Sachin Porwal, Group IT Auditor

Sachin Porwal

Group IT Auditor

Al Shirawi group

Lieu
Émirats Arabes Unis - Dubaï
Éducation
Master, MBA, CISA, CISSP, CISM,PMP, ITIL, CEH, ISO 27001
Expérience
24 years, 9 Mois

Partager Mon CV

Empêcher usager


Expériences professionnelles

Total des années d'expérience :24 years, 9 Mois

Group IT Auditor à Al Shirawi group
  • Émirats Arabes Unis - Dubaï
  • Je travaille ici depuis avril 2012

Working as group IT auditor and managing following areas of work

Audit of IT infrastructure
IT Audit of Oracle EBS and other applications
Audit of new IT initiatives
Provide expertise in ISO 27001 and ISO 9001 audit, operation and implementation
Provide inputs and SME opinion on different initiatives, agreements, new development
Highlight key findings on monthly basis in the Audit and IT committee comprising of CEOs, IT Director and Head of Internal Audit and Finance

Consultant - Security, Audit, Governance, Risk and Compliance à IBM
  • Inde - Pune
  • Je travaille ici depuis mars 2010

 Assessment of SOX and SAS 70 controls
 Data Security and Privacy consultant for the project
 Review of user management, change management, incident management, on-off boarding activities and workplace security
 Suggest process improvements and facilitate better understanding on audit requirements
 Prepare detailed work papers to document assessment methodology and results
 Review work papers and documentation /evidences of other assessors and guide them
 Respond to queries from client’s auditors
 Reporting on overall project status and compliance status to senior management
 Ensured applications supported by me had no findings in the external auditors report

Consultant - Audit, Compliance, Security, GRC à Capgemini
  • Inde - Pune
  • janvier 2005 à mars 2010

 Planning of Audits: Decide Focus Areas, Selection of projects and functions, Publishing audit plan, Conducting audit orientation / training
 Execution of Audits: Prepare audit checklist; conduct audits against company defined security policies and procedures, ISO 27001, PCI DSS, ISO 9001, QMS and CMMI
 Review of Project Plan, Process Documents, Risk management, Access Controls, BCM, amongst other things required by PCI DSS and ISO standards for Security Compliance and data privacy
 Audit Findings Closure: Assist teams in effective closure of NCs; Verification of NC closure and review of causal analysis, Corrective and Preventive actions
 Internal Audit Reporting: Tracking of audit findings, Weekly status reports, Findings analysis report, Executive summary report for senior management; Ad hoc reports
 Played instrumental role in refining the audit process by introducing and implementing major changes.
 Involved in SAS 70 initiative: defining control objectives and activities; overview and training sessions; conduct audits; evidence review and tracking
 Undergone SOX audit and pre audit tests for Finance team
 Liaison with External Auditors for smooth conduct and facilitation of external audit
 Part of ISO 27001:2005 (ISMS) implementation team and compliance team
 Involved in Risk assessment specific to ISMS implementation and other audits
 Key role in ensuring timely billing and in turn preventing revenue leakage
 Involved in responding to RFI and proposal
 Worked as a Process Consultant / Quality Lead for IT Team
 Involved in documentation of various processes and setups
 Contributed as Audit Team FAR in successful completion of CMMI Level 5 v1.2
 Conducted training sessions on various areas of work.

Manager à Multi Arc India Ltd
  • Inde - Pimpri
  • novembre 2004 à janvier 2005

ERP point of contact for the company
Reporting
Cash flow management
Team management
Signing authority

Analyst - Compliance à Accenture
  • Inde - Pune
  • septembre 2003 à septembre 2004

 Contract Compliance - Review / Audit of invoices on the basis of contracts
 Prepare analysis reports highlighting issues, Follow up and closure
 Applications used: SAP 4.6d, Brio Query, Excel

Deputy Accountant à Hunter Foods FZCO
  • Émirats Arabes Unis - Dubaï
  • juillet 2002 à décembre 2002

Accounting
Reporting
Managing team
Signing authority

Contractor à Garware Group of Companies
  • Inde - Pune
  • septembre 2001 à juin 2002

Accounting

Trainee à Badani Associates
  • Inde - Pune
  • août 1996 à mai 1999

 Audits and set up of Financial systems with better controls for the clients
 Applications used: Tally, Taxbase, Lotus 123, Word, Excel, Foxpro, Dbase

Éducation

Master, MBA, CISA, CISSP, CISM,PMP, ITIL, CEH, ISO 27001
  • à ISC2
  • mars 2011
Diplôme, CEH - Certified Ethical Hacker
  • à EC Council
  • décembre 2009
Diplôme, PMP - Project Management Professional
  • à PMI
  • mai 2009
Diplôme, Passed CISM exam - Certification not taken purposely
  • à ISACA
  • décembre 2007
Diplôme, ISO 27001
  • à IRCA
  • août 2007
Diplôme, CISA - Certified Information Systems Auditor
  • à ISACA
  • décembre 2006

Rank 2 in Pune Region

Master, MBA / MMS Computers
  • à Pune University
  • janvier 2006
Baccalauréat, PGDBM - Generic
  • à Pune University
  • juin 2004
Master, Commerce
  • à Pune University
  • juin 1999
Baccalauréat, Commerce - Banking, Finance, Computer Applications
  • à Pune University
  • juin 1997

Specialties & Skills

IT Audit
Project Management
Information Security Management
ISO 27001
Microsoft Office
IT Security
Process Compliance
IT Audit

Langues

Anglais
Expert
Marathi
Expert
Hindi
Expert
Français
Débutant

Adhésions

ISACA
  • Board Member Pune, Topic leader USA
  • August 2006
ISC2
  • Member
  • March 2011

Formation et Diplômes

CISSP (Certificat)
Date de la formation:
September 2010
Valide jusqu'à:
September 2010

Loisirs

  • Music
    Certificates in chess, trekking, maths