Muhammad Sajjad Mirza, CISA, CISM, Assistant Director – Internal Audit & Compliance

Muhammad Sajjad Mirza, CISA, CISM

Assistant Director – Internal Audit & Compliance

NADRA Regional HeadOffice

Location
Pakistan
Education
Master's degree, Telecom & networks
Experience
19 years, 10 Months

Share My Profile

Block User


Work Experience

Total years of experience :19 years, 10 Months

Assistant Director – Internal Audit & Compliance at NADRA Regional HeadOffice
  • Pakistan - Karachi
  • My current job since March 2012

• Prepare a comprehensive and flexible audit programme which provides complete audit coverage for the Organization and includes any risks, control, compliance, governance or other concerns identified from relevant sources.
• Partake in actual field work as suitable to ensure quality of work.
• Execute annual audit plan and coordinate with External auditors to avoid unnecessary costs.
• Mentor & supervise audit team for conducting branch office audits across regional office.
• Scrutinize and evaluate financial and information systems, recommending controls to ensure system reliability and data integrity.
• Security reviews & assessments of NADRA IT Infrastructure, Business process & Operations.
• Documented relevant facts & information which support the work performed.
• Prepare detailed audit report on findings with recommendations.
• Any special assignment delegated by Director Internal Audit.
• Build knowledge repository for Best Practices and trends in internal audit.

Information Systems Auditor at NADRA Head Office
  • Pakistan - Islamabad
  • July 2009 to February 2012

• Risk based audit Planning & executing IS Audits of IT Infrastructure
(Software, Database, Networks, etc).
• Security reviews & assessments of NADRA IT Infrastructure, Business process & Operations.
• Audit of Oracle ERP Modules (Payroll, Payable, Receivables).
• Mentor technical audit team for conducting branch office technical audits.
• Scrutinize and evaluate financial and information systems, recommending controls to ensure system reliability and data integrity.
• Update Director Internal Audit on audit assignments progress.
• Apply IS audit skills and techniques in testing application software and technology used by NADRA.
• Documented relevant facts & information which support the work performed.
• Prepare detailed audit report on findings with recommendations.
• Any special assignment delegated by Director Internal Audit.
• Build knowledge repository for Best Practices and trends in internal audit.

Sr. Network Analyst at MCB Bank Ltd
  • Pakistan - Karachi
  • January 2007 to July 2009

• IT centers & service provider management.
• Network designing & deployment.
• Coordinate with regional IT Center for completion of projects within deadline.
• Configuring of Firewall, Router, Switches & prepare critical backup to remote location.
• WAN media deployment, management & closing.
• Design, document, develop and oversee implementation of end-to-end integrated systems.
• Deployment of Core banking projects & integration of advance technologies.
• Configure & Implement Access Control Lists (ACL) on Core Routers & Switches.
• Network monitoring of critical sites using Solarwinds, PRTG & WhatsupGold Application Software.
• NOC management.

Banking Operations Officer (Additional charge of Sr. IT Engineer) at MCB Bank Ltd
  • Pakistan - Karachi
  • July 2004 to January 2007

• Analyze, audit & report financial statements to General Manager.
• Management & monitoring of Financial Information System.
• Evaluation and security of IT process.
• Liaison with IT teams and service provider for rectifying IT issues.
• Backup of branch financial data as per Bank policy.
• Record Management.

Education

Master's degree, Telecom & networks
  • at PAF Karachi Institute of Economics & Technology
  • June 2015

Dons MS in Telecom & Networks with specialization in Information Security and Wireless Communication.

Bachelor's degree, Bachelor of Science in Computer Engineering
  • at Sir Syed University of Engineering and Technology
  • December 2003

Specialties & Skills

ISO 27001
Information Security Management
Internal Audit
Report writing
Information Security & Management [ISO 27001:2005]
Project Management
Databases
Risk identification and assessment
Financial Auditing and Assurance

Languages

English
Expert
Urdu
Expert

Memberships

ISACA, USA
  • Bronze Level Member
  • July 2008
Pakistan Engineering Council
  • Professional
  • April 2004

Training and Certifications

ISO 27001:2005 Lead Auditor (ISMS) (Certificate)
Date Attended:
September 2013
Valid Until:
September 2013

Hobbies

  • Book readings
  • Googling