Megan S. Denton
Information Technology Audit Manager, Regional banking
Pittsburgh, PA · (412) 555 0122 · name@example.com · linkedin.com/in/megansdenton
Key Qualifications
EXPERIENCE
Eleven years of information technology audit in banking, five as a manager
INDUSTRIES
Regional banking, payments, core processing
SPECIALTIES
Information technology general controls, Sarbanes Oxley section 404, access management, change control
SYSTEMS
AuditBoard, TeamMate, ServiceNow, Workiva, Tableau
CREDENTIALS
Certified Information Systems Auditor, Information Systems Audit and Control Association
EDUCATION
Bachelor of science in information systems, Duquesne University
Executive Summary
Information technology audit manager at a regional bank with eleven years of audit experience. Owns the annual technology audit plan, the Sarbanes Oxley section 404 testing of information technology general controls, and the relationship with examiners on technology matters. Manages four auditors and two co source partners.
Signature Achievements
- Reduced the Sarbanes Oxley section 404 information technology control population from 210 to 128 by removing duplicate controls, and external audit accepted the reduced set with no added testing.
- Found that eleven privileged accounts on the core banking platform had no named owner, and all were removed or reassigned within three weeks.
- Delivered fourteen technology audits a year against a plan of twelve for four consecutive years.
- Built the continuous testing routine that samples change tickets monthly, which cut change control findings from nine a year to two.
- Answered every technology question raised in two examinations by the Office of the Comptroller of the Currency without a supervisory finding on the audit function.
- Trained the whole internal audit department on information technology general controls so financial auditors could test access controls in their own audits.
Professional Experience
Information Technology Audit Manager
Allegheny Keystone Bank, Pittsburgh, PA 2021 to present
Leads four auditors covering technology risk for a bank with 12 billion dollars in assets and 190 branches.
- Builds the annual technology audit plan from a risk assessment covering 60 applications and four data centers.
- Manages audits of access management, change control, backup and recovery, and vendor hosted systems.
- Owns Sarbanes Oxley section 404 testing of information technology general controls and reports results to external audit.
- Presents technology audit results to the audit committee each quarter.
- Directs a co source partner used for penetration test review and cloud configuration audits.
Senior Information Technology Auditor
Monongahela Trust Company, Pittsburgh, PA 2017 to 2021
Audited technology operations for a trust and wealth business with 30 billion dollars under administration.
- Tested logical access, program change and computer operations controls across fifteen applications.
- Audited the disaster recovery exercise and reported the gap between the tested scope and the critical application list.
- Wrote the first cloud hosting audit program the department used.
Information Technology Auditor
Laurel Highlands Financial Group, Johnstown, PA 2015 to 2017
Supported technology audits at a bank holding company with nine subsidiaries.
- Performed user access reviews and reconciled terminated employees against active accounts.
- Documented process walkthroughs and control descriptions for the audit workpapers.
Licensure and Certification
Certified Information Systems Auditor, Information Systems Audit and Control Association
Certified Internal Auditor, Institute of Internal Auditors
Education
Bachelor of science in information systems, Duquesne University, Pittsburgh, Pennsylvania
Core Skills
Information technology general controls · Sarbanes Oxley testing · Access management audit · Change control audit · Disaster recovery review · Audit planning · Team management · AuditBoard · TeamMate