0 viewsjobseeker
AMEN A. — Senior IT Audit and Compliance Professional from United States

AMEN A.

Senior IT Audit and Compliance Professional

United States 6+ years
Open to offersNew to Platform
Video Introduction
No video introduction yet
The candidate has not added a video.
Contact information and social networks are private. Connect to unlock.
Hidden

About

Amen A. is a seasoned professional in IT Audit, GRC, and Compliance with over six years of experience in leading complex programs in the financial services, healthcare, and technology industries. She has demonstrated expertise in frameworks such as ISO 27001, NIST CSF, COBIT, PCI-DSS, HIPAA, GDPR, and FedRAMP, effectively minimizing audit findings and automating GRC workflows. As an IT Auditor and MAR ITGC Analyst at Acuity Insurance, she built a comprehensive MAR ITGC control matrix and advanced ITGC testing protocols. During her tenure at American Tire Distributors, she orchestrated over 25 IT audits, designed 120 ITGCs, and significantly reduced unauthorized access risk. In her role at Pro Pharma Group, she implemented a SOX 404 compliance program impacting 18 business units and managed RSA Archer to support extensive SOX, HIPAA, GDPR, and FedRAMP requirements. With certifications as a CISA and CISM, Amen maintains a pivotal position in ensuring robust IT compliance and governance.

Experience

  • IT Auditor / MAR ITGC Analyst

    Acuity Insurance · 2025 — Present
    Developed the MAR ITGC control matrix by establishing control objectives, testing procedures, evidence requirements, ownership, and review cadence for financial reporting systems such as Lawson, Active Directory, and UKG. Advanced the Model Audit Rule (MAR) ITGC program through standardization, risk-to-control mapping, governance structure development, and readiness alignment for audits. Conducted ITGC testing for logical access, privileged access management, and change management controls, identifying deficiencies and collaborating with stakeholders for remediation. Carried out user access reviews (UARs) and privileged access recertifications to confirm the appropriateness of elevated access across enterprise applications and databases. Created a centralized framework for IT controls tracking and deficiency management, including governance for remediation, severity classification, and aging metrics. Led walkthroughs of Lawson change management processes, pinpointing control gaps in approvals, testing, documentation, and audit evidence retention.
  • IT Audit & Compliance Specialist

    American Tire Distributors (ATD) · 2022 — 2025
    Oversaw more than 25 comprehensive IT audits that supported compliance for SOX 404, ISO 27001, NIST CSF, HIPAA, and PCI-DSS, achieving a complete audit rate of 100%. Developed, documented, and tested over 120 ITGCs in the areas of access management, change management, and backup/recovery. Achieved a 40% reduction in unauthorized access risk through targeted remediation of privileged access and segregation of duties (SOD) conflicts involving Active Directory, Okta, VPN, and firewall environments, addressing over 5,000 access discrepancies. Streamlined audit workflows and evidence collection using AuditBoard and ServiceNow GRC, minimizing manual work by 25%. Carried out the testing of ToD and ToE to ensure control effectiveness and support external auditor reliance. Completed ITAC testing for key financial and operational applications, reinforcing data integrity and system reliability.
  • Senior IT Compliance & GRC Analyst

    Pro Pharma Group · 2020 — 2022
    Created and rolled out a company-wide SOX 404 compliance program that encompassed 18 business units, including the development and maintenance of Risk Control Matrices (RCMs). Administered RSA Archer as the enterprise GRC platform, facilitating over 100 workflows and controls in accordance with SOX, HIPAA, GDPR, and FedRAMP requirements. Closed more than 150 POA&M remediation items, leading to a 40% improvement in remediation timelines. Conducted annual vendor and third-party risk assessments for over 75 suppliers. Integrated SIEM tools such as Splunk, QRadar, and Sentinel into GRC workflows to enable automated validation of audit evidence. Implemented OneTrust to streamline privacy operations, including RoPA, DPIA, and DSAR processes.
  • IT Risk & Assurance Specialist

    First Bank (1st Bank) · 2016 — Present
    Executed enterprise IT risk assessments across more than 25 IT units, including conducting gap assessments for ISO 27001 and NIST CSF. Evaluated access controls and password policies, documenting findings and plans for remediation intended for senior leadership. Developed executive risk dashboards and audit reports for the C-suite and senior management.

Skills & Expertise

Education

  • Bachelor of Science (B.Sc.) in Accounting
    University of Benin