SlideShare a Scribd company logo
Functional Experience
 ITGC, Sarbanes Oxley,
PCI-DSS, HIPPA /
HiTRUST, Compliance,
GLBA, FDICIA, BASEL,
SSAE16-SOC1 / SOC2,
FACTA, KYC, BSA/AML,
OTS/FDIC
 Internal / External Audit
 Program / Project
Management
 Data Analytics (Minitab,
ACL, R)
 Analysis: ROI, Feasibility
Study
Industry Experience
 Financial Services
 Business Process
Outsourcing (BPO)
 Healthcare
 Sustainability / Energy
Systems Experience
 Platforms: IBM AS 400,
AIX/Unix, Windows
 Tools: MS Office, Adobe
CSx, Visio, TeamMate,
Minitab, ACL, SCSM, R
 SIEM: SolarWinds, RSA
 Apps: MetricStream,
Bankmaster, Alltel, Milvus,
Portia, Fiserv CBS, Vision,
and Precision, Kirchman,
Jack Henry, IBS, Profile,
Systematics, Miser, NICE,
Mercury, Impacs. OMR
 ERP: Peoplesoft,
ORACLE, SAP, BAAN
Certifications
 Certified Information Systems
Auditor (CISA)
 Certified Fraud Examiner
(CFE)
 Certified Lean Six Sigma
Green Belt (CLSSGB)
 Information System
Professional (ISP)
Education
 Stanford University
 MIT
 Florida Atlantic University
 Athabasca University
David W. Graham, CISA, ISP, ITCP, CLSSGB, CFE
Executive Summary
David Graham, is a highly professional and seasoned Information Technology Audit, Compliance,
Business Process, and Data Analytics professional. He brings over 20 years of Technology and
Operations Governance, Risk, Compliance, and audit experience from a verity of industries, with
a strong emphasis on the financial and banking sectors. His experience has been gained through
firms such as KPMG Canada, Ernst & Young, the former Arthur Andersen, his own independent
practice, and with Experis. His work included assessing and monitoring compliance with many
international and national regulations and technology guidelines. David also has experience
interacting with regulators, and has acted as liaison to leading audit firms.
Professional Experience
 Successfully provided IT security, audit and compliance consulting services for 30
international and regional financial firms: Old Mutual, Assurant, FIS Global, Citigroup, RBS,
Scotia Bank International, TD Bank, Deutsche Bank, ING, CIBC, Fidelity, Butterfield Bank
Bermuda / London / Cayman / Guernsey, First Bank-Taiwan, BankUnited, BankAtlantic,
Ocean Bank, TotalBank, Optimum Bank, IFB, Commercial Bank of Florida, FNBC, etc.
 MIT-Big Data, Stanford–Business Risk, and FAU–Lean Six Sigma & PM certificate graduate
 Successfully conducted international IT Infrastructure and application systems reviews,
conversions, and post implementation reviews involving many ERP and banking systems.
 Successfully provided business and technology consulting services to telcom client Telus-
Canada; aerospace contractors HEICO Aerospace and CAE; health care industry client
Mariner Health Care and Ontario Ministry of Health; and, BPO client C3.
 Performed a data integrity analysis of a major bank’s Asset-Management Department’s
portfolio management system and recovered approximately $500,000 on a single audit
engagement project.
 Successfully lead an IT Audit department for an International Bank that oversaw the
operations of subsidiary offices in several global jurisdictions.
 Successfully completed a recent RSA Envision Security Information Event
Management/SIMS review at FIS Global.
 Successfully developed the information security & privacy policy for the American Institute of
Certified Public Accountants (AICPA)
 Successfully conducted network security audits, including Check Point Firewall at several
major financial organization.
Business Experience
 Expert IT Infrastructure, Applications, CoB, Security, Risk, Compliance, & Audit practitioner.
 Lean Six Sigma Process Improvement Engineer, Big Data Analysis practitioner.
 Team Leadership/Supervision, Business Analysis, Project Management.
 Financial Institution Operations Risk Management .
 SAS 70/SSAE 16 (SOC1/SOC2), Sarbanes-Oxley 404, GLBA, PCI-DSS, Basel II/III
compliance assessment practitioner.
 Enterprise Vendor/Supplier Risk Management analyst.
 Financial Institutions, Asset Management, Cash Management, ATM Services, Payment
Processing, AML and Fraud Analysis, ACH Operations review, BRD, FRD practitioner.
Career Assignments
May 2014 – Oct 2015: C3/CustomerContactChannels–Corporate Audit & Analytics Consultant
July 2013 – Apr 2014: Experis Finance – IT Audit and Security Risk Consultant at FIS Global
Jan 2012 – Jul 2013: Citigroup – Global PM & Lead Risk Analyst–Enterprise Supplier Risk
Sep 2010 – Present: Energy Technology Risk Advisors, LLC – Principal, IT Risk Consultant
Apr 2008 – Oct 2009: Ocean Bank – Vice President, IT Audit Supervisor
Jul 2005 – Mar 2008 Accume Partners – Senior Manager, IT Risk & Compliance Consulting
May 2005 – Jul 2005: Protiviti – SOX IT Project Consultant (Consulting Assignment)
May 2004– May 2005: Ernst & Young – Manager, Technology & Security Risk Services
Aug 2002 – May 2004: McArthur Graham & Associates – President & IT Risk Consultant
Jan 2001 – July2002: KPMG Canada – Manager, Information Risk Management
Feb 1997 – Jan 2001: Butterfield Bank Bermuda – Senior IT Auditor
Mar 1991 – Feb 1997: Government of Ontario – Senior EDP Auditor + IT Audit Manger

More Related Content

Viewers also liked

Bikini27
Bikini27Bikini27
Bikini27
rusgirl
 
LinkedIn Tip: How to own your name on LinkedIn
LinkedIn Tip: How to own your name on LinkedInLinkedIn Tip: How to own your name on LinkedIn
LinkedIn Tip: How to own your name on LinkedIn
Andrew Davis
 
Bcbsc136
Bcbsc136Bcbsc136
Bcbsc136
saidawangui
 
Aula 3. sistema informacao gerencial.pptm
Aula 3.   sistema informacao gerencial.pptmAula 3.   sistema informacao gerencial.pptm
Aula 3. sistema informacao gerencial.pptm
Claudio Parra
 
Santiago
SantiagoSantiago
Santiago
edwinmartinezz
 
Ef slides - tc58 n - aula 03 .:. www.tc58n.wordpress.com
Ef   slides - tc58 n - aula 03  .:. www.tc58n.wordpress.comEf   slides - tc58 n - aula 03  .:. www.tc58n.wordpress.com
Ef slides - tc58 n - aula 03 .:. www.tc58n.wordpress.com
Claudio Parra
 
educacao corp e cont nas empresas .:. www;tc58n.wordpress.com
 educacao corp e cont nas empresas .:. www;tc58n.wordpress.com educacao corp e cont nas empresas .:. www;tc58n.wordpress.com
educacao corp e cont nas empresas .:. www;tc58n.wordpress.com
Claudio Parra
 
Bikini16
Bikini16Bikini16
Bikini16rusgirl
 
Taxifacil.ec final
Taxifacil.ec finalTaxifacil.ec final
Taxifacil.ec final
Spysat Ecuador
 
Firma ou denominação
Firma ou denominaçãoFirma ou denominação
Firma ou denominação
Claudio Parra
 
Apresentação EDI Maria de Lourdes Ferreira
Apresentação EDI Maria de Lourdes FerreiraApresentação EDI Maria de Lourdes Ferreira
Apresentação EDI Maria de Lourdes Ferreira
AnaAccioly
 
Ventricular Septal Defects - A Review
Ventricular Septal Defects - A ReviewVentricular Septal Defects - A Review
Ventricular Septal Defects - A Review
Vivek Rana
 
CLASE DE NUDOS QUIRÚRGICOS. PROFESOR DR. LUIS DEL RIO DIEZ
CLASE DE NUDOS QUIRÚRGICOS. PROFESOR DR. LUIS DEL RIO DIEZCLASE DE NUDOS QUIRÚRGICOS. PROFESOR DR. LUIS DEL RIO DIEZ
CLASE DE NUDOS QUIRÚRGICOS. PROFESOR DR. LUIS DEL RIO DIEZ
LUIS del Rio Diez
 
Intro to social media analytics (workshop version)
Intro to social media analytics (workshop version)Intro to social media analytics (workshop version)
Intro to social media analytics (workshop version)
Moustafa Fathy
 
Projeto Integrado - Gestão na Publicidade
Projeto Integrado - Gestão na PublicidadeProjeto Integrado - Gestão na Publicidade
Projeto Integrado - Gestão na Publicidade
Leonardo Macedo
 

Viewers also liked (16)

Bikini27
Bikini27Bikini27
Bikini27
 
LinkedIn Tip: How to own your name on LinkedIn
LinkedIn Tip: How to own your name on LinkedInLinkedIn Tip: How to own your name on LinkedIn
LinkedIn Tip: How to own your name on LinkedIn
 
Bcbsc136
Bcbsc136Bcbsc136
Bcbsc136
 
Aula 3. sistema informacao gerencial.pptm
Aula 3.   sistema informacao gerencial.pptmAula 3.   sistema informacao gerencial.pptm
Aula 3. sistema informacao gerencial.pptm
 
Santiago
SantiagoSantiago
Santiago
 
Ef slides - tc58 n - aula 03 .:. www.tc58n.wordpress.com
Ef   slides - tc58 n - aula 03  .:. www.tc58n.wordpress.comEf   slides - tc58 n - aula 03  .:. www.tc58n.wordpress.com
Ef slides - tc58 n - aula 03 .:. www.tc58n.wordpress.com
 
educacao corp e cont nas empresas .:. www;tc58n.wordpress.com
 educacao corp e cont nas empresas .:. www;tc58n.wordpress.com educacao corp e cont nas empresas .:. www;tc58n.wordpress.com
educacao corp e cont nas empresas .:. www;tc58n.wordpress.com
 
Bikini16
Bikini16Bikini16
Bikini16
 
Taxifacil.ec final
Taxifacil.ec finalTaxifacil.ec final
Taxifacil.ec final
 
osha
oshaosha
osha
 
Firma ou denominação
Firma ou denominaçãoFirma ou denominação
Firma ou denominação
 
Apresentação EDI Maria de Lourdes Ferreira
Apresentação EDI Maria de Lourdes FerreiraApresentação EDI Maria de Lourdes Ferreira
Apresentação EDI Maria de Lourdes Ferreira
 
Ventricular Septal Defects - A Review
Ventricular Septal Defects - A ReviewVentricular Septal Defects - A Review
Ventricular Septal Defects - A Review
 
CLASE DE NUDOS QUIRÚRGICOS. PROFESOR DR. LUIS DEL RIO DIEZ
CLASE DE NUDOS QUIRÚRGICOS. PROFESOR DR. LUIS DEL RIO DIEZCLASE DE NUDOS QUIRÚRGICOS. PROFESOR DR. LUIS DEL RIO DIEZ
CLASE DE NUDOS QUIRÚRGICOS. PROFESOR DR. LUIS DEL RIO DIEZ
 
Intro to social media analytics (workshop version)
Intro to social media analytics (workshop version)Intro to social media analytics (workshop version)
Intro to social media analytics (workshop version)
 
Projeto Integrado - Gestão na Publicidade
Projeto Integrado - Gestão na PublicidadeProjeto Integrado - Gestão na Publicidade
Projeto Integrado - Gestão na Publicidade
 

Similar to David W. Graham, CEO, Energy Technology Risk Advisors, LLC

Senior Independent IT Auditor (GRC), CISSP & CISA_April 28th, 2015
Senior Independent IT Auditor (GRC), CISSP & CISA_April 28th, 2015Senior Independent IT Auditor (GRC), CISSP & CISA_April 28th, 2015
Senior Independent IT Auditor (GRC), CISSP & CISA_April 28th, 2015
Pw Carey
 
Komal Vora
Komal VoraKomal Vora
Komal Vora
Komal Vora
 
Assessing IT Security and Compliance Risk for Acquisitions and Mergers
Assessing IT Security and Compliance Risk for Acquisitions and MergersAssessing IT Security and Compliance Risk for Acquisitions and Mergers
Assessing IT Security and Compliance Risk for Acquisitions and Mergers
Melanie Brandt
 
GRCAlert Capabilities Deck - 2018
GRCAlert Capabilities Deck - 2018GRCAlert Capabilities Deck - 2018
GRCAlert Capabilities Deck - 2018
Richard Marti - Principal
 
ArunKJ BigData3-0 Analytics
ArunKJ BigData3-0 AnalyticsArunKJ BigData3-0 Analytics
ArunKJ BigData3-0 Analytics
Arun Kumar J
 
1
11
George B - profile [BA,TM], 2016 v.3a
George B -  profile [BA,TM], 2016 v.3aGeorge B -  profile [BA,TM], 2016 v.3a
George B - profile [BA,TM], 2016 v.3a
George Bogoevski
 
Iob gm's lecture 7th jan 2014 GRC and corporate governance in Financial serv...
Iob gm's lecture 7th jan 2014  GRC and corporate governance in Financial serv...Iob gm's lecture 7th jan 2014  GRC and corporate governance in Financial serv...
Iob gm's lecture 7th jan 2014 GRC and corporate governance in Financial serv...
subramanian K
 
6188336.ppt
6188336.ppt6188336.ppt
6188336.ppt
ssuserffce38
 
Resume - Kenneth Turano
Resume - Kenneth TuranoResume - Kenneth Turano
Resume - Kenneth Turano
Ken Turano
 
Csb pr 02.24 csb presentation en
Csb pr 02.24   csb presentation enCsb pr 02.24   csb presentation en
Csb pr 02.24 csb presentation en
cdinu
 
CMG Brasil 2011 Keynote por Adam Grummit
CMG Brasil 2011 Keynote por Adam GrummitCMG Brasil 2011 Keynote por Adam Grummit
CMG Brasil 2011 Keynote por Adam Grummit
Joao Galdino Mello de Souza
 
Resume_Nidhi Malhotra_BA_shared
Resume_Nidhi Malhotra_BA_sharedResume_Nidhi Malhotra_BA_shared
Resume_Nidhi Malhotra_BA_shared
Nidhi Malhotra
 
Venkat_CV_PM
Venkat_CV_PMVenkat_CV_PM
Venkat_CV_PM
Venkat Iyer
 
Venkat cv pm
Venkat cv pmVenkat cv pm
Venkat cv pm
Venkat Iyer
 
B. Lee Jones - Resume 2021
B. Lee Jones - Resume 2021B. Lee Jones - Resume 2021
B. Lee Jones - Resume 2021
Silicon Valley Innovation School
 
Richard Moore Resume 2016
Richard Moore Resume 2016Richard Moore Resume 2016
Richard Moore Resume 2016
Richard Moore
 
APM
APMAPM
Abhinav aggarwal 06_30_2016
Abhinav aggarwal 06_30_2016Abhinav aggarwal 06_30_2016
Abhinav aggarwal 06_30_2016
Abhinav Aggarwal
 
AbhinavAggarwal_06_30_2016
AbhinavAggarwal_06_30_2016AbhinavAggarwal_06_30_2016
AbhinavAggarwal_06_30_2016
Abhinav Aggarwal
 

Similar to David W. Graham, CEO, Energy Technology Risk Advisors, LLC (20)

Senior Independent IT Auditor (GRC), CISSP & CISA_April 28th, 2015
Senior Independent IT Auditor (GRC), CISSP & CISA_April 28th, 2015Senior Independent IT Auditor (GRC), CISSP & CISA_April 28th, 2015
Senior Independent IT Auditor (GRC), CISSP & CISA_April 28th, 2015
 
Komal Vora
Komal VoraKomal Vora
Komal Vora
 
Assessing IT Security and Compliance Risk for Acquisitions and Mergers
Assessing IT Security and Compliance Risk for Acquisitions and MergersAssessing IT Security and Compliance Risk for Acquisitions and Mergers
Assessing IT Security and Compliance Risk for Acquisitions and Mergers
 
GRCAlert Capabilities Deck - 2018
GRCAlert Capabilities Deck - 2018GRCAlert Capabilities Deck - 2018
GRCAlert Capabilities Deck - 2018
 
ArunKJ BigData3-0 Analytics
ArunKJ BigData3-0 AnalyticsArunKJ BigData3-0 Analytics
ArunKJ BigData3-0 Analytics
 
1
11
1
 
George B - profile [BA,TM], 2016 v.3a
George B -  profile [BA,TM], 2016 v.3aGeorge B -  profile [BA,TM], 2016 v.3a
George B - profile [BA,TM], 2016 v.3a
 
Iob gm's lecture 7th jan 2014 GRC and corporate governance in Financial serv...
Iob gm's lecture 7th jan 2014  GRC and corporate governance in Financial serv...Iob gm's lecture 7th jan 2014  GRC and corporate governance in Financial serv...
Iob gm's lecture 7th jan 2014 GRC and corporate governance in Financial serv...
 
6188336.ppt
6188336.ppt6188336.ppt
6188336.ppt
 
Resume - Kenneth Turano
Resume - Kenneth TuranoResume - Kenneth Turano
Resume - Kenneth Turano
 
Csb pr 02.24 csb presentation en
Csb pr 02.24   csb presentation enCsb pr 02.24   csb presentation en
Csb pr 02.24 csb presentation en
 
CMG Brasil 2011 Keynote por Adam Grummit
CMG Brasil 2011 Keynote por Adam GrummitCMG Brasil 2011 Keynote por Adam Grummit
CMG Brasil 2011 Keynote por Adam Grummit
 
Resume_Nidhi Malhotra_BA_shared
Resume_Nidhi Malhotra_BA_sharedResume_Nidhi Malhotra_BA_shared
Resume_Nidhi Malhotra_BA_shared
 
Venkat_CV_PM
Venkat_CV_PMVenkat_CV_PM
Venkat_CV_PM
 
Venkat cv pm
Venkat cv pmVenkat cv pm
Venkat cv pm
 
B. Lee Jones - Resume 2021
B. Lee Jones - Resume 2021B. Lee Jones - Resume 2021
B. Lee Jones - Resume 2021
 
Richard Moore Resume 2016
Richard Moore Resume 2016Richard Moore Resume 2016
Richard Moore Resume 2016
 
APM
APMAPM
APM
 
Abhinav aggarwal 06_30_2016
Abhinav aggarwal 06_30_2016Abhinav aggarwal 06_30_2016
Abhinav aggarwal 06_30_2016
 
AbhinavAggarwal_06_30_2016
AbhinavAggarwal_06_30_2016AbhinavAggarwal_06_30_2016
AbhinavAggarwal_06_30_2016
 

Recently uploaded

"$10 thousand per minute of downtime: architecture, queues, streaming and fin...
"$10 thousand per minute of downtime: architecture, queues, streaming and fin..."$10 thousand per minute of downtime: architecture, queues, streaming and fin...
"$10 thousand per minute of downtime: architecture, queues, streaming and fin...
Fwdays
 
Lee Barnes - Path to Becoming an Effective Test Automation Engineer.pdf
Lee Barnes - Path to Becoming an Effective Test Automation Engineer.pdfLee Barnes - Path to Becoming an Effective Test Automation Engineer.pdf
Lee Barnes - Path to Becoming an Effective Test Automation Engineer.pdf
leebarnesutopia
 
JavaLand 2024: Application Development Green Masterplan
JavaLand 2024: Application Development Green MasterplanJavaLand 2024: Application Development Green Masterplan
JavaLand 2024: Application Development Green Masterplan
Miro Wengner
 
"Choosing proper type of scaling", Olena Syrota
"Choosing proper type of scaling", Olena Syrota"Choosing proper type of scaling", Olena Syrota
"Choosing proper type of scaling", Olena Syrota
Fwdays
 
GlobalLogic Java Community Webinar #18 “How to Improve Web Application Perfor...
GlobalLogic Java Community Webinar #18 “How to Improve Web Application Perfor...GlobalLogic Java Community Webinar #18 “How to Improve Web Application Perfor...
GlobalLogic Java Community Webinar #18 “How to Improve Web Application Perfor...
GlobalLogic Ukraine
 
Essentials of Automations: Exploring Attributes & Automation Parameters
Essentials of Automations: Exploring Attributes & Automation ParametersEssentials of Automations: Exploring Attributes & Automation Parameters
Essentials of Automations: Exploring Attributes & Automation Parameters
Safe Software
 
Dandelion Hashtable: beyond billion requests per second on a commodity server
Dandelion Hashtable: beyond billion requests per second on a commodity serverDandelion Hashtable: beyond billion requests per second on a commodity server
Dandelion Hashtable: beyond billion requests per second on a commodity server
Antonios Katsarakis
 
Getting the Most Out of ScyllaDB Monitoring: ShareChat's Tips
Getting the Most Out of ScyllaDB Monitoring: ShareChat's TipsGetting the Most Out of ScyllaDB Monitoring: ShareChat's Tips
Getting the Most Out of ScyllaDB Monitoring: ShareChat's Tips
ScyllaDB
 
Discover the Unseen: Tailored Recommendation of Unwatched Content
Discover the Unseen: Tailored Recommendation of Unwatched ContentDiscover the Unseen: Tailored Recommendation of Unwatched Content
Discover the Unseen: Tailored Recommendation of Unwatched Content
ScyllaDB
 
Day 2 - Intro to UiPath Studio Fundamentals
Day 2 - Intro to UiPath Studio FundamentalsDay 2 - Intro to UiPath Studio Fundamentals
Day 2 - Intro to UiPath Studio Fundamentals
UiPathCommunity
 
Northern Engraving | Nameplate Manufacturing Process - 2024
Northern Engraving | Nameplate Manufacturing Process - 2024Northern Engraving | Nameplate Manufacturing Process - 2024
Northern Engraving | Nameplate Manufacturing Process - 2024
Northern Engraving
 
AI in the Workplace Reskilling, Upskilling, and Future Work.pptx
AI in the Workplace Reskilling, Upskilling, and Future Work.pptxAI in the Workplace Reskilling, Upskilling, and Future Work.pptx
AI in the Workplace Reskilling, Upskilling, and Future Work.pptx
Sunil Jagani
 
GraphRAG for LifeSciences Hands-On with the Clinical Knowledge Graph
GraphRAG for LifeSciences Hands-On with the Clinical Knowledge GraphGraphRAG for LifeSciences Hands-On with the Clinical Knowledge Graph
GraphRAG for LifeSciences Hands-On with the Clinical Knowledge Graph
Neo4j
 
Apps Break Data
Apps Break DataApps Break Data
Apps Break Data
Ivo Velitchkov
 
Christine's Supplier Sourcing Presentaion.pptx
Christine's Supplier Sourcing Presentaion.pptxChristine's Supplier Sourcing Presentaion.pptx
Christine's Supplier Sourcing Presentaion.pptx
christinelarrosa
 
"NATO Hackathon Winner: AI-Powered Drug Search", Taras Kloba
"NATO Hackathon Winner: AI-Powered Drug Search",  Taras Kloba"NATO Hackathon Winner: AI-Powered Drug Search",  Taras Kloba
"NATO Hackathon Winner: AI-Powered Drug Search", Taras Kloba
Fwdays
 
What is an RPA CoE? Session 1 – CoE Vision
What is an RPA CoE?  Session 1 – CoE VisionWhat is an RPA CoE?  Session 1 – CoE Vision
What is an RPA CoE? Session 1 – CoE Vision
DianaGray10
 
Demystifying Knowledge Management through Storytelling
Demystifying Knowledge Management through StorytellingDemystifying Knowledge Management through Storytelling
Demystifying Knowledge Management through Storytelling
Enterprise Knowledge
 
Leveraging the Graph for Clinical Trials and Standards
Leveraging the Graph for Clinical Trials and StandardsLeveraging the Graph for Clinical Trials and Standards
Leveraging the Graph for Clinical Trials and Standards
Neo4j
 
Astute Business Solutions | Oracle Cloud Partner |
Astute Business Solutions | Oracle Cloud Partner |Astute Business Solutions | Oracle Cloud Partner |
Astute Business Solutions | Oracle Cloud Partner |
AstuteBusiness
 

Recently uploaded (20)

"$10 thousand per minute of downtime: architecture, queues, streaming and fin...
"$10 thousand per minute of downtime: architecture, queues, streaming and fin..."$10 thousand per minute of downtime: architecture, queues, streaming and fin...
"$10 thousand per minute of downtime: architecture, queues, streaming and fin...
 
Lee Barnes - Path to Becoming an Effective Test Automation Engineer.pdf
Lee Barnes - Path to Becoming an Effective Test Automation Engineer.pdfLee Barnes - Path to Becoming an Effective Test Automation Engineer.pdf
Lee Barnes - Path to Becoming an Effective Test Automation Engineer.pdf
 
JavaLand 2024: Application Development Green Masterplan
JavaLand 2024: Application Development Green MasterplanJavaLand 2024: Application Development Green Masterplan
JavaLand 2024: Application Development Green Masterplan
 
"Choosing proper type of scaling", Olena Syrota
"Choosing proper type of scaling", Olena Syrota"Choosing proper type of scaling", Olena Syrota
"Choosing proper type of scaling", Olena Syrota
 
GlobalLogic Java Community Webinar #18 “How to Improve Web Application Perfor...
GlobalLogic Java Community Webinar #18 “How to Improve Web Application Perfor...GlobalLogic Java Community Webinar #18 “How to Improve Web Application Perfor...
GlobalLogic Java Community Webinar #18 “How to Improve Web Application Perfor...
 
Essentials of Automations: Exploring Attributes & Automation Parameters
Essentials of Automations: Exploring Attributes & Automation ParametersEssentials of Automations: Exploring Attributes & Automation Parameters
Essentials of Automations: Exploring Attributes & Automation Parameters
 
Dandelion Hashtable: beyond billion requests per second on a commodity server
Dandelion Hashtable: beyond billion requests per second on a commodity serverDandelion Hashtable: beyond billion requests per second on a commodity server
Dandelion Hashtable: beyond billion requests per second on a commodity server
 
Getting the Most Out of ScyllaDB Monitoring: ShareChat's Tips
Getting the Most Out of ScyllaDB Monitoring: ShareChat's TipsGetting the Most Out of ScyllaDB Monitoring: ShareChat's Tips
Getting the Most Out of ScyllaDB Monitoring: ShareChat's Tips
 
Discover the Unseen: Tailored Recommendation of Unwatched Content
Discover the Unseen: Tailored Recommendation of Unwatched ContentDiscover the Unseen: Tailored Recommendation of Unwatched Content
Discover the Unseen: Tailored Recommendation of Unwatched Content
 
Day 2 - Intro to UiPath Studio Fundamentals
Day 2 - Intro to UiPath Studio FundamentalsDay 2 - Intro to UiPath Studio Fundamentals
Day 2 - Intro to UiPath Studio Fundamentals
 
Northern Engraving | Nameplate Manufacturing Process - 2024
Northern Engraving | Nameplate Manufacturing Process - 2024Northern Engraving | Nameplate Manufacturing Process - 2024
Northern Engraving | Nameplate Manufacturing Process - 2024
 
AI in the Workplace Reskilling, Upskilling, and Future Work.pptx
AI in the Workplace Reskilling, Upskilling, and Future Work.pptxAI in the Workplace Reskilling, Upskilling, and Future Work.pptx
AI in the Workplace Reskilling, Upskilling, and Future Work.pptx
 
GraphRAG for LifeSciences Hands-On with the Clinical Knowledge Graph
GraphRAG for LifeSciences Hands-On with the Clinical Knowledge GraphGraphRAG for LifeSciences Hands-On with the Clinical Knowledge Graph
GraphRAG for LifeSciences Hands-On with the Clinical Knowledge Graph
 
Apps Break Data
Apps Break DataApps Break Data
Apps Break Data
 
Christine's Supplier Sourcing Presentaion.pptx
Christine's Supplier Sourcing Presentaion.pptxChristine's Supplier Sourcing Presentaion.pptx
Christine's Supplier Sourcing Presentaion.pptx
 
"NATO Hackathon Winner: AI-Powered Drug Search", Taras Kloba
"NATO Hackathon Winner: AI-Powered Drug Search",  Taras Kloba"NATO Hackathon Winner: AI-Powered Drug Search",  Taras Kloba
"NATO Hackathon Winner: AI-Powered Drug Search", Taras Kloba
 
What is an RPA CoE? Session 1 – CoE Vision
What is an RPA CoE?  Session 1 – CoE VisionWhat is an RPA CoE?  Session 1 – CoE Vision
What is an RPA CoE? Session 1 – CoE Vision
 
Demystifying Knowledge Management through Storytelling
Demystifying Knowledge Management through StorytellingDemystifying Knowledge Management through Storytelling
Demystifying Knowledge Management through Storytelling
 
Leveraging the Graph for Clinical Trials and Standards
Leveraging the Graph for Clinical Trials and StandardsLeveraging the Graph for Clinical Trials and Standards
Leveraging the Graph for Clinical Trials and Standards
 
Astute Business Solutions | Oracle Cloud Partner |
Astute Business Solutions | Oracle Cloud Partner |Astute Business Solutions | Oracle Cloud Partner |
Astute Business Solutions | Oracle Cloud Partner |
 

David W. Graham, CEO, Energy Technology Risk Advisors, LLC

  • 1. Functional Experience  ITGC, Sarbanes Oxley, PCI-DSS, HIPPA / HiTRUST, Compliance, GLBA, FDICIA, BASEL, SSAE16-SOC1 / SOC2, FACTA, KYC, BSA/AML, OTS/FDIC  Internal / External Audit  Program / Project Management  Data Analytics (Minitab, ACL, R)  Analysis: ROI, Feasibility Study Industry Experience  Financial Services  Business Process Outsourcing (BPO)  Healthcare  Sustainability / Energy Systems Experience  Platforms: IBM AS 400, AIX/Unix, Windows  Tools: MS Office, Adobe CSx, Visio, TeamMate, Minitab, ACL, SCSM, R  SIEM: SolarWinds, RSA  Apps: MetricStream, Bankmaster, Alltel, Milvus, Portia, Fiserv CBS, Vision, and Precision, Kirchman, Jack Henry, IBS, Profile, Systematics, Miser, NICE, Mercury, Impacs. OMR  ERP: Peoplesoft, ORACLE, SAP, BAAN Certifications  Certified Information Systems Auditor (CISA)  Certified Fraud Examiner (CFE)  Certified Lean Six Sigma Green Belt (CLSSGB)  Information System Professional (ISP) Education  Stanford University  MIT  Florida Atlantic University  Athabasca University David W. Graham, CISA, ISP, ITCP, CLSSGB, CFE Executive Summary David Graham, is a highly professional and seasoned Information Technology Audit, Compliance, Business Process, and Data Analytics professional. He brings over 20 years of Technology and Operations Governance, Risk, Compliance, and audit experience from a verity of industries, with a strong emphasis on the financial and banking sectors. His experience has been gained through firms such as KPMG Canada, Ernst & Young, the former Arthur Andersen, his own independent practice, and with Experis. His work included assessing and monitoring compliance with many international and national regulations and technology guidelines. David also has experience interacting with regulators, and has acted as liaison to leading audit firms. Professional Experience  Successfully provided IT security, audit and compliance consulting services for 30 international and regional financial firms: Old Mutual, Assurant, FIS Global, Citigroup, RBS, Scotia Bank International, TD Bank, Deutsche Bank, ING, CIBC, Fidelity, Butterfield Bank Bermuda / London / Cayman / Guernsey, First Bank-Taiwan, BankUnited, BankAtlantic, Ocean Bank, TotalBank, Optimum Bank, IFB, Commercial Bank of Florida, FNBC, etc.  MIT-Big Data, Stanford–Business Risk, and FAU–Lean Six Sigma & PM certificate graduate  Successfully conducted international IT Infrastructure and application systems reviews, conversions, and post implementation reviews involving many ERP and banking systems.  Successfully provided business and technology consulting services to telcom client Telus- Canada; aerospace contractors HEICO Aerospace and CAE; health care industry client Mariner Health Care and Ontario Ministry of Health; and, BPO client C3.  Performed a data integrity analysis of a major bank’s Asset-Management Department’s portfolio management system and recovered approximately $500,000 on a single audit engagement project.  Successfully lead an IT Audit department for an International Bank that oversaw the operations of subsidiary offices in several global jurisdictions.  Successfully completed a recent RSA Envision Security Information Event Management/SIMS review at FIS Global.  Successfully developed the information security & privacy policy for the American Institute of Certified Public Accountants (AICPA)  Successfully conducted network security audits, including Check Point Firewall at several major financial organization. Business Experience  Expert IT Infrastructure, Applications, CoB, Security, Risk, Compliance, & Audit practitioner.  Lean Six Sigma Process Improvement Engineer, Big Data Analysis practitioner.  Team Leadership/Supervision, Business Analysis, Project Management.  Financial Institution Operations Risk Management .  SAS 70/SSAE 16 (SOC1/SOC2), Sarbanes-Oxley 404, GLBA, PCI-DSS, Basel II/III compliance assessment practitioner.  Enterprise Vendor/Supplier Risk Management analyst.  Financial Institutions, Asset Management, Cash Management, ATM Services, Payment Processing, AML and Fraud Analysis, ACH Operations review, BRD, FRD practitioner. Career Assignments May 2014 – Oct 2015: C3/CustomerContactChannels–Corporate Audit & Analytics Consultant July 2013 – Apr 2014: Experis Finance – IT Audit and Security Risk Consultant at FIS Global Jan 2012 – Jul 2013: Citigroup – Global PM & Lead Risk Analyst–Enterprise Supplier Risk Sep 2010 – Present: Energy Technology Risk Advisors, LLC – Principal, IT Risk Consultant Apr 2008 – Oct 2009: Ocean Bank – Vice President, IT Audit Supervisor Jul 2005 – Mar 2008 Accume Partners – Senior Manager, IT Risk & Compliance Consulting May 2005 – Jul 2005: Protiviti – SOX IT Project Consultant (Consulting Assignment) May 2004– May 2005: Ernst & Young – Manager, Technology & Security Risk Services Aug 2002 – May 2004: McArthur Graham & Associates – President & IT Risk Consultant Jan 2001 – July2002: KPMG Canada – Manager, Information Risk Management Feb 1997 – Jan 2001: Butterfield Bank Bermuda – Senior IT Auditor Mar 1991 – Feb 1997: Government of Ontario – Senior EDP Auditor + IT Audit Manger