Muhammad Sajjad Mirza, CISA, CISM, Assistant Director – Internal Audit & Compliance

Muhammad Sajjad Mirza, CISA, CISM

Assistant Director – Internal Audit & Compliance

NADRA Regional HeadOffice

Lieu
Pakistan
Éducation
Master, Telecom & networks
Expérience
19 years, 10 Mois

Partager Mon CV

Empêcher usager


Expériences professionnelles

Total des années d'expérience :19 years, 10 Mois

Assistant Director – Internal Audit & Compliance à NADRA Regional HeadOffice
  • Pakistan - Karachi
  • Je travaille ici depuis mars 2012

• Prepare a comprehensive and flexible audit programme which provides complete audit coverage for the Organization and includes any risks, control, compliance, governance or other concerns identified from relevant sources.
• Partake in actual field work as suitable to ensure quality of work.
• Execute annual audit plan and coordinate with External auditors to avoid unnecessary costs.
• Mentor & supervise audit team for conducting branch office audits across regional office.
• Scrutinize and evaluate financial and information systems, recommending controls to ensure system reliability and data integrity.
• Security reviews & assessments of NADRA IT Infrastructure, Business process & Operations.
• Documented relevant facts & information which support the work performed.
• Prepare detailed audit report on findings with recommendations.
• Any special assignment delegated by Director Internal Audit.
• Build knowledge repository for Best Practices and trends in internal audit.

Information Systems Auditor à NADRA Head Office
  • Pakistan - Islamabad
  • juillet 2009 à février 2012

• Risk based audit Planning & executing IS Audits of IT Infrastructure
(Software, Database, Networks, etc).
• Security reviews & assessments of NADRA IT Infrastructure, Business process & Operations.
• Audit of Oracle ERP Modules (Payroll, Payable, Receivables).
• Mentor technical audit team for conducting branch office technical audits.
• Scrutinize and evaluate financial and information systems, recommending controls to ensure system reliability and data integrity.
• Update Director Internal Audit on audit assignments progress.
• Apply IS audit skills and techniques in testing application software and technology used by NADRA.
• Documented relevant facts & information which support the work performed.
• Prepare detailed audit report on findings with recommendations.
• Any special assignment delegated by Director Internal Audit.
• Build knowledge repository for Best Practices and trends in internal audit.

Sr. Network Analyst à MCB Bank Ltd
  • Pakistan - Karachi
  • janvier 2007 à juillet 2009

• IT centers & service provider management.
• Network designing & deployment.
• Coordinate with regional IT Center for completion of projects within deadline.
• Configuring of Firewall, Router, Switches & prepare critical backup to remote location.
• WAN media deployment, management & closing.
• Design, document, develop and oversee implementation of end-to-end integrated systems.
• Deployment of Core banking projects & integration of advance technologies.
• Configure & Implement Access Control Lists (ACL) on Core Routers & Switches.
• Network monitoring of critical sites using Solarwinds, PRTG & WhatsupGold Application Software.
• NOC management.

Banking Operations Officer (Additional charge of Sr. IT Engineer) à MCB Bank Ltd
  • Pakistan - Karachi
  • juillet 2004 à janvier 2007

• Analyze, audit & report financial statements to General Manager.
• Management & monitoring of Financial Information System.
• Evaluation and security of IT process.
• Liaison with IT teams and service provider for rectifying IT issues.
• Backup of branch financial data as per Bank policy.
• Record Management.

Éducation

Master, Telecom & networks
  • à PAF Karachi Institute of Economics & Technology
  • juin 2015

Dons MS in Telecom & Networks with specialization in Information Security and Wireless Communication.

Baccalauréat, Bachelor of Science in Computer Engineering
  • à Sir Syed University of Engineering and Technology
  • décembre 2003

Specialties & Skills

ISO 27001
Information Security Management
Internal Audit
Report writing
Information Security & Management [ISO 27001:2005]
Project Management
Databases
Risk identification and assessment
Financial Auditing and Assurance

Langues

Anglais
Expert
Urdu
Expert

Adhésions

ISACA, USA
  • Bronze Level Member
  • July 2008
Pakistan Engineering Council
  • Professional
  • April 2004

Formation et Diplômes

ISO 27001:2005 Lead Auditor (ISMS) (Certificat)
Date de la formation:
September 2013
Valide jusqu'à:
September 2013

Loisirs

  • Book readings
  • Googling