ATIF AHMED KHAN, Teamleader Audit & Compliance

ATIF AHMED KHAN

Teamleader Audit & Compliance

National Database & Registration Authority

Location
Pakistan
Education
Bachelor's degree, Accounting Audit and Finance
Experience
19 years, 10 Months

Share My Profile

Block User


Work Experience

Total years of experience :19 years, 10 Months

Teamleader Audit & Compliance at National Database & Registration Authority
  • Pakistan - Islamabad
  • My current job since March 2012

Participates on board meetings and audit committee meetings as focal person for Department. Administratively supervises and mentors 25 X IA staff located in the 08 X regions acting as a Team Leader; prepares and presents annual performance reviews and staff development plans. Furthermore my duties require me to actively participate as part of the Audit Department's Senior Leadership Team.

Senior IT Consultant at Multiple Telco Clients
  • Qatar - Doha
  • My current job since January 2019

Conducting remote and onsite ICOFR Audits, domains covered are ITGC, Application and Revenue Assurance Controls.
Using sampling methodologies effectively highlighting the deficiencies and vulnerabilities discovered along with remedial actions.

Senior IS Auditor at National Database & Registration Authority
  • Pakistan - Islamabad
  • August 2009 to February 2012

Participates in complex IT, Internal Audits and Special Investigative Assignments. Utilizing independent judgment and discretion in different systems & operations including scheduling; processing; input/output systems flow, controls and edits; data storage; and security procedures. Audits applications, systems and programs to ensure that systems C.I.A triad exist. Reviews adequacy of proposed controls of new & morphed systems. Provide IS Security best practices advisory in ongoing projects. Ensures appropriate functionality and controls are in place within technical/functional/operational infrastructure, applications, and business processes.

Assistant Manager IT Audit at Etisilat-PTCL
  • Pakistan - Islamabad
  • January 2008 to August 2009

Performed my duties in the largest telecommunication company in Pakistan; conducted the audits of multiple areas including ERP (SAP R/3), Telecommunication, Infrastructure, Networks and Databases. Analyzed data using CAATS (ACL, SQL, IDEA & MS Excel) to evaluate effectiveness of controls, revenue leakage, mediation and billing related validation and determined accuracy of reports, efficiency and security of operations. Devised controls for new or modified computer applications to prevent inaccurate calculations & data loss and to ensure discovery of errors. Conducted audits of IT operations and IT projects including analysis of business

Information Systems Auditor at NADRA
  • Pakistan
  • September 2006 to December 2007

Hired as the first ever IS Auditor in NADRA; devised audit programs and procedures for the NADRA country wide IT Infrastructure with team of Internal Audit and Technical Staff. Evaluated Information Systems, discover weaknesses and recommended improvements/necessary actions following the industry best practices. Introduced COBIT based framework for audit reporting in different domains. Successfully carried out first ever audit of Oracle E.B.Suite covering the functional and technical aspects. Conducted technical, administrative/operational and financial audit in NADRA 800+ regional offices for streamlining them to a NADRA benchmark standard. Perform periodic walkthroughs to validate process flows and control activities. Liaise with business owners in creation of Functional Business Requirement Documentation and User Acceptance Testing, as required & develop and execute IT audit engagements. Reviewed major System Development and Maintenance Projects.

IT Security Compliance Officer at Capital Developement Authority
  • Pakistan - Islamabad
  • November 2003 to December 2005

As IT Security Compliance Officer, actively participated in:
• Development & delivery of Comprehensive Information Security.
• Protection of Information & Infrastructure from internal & external threats.
• Assurance to comply with statutory and regulatory requirements.
• Creation & maintenance of Incident Response System.
• Develop and implemented risk assessment program and risk universe.
• Deployment of threats related knowledge base.
• Identifying gaps, workarounds, and customization requirements.

Education

Bachelor's degree, Accounting Audit and Finance
  • at Allama Iqbal Open University
  • April 2011

Financial /Cost Accounting Economics Auditing Taxation

Specialties & Skills

Coaching
Certified information Systems Auditor
Oracle E Business Suite
Audit Management
IS AUDIT
R 12 & 11i Oracle EBS
COMPUTER FORENSICS
MS SQL 2000
Linux Audit
Project Auditing
ISO 27001:2013
Internal Audit
Patch Management Audits
Vulnerability Assesment Audits

Social Profiles

Personal Website
Personal Website

URL removed due to policy violation. Please contact support for further information.

Languages

English
Expert

Memberships

ISACA
  • ISACA Platinum Level Member
  • April 2002
IIA
  • Local Chapter Member
  • February 2010

Training and Certifications

IT Auditing & Controls (Training)
Training Institute:
ICIL
Date Attended:
September 2007
CCNA-CISCO Networking (Certificate)
Date Attended:
July 1999
Valid Until:
June 2001
CRISC-ISACA (Certificate)
Date Attended:
January 2011
Valid Until:
January 2020
CISA-ISACA (Certificate)
Date Attended:
December 2006
Valid Until:
December 2021
Cobit 5 Foundation (Certificate)
Date Attended:
December 2018
Valid Until:
December 2020
Training on Penetration Testing & Ethical Hacking (Certificate)
Date Attended:
December 2006
Valid Until:
December 2006
Audit Command Language (ACL 9) (Certificate)
Date Attended:
April 2008
Valid Until:
April 2008
CA Foundation-ICAP (Certificate)
Date Attended:
June 1999
Valid Until:
June 1999
R-12 Oracle E-Business Suite Essentials for Implementers Certification-Oracle Corp (Certificate)
Date Attended:
April 2013
ISO-27001:2013 ISMS - Auditor/Lead Auditor (Certificate)
Date Attended:
April 2016
Valid Until:
March 2019
Oracle 11G Admin-I & Admin-II (Certificate)
Date Attended:
November 2011
Valid Until:
December 2011
Technical Audit of Telecom Exchanges (Certificate)
Date Attended:
March 2008
Valid Until:
March 2008

Hobbies

  • Swimming, Hiking.