ساشين برول, Group IT Auditor

ساشين برول

Group IT Auditor

Al Shirawi group

البلد
الإمارات العربية المتحدة - دبي
التعليم
ماجستير, MBA, CISA, CISSP, CISM,PMP, ITIL, CEH, ISO 27001
الخبرات
24 years, 9 أشهر

مشاركة سيرتي الذاتية

حظر المستخدم


الخبرة العملية

مجموع سنوات الخبرة :24 years, 9 أشهر

Group IT Auditor في Al Shirawi group
  • الإمارات العربية المتحدة - دبي
  • أشغل هذه الوظيفة منذ أبريل 2012

Working as group IT auditor and managing following areas of work

Audit of IT infrastructure
IT Audit of Oracle EBS and other applications
Audit of new IT initiatives
Provide expertise in ISO 27001 and ISO 9001 audit, operation and implementation
Provide inputs and SME opinion on different initiatives, agreements, new development
Highlight key findings on monthly basis in the Audit and IT committee comprising of CEOs, IT Director and Head of Internal Audit and Finance

Consultant - Security, Audit, Governance, Risk and Compliance في IBM
  • الهند - بونة
  • أشغل هذه الوظيفة منذ مارس 2010

 Assessment of SOX and SAS 70 controls
 Data Security and Privacy consultant for the project
 Review of user management, change management, incident management, on-off boarding activities and workplace security
 Suggest process improvements and facilitate better understanding on audit requirements
 Prepare detailed work papers to document assessment methodology and results
 Review work papers and documentation /evidences of other assessors and guide them
 Respond to queries from client’s auditors
 Reporting on overall project status and compliance status to senior management
 Ensured applications supported by me had no findings in the external auditors report

Consultant - Audit, Compliance, Security, GRC في Capgemini
  • الهند - بونة
  • يناير 2005 إلى مارس 2010

 Planning of Audits: Decide Focus Areas, Selection of projects and functions, Publishing audit plan, Conducting audit orientation / training
 Execution of Audits: Prepare audit checklist; conduct audits against company defined security policies and procedures, ISO 27001, PCI DSS, ISO 9001, QMS and CMMI
 Review of Project Plan, Process Documents, Risk management, Access Controls, BCM, amongst other things required by PCI DSS and ISO standards for Security Compliance and data privacy
 Audit Findings Closure: Assist teams in effective closure of NCs; Verification of NC closure and review of causal analysis, Corrective and Preventive actions
 Internal Audit Reporting: Tracking of audit findings, Weekly status reports, Findings analysis report, Executive summary report for senior management; Ad hoc reports
 Played instrumental role in refining the audit process by introducing and implementing major changes.
 Involved in SAS 70 initiative: defining control objectives and activities; overview and training sessions; conduct audits; evidence review and tracking
 Undergone SOX audit and pre audit tests for Finance team
 Liaison with External Auditors for smooth conduct and facilitation of external audit
 Part of ISO 27001:2005 (ISMS) implementation team and compliance team
 Involved in Risk assessment specific to ISMS implementation and other audits
 Key role in ensuring timely billing and in turn preventing revenue leakage
 Involved in responding to RFI and proposal
 Worked as a Process Consultant / Quality Lead for IT Team
 Involved in documentation of various processes and setups
 Contributed as Audit Team FAR in successful completion of CMMI Level 5 v1.2
 Conducted training sessions on various areas of work.

Manager في Multi Arc India Ltd
  • الهند - بيمبري
  • نوفمبر 2004 إلى يناير 2005

ERP point of contact for the company
Reporting
Cash flow management
Team management
Signing authority

Analyst - Compliance في Accenture
  • الهند - بونة
  • سبتمبر 2003 إلى سبتمبر 2004

 Contract Compliance - Review / Audit of invoices on the basis of contracts
 Prepare analysis reports highlighting issues, Follow up and closure
 Applications used: SAP 4.6d, Brio Query, Excel

Deputy Accountant في Hunter Foods FZCO
  • الإمارات العربية المتحدة - دبي
  • يوليو 2002 إلى ديسمبر 2002

Accounting
Reporting
Managing team
Signing authority

Contractor في Garware Group of Companies
  • الهند - بونة
  • سبتمبر 2001 إلى يونيو 2002

Accounting

Trainee في Badani Associates
  • الهند - بونة
  • أغسطس 1996 إلى مايو 1999

 Audits and set up of Financial systems with better controls for the clients
 Applications used: Tally, Taxbase, Lotus 123, Word, Excel, Foxpro, Dbase

الخلفية التعليمية

ماجستير, MBA, CISA, CISSP, CISM,PMP, ITIL, CEH, ISO 27001
  • في ISC2
  • مارس 2011
دبلوم, CEH - Certified Ethical Hacker
  • في EC Council
  • ديسمبر 2009
دبلوم, PMP - Project Management Professional
  • في PMI
  • مايو 2009
دبلوم, Passed CISM exam - Certification not taken purposely
  • في ISACA
  • ديسمبر 2007
دبلوم, ISO 27001
  • في IRCA
  • أغسطس 2007
دبلوم, CISA - Certified Information Systems Auditor
  • في ISACA
  • ديسمبر 2006

Rank 2 in Pune Region

ماجستير, MBA / MMS Computers
  • في Pune University
  • يناير 2006
بكالوريوس, PGDBM - Generic
  • في Pune University
  • يونيو 2004
ماجستير, Commerce
  • في Pune University
  • يونيو 1999
بكالوريوس, Commerce - Banking, Finance, Computer Applications
  • في Pune University
  • يونيو 1997

Specialties & Skills

IT Audit
Project Management
Information Security Management
ISO 27001
Microsoft Office
IT Security
Process Compliance
IT Audit

اللغات

الانجليزية
متمرّس
المراتي
متمرّس
الهندية
متمرّس
الفرنسية
مبتدئ

العضويات

ISACA
  • Board Member Pune, Topic leader USA
  • August 2006
ISC2
  • Member
  • March 2011

التدريب و الشهادات

CISSP (الشهادة)
تاريخ الدورة:
September 2010
صالحة لغاية:
September 2010

الهوايات

  • Music
    Certificates in chess, trekking, maths