• Served as a security engineer to ensure production systems are able to deal robustly with possible sources of disruption in accordance to NIST Special Publication 800-53
• Advised project teams in developing various applications throughout the Software Development Lifecycle (Waterfall and Agile methodology)
• Managed the software development lifecycle in implementing the IT service management tool, ServiceNow, including business process definition, workflow construction, requirements documentation, and Customer Acceptance Testing (CAT) with the ultimate goal of building a mature, enterprise-wide Governance, Risk, and Compliance (GRC) management system
o Developed and communicated strategies and processes regarding ServiceNow
system development to cross functional groups and management to ensure the
smooth delivery of the system
o Lead the ServiceNow Integration team to improve upon existing manual business
processes by automating the processes through ServiceNow development and
deployment
• Provided IT advisory services related to internal control, risk management, IT controls,
Sarbanes-Oxley (SOX) compliance, and Payment Card Industry (PCI) compliance
• Lead the internal project management team, utilizing partnerships with cross-functional
workstreams, to provide assessments of IT SOX GCC Controls and recommendations for
improving internal control procedures to IT management and leadership
• Represented the client in coordinating with external auditors in order to finalize external
audit findings, develop remediation strategies, and drive issues to closure
o Lead a team to address and manage key remediation efforts for all Office of
Inspector General (OIG) IT audit findings
o Lead efforts to analyze completed and outstanding audit findings in response to an
IT security breach to ultimately prepare the CIO in a Congressional hearing