Experience
Resume
Experience
Jan 2025 - Present
IT Audit Senior
Schellman · Columbus, Ohio
- Cut audit preparation time 25% in six months by redesigning the sampling process for a large enterprise client.
- Identify and document control deficiencies across 10+ SOC examinations a year, then partner with control owners to build and execute remediation plans.
- Lead control walkthroughs with engineering, IT operations, internal audit, and HR stakeholders to scope and validate evidence across the control environment.
- Map client control sets to SOC 2, ISO 27001, and HIPAA requirements to rationalize overlapping controls and cut repeat findings year over year.
- Guide first-time clients through their initial SOC 2 examination, mapping existing controls to the Trust Services Criteria to identify where controls currently operate and where coverage is thin.
- Mentor 3+ associate auditors on AICPA guidance and audit methodology, reviewing their workpapers and testing approach.
Jul 2023 - Dec 2024
IT Audit Associate
Schellman · Columbus, Ohio
- Tested controls across 15+ SOC 1 and SOC 2 engagements, focused on access management, change management, and logical security.
- Cut audit cycle times 40% by driving adoption of a new audit platform and running team enablement sessions.
- Served as primary point of contact for client control owners through evidence collection, keeping engagements on schedule.
- Flagged and consolidated redundant controls across SOC 1/2, HIPAA, and ISO 27001 engagements to reduce testing overhead.
Education
Jul 2026 - Present
Master of Science, Cybersecurity and Information Assurance
Western Governors University · Remote
- Expected graduation July 2027.
Aug 2020 - Dec 2022
Bachelor of Science in Business Administration, Accounting
The Ohio State University · Columbus, Ohio
Skills
Audit & Assurance
- SOC 1 & SOC 2 examinationsLead end-to-end Type I and Type II examinations across 10+ clients a year.
- Control walkthroughsScope and validate evidence with engineering, IT operations, internal audit, and HR stakeholders.
- Evidence collectionPrimary point of contact for client control owners, keeping engagements on schedule.
- Deficiency identification & remediationDocument control deficiencies, then partner with control owners to build and execute remediation plans.
- Readiness for first-time examinationsGuide clients through an initial SOC 2, identifying where controls operate today and where coverage is thin.
- Workpaper review & mentoringMentor associate auditors on AICPA guidance and audit methodology, reviewing their workpapers and testing approach.
Frameworks & Standards
- SOC 2 (Type I / II)Map existing control sets to the Trust Services Criteria.
- SOC 1 (Type I / II)Controls at a service organization relevant to user entities' financial reporting.
- ISO 27001
- HIPAA
- Control rationalizationMap one control set across SOC 2, ISO 27001, and HIPAA to reduce overlapping tests and repeat findings.
GRC Competencies
- Control design & testingAssess whether a control is designed to meet its objective, then test operating effectiveness.
- IT general controls (ITGC)
- Access managementA primary testing focus across 15+ SOC 1 and SOC 2 engagements, alongside change management and logical security.
- Change management
- Logical security
- Risk assessment
- Third-party / vendor risk
Audit Process & Delivery
- Sampling designRedesigned the sampling approach for a large enterprise client, cutting audit preparation time 25% in six months.
- Audit tooling adoptionDrove adoption of a new audit platform and ran team enablement sessions, cutting cycle times 40%.
- Stakeholder communicationTranslate control findings into remediation owners can act on, across technical and non-technical teams.
Cloud & Security
- AWSAWS Certified Cloud Practitioner.
- Cloud securityCertificate of Cloud Security Knowledge (CCSK v4), Cloud Security Alliance.
- Security domainsAssociate of ISC2, CISSP exam passed.
Contact
See also certifications and projects.