Information Security Analyst with more than 8 years of experience working in Information Security looking for a position where I can have lasting impact to the organization. This would be accomplished by providing information security solutions in a challenging environment where I can utilize my security knowledge, solutions design experience and problem solving abilities. I have a combination of technical and Information Security skills including the industry recognized CISSP and CISA certifications. My interests focus on Project Security, Governance, IT Audit, Risk Management and IT Leadership. I am recognized as an ambitious individual that values integrity and a valuable contributor in a team environment.
Perform and plan Information Technologies audits and process reviews.
Ensure internal controls are effective and efficient to minimize risks to the company.
Identify amelioration opportunities on internal controls that can be implemented on IT infrastructure, IT systems, operations and processes.
Deliver high quality work with a risk driven approach.
Determine if processes and controls are compliant with policies, laws and contractual obligations related to information security and confidentiality of the information.
Communicate strengths and weaknesses of internal controls to executives and develop with them an efficient and integrated approach to resolve weaknesses.
Complete audit mandate on time and on budget.
Assist the executives in various requests and perform special mandates.
Advisor (Subject Matter Expert) to executives and key people on subjects related to Information Technologies.
Assist the audit team during their mandates.
Development and execution of an IT training for the audit team.
Advisor to IT services teams on various projects and/or questions to ensure that adequate and sufficient controls are implemented.
Elaborate audit tools and methods to ameliorate (make more effective) the audit processes.
Ensure that projects comply with corporate policies and directives and advise on required security controls.
Contract review to ensure that security clauses were included.
Review weekly application and technology change requests as a core member of the change advisory board based on ITIL framework.
Deliver Information Security Awareness material to new hires to inform them about the company policies and sensitize them regarding the threats that the company faces related to information security. Over 2000 new employees trained.
Supervised interns on Information Security technology process and tools development projects.
Development and implementation of the Information Security policy exception process to ensure that exception to policies are properly documented.
Develop & launch of the on-line Information Security Awareness training program deployed to more than 15 000 employees.
Conduct security investigations for various business units (Ex. Legal Services, Human Resources, etc... )
Assist IT colleagues from Wichita, Belfast, Toronto and other regions in the implementation of IT security processes.