Alana Avis, CISA
Strategic Leader in Cybersecurity & IT Governance Risk & Compliance | FinTech & Banking Specialist
22 yrs experience · Atlanta, GA · <10 hrs/week
About
Critical thinking technology professional with over 20 years of success in IT Governance, Risk, and Compliance (GRC), IT Audit, and Cybersecurity. Proven track record of operationalizing IT GRC frameworks, transforming technology and security postures through strategic risk management, compliance strategies, and operational efficiencies. Adept at designing and executing IT risk management programs, establishing internal control environments, and driving change through cross-functional partnerships and leadership. Known for building new solutions, leading large-scale Cybersecurity solutions, and enhancing organizational risk resilience, contributing to business growth. Experienced in FinTech, banking, and global risk management.
Experience
- Sr. IT Governance, Risk & Compliance Consultant | Advisory · RGP2019-03-01 –
Helping clients operationalize and transform their Cybersecurity and IT GRC programs. Projects include, but not limited to IT audit, Cybersecurity program development, IT SOX governance, Application security testing, IT GRC oversight for enterprise-wide implementations, AI Risk Management.
- IT Governance, Risk & Compliance Consultant · Avis Management Consulting LLC2017-05-01 – 2019-03-01
Helping clients operationalize their IT GRC programs. Guided clients in establishing and executing IT SOX testing programs, SOC2 oversight, PCI Compliance, IT audit testing and issues management, and executive GRC reporting, enhancing compliance posture and risk mitigation.
- SVP, Cybersecurity & IT Governance Risk & Compliance (Global) · U.S. Bank2014-08-01 – 2017-05-01
Part of the Payments Services Chief Risk Office (2nd line of defense) led a global team of 35 risk officers. Implemented IT Risk Assessment Program. Matured IT Governance, IT Audit & Exam, and IT Control Testing programs in line with audit and regulatory expectations, business objectives and risk tolerance. Member of the Payment Services Risk Committee and varied cross functional leadership committees (Operational risk, Cybersecurity, Program management, Infrastructure, CIO/CISO). Established varied IT GRC, KI program and continuous control monitoring.
- VP, IT Governance & Compliance (Global) · U.S. Bank2012-02-01 – 2014-08-01
Part of the Payments Services Chief Risk Office (2nd line of defense) led a global team of 20 risk officers. Responsible for IT Audit & Exams, IT Control Testing & Issue Management, and IT Governance. Performed credible challenge of first line programs, driving oversight, governance, risk management, and reporting to senior management, risk committees and the Board of Directors. Lead varied cybersecurity program implementations. Established IT risk management program adopted by the Enterprise.
- Sr. Director, IT Compliance (Global) · U.S. Bank2009-10-01 – 2012-02-01
Part of the Payments Services Chief Risk Office (2nd line of defense) led a team of 10 risk officers responsible for overseeing global IT compliance activities, executing the annual GLBA program, facilitating IT audits and exams. Collaborated with organizational units and provided reporting to Senior Management and varied Risk Committees.
- Senior IT Audit Manager · Control Solutions International2004-08-01 – 2009-10-01
Managed portfolio of IT audit engagements for Fortune 500 companies, generating $3 million in revenue with zero client charge backs. Engagements included but not limited to, General Computer Controls reviews, Sarbanes-Oxley Section 404, PCI DSS, and FFIEC projects. Documenting and testing IT controls, Development and implementation of cost-effective remediation plans, Information Security policies and procedures compliance reviews, Business process analysis, design and optimization.
- Senior IT Project Manager · Web.com2001-02-01 – 2004-08-01
Managed complex global IT project and programs on time and in budget, successfully achieving programs objectives.
- Senior IT Project Manager · Web.com2001-02-01 – 2004-08-01
Managed complex global IT project and programs on time and in budget, successfully achieving programs objectives.
- IT Product Manager · Insurance Billing Company1998-01-01 – 1999-01-01
Managed IT product lifecycle, responsible for product strategy and development across various platforms.
- Trainer Administrator · Perot Systems1999-01-01 – 2001-01-01
Oversaw training program development and implementation, ensuring alignment with business objectives.
- Senior IT Project Manager · Web.com2001-02-01 – 2004-08-01
Managed complex global IT project and programs on time and in budget, successfully achieving programs objectives.
Education
- Concordia UniversityBachelor of Commerce, Management Information Systems, Minor: Accounting
Similar talent on Pangea
Hire Alana through Pangea
Describe your project to the Pangea agent — see if Alana is a fit, with transparent pricing and interviews booked straight onto your calendar. No contact details change hands until you hire.
See if Alana is a fit