Results-driven IT technology, cybersecurity, compliance and audit professional with over 20 years of experience enhancing enterprise security, managing risk, and performing audits for Global 500 companies. Certified in CISSP, CCSP, CISA, CRISC, with expertise in NIST and COBIT. Proven track record of improving risk profiles and delivering actionable solutions.
Overview
25
25
years of professional experience
1
1
Certification
Work History
IT Security and Technology Audit & Compliance Consultant
SparrSecure Solutions Inc
07.2014 - Current
Performing Information Security Risk Assessments on new projects and releases for applications, api’s and infrastructure and cloud including compliance requirements.
Provide the required support to management on matters related to information security.
Providing IT Technology & cybersecurity audit services
Senior IT Infrastructure & Cybersecurity Audit Manager
OLG | Ontario Lottery Gaming Corporation
Toronto, Ontario
03.2022 - 07.2024
Contributed to the annual audit plan, planned audit engagements and developed audit programs. Executing audits and ensuring test results were adequately documented. Providing direction for auditors. Assessment of control risks.
Gained a comprehensive understanding of business, application, and infrastructure processes by reviewing interviews, architecture documents, and past audit and regulatory findings, enabling the selection of relevant areas and controls for testing.
Utilized COBIT, NIST and CIS Frameworks.
Ensured audit conclusions and recommendations were properly supported with appropriate documented audit evidence.
Prepared and discussed audit findings with client management; identified significant issues in a business context, working with audit clients to identify and recommend feasible solutions.
Ensured audit reports were clear, concise and supported by the audit work completed.
Audits performed: Infrastructure and Cyber Security internal OLG as well as for 3rd Party Service providers such as Casinos. Led mandatory lottery and gaming audits to attest compliance for the two primary regulators ILC and AGCO.
Identified key risk exposures which led to important improvements in OLG’s risk profile in the following areas: Disaster Recovery, backups, Highly Privileged access , IAM, Security Event monitoring, Servers, workstations and mobiles, Encryption, Privacy, Network segregation, Hardening, Patching, Data Governance and 3rd Party management Cyber controls, API’s, Penetration Testing, Change Management, SDLC, CI/CD pipelines – Azure Dev Ops, IT Policies and standards, Password Policies.
Examples of Platforms audited, Windows, Aix and Linux Servers, A.D., Open VMS system, MS-SQL, Sybase, Oracle, Cisco switches and Firewalls, Q-Radar, Rapid 7, Nessus-Tenable, Azure Cloud Access reviews, Azure Dev Ops, Saas and SOC 11 assessments.
Consistently evaluated evidence submitted by auditees for audit issue closures, advising IT and Security teams on meeting deadlines by conducting early evidence reviews and recommending adjustments as needed to ensure timely resolution.
Led advisory support for IT projects by assessing enterprise controls selected by OLG IT and IT Security, aligning AGCO regulatory self-attestations with COBIT and internal IT Security controls with NIST, delivering targeted enhancements to strengthen the non-audit Compliance department’s internal testing for regulatory requirements while establishing consensus on IT Security’s control framework.
Senior IT Auditor
Stars Group Technologies (Flutter Entertainment)
Richmond Hill, Ontario
04.2020 - 03.2022
Managed domestic/international internal and external audits and compliance activities including SOX, and ARJEL.
Performed Cybersecurity audits of Vulnerability Management, Patching, Pen Testing and hardening, A.V. Identity and Access Management, SDLC and CI/CD pipelines and Cybersecurity standards and policies resulting in key changes to improve Flutter’s risk profile.
Thru interviews, architecture documents obtained, and previous audit and regulatory issues gained adequate understanding of the business, applications and infrastructure processes to select pertinent areas and controls for testing.
Utilized COBIT, NIST and CIS Frameworks.
Ensured audit conclusions and recommendations were properly supported with appropriate documented evidence.
Regularly reviewed and assessed evidence submitted for audit issue closures.
Directed audit advisory efforts for IT projects, including the review and approval of key standards such as the Database Standard, Security Vulnerability Management Framework, Antivirus Policy, Access Management Guidelines, and SDLC-related standards.
Senior IT Security Advisor
Aviva Canada
Markham, Ontario
05.2019 - 11.2019
Performing Information Security Risk Assessments on new projects and releases for applications, api’s and infrastructure changes.
Perform security assessments of Third-Party suppliers.
Privileged Access Management reviews.
Management of the Web Penetration Testing program including management of the contracted 3rd party pen testers.
Promote awareness of Aviva’s Information Security standards and policies.
Rotated in for CAB membership duties to represent IT Security.
Ensure adequate and timely resolutions of audit/review issues. Assist with solutioning when required.
Provide the required support to management on matters related to information security.
IT Infrastructure & Cybersecurity Audit Manager
Scotiabank
Toronto, Ontario
09.2015 - 05.2019
Planned audit engagements, executing test steps, and documenting test results.
Exercised sound professional judgement in the assessment of risks and to conclude whether risks are appropriately managed through the existence of effective controls.
Ensured there was an adequate understanding of the business, application or infrastructure processes being audited.
Followed the Audit Standard Guidelines of the Bank and operations audit methodologies and utilized frameworks including COBIT and NIST.
Ensured audit conclusions and recommendations were properly supported with appropriate documented audit evidence.
Prepared and discussed audit findings with client management; identified significant issues in a business context, working with audit clients to identify and recommend feasible solutions.
Ensured Audit reports were clear, concise and supported by the audit work completed.
Identified key risks which led to important improvements in the Bank's IT risk profile in the following areas: International & Canadian Banking Disaster Recovery, Cybersecurity, Vulnerability Management, Hardening, Patching and Penetration testing, Security Event Monitoring, Highly Privileged Access, Active Directory.
Examples of platforms audited: Windows, Aix and Linux Servers, AS400, MS-SQL, Oracle and Sybase, QRadar and Tripwire IP360.
Regularly reviewed and assessed evidence submitted by auditees for audit issue closures.
Collaborated on a bank-wide initiative to consolidate SOX controls from five distinct business units, previously designed and tested independently by four non-audit teams, unifying the most effective controls into a standardized framework adopted bank-wide and audited by the Audit team.
Senior IT Technical Specialist
Scotiabank
Toronto, Ontario
07.2007 - 09.2015
IIS Web Server and SQL Server DBA and ETL Support for internally developed applications across environments in PROD, Testing and Dev environments.
Programming report module for Bank Capital Management using SQL Stored procedures for tacking and forecasting application.
Troubleshooting performance issues affecting, Server, Web or database settings. Successfully implemented indexing solutions to dramatically increase report query speeds.
Application support for the following 3 software solutions utilized in Finance: INEA (application utilized by the Bank for quarterly reporting), Bancware and SmartStream (accounts payable system). Responsible for day-to-day availability, performance as well as upgrades, testing, patching and vendor management. Level 3 Technical Support of cross - Canadian Bank branch application.
Implemented and supported Disaster Recovery technology such as DoubleTake including database replication and failing over entire application ecosystems for annual disaster recovery testing to meet regulatory requirements.
Senior IT Infrastructure & Application Analyst
DBRS
Toronto, Ontario
07.2006 - 07.2007
Administration of MS SQL and Oracle databases, Citrix, and Windows, Linux and Exchange Servers.
Administration of Active Directory and Access Management.
Application Support and maintenance of Account Payables/Receivables system Infor-SunSystem.
Implemented and supported ERP system running on Linux Red Hat Enterprise and Oracle 10g utilizing JBoss engine.
Senior IT Infrastructure Analyst
Torstar (Metroland)
Mississauga, Ontario
09.2004 - 07.2006
Install, configure and maintain all Citrix servers on Windows Server platform including hardware/OS implementation and support and utilizing Citrix Metaframe XP FR3 to support a 32 Citrix server farm to facilitate over 80 remote sites connecting to the primary Corporate ERP applications PBS and Inca.
Citrix printing support for HP/Lexmark/Xerox. Developed preferred driver lists and alternative mappings.
Responsible for the security patch process with testing and implementation phases.
Ensured backups of Citrix datastores and ongoing readiness for restoring systems from image backups.
2nd and 3rd level support for Citrix end users.
Close co-operation with Development teams to ensure new versions of applications were properly tested and compatible with Citrix.
Active Directory Administration. User management and replicating user changes across domain controllers to resolve issues.
System monitoring for alert thresholds.
IT Infrastructure & Security Manager
Aecon Group Inc.
Toronto, Ontario
01.2000 - 09.2004
Responsible for all network operations including Windows PDC’s, BDC’s WINS, DNS, DHCP, and TCP/IP. Responsible for Cisco router configurations for site connections to Head Office utilizing ISDN and T1 leased lines. Purchased, implemented and managed all networking equipment utilizing 3 Com, Dell, Cisco and Foundry switches and Cisco routers. Procured and managed the Telco’s for the required WAN leased lines. Registered and managed all DNS requirements.
Worked with data cabling firms to assist with installation of cross connected cabling and patch panels when required.
Managed and administered the NG Checkpoint Firewalls ensuring any rule changes followed best practises.
Implemented and supported the Norton Anti-Virus for Exchange and Norton Corporate Edition for all servers and workstations. All updates to virus definitions were centrally managed and monitored for compliance.
Implementation and support of the NG Checkpoint VPN software solution for remote access.
Implemented and managed the Message Labs email filtering solution for corporate email systems.
Logical Access and Highly Privileged account management.
Server updates and security patching.
Responsible for proactive monitoring of all firewalls, server and backup software logs for security violations, errors and failures.
Managed the ethical penetration testing and web application testing process.
Managed all Server hardware and OS purchases, installations and maintenance utilizing Dell Poweredge and IBM Servers.
Responsible for the security and environmental integrity of the server room.
Implemented and managed all backup and recovery technology for the organizations backup and recovery requirements including offsite storage. Utilized DLT’s, 8mm Sony, and a Dell Tape Library as well as Veritas Backup Exec backup software Metaframe.
Responsible for All Citrix Server 1.8 and XP implementations and administration. Provided 2nd level Citrix end user support when required. All remote users connected via Citrix Servers thru the various WAN connected sites throughout Ontario to facilitate access to all applications at Head Office including ERP, project management, email and file server access.
Implementation and support of all enterprise applications which were running on the Microsoft SQL Server platform. This included FOS the corporate ERP system and the Payroll system.
Implemented and supported Exchange Mail Servers at various corporate locations which supported all employee’s mailboxes. Also implemented and supported Blackberry Server and provided 2nd level RIM user support.
Education
Bachelor of Arts -
University of Toronto
MicroComputer Programming - undefined
George Brown College
Certification
Certified Information Systems Security Professional (CISSP), ISC², Active
Certified Cloud Security Professional (CCSP), ISC², Active
Certified Information Systems Auditor (CISA), ISACA, Active
Certified in Risk and Information Systems Control (CRISC), ISACA, Active
Certified in the Governance of Enterprise IT (CGEIT), ISACA, Active
AWS Certified Cloud Practitioner, Amazon Web Services, Active
Linux+, CompTIA, Active
Microsoft Azure Fundamentals, Microsoft, Active
Microsoft Certified Database Administrator (MCDBA), Microsoft, Active
Microsoft Certified Systems Engineer (MCSE), Microsoft, Expired
Timeline
Senior IT Infrastructure & Cybersecurity Audit Manager
OLG | Ontario Lottery Gaming Corporation
03.2022 - 07.2024
Senior IT Auditor
Stars Group Technologies (Flutter Entertainment)
04.2020 - 03.2022
Senior IT Security Advisor
Aviva Canada
05.2019 - 11.2019
IT Infrastructure & Cybersecurity Audit Manager
Scotiabank
09.2015 - 05.2019
IT Security and Technology Audit & Compliance Consultant
Spearheaded cross-functional onboarding initiatives for Assist 365, streamlining access provisioning for global support teams.
Directed migration of Amplify wikis to Engineering Hub, improving content discoverability and compliance.
Resolved escalated incidents in Tier 1, 2, and 3 technical support, enhancing SLA resolution rates by 50%.
Implemented security configurations for Microsoft 365 and Azure AD services, increasing identity security by 40%.
Managed a team of technical writers responsible for developing wiki content for Amplify features.
Facilitated weekly operational syncs and audit readiness activities, encompassing risk assessments, and SLA tracking.
Collaborated with audit teams to achieve successful third-party security audits with zero non-conformities.
Authored knowledge base articles and FAQs, decreasing support ticket volume by 15%. at Tech Mahindra AllyisSpearheaded cross-functional onboarding initiatives for Assist 365, streamlining access provisioning for global support teams.
Directed migration of Amplify wikis to Engineering Hub, improving content discoverability and compliance.
Resolved escalated incidents in Tier 1, 2, and 3 technical support, enhancing SLA resolution rates by 50%.
Implemented security configurations for Microsoft 365 and Azure AD services, increasing identity security by 40%.
Managed a team of technical writers responsible for developing wiki content for Amplify features.
Facilitated weekly operational syncs and audit readiness activities, encompassing risk assessments, and SLA tracking.
Collaborated with audit teams to achieve successful third-party security audits with zero non-conformities.
Authored knowledge base articles and FAQs, decreasing support ticket volume by 15%. at Tech Mahindra Allyis
<ul>
<li>Hours per week: 40.</li>
</ul>
<p><strong>Duties, Accomplishments, and Related Skills:</strong></p>
<ul>
<li>Supervise and coordinate daily administrative workflows for a team of 15 employees, ensuring timely task execution, adherence to protocols, and consistent performance monitoring.</li>
<li>Maintain accurate records and documentation related to property intake, detainee processing, transportation, and deportation; verify and audit files to ensure regulatory compliance, and data integrity.</li>
<li>Execute high-volume data entry (up to 8 hours per day), including the entry of case notes, customs documentation, custody logs, and internal reports into secure federal databases.</li>
<li>Develop, review, and edit administrative reports and forms for internal use and government audits; ensure completeness, accuracy, and policy alignment.</li>
<li>Serve as the primary liaison between facility staff, supervisors, and stakeholders; facilitate clear, professional communication, and documentation flow across departments.</li>
<li>Identified discrepancies in data entries and corrected them accordingly.</li>
<li>Oversee inventory control processes, including the secure receipt, tracking, and storage of personal property, using standardized procedures and government tracking systems.</li>
<li>Conduct routine audits and quality control reviews to ensure that administrative practices meet federal operational standards.</li>
<li>Apply sound judgment to evaluate options, solve problems, and make informed recommendations on administrative and operational matters, contributing to efficient workflow management, and compliance with agency standards.</li>
<li>Assist in developing and revising privacy and security policies concerning Personally Identifiable Information (PII); identify potential compliance risks, and recommend solutions.</li>
<li>Coordinate logistics for detainee transportation to court and medical appointments, manage schedules, and track movement through detailed administrative planning.</li>
<li>Conduct roll calls, and ensure accountability through diligent documentation, system updates, and status reporting.</li>
</ul>
<p>Supervisor: Scott Jackson (949) 456-2706.</p>
<p>Permission to contact: Yes.</p> at ProTech USA LLC, Government Contracting<ul>
<li>Hours per week: 40.</li>
</ul>
<p><strong>Duties, Accomplishments, and Related Skills:</strong></p>
<ul>
<li>Supervise and coordinate daily administrative workflows for a team of 15 employees, ensuring timely task execution, adherence to protocols, and consistent performance monitoring.</li>
<li>Maintain accurate records and documentation related to property intake, detainee processing, transportation, and deportation; verify and audit files to ensure regulatory compliance, and data integrity.</li>
<li>Execute high-volume data entry (up to 8 hours per day), including the entry of case notes, customs documentation, custody logs, and internal reports into secure federal databases.</li>
<li>Develop, review, and edit administrative reports and forms for internal use and government audits; ensure completeness, accuracy, and policy alignment.</li>
<li>Serve as the primary liaison between facility staff, supervisors, and stakeholders; facilitate clear, professional communication, and documentation flow across departments.</li>
<li>Identified discrepancies in data entries and corrected them accordingly.</li>
<li>Oversee inventory control processes, including the secure receipt, tracking, and storage of personal property, using standardized procedures and government tracking systems.</li>
<li>Conduct routine audits and quality control reviews to ensure that administrative practices meet federal operational standards.</li>
<li>Apply sound judgment to evaluate options, solve problems, and make informed recommendations on administrative and operational matters, contributing to efficient workflow management, and compliance with agency standards.</li>
<li>Assist in developing and revising privacy and security policies concerning Personally Identifiable Information (PII); identify potential compliance risks, and recommend solutions.</li>
<li>Coordinate logistics for detainee transportation to court and medical appointments, manage schedules, and track movement through detailed administrative planning.</li>
<li>Conduct roll calls, and ensure accountability through diligent documentation, system updates, and status reporting.</li>
</ul>
<p>Supervisor: Scott Jackson (949) 456-2706.</p>
<p>Permission to contact: Yes.</p> at ProTech USA LLC, Government Contracting
<ul><li>Company Overview: Group Company of PUIG, Spain</li><li>Team Leadership & Process Excellence: Organised the transformation of the Finance & Accounts function, establishing performance-driven goals, and embedding a culture of accountability and continuous improvement. Drove operational efficiency through process redesigns, SOP implementation and optimal resource deployment, leading to measurable improvements in turnaround time and accuracy.</li><li>Strategic Partnering with CXOs: Acted as a key advisor to the CEO, CFO, and other CXOs on business planning, pricing strategies, and business model pivots to support scale-up and profitability. Contributed to investor communications with data-backed insights to enhance stakeholder confidence and secure strategic funding.</li><li>Cross-Functional & Global Stakeholder Management: Functioned as the strategic finance business partner to cross-functional heads and the PUIG global finance team, aligning local execution with global financial strategies and compliance requirements.</li><li>ERP Transformation & System Automation: Led end-to-end ERP reimplementation to address system gaps, enforce role-based controls, and automate core finance processes—resulting in enhanced data accuracy, faster reporting and improved internal controls.</li><li>Costing, Inventory & Profitability Optimization: Designed and implemented plant-level costing models to ensure accurate COGS determination. Improved inventory management across pricing, consumption tracking, and aging analysis—enabling better working capital control and cost efficiency.</li><li>Manufacturing Finance & Statutory Compliance: Supervised end-to-end accounting for manufacturing operations and ensured full statutory compliance.</li><li>Financial Reporting, MIS & Profitability Analytics: Delivered accurate and timely monthly MIS reports, including P&L, Balance Sheet and KPI dashboards with deep-dive variance analysis across stores, business verticals, and geographies. Supported board-level decision-making through insightful presentations on financial health and business performance.</li><li>Budgeting, Forecasting & Business Planning: Led the Annual Operating Plan (AOP) and rolling forecasts, ensuring alignment with strategic objectives and market dynamics. Monitored key financial metrics to enable business decisions and proactive cost management.</li><li>Statutory, Internal & Tax Audit Management: Finalized standalone and consolidated financials under Ind AS and IFRS, ensured timely group reporting and compliance with international standards. Delivered clean and timely closures of statutory, tax, and internal audits in coordination with Big 4 auditors. Strengthened audit readiness through pre-audit diagnostics and rectification of recurring control gaps.</li><li>Regulatory Compliance & Risk Management: Ensured end-to-end compliance which includes ROC, RBI, FEMA, Income Tax, GST, Transfer Pricing, DTAA, and Customs. Reviewed cross-border contracts and transactions to ensure arm’s length pricing, accurate TDS application, and proper documentation under Transfer Pricing regulations.</li><li>Commercial Negotiation & Contract Governance: Led commercial negotiations and structured deals with vendors and franchisees. Reviewed key business contracts to ensure financial viability, risk protection, and compliance with regulatory standards.</li><li>Treasury & External Commercial Borrowing (ECB): Managed fund planning and liquidity management including ECB drawdowns, bank negotiations, and interest optimization. Improved working capital cycles through proactive cash flow forecasting and receivables control.</li><li>Internal Controls & Governance Framework: Led organization-wide reviews of internal control systems, identified process gaps, and redesigned or implemented over 40 SOPs and IFCs. Established a governance structure for financial discipline, risk mitigation, and policy compliance across departments.</li></ul> at Kama Ayurveda Pvt. Ltd. & PUIG India Pvt. Ltd.<ul><li>Company Overview: Group Company of PUIG, Spain</li><li>Team Leadership & Process Excellence: Organised the transformation of the Finance & Accounts function, establishing performance-driven goals, and embedding a culture of accountability and continuous improvement. Drove operational efficiency through process redesigns, SOP implementation and optimal resource deployment, leading to measurable improvements in turnaround time and accuracy.</li><li>Strategic Partnering with CXOs: Acted as a key advisor to the CEO, CFO, and other CXOs on business planning, pricing strategies, and business model pivots to support scale-up and profitability. Contributed to investor communications with data-backed insights to enhance stakeholder confidence and secure strategic funding.</li><li>Cross-Functional & Global Stakeholder Management: Functioned as the strategic finance business partner to cross-functional heads and the PUIG global finance team, aligning local execution with global financial strategies and compliance requirements.</li><li>ERP Transformation & System Automation: Led end-to-end ERP reimplementation to address system gaps, enforce role-based controls, and automate core finance processes—resulting in enhanced data accuracy, faster reporting and improved internal controls.</li><li>Costing, Inventory & Profitability Optimization: Designed and implemented plant-level costing models to ensure accurate COGS determination. Improved inventory management across pricing, consumption tracking, and aging analysis—enabling better working capital control and cost efficiency.</li><li>Manufacturing Finance & Statutory Compliance: Supervised end-to-end accounting for manufacturing operations and ensured full statutory compliance.</li><li>Financial Reporting, MIS & Profitability Analytics: Delivered accurate and timely monthly MIS reports, including P&L, Balance Sheet and KPI dashboards with deep-dive variance analysis across stores, business verticals, and geographies. Supported board-level decision-making through insightful presentations on financial health and business performance.</li><li>Budgeting, Forecasting & Business Planning: Led the Annual Operating Plan (AOP) and rolling forecasts, ensuring alignment with strategic objectives and market dynamics. Monitored key financial metrics to enable business decisions and proactive cost management.</li><li>Statutory, Internal & Tax Audit Management: Finalized standalone and consolidated financials under Ind AS and IFRS, ensured timely group reporting and compliance with international standards. Delivered clean and timely closures of statutory, tax, and internal audits in coordination with Big 4 auditors. Strengthened audit readiness through pre-audit diagnostics and rectification of recurring control gaps.</li><li>Regulatory Compliance & Risk Management: Ensured end-to-end compliance which includes ROC, RBI, FEMA, Income Tax, GST, Transfer Pricing, DTAA, and Customs. Reviewed cross-border contracts and transactions to ensure arm’s length pricing, accurate TDS application, and proper documentation under Transfer Pricing regulations.</li><li>Commercial Negotiation & Contract Governance: Led commercial negotiations and structured deals with vendors and franchisees. Reviewed key business contracts to ensure financial viability, risk protection, and compliance with regulatory standards.</li><li>Treasury & External Commercial Borrowing (ECB): Managed fund planning and liquidity management including ECB drawdowns, bank negotiations, and interest optimization. Improved working capital cycles through proactive cash flow forecasting and receivables control.</li><li>Internal Controls & Governance Framework: Led organization-wide reviews of internal control systems, identified process gaps, and redesigned or implemented over 40 SOPs and IFCs. Established a governance structure for financial discipline, risk mitigation, and policy compliance across departments.</li></ul> at Kama Ayurveda Pvt. Ltd. & PUIG India Pvt. Ltd.