Experience
Resume
Experience
Jan 2023 - Present
IT Auditor
REPLACE - Current Employer · REPLACE - City, State
- Plan and execute IT general controls testing across access management, change management, and IT operations.
- Built policy-as-code checks that evaluate infrastructure changes automatically, replacing manual sample-based review.
- Partner with engineering teams to design controls into deployment pipelines rather than auditing around them.
- Communicate findings and remediation paths to both technical owners and executive stakeholders.
Jun 2021 - Dec 2022
IT Audit Associate
REPLACE - Previous Employer · REPLACE - City, State
- Supported SOX ITGC testing across financially significant systems.
- Documented control narratives and process flows used by the wider audit team.
- Standardized evidence collection, cutting turnaround time on recurring requests.
Education
Aug 2017 - May 2021
REPLACE - B.S. in Your Major
REPLACE - University Name · REPLACE - City, State
Skills
Policy as Code
- Open Policy Agent / RegoAuthor and unit-test policies that evaluate infrastructure plans before apply.
- Terraform plan evaluationGate deployments on control checks using machine-readable plan output.
- Control-to-code mappingTranslate NIST 800-53 control text into deterministic, testable rules.
Cloud & Infrastructure
- TerraformProvision resources that are compliant by default rather than remediated later.
- AWSIAM, S3, encryption at rest, tagging strategy, and resource-level access control.
- Infrastructure as Code reviewRead IaC as an audit artifact - configuration becomes reviewable evidence.
Automation & Tooling
- Git & version controlChange history as an audit trail; pull requests as approval records.
- CI/CD pipelinesRun control checks automatically on every change, not quarterly.
- Bash & PythonEvidence collection, verification scripts, and reporting.
Governance, Risk & Compliance
- NIST 800-53Control selection, tailoring, and implementation statements.
- SOX / ITGCAccess, change management, and operations controls over financial systems.
- Risk assessmentIdentify, rate, and track risks through to accepted or mitigated.
- Continuous control monitoringReplace point-in-time sampling with always-on automated testing.
Audit & Assurance
- IT general controls testingDesign and operating effectiveness testing across the control environment.
- Evidence & workpapersReproducible evidence generated by pipelines instead of screenshots.
- Control narrativesDocument control intent so engineers and auditors read the same thing.
- Stakeholder communicationTranslate technical findings into business risk for non-technical owners.
Contact
See also certifications and projects.