Lead, Risk Management & Compliance Resume
New York, NY
SUMMARY:
- A Senior Risk, Compliance, Regulatory Affairs & Program Management Lead serving cross functional industries.
- I build Compliance by design products as a liaison between Legal, Business, IT, PMO, Sponsors, Regulatory agencies (FDA, SEC) with strong cross functional collaboration.
- I intend to parlay my unique combination of business\risk management and technical expertise into a leadership role.
COMPETENCIES:
Program/Project Management
Compliance & Regulatory Affairs
Financial Risk Management
NIST, HIPAA, SEC/NFA Guidelines
Privileged A/C & SOD
Mergers, Acquisitions & Integrations
Vendor Management
Cross Functional Leadership
Asset Governance
Business Continuity\DR
CoBiT 5.0, COSO, 21CFR Part II
Identity Access Managment
Audits and Assessments
ISO 14971, ITIL, PCI, PII, SPII
On Shore/Offshore Model
Sox 302, 404, SAS 70 (SOC1)
ICH, Q9, ISO 17799, ISO 27001
Defense Risk Assessment
Metric Stream, Archer, GRC
Presentations & Seminars
CAPA, Risk Analysis, Mitigation
Data Migration & Analysis
EXPERIENCE:
Confidential, New York, NY
Lead, Risk Management & Compliance
Responsibilities:
- Information Governance and Management (IGM) compliance function reports into the CIO and covers Information Security, IT and Risk Management, Compliance (GxP).
- Standardize and Streamline the IT Landscape, drive business innovation through Digital and strengthen Information Security against rising Cyber threats.
- Developed & Managed a GRC solution roadmap for Confidential internal & external entities.
- Authored a ‘Playbook’ for hosting systems in Cloud partnering with Legal, Business\IT. This was published as Governance for vendor hosted solutions.
- Lead Information Governance Management (IGM) function for IT, Digital, Security and Business, partnering to build foundation that protect organization’s assets.
- Provide IGM advice & expertise to contribute to business progress and change to enhance security via controls, CAPA, risk identification, mitigation for compliance.
- Rollout IGM activities according to the Global IGM strategy in alignment with the IT Leadership Team and relevant business stakeholders (e.g. QA, Legal, Finance, etc.).
- Enabler for innovation and innovative technology solutions to increase value proposition towards business growth, while weighing off the risks.
- Championed GRP (Governance, Risk & Process) & Compliance Center of Excellence.
- Performed RM&C activities for audit readiness, received ‘4/4 - A’ GOOD rating.
- Developed the “Audit Readiness Program” & created Audit preparation kits.
- First line of defense for Business partners providing compliance & regulatory direction.
- Second line of defense for Internal Audits and External agencies (Big 4, FDA, SEC).
- Partnered with Vendor Compliance Assessment Services VCAS team for Vendor assessment of Processes, Data storage, PI, EU data, DMZ, SoX for Hosting and Managed Services.
- Launched Internal Treasury Thomson Reuters, SunGard. 5 successful audits.
- Manage a team of IT Security professionals, review deliverables, resource planning, skills development, and foster a high-performance culture. 68 Compliance reports.
- Author* Confidentiality, Integrity, Availability of Assets as Compliance As Risk Enterprise.
- Performed Gap Analysis of SoX systems and created a remediation SOP.
- Reduced costs through strategic internal audit outsourcing and co-sourcing.
- Familiarity with GRC platforms Archer, BWise, Metric Stream.
- Confirmed remediation plan with BPOs and ensure agreement with milestone dates.
- Ensured weaknesses are corrected before date of the assertion and attestation.
- Confirmed progress, follow up with sites to confirm that the issue has been remediated.
- Ensured weaknesses are corrected before date of the assertion and attestation.
- Monitored Adverse events for Corrective Action \Preventive Action for remediation.
- Presented to BPO/Finance Director clearly explain the purpose and use of Shadow, Clearing and Suspense accounts.
- Control assessments & Testing for Periodic review for Enterprise Systems.
- Devised & piloted HPQC ALM in F&BO-HR BT for e-sig as Enterprise testing model.
- Mobilized cross-functional business resources. Successful Merger of Bank Entities.
- Built ITGC framework for assets Hardware\Software\Data on time within budget.
- Reduced deficiencies\service requests from 42% to 18% via QMS (Quality tools).
- Control assessments & Testing for Periodic review for Enterprise Systems.
- Partnered to build Accord(Access) Aveksa4.2.3 for User Access governance
- Designed Control Design effectiveness, Operating effectiveness & SOPs.
Strategy & Innovation Lead, CE COE, Global Commercial
Confidential
Responsibilities:
- Developed Governance framework by influencing Sr. Leadership ensuring adherence to global policies & regulations on congress and convention management.
- Authored a Road Map for congress\convention with various stakeholders.
- Monitored & Reported HCP data to avoid compliance risk.
- Partnered with PMO for project delivery. Assisted in project timeline forecasting, scope control, and budget management. Managed contractors.
- Reviewed and participated in quality metrics criterion for continuous improvement.
- Championed and streamlined SDLC & Agile methodology for FLEX program.
- Maintained & delivered a portfolio of 2 BU with 16 projects by harmonizing processes.
- Volunteered and reviewed Change Management SOPs. Quality of RFCs improved.
- Drafted & presented a framework for SOPs and Job Aids for strategy & SDLC.
- Led a global team of 30+, developed metrics for assessing SoX gaps and trends.
- Established the mantra “We got your back” as a Quality Business Partner.
- Trained (Business, BT, Audit, Vendors, Clients, & Shared Services) for best practices.
- Coached & Mentored BT & Business partners ensuring One BT-1BT partner focus.
- Assisted with SOX 302 quarterly control certification surveys of process owners and process managers with Embedded Self Assessments for 60+ applications.
- Identified opportunities in ‘Lessons learned’, implemented in change management.
Business Systems Lead
Confidential
Responsibilities:
- Spearheaded implementation in LATAM & AFME regions covering at least 28 markets.
- Managed and lead 11 cross functional projects. Delivered on time & within budget.
- Conducted training & Managed On shore & Off Shore teams remote\onsite up to 30.
- Partnered with country BU leads. Manufacturing discrepancies reduced by at least 15%.
- Led team (5) for security risk Gap Analysis for 75 systems from pool of 1500 +.
- Achieved compliance for over 120 remediated high\ medium risk systems with 7 PMs.
- Led team of 4 & created standard Part 11 standards increasing business efficiency.
- Managed and validated GLP & GCP regulated information systems(Ri\Di\Ei.)
- Led the retirement and decommissioning effort at an enterprise level with PMO.
Confidential
Business Analyst
Responsibilities:
- Developed list of commercial banks\mortgage products for trading up to $64 million.
- Performed System Analysis & Design for Mortgage & Web based-MERS registrations.
