Anjum User
@anjumuser1
CISA-certified IT audit and risk leader with 9+ years driving SOX, GRC, and cybersecurity assurance worldwide.
What I'm looking for
I’m a CISA-certified IT Audit & Risk Manager with 9+ years of experience leading 27+ global IT Audit, SOX, Cybersecurity, SAP Security, and GRC engagements across North America, Europe, APAC, LATAM, and India. I build trusted relationships with executive leadership, lead risk-based decision-making, and strengthen security, compliance, and business resilience through practical governance.
In my current role, I lead end-to-end global IT Audit/SOX/cybersecurity programs, managing teams of up to nine auditors while ensuring 100% on-time delivery and zero delivery escalations. I standardize audit methodologies, optimize SOX scope, and improve control maturity by aligning governance frameworks to NIST, ISO 27001, PCI DSS, SOC, IAM/PAM, Data Privacy, and Cloud Security—partnering with cross-functional and SAP teams across the control lifecycle.
Experience
Work history, roles, and key accomplishments
Senior Analyst, Internal Audit
Whirlpool Corporation
Mar 2023 - Present (3 years 4 months)
Led global IT Audit, SOX, and advisory engagements, managing audit planning, execution, reporting, and stakeholder management across multiple regions. Directed ITGC, ITAC, SAP Security, and cybersecurity audits and helped standardize audit methodologies to improve audit quality and consistency.
Solution Advisor - Internal Controls
Jul 2021 - Mar 2023 (1 year 8 months)
Delivered IT audit engagements aligned with SOX 404, SOC 1/SOC 2 (SSAE 18), and ICFR, managing end-to-end delivery and reporting. Conducted ITGC, ITAC, SAP Security, and ERP controls reviews and recommended control optimization and remediation strategies.
Executed IT audits including SOX and ISO 27001 control testing and supported remediation planning to strengthen the control environment. Performed application security, user access reviews, and Segregation of Duties (SoD) assessments and prepared audit workpapers and reports.
Performed IT General Controls (ITGC), SOX, and SOC 2 control testing across information systems and collaborated with process owners to evaluate control design and operating effectiveness.
Managed end-to-end IT audit engagements and performed ITGC, SOX, SOC 2, ITAC, and infrastructure audits to evaluate control design and operating effectiveness. Used Excel and SQL for data analysis to identify trends, anomalies, and control gaps and documented risk-based audit procedures.
Security Analyst - Vulnerability Mgmt
May 2017 - Aug 2018 (1 year 3 months)
Conducted vulnerability assessments using Rapid7 Nexpose and supported configuration compliance scanning with CCM to identify non-compliant systems. Performed ICFR and ITGC assessments, built dashboards and compliance reports, and automated weekly reporting using Excel macros to improve risk remediation visibility.
Education
Degrees, certifications, and relevant coursework
Amity University
Bachelor of Technology (B.Tech), Computer Science and Engineering
2012 - 2016
Grade: 89.80
Completed a B.Tech in Computer Science and Engineering at Amity University from 2012 to 2016, achieving a score of 89.80.
Tech stack
Software and tools used professionally
Availability
Location
Authorized to work in
Social media
Job categories
Skills
Interested in hiring Anjum?
You can contact Anjum and 90k+ other talented remote workers on Himalayas.
Message AnjumGet matched with your dream remote job
Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!
