As a former Senior Manager at a big consulting firm, I have certainly well-founded compliance & security knowledge. I also gained the CISA qualification as well as a COBIT certification.
Risk management, auditing of regulatory compliance, information security, business continuity, efficiency and effectiveness of IT organizations / processes and the assessment of the design and effectiveness of automated application controls are tasks of my daily work.
In addition to various medium-sized IT revisions and special audits (e.g. project revision), I managed the worldwide IT audit (SOX environment) for one of the largest clients of the big consulting firm in Switzerland.
In this activity, I was fully responsible for planning, implementation, quality assurance and reporting. I directly coordinated 16 IT auditors worldwide and was contact for all other involved IT auditors. In addition, I was in charge to communicate the IT audit results to the client and to financial and special auditors.
For the global IT audit, I was able to optimize the efficiency of IT audit work on a sustained basis (scope, time and budget).
I provide a broad range of experience on all relevant IT audit areas like organization, infrastructure, technology, outsourcing and applications software.
IT security is one of the baselines of my transformational work. Given the fact, that a cloud environment can provide a higher level of security, it is crucial to have a very good understanding of the related organizational and technological measures to deal with cyber risks. I have hands-on experience with cyber security threats and efficient countermeasures.
The big Swiss insurance company is the first Swiss financial company to receive approval from FINMA to transfer the entire enterprise IT into a hybrid cloud environment. As the “IT stakeholder” as part of a multidisciplinary task force, which has been working for more than 1.5 years, I have helped to solve the IT-relevant tasks and contributed significantly to this success.
The experience with the insurance company helped me to develop a sophisticated approach to deal with cloud compliance and security in a highly regulated environment at the big professional service company. That work included the development of a specific cloud control framework and the successful alignment with e.g. FINMA and RAB.