Highly motivated Risk Management professional with more than 13 yrs. of Governance, Risk and Compliance (GRC), Product Management as well as Project Management experience in a large scale, global financial services organization Subject Matter Expert in Compliance / AML Risk Management, Operational Risk Management, Risk Systems Processes, Project Management, Business Strategy, Governance, Risk and Compliance (GRC) Frameworks Strong analytical and communication skills with organized ability to multi-task and meet project deadlines
Energetic self-starter with excellent team development, conflict resolution and negotiation skills
Overview
22
22
years of professional experience
Work History
Business Analyst
One80 Intermediaries
05.2015 - Current
Designed the end to end enterprise wide Vendor Risk Management process and Prevalent Vendor Risk Management vendor tool for execution of this process.
Designed the end to end enterprise wide ITGRC process and the Metric Stream vendor tool for execution of this process.
Demonstrated leadership skills and the ability to engage with all management levels of IT Security as well as the other groups across the organization such as Legal, Procurement and the business for socialization and adoption of these processes within the organization
Managed the entire SDLC for the GRC and the VRM tools including gathering product requirements, development guidance, UAT, Training and Go-Live
Managed effective vendor relationships, negotiated and implemented new projects to expand scope of engagement.
Gained in-depth understanding of Emblem Health's products and services as well as knowledge of the various aspects of Risk Management including but not limited to IT Security Risk and Vendor Risk.
Senior Vice President
Acosta, Inc.
09.2012 - 04.2015
Managed planning to execution of the key Compliance and Federal Consent order projects such as enhancement of the Enterprise Wide AML and Compliance Risk Assessments (including the Anti-Bribery & Corruption and OFAC/Sanctions Risk Assessments) and design of the New Product Approval (NPA) process and system across Citi's multiple regions, products, and risk disciplines.
Project Office Lead for building and performing global roll out of an automated and workflow based New Product Approval (NPA) System aligned to the objectives of Citi's Global Compliance/AML organization
Defined opportunities to utilize metrics to quantify AML risk across various products and geographies in collaboration with the Global Compliance Metrics teams
Demonstrated leadership skills and the ability to engage with all management levels of Global Compliance Risk Management, Risk System & Technology as well as the business during all phases of the projects
Delivered results to the senior management and led / engage compliance advisory members in discussion regarding business impact and plans to address areas of concern
Conducted interviews with Citi's senior leadership and business users to collect information on compliance business processes and user requirements in order to enhance the existing Risk Management tools and technologies.
Performed vendor selection and cost and benefit analysis for the launch of the automated global compliance Risk Management tool
Managed internal product assurance testing cycles, including test plan creation and led co-ordination of user acceptance testing (UAT) for more than 100 users concurrently
Demonstrated strong risk and issue identification and creative practical problem solving techniques.
Business Consultant - Citi
Vistra
01.2009 - 09.2012
Designed and launched the global roll out of the enterprise wide Managers Control Assessment (MCA) tool to measure and manage organization's operational risk across global processes, risks and controls Working Group lead for design, development and enhancement of the globally implemented Risk and Control Self-Assessment Product (Catalyst RCSA) and the Regulatory Control Matrix (RCM) systems aligned with the Strategic Objectives for the organization Supervised product technology teams by reviewing the product functional requirements, providing direction, establishing goals and projecting outcomes for product implementation and addressing business risk challenges Created and maintained an extensive database of the product enhancements requested by the global businesses and communicated results with recommendations to senior management Designed the strategic roadmap for compliance and control systems integration by performing an in-depth analysis of the in-house organizational risk management tools in order to save millions of dollars to the organization.
Senior Consultant
One80 Intermediaries
08.2004 - 08.2008
Engaged with the Deloitte senior and executive management for developing and enhancing industry specific GRC frameworks, information security architecture used for executive panel discussions including global financial institutions Developed multimillion dollar client IT risk assessment proposals, evaluation of existing business strategies, future risk roadmaps recommending IT risk mitigating and implementation of solutions within areas of governance, data privacy and protection, data loss prevention, program management, risk management, risk reporting and operations management
Designed a comprehensive Information Security program framework consisting of more than 48 Information Security IS) domains to evaluate an organization's current security posture in relation to industry best practices
Developed a Data Protection and Data Loss Prevention Overview Strategy to help protect, control and audit sensitive data and its usage
Conducted global knowledge transfer sessions via online training, workshops and webinars to conduct walk through for the application feeds integration process flow and methods of performing the semi -annual entitlement reviews Managed current state of Developers Access to Production (DAP) and its development lifecycle (SDLC) to identify common compliance issues, defining compensating control enhancements and requirements for DAP automation tools Demonstrated advanced business writing skills by developing documentation such as "Program Charters", "Project Plans", Statement of Work", "Project Financials", "Process Control Manuals", "Risk Matrices", "Narratives for technology platforms", "Global Entitlement Management Standards", "Application Integration Guidelines", "Business Requirement Documentation (BRD's)", "Functional Requirement Documentation (FRD's)", "Policy Assessment Guidelines", "Executive Presentations for High Level Program Overview", "Executive Roadmaps", "Information Security Frameworks", "Global Training Materials and Guidelines for Project Managers" and many others during the course of each client project initiative.
Business Analyst
One80 Intermediaries
04.2004 - 08.2004
Performed annual wireless network security risk assessments to assess business risks and therefore develop a secure and efficient wireless network topology.
Performed detailed vendor cost-benefit analysis to support and enhance the existing wireless security framework for the organization.
Business Analyst
AT&T Professional Services
09.2002 - 04.2004
Developed, produced and enhanced risk reports for all business units. Performed a detailed review of the network infrastructure including local, long distance, DSL, ATM, frame relay and perform LAN/ WAN security assessments large financial service organizations