Experience in control rationalization, optimization, effectiveness or efficiency.
I have more than 1 year of experience rationalizing controls
and measuring controls effectiveness and efficiency. I gained this experience
through working as an auditor for BCD Travel where I measured the effectiveness
of a quality management system of BCD Travel, in compliance with ISO 9001:2008,
an international quality system standard to begin my career. Again, I have more
than 1 year of experience rationalizing and optimizing controls for Wells
Fargo.
I will expand on my Wells Fargo Experience here. While working for the bank, I
was part of a project that measured the health and effectiveness of a specific
group of applications. As a part of our SDLC control, this group had to show
that they were on a certified Continuous Integration pipeline. Show that the
application performed automated unit testing during build. Show that the
application utilized logging enabled by Splunk. Show that static scans were
being performed on the app. Show that visibility was enabled using application
monitoring.
Part of my job was to not only report on the effectiveness of applications to
successfully meet these goals but, on the other side I was part of a team that
rationalized the effectiveness of existing tools to meet those goals set for us
by management. For example, we were constantly looking for better ways to
automate the SDLC process using better DevOps tools.
For example, we were looking for a way to integrate our Vulnerability
management system into Service Now because we were struggling to get RFCs for
vulnerabilities in Threadfix on the same page with Change Management. So, we
decided to ditch Threadfix and merge vulnerabilities management into
ServiceNow, which streamlined the process into one single pane of
glass.
Comments
Post a Comment