Shravan Bhutada, Audit Portfolio Manager

Shravan Bhutada

Audit Portfolio Manager

Petrofac

Location
United Arab Emirates
Education
Diploma, CRISC
Experience
19 years, 4 Months

Share My Profile

Block User


Work Experience

Total years of experience :19 years, 4 Months

Audit Portfolio Manager at Petrofac
  • United Arab Emirates - Sharjah
  • My current job since June 2016

Audit Portfolio Manager
Petrofac, Sharjah, UAE
June 2016 - Present
Job Profile:
Lead a portfolio of audits identified at the beginning of the year. accountable for planning, delivery (Scoping, Planning, Execution, Reporting and Closure) monitoring and reporting to the CAE.
responsible for uploading the Findings to the database of Findings and assigning the relevant owner for each finding.
Responsible for delivering the assigned audit work in line with INA methodology with minimal supervision and providing direct support and where appropriate coaching to the Audit Lead and other team members.
Responsible for developing the Annual IT Audit Programme by identifying risk based audits in areas of expertise/business.
Verifying completion of Agreed Management Actions for Findings.
Support quarterly reporting to Management and the Board (e.g. ExCom and the Audit Committee). This includes updating data, writing sections of reports, developing insights and themes.
Adequately analyzing and documenting all information systems and related controls, and developing an appropriate audit program to test the controls identified.
Preparing draft audit reports in good form, with recommendations, appraisals, or analyses that will assist the key auditees discharge of his or her responsibilities.
Evaluating the adequacy of the security and processing controls as they relate to each audit, and the effectiveness of general computer controls in effect in the IT environment.
Monitoring the project status of new systems development, disaster recovery testing, and the organization's business continuity plan, and other activities related to IT processing.
Reviewing the reliability and integrity of the financial and operating information and the means used to identify, measure, classify, and report such information.
Reviewing the means of safeguarding information assets and monitoring of ongoing performance metrics established by the IT and Security Departments
Appraising the economy and efficiency of how resources are employed.
Reviewing operations and programs to determine if results are consistent with department goals and objectives.
Preparing audit workpapers according to established department guidelines and industry standards.
Providing assistance and guidance to the outside SME auditors to insure a timely and efficient completion of the audit.
Providing assistance to the Head of Internal Audit and the other Senior Audit Manager on special projects and assignments.
Presenting audit findings or other relevant information to Senior Management and/or the Audit Committee on the effectiveness and adequacy of risk management, governance, and internal control procedures.
Developing and maintaining effective interpersonal relationships with IT, business and management

Sr Manager Technology Risk at 3i Infotech
  • United Arab Emirates - Abu Dhabi
  • June 2012 to December 2015

Responsible for Technology and vendor evaluation and assessments and timely closure of all issues identified
Responsible for Quarterly Data Center and IT process audits as part of ISO27001 Audit preparations.
Responsible for development and management of the Archer eGRC application modules and templates.
Applying regular content update and upgrades to latest versions of Archer eGRC
End-user awareness / Training in Information security.
Responsible for Policy, Standards and Baseline updates and reviews.
Providing support and assist in internal and external ISO27001 surveillance audits
Advising CISO on information security technologies and related regulatory issues

Achievements:
Awarded best performer award for my continuous efforts and process improvements
Received SISA Champion award for excellent performance during the CPISI workshop and awarded CPISI certificate

Manager IT Risk and Internal controls at Bank Of America
  • India - Hyderabad
  • October 2010 to June 2012

Identify areas of risk; Assess control environment, Key Risk indicators and the Change control mechanism for assigned processes or functions of the company
• Work with various internal departments and become familiar with the overall businesses strategy to effectively execute each risk & control program.
• Assisting internal clients in implementing and deploying an operational risk strategy, including services such as: operational risk governance/ framework development, risk and control self assessments, key risk indicators.
• Conduct risk based assessments on ITS (Software Development, Production Support, Database Admin, System Admin, Information Security Admin, Testing, QA) processes in order to better determine areas of focus for internal controls.
• Evaluating the design effectiveness of internal control processes for ITS processes.
• Assist in creating governance standards and necessary tools required to support requirements.
• Developing, implementing and monitoring compliance.
• Support day to day management of relationships and communications with business partners at various levels of the organization, as well as other internal and external resources.
• Travel in company locations in India for achieving above stated objectives.
• To work in a six sigma controlled and process oriented environment

Asst Mgr Information Security Risk, BIRO at HSBC
  • India - Hyderabad
  • August 2004 to October 2010

Promoted as part of Step-up Role from Assistant Manager - IT Security (technical) to Assistant Manager Operation - IT Security owing to excellent procedural knowledge and experience in handling various difficult issues and people.
• Managing 10 Assistant Managers - IT Security(Technical) report to me as Directs and functionally another 4 for day to day process related tasks and issues.
• Handling additional responsibility of Lead Business Information Risk Officer (BIRO).
• Prepared Action Plan and coach analysts effectively.
• Contributed to Quality initiatives and ensure team performance is in sync with process goals.
• Performed random audits of team Internet and emails usage on regular basis.
• Performed AM Stack Ranking and monthly Reviews.
• Facilitated new tasks migration for all the process reporting under me.
• Proactively contributed to process documentation, transition, training and implementation for new task migration.
• Ensured effective cross training of staff by designing training plans and implementation.
• Ensured sharing of best practices is done on regular basis by conducting tech forum every Friday, motivate all staff participate and share information.
• Ensured all monthly metrics for the process are delivered on time by delegating tasks and checked for accuracy and completeness within deadlines.
• Recent Audit and Compliance review done for the process resulted in satisfactory ratings.
• Developed and maintained good rapport with Directs, peers group, management and business partners.

Education

Diploma, CRISC
  • at ISACA
  • March 2015
Diploma, certified information security manager (CISM)
  • at ISACA
  • December 2013
Diploma, ECSA
  • at EC Council
  • August 2013

EC Council Certified Security Analyst

Diploma, CISSP
  • at ISC2
  • June 2013

Certified Information System Security Professional

Diploma, ISO 27001 ISMS Lead Auditor
  • at IRCA
  • April 2011
Diploma, Certified Information Systems Auditor (CISA)
  • at ISACA
  • March 2010
Diploma, Certified Ethical hacker (CEH)
  • at EC Council
  • March 2009
Diploma, Information technology
  • at Symbiosis center for Distance Learning
  • May 2007
Master's degree, Theatre Arts
  • at Hyderabad Central University
  • May 2002

Specialties & Skills

Internal Controls
Compliance Review
Data Center
Policy Review
Risk Assessment
Risk Management
Threat Management
Incident Management
Compliance Management

Languages

English
Expert
Hindi
Expert
Urdu
Intermediate
Telugu
Expert

Memberships

ISACA
  • CISA
  • August 2009
EC Council
  • CEH
  • February 2009
EXIN
  • ITIL Foundation
  • March 2009
IRCA
  • ISO 27001 ISMS LA
  • April 2011
ISC2
  • Member
  • May 2013

Training and Certifications

ECSA (Certificate)
Date Attended:
April 2013
CISSP (Certificate)
Date Attended:
August 2013
CISM (Certificate)
Date Attended:
March 2014
CRISC (Certificate)
Date Attended:
March 2015
CEH (Certificate)
Date Attended:
April 2010
CISA (Certificate)
Date Attended:
March 2009
Certified PaymentCard Industry Security Implementor (CPISI) (Certificate)
Date Attended:
January 2013
Valid Until:
January 2013