Certified Information Technology, Auditing and Privacy Professional
Greater New York City Area
Certified Information Technology, Auditing and Privacy Professional
Greater New York City Area
Information Technology and Audit professional performing consulting services around Corporate & Risk Management, Ethics & Compliance and Data Privacy.
Certified Internal Auditor (CIA): 2000
Certified Information Systems Auditor (CISA): 2001
Certified Information Privacy Professional (CIPP): 2007
~ Data Privacy ~ Risk Management
~ EU US Safe Harbor
~ Audit Planning & Management ~ Access controls
~ Risk and Control Assessment ~ Information Security
~ Application Security ~ Computer Forensics
~ Incident Handling & Response ~ Network Scanning
~ Firewall, Router Audits ~ Cryptography
~ Windows Security ~ Unix Security
~ Defense In-depth Concepts ~ Business Impact Analysis
~ IT Contingency and Continuity Planning
~ Computer Security Policies ~ Building and Leading Teams
(Privately Held; 10,001 or more employees; Accounting industry)
July 2007 — Present (2 years 1 month)
Benjamin Farrar, from the Technology & Security Risk Services (TSRS) practice, has joined the Quality & Risk Management (Q&RM) Ethics and Compliance team at Ernst & Young. In his new role, Benjamin will assist in the continued development, implementation and monitoring of data privacy initiatives across the United States. Benjamin will join the other members of the Ethics & Compliance team working with the Chief Ethics, Compliance and Privacy Officers advising on various data privacy issues including United States and European Union Safe Harbor Certification, Incident Management, Breach Notification, Global Application Reviews, Privacy Auditing & Monitoring and Information Security.
(Privately Held; 10,001 or more employees; Accounting industry)
September 2005 — June 2007 (1 year 10 months)
Benjamin is a senior consultant for Ernst & Young’s Technology and Security Risk Services (TSRS) practice in the Financial Services Office (FSO) in New York. He has over 8 years experience covering the Investment Banking, Mortgage, Insurance and Healthcare industries. Benjamin has worked on multiple engagements in these industries providing guidance on Sarbanes Oxley (SOX), Statement on Accounting Standard 70 (SAS70) reports, IT risk and controls, privacy, policy design and development.
Selected Major Projects:
• Assisted an international Investment Banking and Capital Markets client with their SOX year 3 and 4 testing and reporting requirements.
• Managed and performed a multi year SAS70 reporting engagement for a Wealth Management division of Financial Services Company assessing IT controls, application security and access management.
• Assisted a leading mortgage backed security administrator with an assessment of their SOX control documentation prior to audit.
(Non-Profit; 5001-10,000 employees; Hospital & Health Care industry)
January 2002 — August 2005 (3 years 8 months)
Department of Corporate Audit, Compliance, Privacy & Security
Reporting to the Vice President of Corporate Audit
> Responsible for conducting Information Technology and Operational Audits; independently, cooperatively, and leading staff; achieving agreed upon objectives within time requirements.
> Designed and implemented an organizational wide HIPAA Security Compliance program for a Clinic / Hospital entity with over 600 physicians and 6,500 employees.
> Conducted multiple Risk and Vulnerability Assessments, reporting results to management.
> Directed weekly meetings with Managers, Administrators, Programmers and Users to develop a policy and standards framework for HIPAA Security Compliance.
(Non-Profit; 5001-10,000 employees; Hospital & Health Care industry)
March 2000 — December 2001 (1 year 10 months)
Department of Decision Support, Business Services
Supporting the Vice President of Finance
Responsible for monthly reporting of financial and performance metrics informing management of reimbursement and accounts receivable activities of healthcare billing operations.
Performed reimbursement audits of insurance company payments identifying underpayments and incorrect adjudications.
B.S , ISDS, Information Systems & Decision Sciences - Management Information Systems , August 1994 — December 1999
Courses of Study:
> Internal Auditing I & II
> Advanced Business Programming
> System Development
> Lotus Notes
> Strategic Management
> Database Management
> Financial Accounting
> Business Statistics I & II
> Auditing Case Studies
> Operations Management
> Telecommunications
> Data Warehousing