
IT Audit, Risk, Compliance and Governance Professional - Blogger:"Today's Audit Journal"
Greater New York City Area

IT Audit, Risk, Compliance and Governance Professional - Blogger:"Today's Audit Journal"
Greater New York City Area
IT Auditor with more than 14 years experience in software development, infrastructure and network administration. However, my focus is Enterprise Risk Management. In the 1990's I founded a successful network integration company and transitioned it to a financial services ASP.
Experienced in ITIL, CobiT and Six Sigma frameworks.
As IT Auditor my responsibility is to provide independent and objective assessments of the adequacy and effectiveness of risk management and internal controls in order to ensure that IT & Business System risks are effectively managed in accordance with all relevant policies and regulations.
I have provided high level leadership to Fortune 500 companies in the areas of IT Security, Disaster Recovery, Business Continuity, and Regulatory Compliance. I have experience in risk assessments, business impact analysis, root cause analysis, project management, technical training and in the complete technology sales cycle. With an emphasis on Sarbanes-Oxley and Basel II auditing and compliance, I have often acted as an information clearinghouse between the technical and executive teams, and as project manager. Although, strong on the technical side, my emphasis has been, and will continue to be, in the strategic management area as a solutions architect and a visionary directing the technical staff, and making sure all the elements in the operational risk organization flow smoothly, and without surprises.
Road Warrior with extensive national and overseas travel, and work in India and Latin America.
Statistical Decision Modeling. Operational Risk Analysis. Disaster/Crisis Simulation. CobiT, COSO, Sarbanes-Oxley. Paisley, ACL Analytics. Enterprise Risk Management (ERM). Fluent in Spanish.
Follow Joel's "Today's Audit Journal" on Twitter here:
http://twitter.com/AuditJournal
(Public Company; Financial Services industry)
August 2007 — July 2009 (2 years )
Responsible for regulatory compliance work and SOX IT audits/testing for the Loews Corporation, one of the largest diversified financial corporations in the United States. Its principal subsidiaries being CNA Financial Corporation (NYSE: CNA) Chicago, IL, Boardwalk Pipeline Partners, LP (NYSE: BWP) Houston, TX, Diamond Offshore Drilling, Inc. (NYSE: DO) Houston, TX, HighMount Exploration & Production LLC, Houston, TX and Loews Hotels located throughout the USA.
(Public Company; 10,001 or more employees; CLUB; Health, Wellness and Fitness industry)
January 2007 — August 2007 (8 months)
Responsible for IT Audits, internal certifications, regulatory compliance and reporting. Sarbanes-Oxley, process, quality, security, and business continuity monitoring. Town Sports International is the parent company of the New York Sports Clubs, Boston Sports Clubs, Philadelphia Sports Clubs and Washington Sports Clubs.
(Privately Held; 1001-5000 employees; SDS; Information Technology and Services industry)
July 2006 — December 2006 (6 months)
Provided business continuity and risk management services to Fortune 1000 companies and public sector enterprises throughout the USA.
Work focused on:
1) Business Continuity
2) Disaster Recovery
3) Operational Risk Management
4) Business Process Management
5) Regulatory Compliance
6) Internal Certifications
7) Change / Configuration Management
8) Crisis Management
9) Incident Response
10) IT Governance
(Public Company; 10,001 or more employees; Computer & Network Security industry)
March 2005 — June 2006 (1 year 4 months)
Advised businesses and corporate IT infrastructure departments in the development and implementation of information security policies, configuration management, disaster recovery and business continuity. Provided clients with the tools and knowledge required to comply with IT Audits, BCP/DR mandates and issues pertaininig to State and Federal IT Security regulations. Key clients included: NYCHA, DoITT, CALPERS, and UBS.
(Public Company; 10,001 or more employees; CRZBY; Investment Banking industry)
June 2004 — November 2004 (6 months)
· Provided technical support to both Infrastructure and Desktop Support teams.
· Assisted in Cisco and HP predominant Data Center upgrade.
· Offsite disaster recovery configuration.
· Quality Assurance testing of systems and applications for planned Enterprise wide Windows XP upgrade.
· Coordinated deployment issues and testing with offices in Europe and NYC users, to assure organizational security policies were properly followed.
· Assisted in review of all technological security risks and documentation in preparation for internal audit.
(Privately Held; 1-10 employees; Computer & Network Security industry)
January 2002 — May 2004 (2 years 5 months)
· Provide Systems Analysis and networking support services to mid market companies.
· Create and sell security risk assessment programs, disaster recovery support services, and technology master plans.
· Administer penetration tests, human engineering evaluations, server and desktop security product evaluations, and prepared security policies.
· Configured firewalls, VPNs, Routers and E-Mail Spam filters. Installed Open Source IDS systems, virus detection, and trained network administrators in their proper use and filtering of log activities and reports.
(Privately Held; Information Technology and Services industry)
June 1995 — February 2002 (6 years 9 months)
· Founded company as a network integration VAR providing services to the Insurance and Banking sectors.
· Transitioned company into a software development and ASP service provider, specializing in Taft-Hartley Employee Benefit administration and Pension administration software.
· Provided hardware and software technical support for Win. NT and 2000 LAN’s.
· Hired and trained a full time staff of programmers, network engineers, sales and administrative personnel comprised of 11 persons.
· Technology writer for various software and Internet product manuals.
· Xerox, IBM, Novell, and HP Business Partner.
. Attracted private venture capital and brought company through legal and administrative process to a pre IPO stage, prior to changes in the investment capital market place (.com implosion).
(Information Technology and Services industry)
September 1990 — June 1995 (4 years 10 months)
· Responsible for sales of proprietary commodities trading system designed to reduce bulk-purchasing costs and improve supplier efficiencies to Fortune 500 companies in the NY metropolitan region.
· Sold the company’s computerized system operated as a private auction service with Electronic Data Interchange (EDI) features.
· Member of product development team responsible for software upgrades and Beta site coordination. This system was adopted nationwide during its last year of operations. Promoted from Manager to this position within a year.
CISA , IT Audit , 2008 — 2008
ICS, NIMS, NRP and COOP , Incident Controls and Management Certified , 2005 — 2006
CBCP , Business Continuity , 2005 — 2005
Have been involved in DR and BC for more than seven years, with focus on BC in the last five.
CISSP Course , 8 Week CISSP Boot Camp. , 2004 — 2004
Program is part of Bloomfield College, Bloomfield, New Jersey.
BA , Urban Planning/Business Administration , January 1986 — June 1990
Paid 60% of college expenses by working part time.
Technology. My main interest is technology, computer networks, business continuity and IT security in particular. I also have strong technical writing skills, project management experience and have managed multi-million dollar projects from inception to completion.
Association of Contingency Planners (ACP)
The Institute of Internal Auditors (IIA)
Information Systems Audit and Control Association (ISACA)
Institute of Electrical and Electronics Engineers (IEEE)
Centro Cultural Cubano - NYC
Association for the Study of the Cuban Economy - (Whatever is left!)
Ham Radio Operator - N2JQT - General Privileges - 1995 to 1999.