Marcus H. Loftin
Governance Risk and Compliance Analyst, Regional banking
Charlotte, NC · (847) 555 0196 · name@example.com · linkedin.com/in/marcushloftin
Key Qualifications
EXPERIENCE
Six years in security governance risk and compliance, all in financial services
INDUSTRIES
Regional banking, payment processing
SPECIALTIES
System and Organization Controls 2 readiness, access reviews, third party risk, policy management
SYSTEMS
ServiceNow, Archer, Splunk, Tableau, Microsoft 365
CREDENTIALS
Certified Information Systems Auditor, Certified in Risk and Information Systems Control
EDUCATION
Bachelor of Science in information systems, University of North Carolina at Charlotte
Results at a Glance
2
Type report
140
Third party vendors
21 days
By giving managers
Executive Summary
Governance risk and compliance analyst with six years in banking technology, where the control owner and the auditor rarely speak the same language. Runs the System and Organization Controls 2 evidence cycle, quarterly access reviews and third party assessments for a bank technology subsidiary. Reads the control before arguing about the finding.
Signature Achievements
- Carried the first System and Organization Controls 2 Type 2 report for a new payments platform with a clean opinion.
- Cut evidence collection for the annual audit from nine weeks to five by moving 60 requests into a ServiceNow workflow.
- Reviewed 140 third party vendors against the security questionnaire and moved 18 of them onto remediation plans.
- Closed 34 of 39 findings from a National Institute of Standards and Technology special publication 800 53 gap assessment within two quarters.
- Reduced access review completion time from 21 days to 9 by giving managers a report they could act on directly.
- Wrote the control narratives the qualified security assessor accepted without rework.
Professional Experience
Governance Risk and Compliance Analyst
Catawba Ridge Financial Technology, Charlotte, NC 2022 to present
One of four analysts covering security control assurance for a bank technology subsidiary of 1,100 staff serving 38 community banks.
- Runs the System and Organization Controls 2 Type 2 evidence cycle from request list through auditor walkthrough.
- Owns quarterly user access reviews across 22 in scope applications and reports exceptions to the risk committee.
- Assesses third party vendors before contract and on a risk based schedule afterward.
- Maintains the control mapping between National Institute of Standards and Technology special publication 800 53 and the internal policy set.
Information Security Analyst
Uwharrie Card Services, Greensboro, NC 2020 to 2022
Two person security function at a card processing firm handling 40 million transactions a year.
- Prepared the annual Payment Card Industry Data Security Standard assessment including scope diagrams and control narratives.
- Tracked remediation of scan findings with the infrastructure team and reported status monthly.
Information Technology Auditor
Yadkin Valley Bancshares, Winston Salem, NC 2019 to 2020
Internal audit team of six at a community bank holding company with 24 branches.
- Tested general technology controls covering change management, backup and access.
Licensure and Certification
Certified Information Systems Auditor, 2022
Certified in Risk and Information Systems Control, 2024
Member, Information Systems Audit and Control Association
Education
Bachelor of Science in information systems, University of North Carolina at Charlotte, 2019
Core Skills
System and Organization Controls 2 readiness · Access reviews · Third party risk · Control mapping · Policy management · Payment card compliance · ServiceNow workflows · Audit coordination · Risk reporting