Results-driven Enterprise Risk Manager with expertise in IT audit, showcasing a proven track record in formulating and executing comprehensive risk management strategies. Specializing in leading ISO 27001 audits, I ensure stringent compliance with information security standards. Recognized for adeptly identifying, assessing, and mitigating potential risks to fortify organizational resilience. A strategic thinker, I bring a proactive approach to risk assessment, coupled with a commitment to continuous improvement. Renowned for facilitating external audits, optimizing business continuity plans, and fostering a culture of heightened risk awareness. With strong analytical skills and a collaborative leadership style, I am prepared to contribute dynamic insights and effective risk mitigation strategies to elevate enterprise risk management standards.
• Compliance Management:
Successfully led client audits, reducing observations to single digits, showcasing adeptness in navigating complex audit scenarios.
Conducted thorough Internal Audits, Contractual Audits, and Client Audits, ensuring adherence to ISO27001 and Compliance Assurance Test (CAT) standards.
• Risk Assessment and Mitigation:
Specialized in IT risk management, identifying and rectifying major gaps in the asset management/handling process.
Engaged in multiple calls and presentations with leadership and stakeholders, highlighting pain points and proposing remediation steps, resulting in a streamlined asset management process.
Encouraged stakeholders to approach assessments analytically and offer unique insights to bring new understanding to risk management programs
Developed short-term goals and long-term strategic plans to improve risk control and mitigation
• External Audit Facilitation:
Facilitated external audits by clients and regulatory agencies, demonstrating leadership in addressing and resolving audit observations effectively.
Established clear communication channels and presented findings to ensure a comprehensive understanding of audit requirements.
• Business Continuity Planning (BCP):
Prepared and updated Business Continuity Plans (BCPs) for existing clients, incorporating insights from in-depth risk assessments.
Implemented strategic initiatives to enhance BCP effectiveness, ensuring continuity of critical business functions during unforeseen events.
• ISO27001 Compliance:
Established and maintained ISO27001 standards, ensuring a high level of information security and compliance with international best practices.
Performed regular compliance checks and instituted corrective actions to address any deviations from established standards.
• Continuous Improvement:
Conducted in-depth Root Cause Analysis (RCA) of repeated and major findings related to asset management, compliance of Endpoint systems, and client audits.
Developed a strategic plan of action, converted the project to six sigma, and streamlined processes, ensuring contractual compliance and boosting revenue and goodwill.
• Collaborative Team Player:
Collaborated effectively with cross-functional teams, fostering a culture of continuous improvement and risk-awareness.
Contributed to the development of best practices, ensuring a cohesive and proactive approach to enterprise risk management.
• Results-Driven:
Increased operational efficiency by implementing solutions derived from RCA, resulting in improved project revenue and enhanced organizational goodwill.
Established a track record of achieving and surpassing organizational goals related to information security, audit efficiency, and risk mitigation.
Risk advisory
undefinedISO 27001 Lead Auditor
ISO 27001 Lead Auditor
Six Sigma