SlideShare a Scribd company logo
1 of 7
John LaCagnina
29 Briar Ct.
Hamburg, NJ 07419
Mobile phone 917-817-0467
johnnylac@aol.com
SUMMARY:
• A Certified Information Systems Auditor (CISA) with 12+ years of experience in internal audit and SOX compliance
in the Financial Services, Pharmaceutical, and Hospitality industries
• Eight years of experience auditing, implementing security controls, and ensuring regulatory compliance with GxP, 21
CFR Part 11, and GDP regulations in the Pharmaceutical industry
• Eight years of experience with Qualification and Validation in the Pharmaceutical industry
• Five years of experience in Vendor Compliance Management
• A certified Project Manager (PMP) with 20+ years of broad experience in a large corporate environment
• Certified Internal Control Management Professional (CICMP)
• Certified IT- Governance, Risk, and Compliance (GRC) Professional/Manager (CGRCM-IT)
• Familiarity with COSO and CobiT frameworks, CMM, and ITIL methodology
• Excellent understanding, and experience in implementation of PCI DSS requirements
• Many years of Customer Service and Customer Relationship Management
• Many years of experience interacting with C level management
• Verifiable process improvement skills, oral, written, organizational, interpersonal, team building, and presentation
skills
• Extremely strong Change Management, process analysis, gap analysis, and documentation skills
• ISACA member in good standing (http://www.isaca.org/) – Strong IT Governance skills, CobiT Foundation certified
and completed the CobiT for Sarbanes-Oxley Compliance course
• Sarbanes-Oxley institute board member (http://www.soxinstitute.org/) - CSOXP certified (Sarbanes-Oxley Institute).
Contributing author and pre-production editor of the SOX guide for Financial and IT professionals 2nd
Edition (Wiley
Publications) and The Sarbanes-Oxley Act – An Introduction (Van Haren Publishing)
• GRC Institute (Governance, Risk, and Compliance) member in good standing (http://www.grcg.com/)
• Experience with data extraction and analysis using IBM’s GRD, Iron Mountain’s DRCi, Remedy, and Service-Now
• Demonstrated competency in management of multiple audits, operational responsibilities, and projects simultaneously
• Excellent leadership ability, client focus, and customer service skills
• Consulting and external client experience – interfacing with C level and senior management, clients, and off-shore
vendors
• Experience in working in environments of constantly changing priorities
CERTIFICATIONS/EDUCATION:
• CISA, Certified Information Systems Auditor
• PMP, Project Management Professional
• CICMP, Certified Internal Control Management Professional
• CGRCM-IT, Certified IT- Governance, Risk, and Compliance
• CSOXP, Certified Sarbanes-Oxley Professional
• CobiT Foundation Certified
• MCSE, MCP+I, CNA
Page 1 of 6
City University of NY graduate 1981
• ElectronicComputer Engineering degree
TECHNICAL SKILLS PROFILE:
• ClientServer environment: - Microsoft and Novell certified.
• Experience with the Remedy ARS system, IBM GRD, Service-Now, and Iron Mountain DRCi for data extraction,
reporting, and SLA management
• Familiarity with Business Continuity (BC) and Disaster Recovery (DR) policies and procedures, WAN technologies,
AD, ACLs, encryption technology, etc.
• Ability ranging from proficient to expert using MS Visio, MS Project, MS Excel, MS Word, MS PowerPoint, MS
Outlook, Lotus Notes, SharePoint, Remedy ARS, Peregrine
EMPLOYMENT HISTORY:
Datalynx-US January 2013 to present
VP of Consulting Services – Eastern Region
Relationship Management between Novartis and Datalynx contractors at the East Hanover site. These duties were
performed in addition to the services I provided for Novartis listed below and included the settling of disputes, approval of
personal time off, and other day-to-day management of the account.
Novartis July 2010 to present
Contractor for Datalynx-US providing services for Novartis – IT Quality & Compliance Manager
• Project Quality Manager for 5 Portfolio Transformation MA&D projects, CFEngine, Vblock
consolidation, EVO, and NAS, just to name just a few
• Operational Quality Manager for the Service-Now SaaS – Quality manager for the Validation of new
releases, Change Approvals, and approval of all validation documentation
• Quality Manager for UNIX Gemini Transition, Service Now, and the GIS managed DR Service
• Operational Quality Manager for the UNIXLINUX, Storage, and B&R Global service lines
• Vendor Compliance Management of IBM
• NVS Compliance Officer – interface with IBM management to review and resolve all compliance
issues. Represented GIS in the Incident Management PID renegotiations with IBM
• Qualification Procedure Development – drove and facilitated the creation of the relevant Qualification
Procedures for the Wintel, UNIX/LINUX, Database, and Storage towers.
• Conducted annual Maturity Assessments and HLBIAs for the Wintel, UNIX/LINUX, Database, and
Storage towers
• Participate on quarterly and annual SOX and Vendor Compliance Audits including hands-on
participation in Switzerland and Argentina
• Technical Writer for the Exadata initiative
• Continuous improvement of existing quality systems to meet and sustain compliance with internal and
external regulatory requirements
• Conduct Quality Reviews to evaluate if processes and deliverables fulfill the requirements for quality, to
uncover errors or deficiencies in processes and deliverables, and to identify strengths and opportunities
for improvement
• Interface with other quality and compliance stakeholders to ensure customer practices are aligned with
regulatory expectations and industry best practices
Page 2 of 6
Hermes of Paris May 2010 to July 2010
Consultant – PCI-DSS Compliance Project Manager
Responsible to drive the PCI/PA-DSS compliance initiative. This was a Cegid POS and ICVerify database environment.
In this role I performed these duties:
• Monitor and control project
• PCI SME to assist in updating and maintaining their SAQ based on version 1.2 of the PCI DSS
• POC with the QSAs (Coalfire) providing them with evidence of compliance and arranging interviews, meetings,
pen testing, etc.
• IT Auditor to identify compliance gaps and compensating controls ensuring HOP’s compliance
• Security Analyst to ensure that HOP was secure as well as compliant
• Acted in an advisory capacity in choosing the QSA and security solutions
• Documentation SME to review, update, and perform a gap analysis of their existing Security and Incident
Management documents
I interacted daily with the VP of Information Services, Director of Audit and Operations, IT Operations Manager,
Information Security Officer, Cyber-Security SME, Security Engineers, Network Admins, and the on-site security
vendor (Reliant Security) to achieve PCI-DSS compliance. I also provided weekly and ad hoc status reports to the
CFO.
WYNDHAM HOTEL GROUP July 2009 to December 2009
Consultant (returned by request) – Sr. IT Auditor / Security and Compliance Specialist
Returned by request to the Wyndham Hotel Group in the IT Security and Risk Management group to perform the audit
and testing for their 2009 SOX audit initiative as well as managing their 2009 recertification initiative, and requirements
and documentation gathering for their PDI-DSS certification initiative. The areas of audit and testing are as follows:
• Host Security for Windows, UNIX, LINUX, Network Devices
• Database Security for Oracle and DB2
• Security Administration of CHIME, Clarity, EDW, Wyndham Rewards
• Physical Security
• Backup and Recovery
• Change Management
• In addition, interacted with the external auditors to complete the audit and subsequent remediation.
TREC GLOBAL BUSINESS PROCESS SOLUTIONS Feb. 2009 to July 2009
Consultant - Business Analyst
• TREC Global Solutions provides outsourced business solutions and call center services. Process analysis as part of
the discovery process in the Program Management group for Pre-Business Development. Performed analysis of
business objectives, strategies, timelines, performance targets, budget limitations, and overall scope of work. Details
are as follows:
• Interfaced with the client to determine business needs, review existing business processes, perform Test of Design
and Test of Effectiveness, and identify performance metrics. Acted as a single point of contact to ensure the end-
to-end execution for the campaign.
• Consulted with Business Development team to report findings of discovery phase, determine solutions, establish
transition process, and provide client specific training.
• Assisted Quality Assurance team in conducting routine quality audits and reporting findings to senior
management.
Page 3 of 6
Page 4 of 6
WYNDHAM HOTEL GROUP July 2008 to Jan. 2009
Consultant – Sr. IT Auditor / Security and Compliance Specialist
• Wyndham Worldwide engagement as part of the Wyndham Hotel Group in the IT Security and Risk Management
Group. Performed as many as four concurrent audits to ensure regulatory compliance of their SDLC, PMLC and
Change Management processes, as well as the Security Administration of their Windows, UNIX, and Database
environments. Major responsibilities included extensive SOX testing and subsequent interaction with external
auditors, management of the annual user recertification process, and assisting them in their PDC-DSS Self-
Assessment Questionnaire. Details are as follows:
• Security Administration for Windows, UNIX, Oracle, DB2, Informix, and the Electronic Data Warehouse (EDW)
• Authentication Administration, Security Patching, System Hardening, Logging, Password Administration,
ACLs
• Security Administration of Applications – CHIME, Clarity, Informatica, My Portal, Oblix
• SDLC and PMLC policy
• Change management, Change control, Version control, Segregation of development, test, and production
environments, Adherence to the funding and approval process, Unit and system testing, Data conversion
• Annual User ID Recertification report for SOX compliance
• Obtain verification of status and permissions of all end users from their respective performance managers
• Administrative
• Creation and Maintenance of directory structure in SharePoint for storing and sharing reports and artifacts
• Daily and weekly status reports to leadership
• Scheduled and led meetings with auditees for acceptance and remediation of findings
• Participated in remediation meetings with external auditors and provided evidence of compliance.
PFIZER Feb. 2008 to June 2008
Consultant - Sr. IT Auditor / Security and Compliance Specialist
• Pfizer engagement as part of the Shared Applications Management Services group in the IT Security and Compliance
department. Major responsibilities include:
• Continuous Improvement – review and update existing Change Management policies, process documentation, and
related process aids stored in SharePoint.
• Audit –Manage a team of off-shore auditors in the completion of 7 process, 5 application, and 5 ad hoc internal
audits monthly. Responsible for scheduling of audits and conducted meetings with auditees for agreement on
scope and approach, and agreement with auditees on audit findings.
• Security – Management, implementation, monitoring, and control of the Security Incident and Root Cause
Analysis process and documentation.
• Compliance – participate in quarterly SOX audits
• Review RCM
• Review internal control objectives
• Test internal controls
• Report on findings
• Meetings with auditees for agreement on findings and scheduling remediation
Page 5 of 6
KPMG, LLP May 1998 to Feb. 2008
Project Manager Information Technology
• Responsible for project management, Change Management, internal SOX compliance implementations, internal client
relationships, presentations, reporting, and team mentoring and development. Major deliverables included:
• National Infrastructure Change Management project – member of the committee to evaluate existing procedures
and write the initial documentation using ITIL methodology
• Enterprise Management internal SOX audit and process documentation project. Development and implementation
of the Change Management policy using ITIL methodology for the EM group.
• SAS 70 Type I readiness assessment - liaison to service auditor as IT SME for SOX compliance. Duties included
assisting in preparation of scope and approach, preparing the PBC list, and assisting in completing the appropriate
work papers.
• Annual IT CSA Audits – Performed and managed General and Operational internal controls audits for the IS SOX
Compliance Self-Assessment internal audit
• Managed a matrixed team of 6 to bring KPMG’s NY office’s Data Center into compliance
• Performed process verification, testing, risk Identification, gap analysis. Scheduled and lead meetings with
auditees for remediation of findings, metrics, and progress reporting for the agreed upon remediation
• National Disaster Recovery project – performed asset valuation and identification of BC3 applications, services,
and dependencies
• Managed the Tax Data Asset Preservation Compliance Project for the New York Office
• Project Manager for new Construction buildouts, datacenter move, and user relocation
• Performed ongoing SLA Audits to ensure SLAs were met and adherence to ITIL Standards
• Managed issues, escalations, and expectations for the Office of the Chairman, the Office of the General Counsel,
and the Department of Professional Practices
THE CAREER CENTER Jan. 1997 to July 1998
Part-Time Technology and Applications Trainer
• Provided classroom training in Microsoft Office products, Windows 95, NT, and Novell operating systems.
• Built an NT classroom, saving the company over $10,000 in consulting costs.
ALTERNATIVE RESOURCES CORP. April 1994 to May 1998
Desktop Specialist and Team Leader
• Clients included NY Mercantile Exchange, CitiCorp, KPMG, Chase, Minet Insurance Co.
Page 6 of 6
KPMG, LLP May 1998 to Feb. 2008
Project Manager Information Technology
• Responsible for project management, Change Management, internal SOX compliance implementations, internal client
relationships, presentations, reporting, and team mentoring and development. Major deliverables included:
• National Infrastructure Change Management project – member of the committee to evaluate existing procedures
and write the initial documentation using ITIL methodology
• Enterprise Management internal SOX audit and process documentation project. Development and implementation
of the Change Management policy using ITIL methodology for the EM group.
• SAS 70 Type I readiness assessment - liaison to service auditor as IT SME for SOX compliance. Duties included
assisting in preparation of scope and approach, preparing the PBC list, and assisting in completing the appropriate
work papers.
• Annual IT CSA Audits – Performed and managed General and Operational internal controls audits for the IS SOX
Compliance Self-Assessment internal audit
• Managed a matrixed team of 6 to bring KPMG’s NY office’s Data Center into compliance
• Performed process verification, testing, risk Identification, gap analysis. Scheduled and lead meetings with
auditees for remediation of findings, metrics, and progress reporting for the agreed upon remediation
• National Disaster Recovery project – performed asset valuation and identification of BC3 applications, services,
and dependencies
• Managed the Tax Data Asset Preservation Compliance Project for the New York Office
• Project Manager for new Construction buildouts, datacenter move, and user relocation
• Performed ongoing SLA Audits to ensure SLAs were met and adherence to ITIL Standards
• Managed issues, escalations, and expectations for the Office of the Chairman, the Office of the General Counsel,
and the Department of Professional Practices
THE CAREER CENTER Jan. 1997 to July 1998
Part-Time Technology and Applications Trainer
• Provided classroom training in Microsoft Office products, Windows 95, NT, and Novell operating systems.
• Built an NT classroom, saving the company over $10,000 in consulting costs.
ALTERNATIVE RESOURCES CORP. April 1994 to May 1998
Desktop Specialist and Team Leader
• Clients included NY Mercantile Exchange, CitiCorp, KPMG, Chase, Minet Insurance Co.
Page 6 of 6

More Related Content

What's hot

Marjorie Fox Resume-12_8_16
Marjorie Fox Resume-12_8_16Marjorie Fox Resume-12_8_16
Marjorie Fox Resume-12_8_16Marjorie Fox
 
Resume JOYCE CONRAD_0416CRM
Resume JOYCE CONRAD_0416CRMResume JOYCE CONRAD_0416CRM
Resume JOYCE CONRAD_0416CRMJoyce Conrad
 
gracetoramanian-resume 012517
gracetoramanian-resume 012517gracetoramanian-resume 012517
gracetoramanian-resume 012517Grace Toramanian
 
David R Boe Resume
David R Boe ResumeDavid R Boe Resume
David R Boe ResumeDavid Boe
 
Kevin Tart Resume
Kevin Tart ResumeKevin Tart Resume
Kevin Tart Resumekevintart
 
NCI Network Engineering
NCI Network EngineeringNCI Network Engineering
NCI Network EngineeringChris Young
 
final work on Business Analyst resume
final work on Business Analyst resumefinal work on Business Analyst resume
final work on Business Analyst resumeO. Stephen Adesina
 
DianeOakleyResume20170130
DianeOakleyResume20170130DianeOakleyResume20170130
DianeOakleyResume20170130Diane Oakley
 
JLL - Building Surveying 2012
JLL - Building Surveying 2012JLL - Building Surveying 2012
JLL - Building Surveying 2012Colin Harrop
 

What's hot (14)

Santhosh_2016_01
Santhosh_2016_01Santhosh_2016_01
Santhosh_2016_01
 
Marjorie Fox Resume-12_8_16
Marjorie Fox Resume-12_8_16Marjorie Fox Resume-12_8_16
Marjorie Fox Resume-12_8_16
 
Resume JOYCE CONRAD_0416CRM
Resume JOYCE CONRAD_0416CRMResume JOYCE CONRAD_0416CRM
Resume JOYCE CONRAD_0416CRM
 
gracetoramanian-resume 012517
gracetoramanian-resume 012517gracetoramanian-resume 012517
gracetoramanian-resume 012517
 
R.L. Michael Montgomery II_AWS_vC
R.L. Michael Montgomery II_AWS_vCR.L. Michael Montgomery II_AWS_vC
R.L. Michael Montgomery II_AWS_vC
 
David R Boe Resume
David R Boe ResumeDavid R Boe Resume
David R Boe Resume
 
JZacharkan-RES2016
JZacharkan-RES2016JZacharkan-RES2016
JZacharkan-RES2016
 
Kevin Tart Resume
Kevin Tart ResumeKevin Tart Resume
Kevin Tart Resume
 
NCI Network Engineering
NCI Network EngineeringNCI Network Engineering
NCI Network Engineering
 
final work on Business Analyst resume
final work on Business Analyst resumefinal work on Business Analyst resume
final work on Business Analyst resume
 
DianeOakleyResume20170130
DianeOakleyResume20170130DianeOakleyResume20170130
DianeOakleyResume20170130
 
Santosh Kumbar
Santosh KumbarSantosh Kumbar
Santosh Kumbar
 
JLL - Building Surveying 2012
JLL - Building Surveying 2012JLL - Building Surveying 2012
JLL - Building Surveying 2012
 
Marion Russell Resume
Marion Russell ResumeMarion Russell Resume
Marion Russell Resume
 

Viewers also liked

Effects of Lake-Basin Morphological and Hydrological Characteristics on the E...
Effects of Lake-Basin Morphological and Hydrological Characteristics on the E...Effects of Lake-Basin Morphological and Hydrological Characteristics on the E...
Effects of Lake-Basin Morphological and Hydrological Characteristics on the E...Jian Huang
 
Educación STEM
Educación STEM  Educación STEM
Educación STEM ravaprende
 
James Okarimia - IFRS Implementation and How the Banks should Approach it
James Okarimia - IFRS  Implementation and How the Banks should Approach itJames Okarimia - IFRS  Implementation and How the Banks should Approach it
James Okarimia - IFRS Implementation and How the Banks should Approach itJAMES OKARIMIA
 
Diagramas de Venn Educativos
Diagramas de Venn EducativosDiagramas de Venn Educativos
Diagramas de Venn Educativosravaprende
 
Resumen Horizon Universidad 2016_intef_mayo_2016
Resumen Horizon Universidad 2016_intef_mayo_2016Resumen Horizon Universidad 2016_intef_mayo_2016
Resumen Horizon Universidad 2016_intef_mayo_2016ravaprende
 
Re-Ingenieria de Aprendizajes
Re-Ingenieria de AprendizajesRe-Ingenieria de Aprendizajes
Re-Ingenieria de Aprendizajesravaprende
 
James Okarimia - A Summary Of Top 28 Areas Covered By EC Proposed Regulation...
James Okarimia - A  Summary Of Top 28 Areas Covered By EC Proposed Regulation...James Okarimia - A  Summary Of Top 28 Areas Covered By EC Proposed Regulation...
James Okarimia - A Summary Of Top 28 Areas Covered By EC Proposed Regulation...JAMES OKARIMIA
 
Math 2007 pspm
Math 2007 pspmMath 2007 pspm
Math 2007 pspmsscfbackup
 
IFRS Implementation and How the Banks should approach it
IFRS  Implementation and How the Banks should approach itIFRS  Implementation and How the Banks should approach it
IFRS Implementation and How the Banks should approach itJAMES OKARIMIA
 
Estilos de vida generacionales
Estilos de vida generacionalesEstilos de vida generacionales
Estilos de vida generacionalesravaprende
 
Lado social del pais donde vivió jesus
Lado social del pais donde vivió jesusLado social del pais donde vivió jesus
Lado social del pais donde vivió jesusYohannaCarrion
 
Re ingenieria de Aprendizajes
Re ingenieria de AprendizajesRe ingenieria de Aprendizajes
Re ingenieria de Aprendizajesravaprende
 
IFRS Implementation and How the Banks should Approach it
IFRS  Implementation and How the Banks should Approach itIFRS  Implementation and How the Banks should Approach it
IFRS Implementation and How the Banks should Approach itJAMES OKARIMIA
 
Tesis maestría Fuzzy Control
Tesis maestría Fuzzy Control Tesis maestría Fuzzy Control
Tesis maestría Fuzzy Control ravaprende
 
Nota kuliah kimia compressed
Nota kuliah kimia compressedNota kuliah kimia compressed
Nota kuliah kimia compressedsscfbackup
 
досвід роботи гарнаженко л.п.
досвід роботи гарнаженко л.п.досвід роботи гарнаженко л.п.
досвід роботи гарнаженко л.п.sergiyko04
 
JAMES OKARIMIA - IFRS Implementation and How The Banks Should Approach IT
JAMES OKARIMIA  -  IFRS  Implementation and How The Banks Should Approach ITJAMES OKARIMIA  -  IFRS  Implementation and How The Banks Should Approach IT
JAMES OKARIMIA - IFRS Implementation and How The Banks Should Approach ITJAMES OKARIMIA
 

Viewers also liked (20)

Effects of Lake-Basin Morphological and Hydrological Characteristics on the E...
Effects of Lake-Basin Morphological and Hydrological Characteristics on the E...Effects of Lake-Basin Morphological and Hydrological Characteristics on the E...
Effects of Lake-Basin Morphological and Hydrological Characteristics on the E...
 
Educación STEM
Educación STEM  Educación STEM
Educación STEM
 
James Okarimia - IFRS Implementation and How the Banks should Approach it
James Okarimia - IFRS  Implementation and How the Banks should Approach itJames Okarimia - IFRS  Implementation and How the Banks should Approach it
James Okarimia - IFRS Implementation and How the Banks should Approach it
 
Diagramas de Venn Educativos
Diagramas de Venn EducativosDiagramas de Venn Educativos
Diagramas de Venn Educativos
 
Evaluation
EvaluationEvaluation
Evaluation
 
SCN_0001
SCN_0001SCN_0001
SCN_0001
 
Resumen Horizon Universidad 2016_intef_mayo_2016
Resumen Horizon Universidad 2016_intef_mayo_2016Resumen Horizon Universidad 2016_intef_mayo_2016
Resumen Horizon Universidad 2016_intef_mayo_2016
 
Re-Ingenieria de Aprendizajes
Re-Ingenieria de AprendizajesRe-Ingenieria de Aprendizajes
Re-Ingenieria de Aprendizajes
 
James Okarimia - A Summary Of Top 28 Areas Covered By EC Proposed Regulation...
James Okarimia - A  Summary Of Top 28 Areas Covered By EC Proposed Regulation...James Okarimia - A  Summary Of Top 28 Areas Covered By EC Proposed Regulation...
James Okarimia - A Summary Of Top 28 Areas Covered By EC Proposed Regulation...
 
Math 2007 pspm
Math 2007 pspmMath 2007 pspm
Math 2007 pspm
 
IFRS Implementation and How the Banks should approach it
IFRS  Implementation and How the Banks should approach itIFRS  Implementation and How the Banks should approach it
IFRS Implementation and How the Banks should approach it
 
Estilos de vida generacionales
Estilos de vida generacionalesEstilos de vida generacionales
Estilos de vida generacionales
 
Lado social del pais donde vivió jesus
Lado social del pais donde vivió jesusLado social del pais donde vivió jesus
Lado social del pais donde vivió jesus
 
Re ingenieria de Aprendizajes
Re ingenieria de AprendizajesRe ingenieria de Aprendizajes
Re ingenieria de Aprendizajes
 
IFRS Implementation and How the Banks should Approach it
IFRS  Implementation and How the Banks should Approach itIFRS  Implementation and How the Banks should Approach it
IFRS Implementation and How the Banks should Approach it
 
Tesis maestría Fuzzy Control
Tesis maestría Fuzzy Control Tesis maestría Fuzzy Control
Tesis maestría Fuzzy Control
 
Nota kuliah kimia compressed
Nota kuliah kimia compressedNota kuliah kimia compressed
Nota kuliah kimia compressed
 
досвід роботи гарнаженко л.п.
досвід роботи гарнаженко л.п.досвід роботи гарнаженко л.п.
досвід роботи гарнаженко л.п.
 
JAMES OKARIMIA - IFRS Implementation and How The Banks Should Approach IT
JAMES OKARIMIA  -  IFRS  Implementation and How The Banks Should Approach ITJAMES OKARIMIA  -  IFRS  Implementation and How The Banks Should Approach IT
JAMES OKARIMIA - IFRS Implementation and How The Banks Should Approach IT
 
презентация 8
презентация 8презентация 8
презентация 8
 

Similar to J. LaCagnina CV 5-2016

Srinivas pendam resume-nyc
Srinivas pendam resume-nycSrinivas pendam resume-nyc
Srinivas pendam resume-nycspendam
 
Resume bernadette yousif-sr. qa
Resume   bernadette yousif-sr. qaResume   bernadette yousif-sr. qa
Resume bernadette yousif-sr. qaBernadette Yousif
 
Alexander Rhea Resume
Alexander Rhea ResumeAlexander Rhea Resume
Alexander Rhea ResumeAlex Rhea
 
TrustedAgent GRC for Public Sector
TrustedAgent GRC for Public SectorTrustedAgent GRC for Public Sector
TrustedAgent GRC for Public SectorTri Phan
 
TrustedAgent GRC for Public Sector
TrustedAgent GRC for Public SectorTrustedAgent GRC for Public Sector
TrustedAgent GRC for Public SectorTuan Phan
 
Des serveurs créés pour vos usages specifiques, vous en avez reve HP l'a fait.
Des serveurs créés pour vos usages specifiques, vous en avez reve HP l'a fait.Des serveurs créés pour vos usages specifiques, vous en avez reve HP l'a fait.
Des serveurs créés pour vos usages specifiques, vous en avez reve HP l'a fait.Microsoft Décideurs IT
 
Des serveurs créés pour vos usages specifiques, vous en avez reve HP l'a fait.
Des serveurs créés pour vos usages specifiques, vous en avez reve HP l'a fait.Des serveurs créés pour vos usages specifiques, vous en avez reve HP l'a fait.
Des serveurs créés pour vos usages specifiques, vous en avez reve HP l'a fait.Microsoft Technet France
 
Kim Jimenez Resume 2016
 Kim Jimenez Resume 2016 Kim Jimenez Resume 2016
Kim Jimenez Resume 2016Kim Jimenez
 
Greg Carr Resume
Greg Carr ResumeGreg Carr Resume
Greg Carr ResumeGreg Carr
 
Profile pawan chandak
Profile pawan chandakProfile pawan chandak
Profile pawan chandakPawan Chandak
 
Resume G Bisanz Detailed Feb22012
Resume G Bisanz Detailed Feb22012Resume G Bisanz Detailed Feb22012
Resume G Bisanz Detailed Feb22012Gregory Bisanz
 
Fehmida Sayed - IT Head, Senior Manager-Infra and Infosec
Fehmida Sayed - IT Head, Senior Manager-Infra and InfosecFehmida Sayed - IT Head, Senior Manager-Infra and Infosec
Fehmida Sayed - IT Head, Senior Manager-Infra and InfosecFehmida Sayed
 
Greg Bisanz Resume Feb22012 Version1
Greg Bisanz Resume Feb22012 Version1Greg Bisanz Resume Feb22012 Version1
Greg Bisanz Resume Feb22012 Version1Gregory Bisanz
 
Alan Berow Technical Support Resume
Alan Berow Technical Support ResumeAlan Berow Technical Support Resume
Alan Berow Technical Support ResumeAlanBerowLSSGBCSM
 
Tl Resume Aug11
Tl Resume Aug11Tl Resume Aug11
Tl Resume Aug11TomLawson
 
Kim lynchresume july2016
Kim lynchresume july2016Kim lynchresume july2016
Kim lynchresume july2016Kim Lynch
 

Similar to J. LaCagnina CV 5-2016 (20)

Srinivas pendam resume-nyc
Srinivas pendam resume-nycSrinivas pendam resume-nyc
Srinivas pendam resume-nyc
 
Resume bernadette yousif-sr. qa
Resume   bernadette yousif-sr. qaResume   bernadette yousif-sr. qa
Resume bernadette yousif-sr. qa
 
Alexander Rhea Resume
Alexander Rhea ResumeAlexander Rhea Resume
Alexander Rhea Resume
 
QA lead
QA leadQA lead
QA lead
 
QA lead
QA leadQA lead
QA lead
 
TrustedAgent GRC for Public Sector
TrustedAgent GRC for Public SectorTrustedAgent GRC for Public Sector
TrustedAgent GRC for Public Sector
 
TrustedAgent GRC for Public Sector
TrustedAgent GRC for Public SectorTrustedAgent GRC for Public Sector
TrustedAgent GRC for Public Sector
 
Dipesh QA Lead
Dipesh QA LeadDipesh QA Lead
Dipesh QA Lead
 
GRC– The Way Forward
GRC– The Way ForwardGRC– The Way Forward
GRC– The Way Forward
 
Des serveurs créés pour vos usages specifiques, vous en avez reve HP l'a fait.
Des serveurs créés pour vos usages specifiques, vous en avez reve HP l'a fait.Des serveurs créés pour vos usages specifiques, vous en avez reve HP l'a fait.
Des serveurs créés pour vos usages specifiques, vous en avez reve HP l'a fait.
 
Des serveurs créés pour vos usages specifiques, vous en avez reve HP l'a fait.
Des serveurs créés pour vos usages specifiques, vous en avez reve HP l'a fait.Des serveurs créés pour vos usages specifiques, vous en avez reve HP l'a fait.
Des serveurs créés pour vos usages specifiques, vous en avez reve HP l'a fait.
 
Kim Jimenez Resume 2016
 Kim Jimenez Resume 2016 Kim Jimenez Resume 2016
Kim Jimenez Resume 2016
 
Greg Carr Resume
Greg Carr ResumeGreg Carr Resume
Greg Carr Resume
 
Profile pawan chandak
Profile pawan chandakProfile pawan chandak
Profile pawan chandak
 
Resume G Bisanz Detailed Feb22012
Resume G Bisanz Detailed Feb22012Resume G Bisanz Detailed Feb22012
Resume G Bisanz Detailed Feb22012
 
Fehmida Sayed - IT Head, Senior Manager-Infra and Infosec
Fehmida Sayed - IT Head, Senior Manager-Infra and InfosecFehmida Sayed - IT Head, Senior Manager-Infra and Infosec
Fehmida Sayed - IT Head, Senior Manager-Infra and Infosec
 
Greg Bisanz Resume Feb22012 Version1
Greg Bisanz Resume Feb22012 Version1Greg Bisanz Resume Feb22012 Version1
Greg Bisanz Resume Feb22012 Version1
 
Alan Berow Technical Support Resume
Alan Berow Technical Support ResumeAlan Berow Technical Support Resume
Alan Berow Technical Support Resume
 
Tl Resume Aug11
Tl Resume Aug11Tl Resume Aug11
Tl Resume Aug11
 
Kim lynchresume july2016
Kim lynchresume july2016Kim lynchresume july2016
Kim lynchresume july2016
 

Recently uploaded

Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountPuma Security, LLC
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationMichael W. Hawkins
 
Human Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsHuman Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsMark Billinghurst
 
Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...
Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...
Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...HostedbyConfluent
 
Slack Application Development 101 Slides
Slack Application Development 101 SlidesSlack Application Development 101 Slides
Slack Application Development 101 Slidespraypatel2
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking MenDelhi Call girls
 
Install Stable Diffusion in windows machine
Install Stable Diffusion in windows machineInstall Stable Diffusion in windows machine
Install Stable Diffusion in windows machinePadma Pradeep
 
Azure Monitor & Application Insight to monitor Infrastructure & Application
Azure Monitor & Application Insight to monitor Infrastructure & ApplicationAzure Monitor & Application Insight to monitor Infrastructure & Application
Azure Monitor & Application Insight to monitor Infrastructure & ApplicationAndikSusilo4
 
Snow Chain-Integrated Tire for a Safe Drive on Winter Roads
Snow Chain-Integrated Tire for a Safe Drive on Winter RoadsSnow Chain-Integrated Tire for a Safe Drive on Winter Roads
Snow Chain-Integrated Tire for a Safe Drive on Winter RoadsHyundai Motor Group
 
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | DelhiFULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhisoniya singh
 
CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):comworks
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking MenDelhi Call girls
 
Key Features Of Token Development (1).pptx
Key  Features Of Token  Development (1).pptxKey  Features Of Token  Development (1).pptx
Key Features Of Token Development (1).pptxLBM Solutions
 
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024BookNet Canada
 
SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024Scott Keck-Warren
 
The Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxThe Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxMalak Abu Hammad
 
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptx
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptxMaking_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptx
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptxnull - The Open Security Community
 
Benefits Of Flutter Compared To Other Frameworks
Benefits Of Flutter Compared To Other FrameworksBenefits Of Flutter Compared To Other Frameworks
Benefits Of Flutter Compared To Other FrameworksSoftradix Technologies
 

Recently uploaded (20)

Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path Mount
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day Presentation
 
Human Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsHuman Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR Systems
 
Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...
Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...
Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...
 
Slack Application Development 101 Slides
Slack Application Development 101 SlidesSlack Application Development 101 Slides
Slack Application Development 101 Slides
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men
 
Install Stable Diffusion in windows machine
Install Stable Diffusion in windows machineInstall Stable Diffusion in windows machine
Install Stable Diffusion in windows machine
 
Azure Monitor & Application Insight to monitor Infrastructure & Application
Azure Monitor & Application Insight to monitor Infrastructure & ApplicationAzure Monitor & Application Insight to monitor Infrastructure & Application
Azure Monitor & Application Insight to monitor Infrastructure & Application
 
Snow Chain-Integrated Tire for a Safe Drive on Winter Roads
Snow Chain-Integrated Tire for a Safe Drive on Winter RoadsSnow Chain-Integrated Tire for a Safe Drive on Winter Roads
Snow Chain-Integrated Tire for a Safe Drive on Winter Roads
 
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | DelhiFULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
 
Vulnerability_Management_GRC_by Sohang Sengupta.pptx
Vulnerability_Management_GRC_by Sohang Sengupta.pptxVulnerability_Management_GRC_by Sohang Sengupta.pptx
Vulnerability_Management_GRC_by Sohang Sengupta.pptx
 
CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men
 
Key Features Of Token Development (1).pptx
Key  Features Of Token  Development (1).pptxKey  Features Of Token  Development (1).pptx
Key Features Of Token Development (1).pptx
 
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
 
SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024
 
The Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxThe Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptx
 
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptx
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptxMaking_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptx
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptx
 
Benefits Of Flutter Compared To Other Frameworks
Benefits Of Flutter Compared To Other FrameworksBenefits Of Flutter Compared To Other Frameworks
Benefits Of Flutter Compared To Other Frameworks
 
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptxE-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
 

J. LaCagnina CV 5-2016

  • 1. John LaCagnina 29 Briar Ct. Hamburg, NJ 07419 Mobile phone 917-817-0467 johnnylac@aol.com SUMMARY: • A Certified Information Systems Auditor (CISA) with 12+ years of experience in internal audit and SOX compliance in the Financial Services, Pharmaceutical, and Hospitality industries • Eight years of experience auditing, implementing security controls, and ensuring regulatory compliance with GxP, 21 CFR Part 11, and GDP regulations in the Pharmaceutical industry • Eight years of experience with Qualification and Validation in the Pharmaceutical industry • Five years of experience in Vendor Compliance Management • A certified Project Manager (PMP) with 20+ years of broad experience in a large corporate environment • Certified Internal Control Management Professional (CICMP) • Certified IT- Governance, Risk, and Compliance (GRC) Professional/Manager (CGRCM-IT) • Familiarity with COSO and CobiT frameworks, CMM, and ITIL methodology • Excellent understanding, and experience in implementation of PCI DSS requirements • Many years of Customer Service and Customer Relationship Management • Many years of experience interacting with C level management • Verifiable process improvement skills, oral, written, organizational, interpersonal, team building, and presentation skills • Extremely strong Change Management, process analysis, gap analysis, and documentation skills • ISACA member in good standing (http://www.isaca.org/) – Strong IT Governance skills, CobiT Foundation certified and completed the CobiT for Sarbanes-Oxley Compliance course • Sarbanes-Oxley institute board member (http://www.soxinstitute.org/) - CSOXP certified (Sarbanes-Oxley Institute). Contributing author and pre-production editor of the SOX guide for Financial and IT professionals 2nd Edition (Wiley Publications) and The Sarbanes-Oxley Act – An Introduction (Van Haren Publishing) • GRC Institute (Governance, Risk, and Compliance) member in good standing (http://www.grcg.com/) • Experience with data extraction and analysis using IBM’s GRD, Iron Mountain’s DRCi, Remedy, and Service-Now • Demonstrated competency in management of multiple audits, operational responsibilities, and projects simultaneously • Excellent leadership ability, client focus, and customer service skills • Consulting and external client experience – interfacing with C level and senior management, clients, and off-shore vendors • Experience in working in environments of constantly changing priorities CERTIFICATIONS/EDUCATION: • CISA, Certified Information Systems Auditor • PMP, Project Management Professional • CICMP, Certified Internal Control Management Professional • CGRCM-IT, Certified IT- Governance, Risk, and Compliance • CSOXP, Certified Sarbanes-Oxley Professional • CobiT Foundation Certified • MCSE, MCP+I, CNA Page 1 of 6
  • 2. City University of NY graduate 1981 • ElectronicComputer Engineering degree TECHNICAL SKILLS PROFILE: • ClientServer environment: - Microsoft and Novell certified. • Experience with the Remedy ARS system, IBM GRD, Service-Now, and Iron Mountain DRCi for data extraction, reporting, and SLA management • Familiarity with Business Continuity (BC) and Disaster Recovery (DR) policies and procedures, WAN technologies, AD, ACLs, encryption technology, etc. • Ability ranging from proficient to expert using MS Visio, MS Project, MS Excel, MS Word, MS PowerPoint, MS Outlook, Lotus Notes, SharePoint, Remedy ARS, Peregrine EMPLOYMENT HISTORY: Datalynx-US January 2013 to present VP of Consulting Services – Eastern Region Relationship Management between Novartis and Datalynx contractors at the East Hanover site. These duties were performed in addition to the services I provided for Novartis listed below and included the settling of disputes, approval of personal time off, and other day-to-day management of the account. Novartis July 2010 to present Contractor for Datalynx-US providing services for Novartis – IT Quality & Compliance Manager • Project Quality Manager for 5 Portfolio Transformation MA&D projects, CFEngine, Vblock consolidation, EVO, and NAS, just to name just a few • Operational Quality Manager for the Service-Now SaaS – Quality manager for the Validation of new releases, Change Approvals, and approval of all validation documentation • Quality Manager for UNIX Gemini Transition, Service Now, and the GIS managed DR Service • Operational Quality Manager for the UNIXLINUX, Storage, and B&R Global service lines • Vendor Compliance Management of IBM • NVS Compliance Officer – interface with IBM management to review and resolve all compliance issues. Represented GIS in the Incident Management PID renegotiations with IBM • Qualification Procedure Development – drove and facilitated the creation of the relevant Qualification Procedures for the Wintel, UNIX/LINUX, Database, and Storage towers. • Conducted annual Maturity Assessments and HLBIAs for the Wintel, UNIX/LINUX, Database, and Storage towers • Participate on quarterly and annual SOX and Vendor Compliance Audits including hands-on participation in Switzerland and Argentina • Technical Writer for the Exadata initiative • Continuous improvement of existing quality systems to meet and sustain compliance with internal and external regulatory requirements • Conduct Quality Reviews to evaluate if processes and deliverables fulfill the requirements for quality, to uncover errors or deficiencies in processes and deliverables, and to identify strengths and opportunities for improvement • Interface with other quality and compliance stakeholders to ensure customer practices are aligned with regulatory expectations and industry best practices Page 2 of 6
  • 3. Hermes of Paris May 2010 to July 2010 Consultant – PCI-DSS Compliance Project Manager Responsible to drive the PCI/PA-DSS compliance initiative. This was a Cegid POS and ICVerify database environment. In this role I performed these duties: • Monitor and control project • PCI SME to assist in updating and maintaining their SAQ based on version 1.2 of the PCI DSS • POC with the QSAs (Coalfire) providing them with evidence of compliance and arranging interviews, meetings, pen testing, etc. • IT Auditor to identify compliance gaps and compensating controls ensuring HOP’s compliance • Security Analyst to ensure that HOP was secure as well as compliant • Acted in an advisory capacity in choosing the QSA and security solutions • Documentation SME to review, update, and perform a gap analysis of their existing Security and Incident Management documents I interacted daily with the VP of Information Services, Director of Audit and Operations, IT Operations Manager, Information Security Officer, Cyber-Security SME, Security Engineers, Network Admins, and the on-site security vendor (Reliant Security) to achieve PCI-DSS compliance. I also provided weekly and ad hoc status reports to the CFO. WYNDHAM HOTEL GROUP July 2009 to December 2009 Consultant (returned by request) – Sr. IT Auditor / Security and Compliance Specialist Returned by request to the Wyndham Hotel Group in the IT Security and Risk Management group to perform the audit and testing for their 2009 SOX audit initiative as well as managing their 2009 recertification initiative, and requirements and documentation gathering for their PDI-DSS certification initiative. The areas of audit and testing are as follows: • Host Security for Windows, UNIX, LINUX, Network Devices • Database Security for Oracle and DB2 • Security Administration of CHIME, Clarity, EDW, Wyndham Rewards • Physical Security • Backup and Recovery • Change Management • In addition, interacted with the external auditors to complete the audit and subsequent remediation. TREC GLOBAL BUSINESS PROCESS SOLUTIONS Feb. 2009 to July 2009 Consultant - Business Analyst • TREC Global Solutions provides outsourced business solutions and call center services. Process analysis as part of the discovery process in the Program Management group for Pre-Business Development. Performed analysis of business objectives, strategies, timelines, performance targets, budget limitations, and overall scope of work. Details are as follows: • Interfaced with the client to determine business needs, review existing business processes, perform Test of Design and Test of Effectiveness, and identify performance metrics. Acted as a single point of contact to ensure the end- to-end execution for the campaign. • Consulted with Business Development team to report findings of discovery phase, determine solutions, establish transition process, and provide client specific training. • Assisted Quality Assurance team in conducting routine quality audits and reporting findings to senior management. Page 3 of 6
  • 5. WYNDHAM HOTEL GROUP July 2008 to Jan. 2009 Consultant – Sr. IT Auditor / Security and Compliance Specialist • Wyndham Worldwide engagement as part of the Wyndham Hotel Group in the IT Security and Risk Management Group. Performed as many as four concurrent audits to ensure regulatory compliance of their SDLC, PMLC and Change Management processes, as well as the Security Administration of their Windows, UNIX, and Database environments. Major responsibilities included extensive SOX testing and subsequent interaction with external auditors, management of the annual user recertification process, and assisting them in their PDC-DSS Self- Assessment Questionnaire. Details are as follows: • Security Administration for Windows, UNIX, Oracle, DB2, Informix, and the Electronic Data Warehouse (EDW) • Authentication Administration, Security Patching, System Hardening, Logging, Password Administration, ACLs • Security Administration of Applications – CHIME, Clarity, Informatica, My Portal, Oblix • SDLC and PMLC policy • Change management, Change control, Version control, Segregation of development, test, and production environments, Adherence to the funding and approval process, Unit and system testing, Data conversion • Annual User ID Recertification report for SOX compliance • Obtain verification of status and permissions of all end users from their respective performance managers • Administrative • Creation and Maintenance of directory structure in SharePoint for storing and sharing reports and artifacts • Daily and weekly status reports to leadership • Scheduled and led meetings with auditees for acceptance and remediation of findings • Participated in remediation meetings with external auditors and provided evidence of compliance. PFIZER Feb. 2008 to June 2008 Consultant - Sr. IT Auditor / Security and Compliance Specialist • Pfizer engagement as part of the Shared Applications Management Services group in the IT Security and Compliance department. Major responsibilities include: • Continuous Improvement – review and update existing Change Management policies, process documentation, and related process aids stored in SharePoint. • Audit –Manage a team of off-shore auditors in the completion of 7 process, 5 application, and 5 ad hoc internal audits monthly. Responsible for scheduling of audits and conducted meetings with auditees for agreement on scope and approach, and agreement with auditees on audit findings. • Security – Management, implementation, monitoring, and control of the Security Incident and Root Cause Analysis process and documentation. • Compliance – participate in quarterly SOX audits • Review RCM • Review internal control objectives • Test internal controls • Report on findings • Meetings with auditees for agreement on findings and scheduling remediation Page 5 of 6
  • 6. KPMG, LLP May 1998 to Feb. 2008 Project Manager Information Technology • Responsible for project management, Change Management, internal SOX compliance implementations, internal client relationships, presentations, reporting, and team mentoring and development. Major deliverables included: • National Infrastructure Change Management project – member of the committee to evaluate existing procedures and write the initial documentation using ITIL methodology • Enterprise Management internal SOX audit and process documentation project. Development and implementation of the Change Management policy using ITIL methodology for the EM group. • SAS 70 Type I readiness assessment - liaison to service auditor as IT SME for SOX compliance. Duties included assisting in preparation of scope and approach, preparing the PBC list, and assisting in completing the appropriate work papers. • Annual IT CSA Audits – Performed and managed General and Operational internal controls audits for the IS SOX Compliance Self-Assessment internal audit • Managed a matrixed team of 6 to bring KPMG’s NY office’s Data Center into compliance • Performed process verification, testing, risk Identification, gap analysis. Scheduled and lead meetings with auditees for remediation of findings, metrics, and progress reporting for the agreed upon remediation • National Disaster Recovery project – performed asset valuation and identification of BC3 applications, services, and dependencies • Managed the Tax Data Asset Preservation Compliance Project for the New York Office • Project Manager for new Construction buildouts, datacenter move, and user relocation • Performed ongoing SLA Audits to ensure SLAs were met and adherence to ITIL Standards • Managed issues, escalations, and expectations for the Office of the Chairman, the Office of the General Counsel, and the Department of Professional Practices THE CAREER CENTER Jan. 1997 to July 1998 Part-Time Technology and Applications Trainer • Provided classroom training in Microsoft Office products, Windows 95, NT, and Novell operating systems. • Built an NT classroom, saving the company over $10,000 in consulting costs. ALTERNATIVE RESOURCES CORP. April 1994 to May 1998 Desktop Specialist and Team Leader • Clients included NY Mercantile Exchange, CitiCorp, KPMG, Chase, Minet Insurance Co. Page 6 of 6
  • 7. KPMG, LLP May 1998 to Feb. 2008 Project Manager Information Technology • Responsible for project management, Change Management, internal SOX compliance implementations, internal client relationships, presentations, reporting, and team mentoring and development. Major deliverables included: • National Infrastructure Change Management project – member of the committee to evaluate existing procedures and write the initial documentation using ITIL methodology • Enterprise Management internal SOX audit and process documentation project. Development and implementation of the Change Management policy using ITIL methodology for the EM group. • SAS 70 Type I readiness assessment - liaison to service auditor as IT SME for SOX compliance. Duties included assisting in preparation of scope and approach, preparing the PBC list, and assisting in completing the appropriate work papers. • Annual IT CSA Audits – Performed and managed General and Operational internal controls audits for the IS SOX Compliance Self-Assessment internal audit • Managed a matrixed team of 6 to bring KPMG’s NY office’s Data Center into compliance • Performed process verification, testing, risk Identification, gap analysis. Scheduled and lead meetings with auditees for remediation of findings, metrics, and progress reporting for the agreed upon remediation • National Disaster Recovery project – performed asset valuation and identification of BC3 applications, services, and dependencies • Managed the Tax Data Asset Preservation Compliance Project for the New York Office • Project Manager for new Construction buildouts, datacenter move, and user relocation • Performed ongoing SLA Audits to ensure SLAs were met and adherence to ITIL Standards • Managed issues, escalations, and expectations for the Office of the Chairman, the Office of the General Counsel, and the Department of Professional Practices THE CAREER CENTER Jan. 1997 to July 1998 Part-Time Technology and Applications Trainer • Provided classroom training in Microsoft Office products, Windows 95, NT, and Novell operating systems. • Built an NT classroom, saving the company over $10,000 in consulting costs. ALTERNATIVE RESOURCES CORP. April 1994 to May 1998 Desktop Specialist and Team Leader • Clients included NY Mercantile Exchange, CitiCorp, KPMG, Chase, Minet Insurance Co. Page 6 of 6