Muhammad Sajjad Mirza, CISA, CISM, Assistant Director – Internal Audit & Compliance

Muhammad Sajjad Mirza, CISA, CISM

Assistant Director – Internal Audit & Compliance

NADRA Regional HeadOffice

البلد
باكستان
التعليم
ماجستير, Telecom & networks
الخبرات
19 years, 10 أشهر

مشاركة سيرتي الذاتية

حظر المستخدم


الخبرة العملية

مجموع سنوات الخبرة :19 years, 10 أشهر

Assistant Director – Internal Audit & Compliance في NADRA Regional HeadOffice
  • باكستان - كراتشي
  • أشغل هذه الوظيفة منذ مارس 2012

• Prepare a comprehensive and flexible audit programme which provides complete audit coverage for the Organization and includes any risks, control, compliance, governance or other concerns identified from relevant sources.
• Partake in actual field work as suitable to ensure quality of work.
• Execute annual audit plan and coordinate with External auditors to avoid unnecessary costs.
• Mentor & supervise audit team for conducting branch office audits across regional office.
• Scrutinize and evaluate financial and information systems, recommending controls to ensure system reliability and data integrity.
• Security reviews & assessments of NADRA IT Infrastructure, Business process & Operations.
• Documented relevant facts & information which support the work performed.
• Prepare detailed audit report on findings with recommendations.
• Any special assignment delegated by Director Internal Audit.
• Build knowledge repository for Best Practices and trends in internal audit.

Information Systems Auditor في NADRA Head Office
  • باكستان - إسلام أباد
  • يوليو 2009 إلى فبراير 2012

• Risk based audit Planning & executing IS Audits of IT Infrastructure
(Software, Database, Networks, etc).
• Security reviews & assessments of NADRA IT Infrastructure, Business process & Operations.
• Audit of Oracle ERP Modules (Payroll, Payable, Receivables).
• Mentor technical audit team for conducting branch office technical audits.
• Scrutinize and evaluate financial and information systems, recommending controls to ensure system reliability and data integrity.
• Update Director Internal Audit on audit assignments progress.
• Apply IS audit skills and techniques in testing application software and technology used by NADRA.
• Documented relevant facts & information which support the work performed.
• Prepare detailed audit report on findings with recommendations.
• Any special assignment delegated by Director Internal Audit.
• Build knowledge repository for Best Practices and trends in internal audit.

Sr. Network Analyst في MCB Bank Ltd
  • باكستان - كراتشي
  • يناير 2007 إلى يوليو 2009

• IT centers & service provider management.
• Network designing & deployment.
• Coordinate with regional IT Center for completion of projects within deadline.
• Configuring of Firewall, Router, Switches & prepare critical backup to remote location.
• WAN media deployment, management & closing.
• Design, document, develop and oversee implementation of end-to-end integrated systems.
• Deployment of Core banking projects & integration of advance technologies.
• Configure & Implement Access Control Lists (ACL) on Core Routers & Switches.
• Network monitoring of critical sites using Solarwinds, PRTG & WhatsupGold Application Software.
• NOC management.

Banking Operations Officer (Additional charge of Sr. IT Engineer) في MCB Bank Ltd
  • باكستان - كراتشي
  • يوليو 2004 إلى يناير 2007

• Analyze, audit & report financial statements to General Manager.
• Management & monitoring of Financial Information System.
• Evaluation and security of IT process.
• Liaison with IT teams and service provider for rectifying IT issues.
• Backup of branch financial data as per Bank policy.
• Record Management.

الخلفية التعليمية

ماجستير, Telecom & networks
  • في PAF Karachi Institute of Economics & Technology
  • يونيو 2015

Dons MS in Telecom & Networks with specialization in Information Security and Wireless Communication.

بكالوريوس, Bachelor of Science in Computer Engineering
  • في Sir Syed University of Engineering and Technology
  • ديسمبر 2003

Specialties & Skills

ISO 27001
Information Security Management
Internal Audit
Report writing
Information Security & Management [ISO 27001:2005]
Project Management
Databases
Risk identification and assessment
Financial Auditing and Assurance

اللغات

الانجليزية
متمرّس
الأوردو
متمرّس

العضويات

ISACA, USA
  • Bronze Level Member
  • July 2008
Pakistan Engineering Council
  • Professional
  • April 2004

التدريب و الشهادات

ISO 27001:2005 Lead Auditor (ISMS) (الشهادة)
تاريخ الدورة:
September 2013
صالحة لغاية:
September 2013

الهوايات

  • Book readings
  • Googling