•
Conducting risk assessments and developing risk-based audit plans
•
Developing risk management strategies and plans
•
Conducted comprehensive Data Protection Impact Assessments (DPIAs) for new and existing projects to identify risks and enforce mitigation strategies
•
Developed, reviewed, and updated data privacy policies, standards, and procedures to address evolving regulatory requirements
•
Designed and implemented cross-border data transfer mechanisms, ensuring compliance with legal frameworks such as SCCs (Standard Contractual Clauses)
•
Prepared detailed audit reports highlighting areas for improvement and implemented corrective action plans for non-compliance
•
Assessed and managed third-party vendor compliance with data protection standards by reviewing contracts, DPAs (Data Processing Agreements), and security protocols
•
Designed and delivered data protection training programs to employees, raising awareness on handling personal data, data breaches, and privacy risks
•
Established and maintained data breach response protocols, ensuring timely reporting to regulators and mitigating impact on data subjects
•
Investigated and resolved data breaches while providing regulatory-compliant notifications and documentation
•
Designing and implementing internal control frameworks to mitigate risks
•
Leading or participating in investigations of potential fraud, noncompliance or unethical behavior
•
Evaluating the effectiveness of existing controls and recommending improvements
•
Communicating risk management issues and recommendations to senior management
•
Developing and implementing internal audit policies, procedures, and methodologies
•
Conducting internal audits to assess the effectiveness of internal controls, risk management processes, and governance procedures
•
Identifying control gaps and making recommendations to improve processes and controls
•
Evaluating and reporting on the adequacy of management responses to identified risks and control deficiencies
•
Communicating audit results and recommendations to senior management and the board of directors
•
Assisting in the development and implementation of enterprise risk management frameworks and methodologies
•
Providing guidance and training to business units on risk management and control best practices
•
Staying up to date on emerging risks and regulatory requirements that may impact the organization
•
Prepare process documents in relation to Security Incident Management
•
Performed testing of ITGC on multiple strategically important engagements for Internal Audit
•
Advise client on establishing or improving end- end risk management systems, processes, and frameworks to enhance strategic alignment with business goals, enable effective decision making and response, and monitor regulatory compliance
•
Performing IT internal compliance audit involving investigating and checking internal processes and procedures for clients
•
Preparation and implementation of access control policy, database management policy, DLP email Policy, Asset Management, Operational Security Policy, Third Party Policy
•
Risk Control Mapping in domains: Logical Security, Physical Security, Change Management, Problem Management
•
Assessment of information system control, information privacy and integrity
•
To advice the management in developing sound information system audit, control and security functions by providing criteria for development