Leading IT SOX & control compliance across global operations
Owned IT SOX compliance across Global IT Operations, coordinating multiple teams to ensure IT General Controls were designed, implemented, and operating effectively.
A small selection of case highlights showing how I approach complex, high stakes work: reducing risk, embedding controls, and delivering clarity in demanding technical environments.
Owned IT SOX compliance across Global IT Operations, coordinating multiple teams to ensure IT General Controls were designed, implemented, and operating effectively.
Led the ITGC and Security workstream for a Google Cloud Platform migration, embedding access, change management, and data security controls early rather than retrofitting later.
Subject matter expert across new and legacy systems, integrations, improvements and platform upgrades translating technical risk into clear, actionable information for non specialist stakeholders.
Built a practical understanding of how IT infrastructure, cloud services, software components, and data flows interact and how design and delivery decisions translate directly into operational, security, and compliance risk.
This perspective was developed through formal study in software engineering and reinforced through audit leadership and IT operations compliance work, allowing me to engage credibly with engineers, architects, and delivery teams.
Working alongside Agile delivery teams, adapting assurance and control thinking to fit iterative delivery models rather than forcing traditional, linear governance approaches.
Planned and delivered IT audits that combined financial, technical, and data analytics elements, helping embed analytics into the global internal audit function.
Planned and delivered technology audits that integrated financial, technical, and data analytics, moving the audit approach from sample based testing to risk driven analysis across larger data sets. Worked closely with global technology and business teams to embed analytics into the internal audit methodology, improving visibility of control effectiveness, identifying patterns and outliers, and enabling more targeted, decision useful audit outcomes.
While much of this work sits in large corporate environments, the underlying skills can translate directly to most organisations: clear governance, reliable operations, safeguarding aware thinking, and calm. timely, delivery under pressure.