A highly motivated and result driven Information Security professional over 13 years of IT Compliance (SOX) experience; with analytical and logical skills and a strong desire to learn, contribute and make a positive difference to the organization.
Overview
13
13
years of professional experience
1
1
Certification
Work History
Senior Manager –SOX Compliance
Exela technologies Pvt.Ltd.
02.2021 - Current
Project: Leading the IT SOX testing team as a Sr. Manager for carrying out SOX control testing and IT application controls testing for critical business applications for the organization.
Responsible for reporting on the SOX program to top management.
Reviewed of working papers of IT general controls prepared by team and IT application control for number of business process across all major domains.
Obtained SOC reports for third-party applications in scope to perform CUECs testing and evaluations.
Led walkthrough meetings with control owners for ITGCs, IT application controls.
On-boarded new applications into the SOX scoping as per SOX 404 framework.
Identified and tracked deficiencies until the closures.
Coordinated with external auditors to gather all the evidence from relevant stakeholders.
Responsible for project planning to ensure timely completion of audit cycles.
Mentored team members to resolve challenges faced during audit cycles.
Interviewed number of candidates to hire quality resources in the team.
ENO
Credit Suisse INDIA Pvt. Ltd.
07.2018 - 01.2021
Project: Worked with the SOX ITC testing team as an Internal Auditor for SOX and other regulations, carrying out SOX control testing for critical business applications for the bank.
Assurance on management assessment of internal controls from technology perspective (SOX 404)
Scoping of applications relevant for SOX 404 assessment, risk assessment, and analysis.
Worked on ITGC testing for multiple in-house and off the shelf applications in various domains such as interface, change management, computer operations, access management.
Interface scoping from SOX in scope business processes.
Prepared of DET, OET and Control documentation on in-house strategic tool (MARCS)
Involved in program support activities such as effective project planning, scheduling, end of year sign off process
Supported external auditors (KPMG) in testing control effectiveness, population and sampling, compliance documentation, etc.
Issue lifecycle management for issues raised during SOX testing (internal and external)
IT Analyst
TATA consultancy services Ltd.
08.2016 - 06.2018
Project: Working with IT risk and control team for carrying SOX testing for no. of critical business applications for one of leading investment banking client.
Carried out design effectiveness testing for application to validate the applicability controls to applications.
Deal with assessors across the client organization to collect the evidences and for discussing findings in respective controls.
Performed testing more than 100 SOX and Non SOX controls across every risk areas including and not limited to backups, logical access management, change management, logs management, Job failures, data integrity etc.
Carried out operational effectiveness testing (OET) for highly critical business applications to identify the findings.
Carried out testing for MAS which is a Singapore Compliance for no. of application.
Documentation and reporting GAPs to higher management for each tech/business areas.
Creation of GAPs and closure on valid evidence submission.
Interacted with client and higher level stakeholders on frequent basis.
Sr. Associate IT Consultant
KPIT Technologies Ltd.
02.2012 - 07.2016
Project: Working with the IT compliance team and accountable for carrying out Information technology general control reviews/testing and auditing, SOX 404 reviews and IT process Improvements.
Carried IT general control reviews for the applications having significant financial impact
Senior Member of SOX testing and management team and subsequently worked with client’s team to ensure SOX Compliance
Responsible for liaison between Client personnel and external auditors
Based on Client’s IT architecture/landscape, documented IT policies and drafted procedures for User access management, Change management, Incident Closure
Tested and reviewed infrastructure controls to ensure backups of data, Exclusions, antivirus status, data restoration etc.
Reviewed the appropriateness of user’s accesses to application and system accounts with elevated access to the Application, Database and Job Scheduler and took corrective actions for findings identified
Reviewed unauthorized changes and its nature that have been made to the production application and database objects and noted it as GAP in process.
Reviewed appropriateness of segregation of duties among different logical and physical accesses.
Verified security impact assessment and user acceptance testing procedure undertaken for the production changes
Validated established system parameters and their mapping in accordance with management expectations.
Identified key business users with elevated access to production and to obtained the business justification from business
Drafted criteria against which audit will be conducted for change management process
Education
B.E. - Computer
North Maharashtra University
MBA - IT
Pune University
Certification
ISO 27001–Successfully completed & cleared certification course of Information security management system ISO27001.
Perusing CISA certification
PROFESSIONAL SYNOPSIS:
IT general control reviews and SOX compliance
Review of Access Controls, Change Management ,infrastructure, interface controls and communication with Senior level Business and IT stakeholders for evidence gathering and appropriate justifications and corrective actions against findings identified
IT application control testing
SOC reports evaluations
Scoping and onboarding of applications relevant for SOX 404 assessment, risk assessment and analysis
Team management and stakeholder management
MAJOR STRENGTHS:
Excellent communication and presentation skills with demonstrated abilities in leading & motivating team.
Ability to adapt well and perform in a new competitive environment.