Risk & Assurance
IT audit & controls assurance, SOX and ITGC governance, cloud risk and controls, operational resilience, risk management, programme assurance, governance and compliance coordination.
Technology Risk and Operations professional with over ten years' experience across Big 4 consulting, global organisations, and independent business operations. I specialise in IT governance, ITGC, SOX, systems implementation support, cloud risk and controls, and operational resilience, with a practical focus on embedding control into complex service operations. I am especially interested in mission-led organisations, education, and roles where strong governance supports meaningful social impact.
IT audit & controls assurance, SOX and ITGC governance, cloud risk and controls, operational resilience, risk management, programme assurance, governance and compliance coordination.
Multi workstream organisation, documentation quality, stakeholder engagement, reporting, team leadership and coaching.
Operating and managing a consultancy and gaming services business delivering systems implementation support, IT controls and governance advisory, digital operations, facilitation, and client-facing gaming services.
Supporting implementation of a new payroll and HR system within an independent school environment, while providing advisory input on IT controls, governance, and ISO review activity.
Accountable for global IT SOX governance across Vodafone's IT Operations estate, overseeing control design, operating effectiveness, remediation strategy, and executive reporting across multi-region environments.
Led ITGC and Security control oversight for a large scale Google Cloud Platform migration, embedding cloud aligned access, change, and data controls globally and establishing control-by-design principles across DevSecOps and platform engineering teams.
Oversaw multiple concurrent transformation workstreams, ensuring controls were embedded early and remained aligned with regulatory and operational requirements, while supporting assurance strategy and regulatory readiness as an SME across IT governance.
Led delivery of IT audit engagements across financial, operational, and technology domains within a global FMCG environment.
Introduced data analytics into audit testing, increasing coverage and enabling deeper insight into control performance and risk areas; assessed IT, security, and data controls against COBIT, ISO27001, and NIST frameworks.
Managed end to end delivery of technology risk and IT assurance engagements across multiple clients, including planning, scoping, budgeting, and execution.
Led IT audit and digital risk assignments, coordinated cross border delivery across multi location teams, and delivered programme risk management and security review work for transformation initiatives.
Analysed and managed large volumes of global client and operational data, improving reporting quality and supporting business decision making.
Developed IT processes and IT service management practices; delivered training and team management; led system and data update programmes; implemented governance and lifecycle processes for reservations and controlled system usage.
Tailor-made travel consulting and account management, supplier negotiation, and client relations across multiple roles.
Unit and multi site management with staffing, training, P&L responsibility, and delivery during operational change.
MSc — Software Engineering (Oxford Brookes University, 2016)
BSc — Mathematics and Statistics (London Metropolitan University, 2015)
CISA (ISACA, 2018) · CFAB (ICAEW, 2017) · PRINCE2 (2015)
TQUK Level 3 Award in Supporting Teaching and Learning in Schools (2025)
I support community organisations through volunteering, including schools and local support services.
ITGC & SOX, technology risk management, IT audit & assurance, GRC, cloud risk & controls, COBIT / ISO27001 / NIST, risk assessment & control testing, DevSecOps controls, technology transformation assurance, third-party risk, and data analytics.
Stakeholder engagement, risk, audit and delivery teams, risk based decision making, operational resilience, governance and assurance, cross functional communication, and pragmatic leadership in complex, regulated environments.