Welcome to Michael's freelance profile!
This freelancer will be available again on 24.09.2023
Until 24.09.2023
Location and workplace preferences
- Location
- Barcelona, CT, Spain
- Remote only
- Primarily works remotely
Verifications
Freelancer code of conduct signed
Read the Malt code of conduct
Languages
-
English
Native or bilingual
-
Spanish
Basic
-
French
Basic
-
Irish
Fluent
Categories
Skills (6)
-
Beginner Intermediate Advanced
-
Beginner Intermediate Advanced
-
Beginner Intermediate Advanced
-
Beginner Intermediate Advanced
-
Beginner Intermediate Advanced
-
Beginner Intermediate Advanced
Michael in a few words
Being a hybrid information security and cybersecurity professional, I have over 20+ years’ experience across a variety of industries. I have extensive knowledge of global regulatory standards and compliance obligations including Sarbanes-Oxley (SOX), ISO 27001, GDPR, CCPA, PCI DSS, SOC 1 and 2 and Internal Controls over Financial Reporting (ICOFR). My primary practice areas are identity and access management, risk management, logging and monitoring, third party security management, application security, vulnerability management, data security, implementation of security requirements, design specifications and compliance controls, cloud security, internal and external audits, security issues related to software pilots, system upgrades and enhancements, and creation of process/procedure documentation.
Thank you.
Experience
European Commission
Public sector
Information Technology Business Analyst
Working as part of a team this includes the following:
• Project Management across different technologies and environments
• Provision of expert advice and assistance in relation to the IT systems and databases.
• Analysis of business and functional requirements of IT systems and databases under negotiation, including a review of usability of existing IT systems and building blocks. This includes the delivery of a written report on the basis of this analysis.
• Extensive consultation and testing of user requirements with all stakeholders. This includes organising dedicated remote workshops.
• Preparation of vision documents and communication materials, such as mock-ups of the IT systems and databases and other internal presentations.
• Estimation of costs, timescales and resource requirements for the successful development of the IT systems and databases. This includes the delivery of a written report of this estimation.
• Preparation of the necessary internal documents on IT Governance for the development of the IT systems and databases. This includes Project Initiation, Use Cases, Prototypes, Business Case, and Project Charter.
• Liaise with the policy team, as well as other relevant teams, and duly reflect their needs to ensure that the preparation of the information systems and databases reflects the needs of the new system.
• Preparation of a hand-over document for the purpose of the future development of the IT systems and databases.
Accenture - ACCENTURE ORGANISATION
Social Networks
Senior Analyst - Information Security and Risk Management
Managed teams working on Risk Management & Compliance covering the following areas:
• Governance Risk and Compliance Management.
• Security Threat and Risk Assessment Management.
• Security Auditing & Compliance.
• IT Auditing & Compliance controls testing/standards - SSAE 18, SOC1/SOC2, ISO 27001, ISO 27018, ISO 27701, SOX ITGC, PCI & NIST.
• Security & Information Security assessments & System Review (ISMS).
• IT Service Management as per ITIL framework.
• SOC Operations
Federal Home Loan Bank of San Francisco
Banking & Insurance
Senior Business Analyst - IT Security
• IAM Upgrade & Enhancement - Sailpoint IIQ 8.1 upgrade, entitlement description management enhancement & expansion of systems covered.
•Exception Management Enhancement - ServiceNow upgrade (Orlando) along with two phases around approval workflow, SLAs, states and improved form information.
•Vendor Risk Management - CyberGRX rollout and integration.
•UAT Testing, Documentation & Training on these projects using Agile, Stories & Tickets via ServiceNow.
Autodesk - Autodesk
Tech
Senior Security Analyst
• Collaborating with various internal and external teams using ServiceNow, SharePoint, Jira and Confluence (Atlassian wiki) as repositories for documentation, evidence, testing and tracking.
• Engaging with external auditors i.e. KPMG and EY along with internal audit on various efforts.
Allianz - Groupe Allianz
Banking & Insurance
Senior GRC consultant – IT Security
• Running FSA/ICOFR certifications, application risk assessments and acceptances preparation to audit, CyberArk and Tripwire systems, using ServiceNow and Sharepoint along with creating/updating jobaid, runbook, narrative, process flow and overview documentation.
• Preparing, presenting and dealing with internal and external audit requests while using SharePoint as a repository.
• Training personnel from AGCS and IBM on running FSA/ICOFR certifications, CyberArk and Tripwire systems.
• Drafting security governance documents for new system implementation.
• Reviewing and cleaning up privileged access security requests for Access Oversight.
Bank of America Merrill Lynch
Banking & Insurance
Information Security Analyst - Global Information Security
• Project management for all new application integrations into the Central Security Database. Approximately 60 projects (applications)/quarter, responsible for installation/integration of new applications into the Central Security Database, including final assurance that integrated applications were compliant with global financial regulations. For each project, managed a team of 15-20 comprised of application owners, business owners, developers, support teams, vendor teams, transmission support teams, access provisioning teams, architecture support teams.
Merrill Lynch
Banking & Insurance
Security and Risk Analyst - Global Information Security & Privacy
• Teamed with information security systems architects and developers to design, develop, implement and maintain Merrill Lynch’s System Entitlement Reporting Application (SERA) – a global, company-wide access review system.
Are you sure? Your recommendation will be permanently deleted