of detailed reports to ensure risk mitigation.
  • Tested application controls for Point-of-Sale systems, focusing on Application Governance, Change Management, Logical Access, and Network Security.
  • Leveraged the ITIL framework to assess controls governing Helpdesk Management, Service Quality Assurance, and Problem Management.
  • Reviewed data center security controls, strengthening physical and environmental security measures to ensure data protection and compliance with relevant regulations.
  • Utilized the COBIT framework to assess IT Governance controls across key domains including IT Strategy, Organization, Policies, and Risk Management.
  • Supported SOX 404 audits ensuring compliance with regulatory requirements and providing assurance on the effectiveness of internal controls over financial reporting.
  • Business Continuity: Successfully implemented Business Continuity Management System (BCMS) based on international standards (ISO 22301, ISO 27031 and BCI Good Practice Guidelines) and facilitated the certification of 8 large financial institutions and government entities in the Middle East.
  • Supported the rollout of mass notification tool (Everbridge), reducing incident response time by 30%.
  • Conducted Business Impact Analysis (BIA) workshops to identify business-critical processes and Recovery Time Objectives (RTOs).
  • Developed recovery strategies for people, site, and technology using a risk-based approach.
  • Documented Business Continuity Plans (BCPs) outlining procedures for initial response, relocation, recovery, and restoration.
  • Enhanced employee preparedness through customized BCMS training sessions.
  • Devised test scenarios, developed test scripts, and executed full business continuity simulation testing.

February 2021 – June 2023

Banking

Senior Manager

Risk Appetite: Spearheaded risk appetite reporting for Canadian Banking (CB), developing quarterly reports for regulators, and driving the yearly recalibration of risk appetite measures.

  • Cultivated strong relationships with cross-functional risk partners, driving open communication and knowledge sharing, reducing risk incidents by 10% YoY.
  • Designed a tool to automate data entry, reducing time and effort required to generate draft reports by 60%.
  • Created an interactive dashboard with historical risk appetite data to support trend analysis and enable proactive risk mitigation.
  • Ensured alignment between business goals, and top/emerging risks through proactive engagement with first and second-line stakeholders.
  • Developed an integrated risk appetite policy, harmonizing risk frameworks across CB and enterprise levels.

EDUCATION:

January 2012 – September 2013: University

MSc Computer Network Technology (Distinction)

September 2007 – September 2011: Institute of Technology and Science

BE (Hons) Computer Science (First)

CERTIFICATIONS:

  • May 2023: Certified Professional in Accessibility Core Competencies (CPACC) – IAAP
  • April 2018: Certified Information Systems Auditor (CISA) – ISACA

TRAINING:

  • February 2024: Web Accessibility Specialist – IAAP
  • September 2021: Cloud Fundamentals – ISACA
  • July 2016: ISO 22301 Lead Implementer – PECB

References Available Upon Request

If you are interested in this candidate, please contact Andrew Wilson via email awilson@cerfinancial.co.uk or call on 0207 626 6065.

To view other CV's please click here.