Experience

  1. Jan 2023 - Present

    IT Auditor

    REPLACE - Current Employer · REPLACE - City, State

    • Plan and execute IT general controls testing across access management, change management, and IT operations.
    • Built policy-as-code checks that evaluate infrastructure changes automatically, replacing manual sample-based review.
    • Partner with engineering teams to design controls into deployment pipelines rather than auditing around them.
    • Communicate findings and remediation paths to both technical owners and executive stakeholders.
  2. Jun 2021 - Dec 2022

    IT Audit Associate

    REPLACE - Previous Employer · REPLACE - City, State

    • Supported SOX ITGC testing across financially significant systems.
    • Documented control narratives and process flows used by the wider audit team.
    • Standardized evidence collection, cutting turnaround time on recurring requests.

Education

  1. Aug 2017 - May 2021

    REPLACE - B.S. in Your Major

    REPLACE - University Name · REPLACE - City, State

Skills

Policy as Code

  • Open Policy Agent / RegoAuthor and unit-test policies that evaluate infrastructure plans before apply.
  • Terraform plan evaluationGate deployments on control checks using machine-readable plan output.
  • Control-to-code mappingTranslate NIST 800-53 control text into deterministic, testable rules.

Cloud & Infrastructure

  • TerraformProvision resources that are compliant by default rather than remediated later.
  • AWSIAM, S3, encryption at rest, tagging strategy, and resource-level access control.
  • Infrastructure as Code reviewRead IaC as an audit artifact - configuration becomes reviewable evidence.

Automation & Tooling

  • Git & version controlChange history as an audit trail; pull requests as approval records.
  • CI/CD pipelinesRun control checks automatically on every change, not quarterly.
  • Bash & PythonEvidence collection, verification scripts, and reporting.

Governance, Risk & Compliance

  • NIST 800-53Control selection, tailoring, and implementation statements.
  • SOX / ITGCAccess, change management, and operations controls over financial systems.
  • Risk assessmentIdentify, rate, and track risks through to accepted or mitigated.
  • Continuous control monitoringReplace point-in-time sampling with always-on automated testing.

Audit & Assurance

  • IT general controls testingDesign and operating effectiveness testing across the control environment.
  • Evidence & workpapersReproducible evidence generated by pipelines instead of screenshots.
  • Control narrativesDocument control intent so engineers and auditors read the same thing.
  • Stakeholder communicationTranslate technical findings into business risk for non-technical owners.

Contact

See also certifications and projects.